Privacy Policy

Last Updated: 5 June, 2026

Harkara AI Private Limited (“Harkara”, “we”, “us”, or “our”) respects your privacy and is committed to protecting your personal data.

This Privacy Policy describes what information we collect, how we use it, how we store and protect it, and your rights regarding your personal information. This policy applies to the Harkara mobile applications, website, and related services (collectively referred to as the “Platform”). By accessing or using the Platform, you agree to the practices described in this Privacy Policy.


1. Applicability

This Privacy Policy applies to:

  • Customers using the Harkara app
  • Restaurant partners using the partner dashboard
  • Visitors to our website
  • Individuals interacting with Harkara services

This policy does not apply to third parties, including restaurants listed on the platform. Restaurants may collect and process data under their own privacy policies.

2. Information We Collect

A. Information You Provide (Customers)

Account Information:

  • Full name
  • Email address (used for order receipts and communications)
  • Mobile number (used for OTP verification, login, and shared with restaurants for order coordination)

Order Information:

  • Order details, preferences, dietary requirements
  • Reservation details and pre-order selections

B. Information You Provide (Restaurant Partners)

Business Information:

  • Restaurant name and address
  • Email address
  • Phone number
  • FSSAI license number
  • GST registration number

Financial Information:

  • Bank account details (account number, IFSC code, account holder name)
  • PAN details for KYC verification

Note: Bank account details and KYC documents are collected and stored directly by our payment partner, Razorpay. Harkara does not store complete bank account details on its servers.

C. Automatically Collected Information

Device Information:

  • Device type, operating system, browser type
  • IP address and unique device identifiers

Usage Data:

  • Pages viewed, features used, search queries
  • Time spent on Platform, interaction patterns

D. Location Information

We collect precise location data when you grant permission. Location data is used to:

  • Show nearby restaurants based on your current location
  • Enable GPS-based arrival tracking for pickup and dine-in pre-orders
  • Trigger restaurant food preparation based on your estimated arrival time and distance

You may disable location permissions through your device settings. Disabling location will limit certain features including nearby restaurant discovery and arrival-based preparation timing.

E. Information Generated by AI

When restaurants add or update menu items, we use Google Gemini API to generate estimated nutritional information including calories, protein, carbohydrates, fiber, and fat content. This information is AI-generated and should be treated as an estimate only.

F. QR Code Ordering (Dine-In)

When you place orders via restaurant QR codes:

  • Name and email address are collected
  • Phone number is collected for OTP verification
  • Order details are shared with the restaurant

3. Cookies and Tracking Technologies

Harkara may use cookies, analytics tools, and tracking technologies to improve user experience, analyze platform performance, and personalize content. Users may disable cookies through their browser settings.

4. How We Use Your Information

We use your information to:

  • Provide Core Services: Create and manage accounts, enable restaurant discovery, process reservations and orders, and display relevant restaurant listings.
  • Platform Operations: Maintain platform functionality, diagnose technical issues, and monitor performance.
  • Personalization: Recommend restaurants, customize search results, and improve dining recommendations.
  • Communication: Send confirmations, service updates, and respond to support requests.
  • Marketing (Optional): Send promotional communications if you consent. You may opt out at any time.
  • Security and Fraud Prevention: Detect suspicious activity, prevent fraud, and protect platform security.

5. Ingredient Transparency Data

Restaurant partners disclose operational information such as ingredient sourcing, cooking oils, kitchen practices, and preparation methods directly. Harkara does not independently verify these disclosures unless explicitly stated.

6. Sharing of Information

We share your information in the following circumstances:

A. With Restaurant Partners

When you place an order or make a reservation, we share:

  • Your name
  • Your phone number
  • Order details and special requests

B. With Payment Processors (Razorpay)

  • Transaction details for payment processing
  • Restaurant bank account details for settlement payouts
  • KYC documents for restaurant verification

Razorpay processes and stores payment information under their own privacy policy. Harkara does not store complete card details or bank account numbers.

C. With AI Service Providers (Google Gemini API)

  • Menu item names and descriptions for nutritional analysis
  • No personal customer data is shared with AI providers

D. With Cloud Infrastructure (Supabase)

  • All platform data is stored on Supabase servers
  • Data is encrypted in transit and at rest
  • Supabase servers are located in Singapore

E. With Service Providers

Trusted third-party providers including:

  • Cloud hosting and database services (Supabase)
  • Payment processing (Razorpay)
  • Email delivery services
  • Analytics tools
  • Twilio for OTP

All providers are bound by data protection agreements.

F. Legal Requirements

To comply with laws, respond to legal process, protect rights and safety, or cooperate with government authorities.

G. Business Transfers

During mergers, acquisitions, or asset sales, with notice to users.

7. GPS Tracking and Arrival-Based Preparation

For Pickup and Dine-In Pre-Orders:

When you place a pre-order for pickup or dine-in, the Platform may track your real-time GPS location to:

  • Calculate your estimated time of arrival (ETA)
  • Share your ETA with the restaurant
  • Trigger food preparation based on your distance and estimated arrival time

How It Works:

  • GPS tracking activates after you place a pre-order
  • Your location is shared with the restaurant in real-time until order completion
  • Tracking automatically stops when you arrive or cancel the order

Your Controls:

  • You may disable location permissions at any time
  • Disabling location may affect preparation timing accuracy
  • You can manually update the restaurant about your arrival

Data Retention:

  • Real-time location data is not stored after order completion
  • Only order timestamp and completion status are retained

8. AI-Generated Content Disclaimer

Nutritional Information:

The Platform displays estimated nutritional information (calories, protein, carbohydrates, fiber, fat) for menu items. This information is generated using artificial intelligence (Google Gemini API) based on dish names and descriptions provided by restaurants.

Important Disclaimers:

  • Nutritional values are AI-generated estimates, not laboratory-tested
  • Actual nutritional content may vary based on portion size, ingredients, and preparation methods
  • This information should not be used for medical dietary planning
  • Individuals with allergies, medical conditions, or specific dietary requirements should consult restaurants directly

Restaurants are solely responsible for the accuracy of dish descriptions provided to generate nutritional estimates.

9. Third-Party Service Providers

We use the following third-party services:

ServicePurposeData Shared
RazorpayPayments, KYC, SettlementsTransaction data, bank details, KYC documents
SupabaseDatabase & StorageAll platform data (encrypted)
Google Gemini APINutritional analysisMenu item descriptions only
ResendTransactional emailsEmail addresses, order receipts
TwilioOTP verificationMobile phone numbers

Each provider maintains their own privacy policy. We encourage you to review:

10. Data Storage and Retention

Your personal data is stored on secure servers located in India and on secure servers operated by trusted cloud providers. We retain personal data only as long as necessary to provide services, comply with legal obligations, resolve disputes, and enforce agreements.

Data Storage

Your data is stored on servers operated by Supabase Inc. Supabase servers are located in AWS Region — Singapore. Data is encrypted in transit (TLS) and at rest (AES-256). Supabase complies with SOC 2 Type II standards.

11. Data Security

Harkara implements industry-standard security measures including encryption, secure servers, restricted data access, and authentication controls. However, no internet transmission is completely secure and we cannot guarantee absolute security.

12. Your Rights

Under applicable laws including the Digital Personal Data Protection (DPDP) Act, 2023, you have the right to access your personal data, correct inaccurate information, request deletion of your data, and withdraw consent for processing. You may exercise these rights by contacting us at team@harkara-ai.in.

13. Account and Data Deletion

How to request account deletion:

You may delete your account and all associated personal data at any time. You can do this directly through the Harkara app settings, or without the app by emailing us at team@harkara-ai.in from your registered email address or phone number.

  • We will process your deletion request and remove your data from active systems within 30 days.
  • Deleted accounts and data cannot be restored.
  • Note: Secure backups may retain data temporarily for legal, tax, and security purposes in compliance with applicable laws.

14. Data of Minors

The platform is not intended for individuals under 18 years of age. We do not knowingly collect personal information from minors. If we become aware that a minor has submitted personal data, we will take immediate steps to delete such information.

15. Third-Party Links

The Platform may contain links to third-party websites. Harkara is not responsible for the privacy practices of external sites. Users should review third-party privacy policies before sharing information.

16. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated date. Continued use of the Platform constitutes acceptance of the revised policy.

17. Contact Us

Company Name: Harkara AI Private Limited

Grievance Email: team@harkara-ai.in

Support Email: team@harkara-ai.in

For grievances relating to personal data processing, users may contact the Grievance Officer at the above email address in accordance with the Information Technology Act, 2000, and applicable rules.


Payment Processing Disclosure

Payments on Harkara are processed by Razorpay Software Private Limited. By making payments, you agree to Razorpay’s Terms of Service and Privacy Policy available at https://razorpay.com/terms/ and https://razorpay.com/privacy/.

Restaurant bank account details and KYC documents are stored by Razorpay in compliance with RBI guidelines. Harkara does not have access to complete bank account numbers or KYC documents after verification.