Privacy Policy
Last updated: May 29, 2026
1. Introduction
Welcome to NastaBox. We value your trust and are committed to protecting the privacy of our parent users and their children. This Privacy Policy describes how NastaBox ("we," "our," or "us") collects, uses, processes, and protects your personal data when you use the NastaBox mobile applications, website, and related school lunch delivery services.
2. Information We Collect
To provide our specialized meal planning and classroom desk-delivery services, we collect the following types of information:
- Parent Profile Information: Name, registered mobile phone number (used for secure OTP verification), home address, delivery area postal pincode, and billing/transaction details.
- Student/Child Information: Child's name, school name, school postal pincode, standard/grade, division/section, medium of instruction, recess break-time, and dietary/allergy preferences.
- Delivery Coordination Data: Delivery status, real-time location logs from delivery staff, and delivery confirmation proof.
- Device Information: Device models, push notification tokens (FCM tokens), operating system versions, and app usage statistics.
3. How We Use Your Information
We use the collected information for the following business and operational purposes:
- To prepare fresh, custom-scheduled meals according to daily menu choices.
- To coordinate desk-delivery by our verified personnel directly to your child's classroom.
- To send live push notifications and SMS updates regarding order dispatch, delivery verification, and plans.
- To manage flexible subscriptions, absence balance roll-overs, and sandbox/gateway payment verifications.
- To communicate support options, resolve complaints, and protect our platform integrity.
4. Data Sharing and Third Parties
We do not sell or lease your personal information to third parties. We share child and parent information only with trusted service partners required to fulfill operations, such as:
- Our verified, security-cleared delivery partners (who only receive necessary school, division, and child-name details to place the lunchbox on the correct desk).
- ISO-certified commercial kitchen hub managers to verify daily meal item quantities.
- Secure payment processing gateways (e.g. Cashfree) to verify purchases.
- SMS gateway providers (e.g. Vaatchit) solely for issuing secure verification OTP codes.
5. Security of Your Data
We implement strict administrative, technical, and physical security measures to safeguard your personal data. This includes secure databases, end-to-end HTTPS encryption during data transit, tokenized authentication sessions (via Laravel Sanctum), and restrictive access permissions inside our kitchen hubs and delivery networks.
6. Your Rights & Account Deletion
We support user autonomy and data privacy rights. Under our Play Store compliance guidelines, you can request account deactivation and data erasure at any time.
To request account deletion, navigate to the Account Deletion Portal, enter your registered phone number, and authorize the request via secure OTP code. Once confirmed:
- Your account status is changed to inactive and all active sessions/tokens are immediately revoked.
- Active subscriptions, meal histories, and child profiles are queued for erasure.
- A **90-day grace period** is initiated, during which you can reactivate your account by contacting support. After 90 days, all personal data is permanently deleted from our servers.
7. Contact Us
If you have any questions or feedback regarding this Privacy Policy or would like to request manual profile restoration during the grace period, please contact us at:
support@nastabox.com
+91 99090 19992
BLOCK NO. 180/8, ST. NO. 3, DWARKESH RESIDENCY-1, JAMNAGAR.