Last Updated: 1 January 2026
This page summarises, in plain language, the data the BeGrocer app collects, why each type is needed, who it is shared with, and the security practices we follow. It mirrors the data safety information we declare on the Google Play Store.
1. Summary
- Data is encrypted in transit using TLS.
- You can request deletion of your account and data at any time.
- We do not sell personal data to third parties.
- We do not use your data for advertising profiles or credit scoring.
- Data collection is limited to what is needed to deliver your orders.
2. Data Collected and Why
- Name, phone number, email: account creation, order confirmation and delivery coordination. Required.
- Delivery address: to deliver the order to the right place. Required.
- Approximate or precise location: serviceability checks and rider navigation, collected while the app is in use. Optional; you can enter an address manually.
- Purchase and order history: order tracking, invoices, refunds and reorder. Required.
- Payment status and method type: to confirm payment and process refunds. Card numbers, CVV and UPI PINs are never collected or stored by BeGrocer.
- App interactions and crash logs: diagnostics, stability and fraud prevention. Required.
- Photos you upload: only when you attach an image to a quality complaint. Optional.
3. Data We Do Not Collect
- Contacts, call logs and SMS messages.
- Health, fitness or biometric data.
- Files and documents stored on your device.
- Microphone or camera access outside an explicit in-app action you start.
- Background location when the app is closed.
5. App Permissions
- Location: to detect your delivery area and improve address accuracy. Can be declined.
- Notifications: order and delivery updates. Can be declined.
- Camera and photos: only to attach an image to a support request. Can be declined.
- Network access: required for the app to function.
6. Security Practices
- TLS encryption for all data transmitted between your device and our servers.
- Passwords stored using one-way hashing; OTP-based sign-in by default.
- Role-based, least-privilege access controls for internal staff.
- Encrypted backups and access logging on production systems.
- Periodic review of dependencies and security patches.
7. Retention and Deletion
Personal data is retained while your account is active. On deletion, data is removed or anonymised within 30 days, except invoices and transaction records that must be retained for up to eight years under Indian tax law. See our Account Deletion page for the full process.
8. Children's Data
BeGrocer is intended for users aged 18 and above. We do not knowingly collect personal data from children. If we learn that a child's data has been collected, we delete it promptly.
9. Contact
For any question about data safety, or to report a security concern, email support@begrocer.app. Security reports are acknowledged within 48 hours. Full details are available in our Privacy Policy.