CloudMess Your mess. Simple. Your data

CloudMess Privacy Policy

What changed on 2026-09-19

We updated our company contact details (registered name, address, and a new support email at contact@infiworks.co.in) and clarified, in plain language, how your data is handled and protected. What we collect, how we use it, and who can see it are unchanged.

CloudMess (“we”, “us”, “our”) is built and operated by InfiWorks Technologies Private Limited, a company incorporated in India (registered office in Beed, Maharashtra). This Privacy Policy explains what personal data we collect when you use the CloudMess apps (Owner and Customer) and how we handle it. It is written to satisfy India’s Digital Personal Data Protection Act, 2023 (DPDPA) and is the public-facing summary of our internal compliance plan.

If anything below is unclear, or if you want to exercise any of the rights described in §6, please email the contact in §9.


Collection

1. What we collect

We collect only what we need to run a mess subscription service.

CategoryWhatWhy we need it
IdentityFull name, genderTo assign your plan and let the owner identify you
ContactIndian phone number (+91)To sign you in via a login code, and to identify your account for delivery / payment notifications
Sign-in credentials (mess owners)Email address and passwordMess owners sign in with an email address and password instead of a phone code. The password is never stored in readable form — see §8
MembershipPlan type, diet preference, start/end dates, monthly feeTo deliver the meal service you subscribed to
Meal activityQR scan logs, daily survey responses, tiffin dispatch recordsSo your owner knows how many meals to prepare and can credit holidays correctly
PaymentsAmounts paid, UPI transaction references, duesTo produce receipts and resolve payment disputes
Owner’s notes about a memberFree-text notes a mess owner writes on a member’s recordSo the owner can record service details such as an allergy, a preference, or a payment arrangement. Your mess owner alone can see these — see §3
Mess notices (owners only)Announcements a mess owner writes for their membersTo show mess announcements inside the member app
Mess profile (owners only)Mess name, mess code, city, address, capacity, mess photo, public contact number, the mess’s UPI ID, and the service settings the owner chooses (such as veg-only, tiffin and pricing options)To present the business to members, to let members pay the mess by UPI, and to run the features the owner has turned on
DevicePush-notification token, app build versionTo deliver push notifications and diagnose crashes

We do not collect:


Use

2. How we use it

We process your data for these purposes only:

  1. 1Run your account — sign you in (members with a one-time code, mess owners with an email address and password), profile, settings, language and theme preferences.
  2. 2Deliver the service — record your meals, run the daily intent survey, dispatch your tiffin, track your dues.
  3. 3Communicate with you — push notifications, in-app messages, and SMS, used only to send your login code.
  4. 4Protect the service — detect fraud, recover from outages, audit sensitive actions for dispute resolution.
  5. 5Comply with the law — keep financial records for the periods required by Indian tax and accounting rules.

We do not use your data for advertising. We do not sell your data to anyone, ever.

Lawful basis (DPDPA §4)

The DPDPA allows us to process your data on only two grounds: your consent (§6), or one of nine narrowly defined legitimate uses (§7) — none of which cover ordinary service delivery. So for CloudMess, your consent is the basis for everything below.

ActivityBasis
Account creation, OTP loginYour consent (you tap I Agree & Continue before profile setup)
Mess-owner sign-in (email and password)Your consent (you create the account and accept the Terms)
Meal scans, surveys, tiffin dispatch, dues trackingYour consent, given at sign-up
Payment recordsYour consent. We then keep the record for 8 years because Indian tax and accounting law requires us to
Push notifications (non-essential)Your consent (manage in your device’s notification settings)
Audit logsYour consent. We keep them to resolve disputes and protect the integrity of payment records

Access

3. Who can see what

CloudMess is multi-tenant: each mess sees only its own data. Within a mess:

Changes to your records are validated and recorded on our servers, not on your phone, so we can check and audit every one of them.

When you switch from one mess to another (Settings → Switch mess), your old data stays in the database for the old owner’s records and tax compliance, but is hidden from the new mess and from you. We explicitly enforce this through server-side access controls.


Where it lives

4. Where your data lives

ServiceWhat we send themWhere they are
Cloud hosting & database providerAll app dataIndia (Mumbai)
Push-notification providerYour push-notification token
SMS providerYour phone number, to send login codesIndia
Crash-diagnostics providerAnonymised crash reports (stack traces, device model)

These providers process data on our behalf, under our instructions, and are not permitted to use it for their own purposes.

Your data stays in India (Mumbai region) for the primary database. Notification and crash-reporting services use the closest available region to minimise transit time.


Retention

5. How long we keep it

DataWhile account is activeAfter you delete your account
Name, phone, genderUntil you deleteAnonymised after 30 days
Meal scans, surveysActive membership + 1 yearLinked customer record anonymised; aggregate stats kept
Tiffin dispatchSame as meal scansSame
Payment recordsIndefinitely while account activeRetained for 8 years (Indian tax law), name redacted
Audit logsIndefinitelyRetained for 8 years (legal obligation), then anonymised
OTP requests24 hours, then auto-deletedn/a
Push-notification tokensUntil the token refreshes or you deleteRemoved immediately on deletion
Mess-owner email address and passwordWhile the mess account is openDeleted when the account is closed
Mess profile, mess notices, and the mess’s UPI IDWhile the mess account is openDeleted when the account is closed
A mess owner’s notes about a memberUntil the note or the member’s record is removedAnonymised with the member’s record
Mess-owner subscription payments (kept outside the app, in our own accounts)While you are a subscriberRetained for 8 years (Indian tax law)

We never keep data longer than needed for a stated purpose.


Your rights

6. Your rights under DPDPA

You can:


Children

7. Children

CloudMess is intended for users aged 18 and above, and we ask you to confirm that you are 18 or older before you finish signing up.

Under the DPDPA we may not process a child’s personal data without verifiable consent from their parent or guardian, and we may not use a child’s data for behavioural tracking or targeted advertising. We do not run targeted advertising at all.

If you are under 18, please do not create an account. A parent or guardian using the app “on your behalf” does not fix this — the data in the account would still be a child’s. Ask your mess owner to handle your membership without an app account instead.

If you believe we hold data about someone under 18, contact us and we will delete it.


Security

8. Security

If we ever discover a breach affecting your personal data, two separate Indian laws apply and we will act on both:


Contact

9. Contact

Operator
InfiWorks Technologies Private Limited
CIN
U62090ME2026PTC476551
Data Protection contact
Grievance Officer
Email
contact@infiworks.co.in
Phone
+91 74834 01547
Registered office
At 438, Shidod, Shidode, Bid, Beed, Beed, Beed - 431122, Maharashtra

CloudMess is not a Significant Data Fiduciary under DPDPA §10, so we are not required to appoint a formal Data Protection Officer. We are required to publish someone who can answer questions about how we handle your data, and that is the contact above. If our scale or the law changes, we will appoint a dedicated officer and update this policy.


Changes

10. Changes to this policy

If we make material changes to how we process data, we will update the “Effective date” and “Last updated” fields at the top of this document, and summarise what changed in a note below them.

The current version is always readable inside the app under Settings → Privacy Policy, and on the web at cloudmess.in/privacy.

Where the DPDPA requires it, we will ask you to re-confirm your consent before a change applies to you.

This policy is binding on CloudMess. If it conflicts with anything we have said elsewhere (marketing, support emails), this policy wins.