Legal
Privacy Policy
How GreenBaskeet collects, uses, stores and erases your personal data — and the rights you hold over it under India's Digital Personal Data Protection Act, 2023.
Last updated
01Who this policy is from
GreenBaskeet is a quick-commerce grocery service operated from Nagpur, Maharashtra, India. This policy covers the GreenBaskeet mobile app, the storefront at greenbaskeet.com, and this operations console.
Under the DPDP Act, 2023 we are the Data Fiduciary — we decide why and how your personal data is processed. You are the Data Principal. Where this policy says “we”, it means GreenBaskeet.
The software is built and licensed by Lacspace Corporation Pvt. Ltd., which processes data only on our instructions as a Data Processor. See the Software Licence.
Registered office address — to be confirmed
02What we collect
Only what an order actually requires. Each category below is tied to a purpose in §3.
| Category | What it is | Source |
|---|---|---|
| Identity | Name, mobile number, email address | You, at sign-up |
| Delivery | Addresses, landmarks, pincode, delivery instructions, map coordinates you pin | You, when saving an address |
| Order | Items, quantities, prices, bill breakdown, coupons, tips, ratings, cancellations | Generated when you order |
| Payment | Method used, transaction reference and status. We never receive or store card numbers, UPI PINs or bank credentials | Your payment provider |
| Location | Approximate or precise device location, only while the app is open and only if you permit it | Your device, with permission |
| Device and usage | Device model, OS version, app version, IP address, crash reports, pages viewed | Automatically |
| Support | Messages, screenshots and call notes you send us about an order | You, when you contact us |
What we do not collect
We do not collect biometric data, government identity numbers, caste, religion, health records or financial account credentials. We do not buy personal data from third parties, and we do not sell yours to anyone.03Why we collect it
- To deliver your order. Routing it to the nearest dark store, giving the rider an address, and telling you when it will arrive.
- To take payment and issue a bill. Including refunds, and the invoice records tax law requires us to keep.
- To support you. A missing item or a wrong charge cannot be investigated without the order it belongs to.
- To keep the service safe. Detecting fraudulent orders, coupon abuse and account takeover.
- To meet legal obligations. Food safety, consumer protection and tax record-keeping.
- To improve the service. Aggregated, non-identifying analysis of what is ordered and where delivery is slow.
- To send offers — only if you have opted in, and you can opt out at any time without affecting anything else.
04Consent, and withdrawing it
We ask for consent before processing your data, in clear language, for a stated purpose. Consent for marketing is separate from consent to fulfil an order — declining the first never blocks the second.
You may withdraw consent at any time from Account → Privacy in the app, or by writing to privacy@greenbaskeet.com. Withdrawal applies going forward. It does not undo processing already carried out lawfully, and it does not erase records we are legally required to retain (§7).
06Where it is stored
Your data is stored on servers located in India, in the Mumbai (ap-south-1) region. Databases are logically isolated per application and uploaded files are held under a dedicated storage prefix.
If we ever need to transfer data outside India we will do so only to jurisdictions permitted under the DPDP Act, and only with protections at least equal to those described here.
07How long we keep it
Personal data is erased once its purpose is served, unless a law requires us to keep it longer.
| Data | Kept for | Why |
|---|---|---|
| Account profile | While your account is open, plus 90 days | So an account can be restored if closed by mistake |
| Order and invoice records | 8 financial years | Tax and accounting law |
| Delivery addresses | Until you delete them | They are yours to manage |
| Payment references | 8 financial years | Dispute resolution and audit |
| Support conversations | 3 years from closure | Complaint history and recurring-issue analysis |
| Device and usage logs | 180 days | Security investigation and debugging |
| One-time codes | 5 minutes | They expire automatically |
| Marketing consent records | While consent stands, plus 3 years | To evidence that consent was given |
08Your rights
The DPDP Act gives you the following rights. All are free, and all are honoured within 30 days.
- Access. A summary of the personal data we hold about you and who it has been shared with.
- Correction. Have inaccurate or incomplete data fixed or completed.
- Erasure. Have data deleted once its purpose is served, except where retention is legally required.
- Withdraw consent. As described in §4.
- Nominate. Name someone to exercise these rights on your behalf if you die or become incapacitated.
- Grievance redress. Raise a complaint with us first (§13), and escalate to the Data Protection Board of India if unresolved.
To exercise any of these, write to privacy@greenbaskeet.com from the email or phone number on your account, so that we can verify it is you.
09How we protect it
- Encryption in transit (TLS 1.2+) on every connection, and encryption at rest for databases and file storage.
- Passwords are hashed with bcrypt and never stored, logged or returned in a readable form. Nobody at GreenBaskeet can read yours, which is why a reset sets a new password rather than recovering the old one.
- Access is role-based and least-privilege: staff see only what their role requires, and vendors and riders are scoped to a single store.
- Every privileged change is written to an append-only audit trail recording who did it, what changed and when.
- Session tokens are short-lived and rotate; a reused token revokes the entire session family.
- Uploads go directly to storage under time-limited signed URLs, so files never transit our application servers.
No system is perfectly secure. If a breach is likely to affect you, we will notify you and the Data Protection Board of India as the DPDP Act requires.
10Children
GreenBaskeet is not intended for anyone under 18. We do not knowingly collect data from children, and we do not profile children or direct advertising at them — both are prohibited under §9 of the DPDP Act. If you believe a child has given us data, write to privacy@greenbaskeet.com and we will delete it.
12Changes to this policy
When this policy changes we update the date at the top. If a change materially affects how we use your data, we will tell you in the app or by email before it takes effect, and where the law requires it we will ask for fresh consent.
13Grievance redress
If you are unhappy with how your data has been handled, contact our Grievance Officer. We acknowledge within 48 hours and resolve within 30 days, as required by the DPDP Act, 2023 and the Consumer Protection (E-Commerce) Rules, 2020.
Grievance Officer
- Privacy queries
- privacy@greenbaskeet.com
- Postal address
- Registered office — to be confirmed
- Response time
- Acknowledged in 48 hours · resolved in 30 days
- Escalation
- Data Protection Board of India
This policy is governed by the laws of India. The statutes it operates under are DPDP Act 2023, IT Act 2000, Copyright Act 1957, CP Act 2019, FSS Act 2006, LM Act 2009.