Privacy Notice
[LIKE THIS] need real details. Do not rely on it as a compliant privacy policy until reviewed by counsel. Last updated: [DATE].This notice explains how Acajaiba Republic (“we”, “us”) collects and uses your personal data when you use our café membership, JAIBA wallet, ordering, and events services. We are committed to handling your data responsibly and in line with India’s Digital Personal Data Protection Act, 2023 (DPDP Act).
1. Who we are
The Data Fiduciary responsible for your personal data is [LEGAL ENTITY NAME], [REGISTERED ADDRESS], GSTIN [GSTIN]. For any privacy question or request, contact our Grievance Officer (see §10).
2. What personal data we collect
- Your phone number (used to sign in) and, if you provide it, your name and email.
- Your order history and the items you buy.
- Your JAIBA wallet activity (top-ups, spends, refunds — a transaction ledger).
- Membership tier and event tickets / check-ins.
- Basic device and log data (e.g. request logs) needed to run and secure the service.
We do not knowingly collect more than we need to provide these services.
3. Why we use it, and our lawful basis
We use your data to:
- Create and manage your membership and Republic passport.
- Process your orders, payments, wallet top-ups, and event tickets.
- Send you service notifications (e.g. “your order is ready”, low-balance alerts).
- Keep records required by tax and financial law (GST invoices, wallet ledger).
- Detect and prevent fraud and abuse, and keep the service secure.
We rely on your consent (given at sign-up) and, where applicable, on our legal obligations (e.g. tax record-keeping) as the basis for processing.
4. Who we share it with
We share the minimum necessary with service providers who help us operate:
- Our payment gateway [PAYMENT PROVIDER] to process payments.
- Our SMS provider [SMS PROVIDER] to send one-time codes and alerts.
- Our hosting and storage providers [HOSTING PROVIDERS].
We do not sell your personal data. [Confirm any other recipients / transfers.]
5. How long we keep it
We keep your data only as long as needed for the purposes above. Some records — notably your wallet ledger and GST invoices — must be retained for the period required by tax and financial law, even if you ask us to delete your account; in that case we retain those records in a reduced, pseudonymised form. See our internal data-retention policy for periods. [Confirm periods with CA.]
6. Your rights
Subject to the DPDP Act, you can:
- Access and get a copy of your data (in-app “Export my data”).
- Ask us to correct inaccurate data.
- Ask us to erase your data (in-app “Delete my data”) — subject to the retention exception in §5.
- Withdraw consent, and raise a grievance with our Grievance Officer.
We aim to respond within the timelines required by law. [Confirm SLA.]
7. How we protect your data
We use industry-standard safeguards: one-time-code sign-in (no passwords to leak), encrypted transport, hashed tokens, least-privilege access, and audit logging of sensitive actions. No system is perfectly secure, but we work to protect your data.
8. Children
Our services are intended for adults. [State the minimum age and how you handle children’s data / verifiable parental consent per DPDP.]
9. Changes to this notice
We may update this notice. We’ll post the new version here and update the “last updated” date; significant changes will be notified in-app.
10. Contact & Grievance Officer
Grievance Officer: [NAME], [EMAIL], [PHONE]. You may also contact the Data Protection Board of India if your grievance is not resolved.