We updated our company contact details (registered name, address, and a new support email at contact@infiworks.co.in) and clarified, in plain language, how your data is handled and protected. What we collect, how we use it, and who can see it are unchanged.
CloudMess (“we”, “us”, “our”) is built and operated by InfiWorks Technologies Private Limited, a company incorporated in India (registered office in Beed, Maharashtra). This Privacy Policy explains what personal data we collect when you use the CloudMess apps (Owner and Customer) and how we handle it. It is written to satisfy India’s Digital Personal Data Protection Act, 2023 (DPDPA) and is the public-facing summary of our internal compliance plan.
If anything below is unclear, or if you want to exercise any of the rights described in §6, please email the contact in §9.
Collection
1. What we collect
We collect only what we need to run a mess subscription service.
| Category | What | Why we need it |
|---|---|---|
| Identity | Full name, gender | To assign your plan and let the owner identify you |
| Contact | Indian phone number (+91) | To sign you in via a login code, and to identify your account for delivery / payment notifications |
| Sign-in credentials (mess owners) | Email address and password | Mess owners sign in with an email address and password instead of a phone code. The password is never stored in readable form — see §8 |
| Membership | Plan type, diet preference, start/end dates, monthly fee | To deliver the meal service you subscribed to |
| Meal activity | QR scan logs, daily survey responses, tiffin dispatch records | So your owner knows how many meals to prepare and can credit holidays correctly |
| Payments | Amounts paid, UPI transaction references, dues | To produce receipts and resolve payment disputes |
| Owner’s notes about a member | Free-text notes a mess owner writes on a member’s record | So the owner can record service details such as an allergy, a preference, or a payment arrangement. Your mess owner alone can see these — see §3 |
| Mess notices (owners only) | Announcements a mess owner writes for their members | To show mess announcements inside the member app |
| Mess profile (owners only) | Mess name, mess code, city, address, capacity, mess photo, public contact number, the mess’s UPI ID, and the service settings the owner chooses (such as veg-only, tiffin and pricing options) | To present the business to members, to let members pay the mess by UPI, and to run the features the owner has turned on |
| Device | Push-notification token, app build version | To deliver push notifications and diagnose crashes |
We do not collect:
- Any usage or behavioural analytics. We do not currently run analytics of any kind — no screen-view tracking, no feature-usage events, no profiling. If we ever add it, we will update this policy and ask for your consent first.
- Your bank account number, or debit / credit card details. From members we store only the transaction reference you paste in for a cash or UPI payment — never your own UPI ID. (A mess owner does give us the mess’s UPI ID, so that members can pay the mess by UPI.)
- Your location, contacts, microphone, or any other device sensor data beyond the camera (used only when you actively open the scanner). We do not read your photo library — the only image we hold is a mess photo a mess owner chooses to upload.
- Any data about your family, employer, food preferences outside the mess, or anything you have not explicitly entered into the app
Use
2. How we use it
We process your data for these purposes only:
- 1Run your account — sign you in (members with a one-time code, mess owners with an email address and password), profile, settings, language and theme preferences.
- 2Deliver the service — record your meals, run the daily intent survey, dispatch your tiffin, track your dues.
- 3Communicate with you — push notifications, in-app messages, and SMS, used only to send your login code.
- 4Protect the service — detect fraud, recover from outages, audit sensitive actions for dispute resolution.
- 5Comply with the law — keep financial records for the periods required by Indian tax and accounting rules.
We do not use your data for advertising. We do not sell your data to anyone, ever.
Lawful basis (DPDPA §4)
The DPDPA allows us to process your data on only two grounds: your consent (§6), or one of nine narrowly defined legitimate uses (§7) — none of which cover ordinary service delivery. So for CloudMess, your consent is the basis for everything below.
| Activity | Basis |
|---|---|
| Account creation, OTP login | Your consent (you tap I Agree & Continue before profile setup) |
| Mess-owner sign-in (email and password) | Your consent (you create the account and accept the Terms) |
| Meal scans, surveys, tiffin dispatch, dues tracking | Your consent, given at sign-up |
| Payment records | Your consent. We then keep the record for 8 years because Indian tax and accounting law requires us to |
| Push notifications (non-essential) | Your consent (manage in your device’s notification settings) |
| Audit logs | Your consent. We keep them to resolve disputes and protect the integrity of payment records |
Access
3. Who can see what
CloudMess is multi-tenant: each mess sees only its own data. Within a mess:
- Your owner can see your name, phone, plan details, scan history, survey responses, tiffin dispatch records, payment records, and any notes they have written about you — for the mess you are currently a member of.
- You can see your own data. You cannot see other members’ personal data, and you cannot see the notes your owner writes about you inside their own app. If you want to know what those notes say, email the contact in §9 and we will tell you.
- Owners of other messes cannot see your data.
- A small number of authorised people at InfiWorks can reach mess and member records where it is genuinely needed to run the service — to investigate a fault, answer a support request, meet a legal obligation, or suspend a mess that breaks our Terms. This includes resetting a mess owner’s password at their request. Every one of these actions, including simply viewing a mess, is written to a permanent record that cannot be edited or deleted by anyone.
Changes to your records are validated and recorded on our servers, not on your phone, so we can check and audit every one of them.
When you switch from one mess to another (Settings → Switch mess), your old data stays in the database for the old owner’s records and tax compliance, but is hidden from the new mess and from you. We explicitly enforce this through server-side access controls.
Where it lives
4. Where your data lives
| Service | What we send them | Where they are |
|---|---|---|
| Cloud hosting & database provider | All app data | India (Mumbai) |
| Push-notification provider | Your push-notification token | — |
| SMS provider | Your phone number, to send login codes | India |
| Crash-diagnostics provider | Anonymised crash reports (stack traces, device model) | — |
These providers process data on our behalf, under our instructions, and are not permitted to use it for their own purposes.
Your data stays in India (Mumbai region) for the primary database. Notification and crash-reporting services use the closest available region to minimise transit time.
Retention
5. How long we keep it
| Data | While account is active | After you delete your account |
|---|---|---|
| Name, phone, gender | Until you delete | Anonymised after 30 days |
| Meal scans, surveys | Active membership + 1 year | Linked customer record anonymised; aggregate stats kept |
| Tiffin dispatch | Same as meal scans | Same |
| Payment records | Indefinitely while account active | Retained for 8 years (Indian tax law), name redacted |
| Audit logs | Indefinitely | Retained for 8 years (legal obligation), then anonymised |
| OTP requests | 24 hours, then auto-deleted | n/a |
| Push-notification tokens | Until the token refreshes or you delete | Removed immediately on deletion |
| Mess-owner email address and password | While the mess account is open | Deleted when the account is closed |
| Mess profile, mess notices, and the mess’s UPI ID | While the mess account is open | Deleted when the account is closed |
| A mess owner’s notes about a member | Until the note or the member’s record is removed | Anonymised with the member’s record |
| Mess-owner subscription payments (kept outside the app, in our own accounts) | While you are a subscriber | Retained for 8 years (Indian tax law) |
We never keep data longer than needed for a stated purpose.
Your rights
6. Your rights under DPDPA
You can:
- See what we have on you — email the contact below and ask for a copy of your data. We will respond within 30 days.
- Correct anything wrong — most fields you can edit directly in Settings. For fields you cannot edit (your diet type, for example, which is owner-controlled), ask your mess owner to update it. If they refuse and you believe the value is wrong, email us.
- Delete your account — email the contact in §9
and we will close your account and anonymise your records within 30 days.
- If you are a member, tell us the mobile number you sign in with.
- If you are a mess owner, write from the email address you sign in with. Closing a mess-owner account also closes the mess, so your members can no longer use it. We do not wipe the mess’s records: your members’ payment records and our audit log are kept for the periods in §5 because Indian law requires it, and everything else is anonymised. We will tell you exactly what will be kept, and what your members will see, before we act on your request.
- Withdraw consent — to manage push notifications, use your device’s notification settings for CloudMess; essential messages (such as login codes and payment alerts) and your in-app inbox are unaffected. For account-level consent: ask us to delete your account (above). Withdrawal does not affect any processing we did before you withdrew.
- Object to processing — contact us. We will explain what your options are.
- Nominate someone to act for you — the DPDPA lets you name another person who can exercise these rights on your behalf if you die or become unable to act yourself. Email the contact below with their name and phone number and we will record it.
- Raise a grievance — email the contact below. We will acknowledge within 7 days and respond within 30 days.
- Complain to the Data Protection Board of India — if we have not resolved your concern to your satisfaction.
Children
7. Children
CloudMess is intended for users aged 18 and above, and we ask you to confirm that you are 18 or older before you finish signing up.
Under the DPDPA we may not process a child’s personal data without verifiable consent from their parent or guardian, and we may not use a child’s data for behavioural tracking or targeted advertising. We do not run targeted advertising at all.
If you are under 18, please do not create an account. A parent or guardian using the app “on your behalf” does not fix this — the data in the account would still be a child’s. Ask your mess owner to handle your membership without an app account instead.
If you believe we hold data about someone under 18, contact us and we will delete it.
Security
8. Security
- All traffic between the apps and our servers is encrypted in transit.
- Server-side access controls prevent any user from reading data that does not belong to them. They are enforced on our servers and cannot be bypassed by a tampered app.
- Your login codes are never stored in a readable form and never leave our servers — the apps never see them.
- Mess-owner passwords are never stored in readable form. Your password is held only as a cryptographic hash by our authentication provider — we cannot read it or recover it, and the only thing we can do is reset it to a new one at your request.
- Sessions are cryptographically signed and refreshed each time you sign in.
- We log every sensitive action (payments, member changes, mess code rotation, mess switches) to an append-only audit log.
If we ever discover a breach affecting your personal data, two separate Indian laws apply and we will act on both:
- You — we will tell you without delay, in plain language: what happened, which of your data was involved, what we have done about it, and what you can do. We will not wait until we have the complete picture before telling you.
- The Data Protection Board of India — an initial report without delay, followed by a detailed report within 72 hours of us becoming aware of the breach, as the DPDPA requires.
- CERT-In, India’s national cyber-incident agency — within 6 hours of us noticing the incident, as the Information Technology Act requires.
Contact
9. Contact
- Operator
- InfiWorks Technologies Private Limited
- CIN
- U62090ME2026PTC476551
- Data Protection contact
- Grievance Officer
- contact@infiworks.co.in
- Phone
- +91 74834 01547
- Registered office
- At 438, Shidod, Shidode, Bid, Beed, Beed, Beed - 431122, Maharashtra
CloudMess is not a Significant Data Fiduciary under DPDPA §10, so we are not required to appoint a formal Data Protection Officer. We are required to publish someone who can answer questions about how we handle your data, and that is the contact above. If our scale or the law changes, we will appoint a dedicated officer and update this policy.
Changes
10. Changes to this policy
If we make material changes to how we process data, we will update the “Effective date” and “Last updated” fields at the top of this document, and summarise what changed in a note below them.
The current version is always readable inside the app under Settings → Privacy Policy, and on the web at cloudmess.in/privacy.
Where the DPDPA requires it, we will ask you to re-confirm your consent before a change applies to you.
This policy is binding on CloudMess. If it conflicts with anything we have said elsewhere (marketing, support emails), this policy wins.