Privacy Policy for NaanUp

Effective Date: 29 June 2025
Last reviewed: 29 June 2025

Introduction & Scope

Welcome to NaanUp (“NaanUp,” “we,” “us,” or “our”). This Privacy Policy explains—in admittedly meticulous detail—the manner in which personal information is collected, processed, stored, and otherwise handled when you interact with our website located at https://naanup.com (the “Site”) or any related services, features, or content (collectively, the “Services”).

Types of Information We Collect to Only Serve Our Customers

CategoryTypical ExamplesWhy We Need It
Identity & Contact DataName, email address, phone number, delivery addressTo confirm orders, arrange deliveries, and respond to inquiries
Order DetailsMeal selections, subscription preferences, delivery instructionsTo prepare the correct food on the correct day
Technical & Usage DataIP address, browser type, pages visited, cookie identifiersTo maintain site security, improve performance, and understand what dishes people keep drooling over
Voluntary CommunicationsMessages in our contact form, reviews, survey responsesTo provide customer support and improve services

How We Collect It

  1. Directly from you – when you enter information into a form, place an order, or send us an email.
  2. Automatically – via cookies and similar technologies that log basic, non-identifying usage statistics.
  3. From trusted partners – payment processors (e.g., Stripe) confirm your transaction status so we can start cooking.

How We Use Your Information

We process personal data only when we have a lawful basis, typically one or more of the following:

Lawful BasisPractical Example
Contractual necessityFulfilling your Tiffin subscription or single-meal order
Legitimate interestsPreventing fraud, improving recipe variety, keeping our website functional
ConsentSending you marketing offers only if you opt-in
Legal obligationRetaining certain transaction records for tax purposes

Embedded & Third-Party Content

Our Site may display embedded Instagram photos, Google Maps, or other third-party widgets. Such content behaves exactly as though you visited those sites directly, which means they might collect their own cookies or metrics. We encourage you to review their respective policies.

Cookies & Similar Technologies

Essential cookies enable the shopping cart and checkout.

Analytics cookies help us see which menu items get the most clicks.

Preference cookies remember that you love extra-spicy butter chicken (so we don’t keep asking).

You may disable non-essential cookies in your browser, but the Site may not taste quite as fresh (read: some features might break).

How long we retain your data

Data TypeRetention Period
Contact-form submissionsUp to 12 months after resolution of your request
Order & billing records7 years, per U.S. tax regulations
Cookie identifiersVary by type (max 14 months for analytics)
Marketing opt-in recordsUntil you unsubscribe or request deletion

What rights you have over your data

Depending on where you live, you may have the right to:

  • Access – Ask what data we hold about you.
  • Rectify – Correct inaccurate or incomplete data.
  • Erase – Request deletion of personal data we no longer need.
  • Restrict or object – Limit certain processing.
  • Portability – Receive your data in a structured format.

To exercise any right, email contact@naanup.com with your request. We’ll respond within 30 days (often sooner) and never charge an unreasonable fee.

Data Security

We take reasonable technical and organizational measures—TLS encryption, secure firewalls, principle-of-least-privilege access controls—to protect your information from unauthorized access, alteration, or destruction. No internet transmission is 100 % foolproof, but we aim to be as close as a hot naan to a tandoor wall.

Where We Store and Share Data

Data may be stored on secure servers in the United States and processed by trustworthy partners such as:

  • Stripe, Inc. – payment processing
  • Google Workspace – business email
  • Firebase / Firestore – order database (if you subscribe)

Each partner is vetted for GDPR-style safeguards or equivalent contractual protections.

Changes to This Policy

We may update this Privacy Policy to reflect new legal, technical, or culinary developments. Any changes will appear on this page with a revised “Effective Date.” Continued use of the Site after changes constitutes acceptance.

Thanks for reading to the end! Now reward yourself with a mango lassi, you’ve earned it.