Hungry HetaudaOfficial Support Portal

Privacy Policy

This Privacy Policy explains how Hungry Hetauda collects, receives, uses, protects, and deletes personal information when you use our mobile application and services.

Effective:27 September 2026
Updated:27 September 2026
Version:2.0

Google Play Data Safety & Regulatory Compliance

Hungry Hetauda is committed to total transparency. This policy complies with applicable privacy laws, including the Nepal Privacy Act 2075 and Google Play Developer Program Policies.

Document Overview & Entity Details

EntityHungry Hetauda Private Limited
JurisdictionHetauda, Makwanpur, Nepal
Phone Support+977 980-2501461
Official Inquiriescontact@hungryheatauda.com

1. Introduction

Hungry Hetauda Private Limited ("Hungry Hetauda", "Company", "we", "us", or "our") respects your privacy and is committed to protecting your personal information.

This Privacy Policy explains how Hungry Hetauda collects, receives, uses, stores, protects, retains, and deletes information when you:

  • Use the Hungry Hetauda mobile application;
  • Visit or use our website;
  • Create a customer account;
  • Browse our menu;
  • Place a food order;
  • Request food delivery;
  • Make a payment;
  • Contact customer support;
  • Submit a review, rating, complaint, or feedback;
  • Participate in promotions or loyalty programs;
  • Interact with our digital services; or
  • Otherwise communicate with Hungry Hetauda.

This Privacy Policy is intended to provide transparency regarding our data practices and to help users understand their privacy choices.

Hungry Hetauda is committed to complying with applicable privacy, consumer protection, electronic transaction, food-service, and other applicable laws and regulations.

For users in Nepal, our privacy practices are intended to operate consistently with applicable requirements including the Privacy Act, 2075 and other applicable laws. Nepal's Privacy Act recognizes privacy protections concerning personal information and personal data.

We also maintain our Google Play disclosures and Data Safety information in accordance with applicable Google Play requirements when distributing the Hungry Hetauda application through Google Play. Google requires developers to accurately disclose their collection, use, sharing, and handling of user data.

2. Scope of This Privacy Policy

This Privacy Policy applies to information collected through:

  1. Hungry Hetauda Android application;
  2. Hungry Hetauda iOS application, if applicable;
  3. Hungry Hetauda website;
  4. Online ordering systems;
  5. Customer support channels;
  6. Restaurant ordering channels where customer information is digitally recorded;
  7. Promotional campaigns operated by Hungry Hetauda;
  8. Loyalty or rewards services, if available;
  9. Other official Hungry Hetauda digital services.

This Privacy Policy applies to:

  • Registered users;
  • Guest customers;
  • Website visitors;
  • App users;
  • Food-ordering customers;
  • Delivery customers;
  • Customers communicating with support;
  • Users submitting reviews or feedback.

3. Acceptance of This Privacy Policy

By using Hungry Hetauda's Services, you acknowledge that you have read and understood this Privacy Policy.

Where applicable, we will obtain consent or provide required notices before collecting or processing information that requires user permission.

Your use of the Services does not mean that we can collect unlimited information. We will only collect and use information for legitimate and disclosed purposes.

Where consent is required by applicable law or Google Play policy, we will request appropriate consent.

4. Our Privacy Principles

Hungry Hetauda follows the following privacy principles:

4.1 Transparency

We aim to clearly explain what information we collect and why we collect it.

4.2 Data Minimization

We aim to collect only information reasonably necessary for the relevant service or purpose.

4.3 Purpose Limitation

Information collected for one purpose will not be used for unrelated purposes unless permitted by law or otherwise appropriately disclosed.

4.4 Security

We implement reasonable technical and organizational safeguards to protect information.

4.5 User Control

Where applicable, users can access, correct, delete, or control certain categories of their information.

4.6 No Sale of Personal Information

Hungry Hetauda does not sell customers' personal information to third parties for their own marketing purposes.

5. Information We Collect

The exact information collected depends on which features you use.

We may collect the following categories of information.

5.1 Account Information

When you create an account, we may collect:

  • Full name;
  • Email address;
  • Mobile phone number;
  • Login identifier;
  • Password or authentication credentials;
  • Profile information;
  • Account creation date;
  • Account status;
  • Communication preferences.

Passwords should be stored using appropriate one-way password hashing rather than plain-text storage.

We do not intend to store passwords in plain text.

6. Delivery Information

To deliver food, we may collect:

  • Delivery address;
  • Building or house number;
  • Street;
  • Area;
  • City;
  • Postal information where applicable;
  • Landmark;
  • Delivery instructions;
  • Contact phone number;
  • Location coordinates where the user chooses to provide location access.

Delivery information is used primarily to fulfill the customer's order.

7. Location Information

If the application requests location permission, we may collect location information only to support features that require it.

Depending on the actual application functionality, location may be used for:

  • Detecting the user's delivery area;
  • Selecting a nearby restaurant or branch;
  • Helping determine delivery availability;
  • Helping calculate delivery-related information;
  • Selecting or confirming a delivery address;
  • Improving delivery coordination;
  • Providing map-related functionality;
  • Supporting order delivery.

We will not request location permission unless the relevant feature reasonably requires it.

7.1 Foreground Location

Where possible, Hungry Hetauda will prefer foreground location access rather than continuous/background location access.

For example, the application may request location while the user is actively using a map or delivery-address feature.

7.2 Background Location

Hungry Hetauda will not request background location access unless it is genuinely necessary for a core feature and the actual application implements such functionality.

If background location is used, the application will provide the disclosures and permission flows required by Google Play before requesting the relevant permission.

Google treats device location as personal and sensitive user data and requires appropriate disclosure and consent. Background location must have a strong core-functionality justification.

7.3 Location Controls

Users can generally control location permissions through their device settings.

If location access is disabled, users may still be able to manually enter a delivery address where the application supports that functionality.

Certain location-dependent features may not work without location permission.

8. Order Information

When you place an order, we may collect:

  • Order ID;
  • Items ordered;
  • Quantity;
  • Product/customization selections;
  • Special instructions;
  • Delivery address;
  • Order date and time;
  • Restaurant/branch;
  • Order status;
  • Delivery status;
  • Cancellation information;
  • Refund information;
  • Customer support information related to the order.

Order information is required to process and fulfill food orders and maintain appropriate transaction records.

9. Payment Information

Depending on the available payment methods, we may process information relating to:

  • Payment method;
  • Transaction amount;
  • Transaction ID;
  • Payment status;
  • Refund status;
  • Payment reference;
  • Order reference;
  • Payment gateway response.

Where payments are processed through a third-party payment provider, the payment provider may independently process payment information under its own terms and privacy policy.

Unless our actual payment architecture requires otherwise, Hungry Hetauda does not intentionally store complete card numbers, CVV/security codes, or full banking credentials on its own servers.

Payment information should be handled through appropriate secure payment infrastructure.

10. Cash-on-Delivery Information

If Cash on Delivery is available, we may process:

  • Order amount;
  • Customer name;
  • Phone number;
  • Delivery address;
  • Order details;
  • Payment status;
  • Cash collection status.

This information is necessary to complete and reconcile the order.

11. Device Information

When you use the application, certain technical information may automatically be received.

Depending on the actual technologies used, this may include:

  • Device type;
  • Device manufacturer;
  • Operating system;
  • Operating system version;
  • Application version;
  • Screen configuration;
  • Language;
  • Time zone;
  • Network information;
  • IP address;
  • Device configuration;
  • Application installation information;
  • Crash information;
  • Diagnostic information.

We only use such information where reasonably necessary for functionality, security, diagnostics, analytics, or service improvement.

12. Device Identifiers

Depending on the SDKs and technologies actually integrated into the application, technical identifiers may be processed.

Examples may include:

  • App instance identifiers;
  • Firebase installation identifiers;
  • Advertising identifiers;
  • Device-generated identifiers;
  • Session identifiers.

Hungry Hetauda will not intentionally collect device identifiers that are unnecessary for the functionality of the application.

If an SDK collects such information automatically, the applicable Google Play Data Safety disclosure must accurately reflect that behavior.

13. Application Usage Information

We may collect information about how users interact with the application, such as:

  • Screens viewed;
  • Features used;
  • Menu searches;
  • Products viewed;
  • Products added to cart;
  • Products removed from cart;
  • Checkout activity;
  • Successful orders;
  • Failed transactions;
  • Error events;
  • Crash reports;
  • Session information;
  • Application performance information.

This information may help us:

  • Improve usability;
  • Detect bugs;
  • Improve performance;
  • Understand feature usage;
  • Prevent abuse;
  • Improve the ordering experience.

14. Search and Browsing Information

If supported by the application, we may process:

  • Search terms;
  • Menu filters;
  • Viewed food items;
  • Favorite products;
  • Restaurant/branch views;
  • Cart activity;
  • Ordering preferences.

This information may be used to improve search, recommendations, and application functionality.

15. Customer Support Information

When you contact us, we may collect:

  • Name;
  • Phone number;
  • Email;
  • Order number;
  • Complaint;
  • Customer messages;
  • Support tickets;
  • Photos;
  • Screenshots;
  • Other information voluntarily provided by you.

This information is used to investigate and resolve your request.

16. Reviews, Ratings & User-Generated Content

If the application permits reviews, ratings, photos, or feedback, we may collect:

  • Review text;
  • Rating;
  • Uploaded photographs;
  • Date/time of submission;
  • Order reference;
  • Associated account information.

Users should not submit sensitive personal information belonging to themselves or another person through publicly visible reviews.

Users are responsible for content they voluntarily submit.

If the application supports public user-generated content, Hungry Hetauda may moderate or remove content that violates applicable policies or laws.

17. Photos, Camera & Media

If the application allows users to upload:

  • Food complaint photographs;
  • Review photographs;
  • Profile photographs;
  • Other supporting images;

the application may request access to the relevant device media functionality.

Such access should only be requested when the relevant feature is used.

We will not access your photos for unrelated purposes.

If camera access is used, it will only be used for features requiring camera functionality.

18. Contacts

Hungry Hetauda does not require access to your device contacts merely to provide ordinary food ordering functionality.

If a future feature requires contact access, such as a referral feature, the application will request appropriate permission and provide the relevant disclosure before access.

19. Microphone

The standard food-ordering functionality of Hungry Hetauda does not require microphone access.

If a future feature requires microphone functionality, such access will be requested only when necessary and will be appropriately disclosed.

20. Phone and SMS Access

Hungry Hetauda does not require access to private SMS messages merely to provide food ordering functionality.

If OTP verification is implemented, the application should use an appropriate authentication mechanism and request only the permissions technically required.

We will not intentionally read private SMS content for unrelated purposes.

21. Information Received from Third Parties

We may receive limited information from third-party services where necessary to provide functionality.

Examples may include:

  • Payment processors;
  • Authentication providers;
  • Delivery providers;
  • Mapping providers;
  • Notification providers;
  • Hosting providers;
  • Customer support platforms;
  • Analytics providers.

Where social login is actually implemented, information received may include basic profile information permitted by the authentication provider.

We do not receive more information than is reasonably necessary for the relevant integration.

22. How We Use Personal Information

We may use information for the following purposes.

22.1 Account Management

To:

  • Create accounts;
  • Authenticate users;
  • Maintain accounts;
  • Recover accounts;
  • Protect accounts;
  • Manage user preferences.

22.2 Food Ordering

To:

  • Receive orders;
  • Process orders;
  • Prepare food;
  • Communicate order status;
  • Coordinate delivery;
  • Maintain order history;
  • Process cancellations;
  • Process refunds.

22.3 Delivery

To:

  • Confirm delivery addresses;
  • Coordinate delivery;
  • Contact customers;
  • Provide delivery instructions;
  • Track order status;
  • Complete food delivery.

22.4 Payments

To:

  • Process payments;
  • Confirm transactions;
  • Detect failed payments;
  • Process refunds;
  • Reconcile transactions;
  • Prevent payment fraud.

22.5 Customer Support

To:

  • Respond to complaints;
  • Investigate order issues;
  • Resolve disputes;
  • Provide technical support;
  • Process refund requests.

22.6 Security

To:

  • Prevent unauthorized access;
  • Detect fraudulent activity;
  • Detect fake orders;
  • Prevent payment abuse;
  • Protect infrastructure;
  • Investigate security incidents;
  • Protect customers and employees.

22.7 Analytics

Where analytics are enabled, information may be used to:

  • Understand application usage;
  • Improve features;
  • Identify technical problems;
  • Measure application performance;
  • Improve ordering flows;
  • Analyze aggregate trends.

22.8 Product Improvement

We may analyze aggregated or appropriately protected information to:

  • Improve menu presentation;
  • Improve application navigation;
  • Improve delivery operations;
  • Improve restaurant operations;
  • Understand customer demand;
  • Improve service quality.

23. Marketing Communications

We may send promotional communications where permitted and where appropriate consent or another lawful basis is required.

Marketing communications may include:

  • Discounts;
  • Promotional offers;
  • New menu announcements;
  • Festival offers;
  • Loyalty benefits;
  • Special campaigns.

Users may opt out of promotional communications where applicable.

Essential service communications, such as order confirmation, delivery status, payment status, security alerts, and account-related notices, may continue because they are necessary to provide the requested service.

24. Personalized Recommendations

Where implemented, Hungry Hetauda may use information such as:

  • Previous orders;
  • Frequently purchased products;
  • Menu browsing;
  • Favorites;
  • General delivery area;

to provide relevant recommendations.

Personalization will not be used to infer sensitive characteristics unless legally permitted and appropriately disclosed.

26. Information Sharing

Hungry Hetauda does not sell personal information to third parties for their independent marketing purposes.

However, information may be disclosed where reasonably necessary to operate the Services.

26.1 Delivery Providers

Where delivery is performed by delivery personnel or a delivery partner, relevant information may be provided, such as:

  • Customer name;
  • Delivery phone number;
  • Delivery address;
  • Order details;
  • Delivery instructions.

The information provided should be limited to what is reasonably necessary to complete delivery.

26.2 Payment Providers

Payment providers may receive information required to:

  • Process payments;
  • Verify transactions;
  • Confirm payment status;
  • Process refunds;
  • Prevent payment fraud.

26.3 Hosting and Infrastructure Providers

We may use cloud or infrastructure providers to host:

  • Application servers;
  • Databases;
  • Images;
  • Order information;
  • Account information;
  • Other operational data.

Such providers process information on our behalf where applicable.

26.4 Analytics Providers

If analytics tools are used, they may receive technical and usage information according to their respective configurations.

Our Google Play Data Safety declaration will be maintained to reflect actual SDK behavior.

26.5 Communication Providers

We may use:

  • Email providers;
  • SMS providers;
  • Push-notification infrastructure;
  • Customer-support systems;

to communicate with customers.

26.7 Business Transfers

If Hungry Hetauda undergoes:

  • Merger;
  • Acquisition;
  • Restructuring;
  • Sale of assets;
  • Business transfer;

personal information may be transferred as part of the relevant transaction, subject to applicable law and appropriate protections.

27. What We Do Not Do

Hungry Hetauda does not:

  • Sell personal information for third-party marketing;
  • Intentionally collect unnecessary personal information;
  • Store passwords in plain text;
  • Request sensitive device permissions without a relevant feature;
  • Use customer data for unrelated purposes without an appropriate basis;
  • Intentionally collect private messages or contacts for ordinary food ordering;
  • Intentionally collect precise location when it is not required for a disclosed feature.

28. Data Security

We implement reasonable technical and organizational safeguards designed to protect personal information.

Security measures may include:

  • HTTPS/TLS encryption;
  • Secure authentication;
  • Password hashing;
  • Access controls;
  • Role-based access;
  • Administrative restrictions;
  • Server security;
  • Database security;
  • Security monitoring;
  • Logging;
  • Backup procedures;
  • Vulnerability management;
  • Security updates.

Security controls may change as our technology evolves.

29. Administrative Access

Access to customer information is restricted based on business necessity.

Employees, contractors, and service providers should only access information necessary to perform their assigned responsibilities.

Administrative systems may implement:

  • Role-based permissions;
  • Authentication;
  • Multi-factor authentication where available;
  • Access logging;
  • Session controls;
  • Permission reviews.

30. Encryption

Where technically appropriate:

  • Data transmitted between the application and our servers is protected using HTTPS/TLS;
  • Sensitive credentials are protected using appropriate cryptographic mechanisms;
  • Passwords are stored using secure password-hashing techniques.

Encryption does not mean that every category of information is necessarily encrypted in every environment.

31. Security Incidents

Although we use reasonable security measures, no internet-based system can guarantee absolute security.

If we identify a security incident involving personal information, we will:

  1. Investigate the incident;
  2. Contain the incident;
  3. Assess affected systems and information;
  4. Take reasonable corrective measures;
  5. Comply with applicable notification obligations;
  6. Notify affected users where required or appropriate.

We will not promise a fixed breach-notification period unless that period is required by applicable law.

32. Data Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy.

Retention periods depend on:

  • Type of information;
  • Purpose of processing;
  • Account status;
  • Transaction requirements;
  • Legal requirements;
  • Tax/accounting requirements;
  • Fraud-prevention requirements;
  • Dispute-resolution requirements.

33. Account Data Retention

While your account is active, information necessary to operate the account may be retained.

After account deletion, information will be deleted or anonymized where reasonably possible, subject to legally required or legitimate retention.

34. Transaction Data Retention

Certain transaction information may need to be retained for:

  • Tax;
  • Accounting;
  • Payment reconciliation;
  • Fraud prevention;
  • Legal compliance;
  • Dispute resolution.

Deleting an account does not necessarily require deletion of legally required financial records.

35. Backup Data

When information is deleted from active systems, copies may temporarily remain in secure backups until those backups are rotated or overwritten in accordance with our backup lifecycle.

Backup retention is intended for:

  • Disaster recovery;
  • Security;
  • Business continuity.

Backup copies are not intended for ordinary operational use.

36. De-Identified and Aggregated Data

We may create aggregated or de-identified information that cannot reasonably identify an individual.

Such information may be used for:

  • Business analytics;
  • Service improvement;
  • Demand forecasting;
  • Menu analysis;
  • Operational planning;
  • Statistical reporting.

We will not intentionally attempt to re-identify properly de-identified information except where permitted for security or legal purposes.

37. Account Deletion

Users can request deletion of their account at any time.

Where account creation is available, Hungry Hetauda will provide an in-app mechanism for account deletion.

A typical deletion path may be:

Profile → Settings → Account → Delete Account

The exact interface may change as the application is updated.

Users may also contact:

[**contact@hungryheatauda.com**](mailto:contact@hungryheatauda.com)

Google Play requires apps that allow account creation to provide an in-app path for account deletion and associated data deletion requests.

38. Account Deletion Process

When a deletion request is submitted:

  1. We may verify that the request was made by the account owner;
  2. Active operational matters may need to be completed;
  3. The account may be disabled;
  4. Personal information eligible for deletion will be removed or anonymized;
  5. Legally required information may be retained;
  6. Backups may retain information temporarily until normal backup rotation;
  7. The deletion process will be completed within a reasonable period.

39. Information That May Be Deleted

Subject to technical and legal requirements, account deletion may remove:

  • Name;
  • Email;
  • Phone number;
  • Saved addresses;
  • Profile information;
  • Saved preferences;
  • Favorites;
  • Login credentials;
  • Non-required account information.

40. Information That May Be Retained

We may retain limited information when reasonably necessary for:

  • Legal compliance;
  • Tax;
  • Accounting;
  • Financial reconciliation;
  • Fraud prevention;
  • Security;
  • Dispute resolution;
  • Legal claims;
  • Regulatory requirements.

Retained information will not be used for unrelated purposes merely because it remains in a legally required record.

41. Data Access Requests

Depending on applicable law, users may request information regarding personal data associated with their account.

Requests may be sent to:

[**contact@hungryheatauda.com**](mailto:contact@hungryheatauda.com)

We may request reasonable verification before providing information.

This is necessary to prevent unauthorized disclosure of another person's information.

42. Data Correction

Users may request correction of inaccurate personal information.

Where available, users may also update information directly through their account.

Examples include:

  • Name;
  • Phone number;
  • Email;
  • Address;
  • Profile information.

43. Data Deletion Rights

Users may request deletion of their personal information, subject to applicable legal exceptions.

Deletion may not apply to information that must legally be retained.

45. Marketing Opt-Out

Users may opt out of promotional communications through:

  • In-app notification settings;
  • Email unsubscribe mechanisms;
  • Other communication preference controls;
  • Contacting Hungry Hetauda.

Opting out of marketing does not necessarily stop transactional communications.

46. Location Permission Controls

Users can control location access through device settings.

If location permission is denied:

  • Manual address entry may still be available;
  • Location-based features may be unavailable;
  • Delivery-area detection may be limited.

47. Notification Controls

Users can control push notifications through:

  • Application settings;
  • Device notification settings.

Essential order and security communications may still be necessary to provide the Services.

48. Cookies

Our website may use cookies or similar technologies.

Cookies may be used for:

  • Authentication;
  • Session management;
  • Shopping cart functionality;
  • Security;
  • Preferences;
  • Analytics;
  • Performance.

49. Types of Cookies

Essential Cookies

Required for basic website functionality.

Functional Cookies

Used to remember preferences and settings.

Analytics Cookies

Used to understand website performance and usage.

Marketing Cookies

If used, these may help measure advertising campaigns or marketing performance.

Marketing cookies should only be used in accordance with applicable law and consent requirements.

50. Mobile Application Analytics

Mobile applications may use analytics or crash-reporting technologies.

If implemented, these tools may collect:

  • Application events;
  • Device information;
  • Crash reports;
  • Performance information;
  • Approximate technical information.

The actual SDKs used by the application must be reflected accurately in Google Play's Data Safety declaration.

51. Third-Party SDKs

The application may use third-party software development kits ("SDKs") to provide functionality.

Examples may include:

  • Firebase services;
  • Payment SDKs;
  • Mapping SDKs;
  • Push notification services;
  • Authentication services;
  • Analytics services;
  • Crash-reporting services.

Only services actually integrated into the production application should be listed as active data processors.

Each SDK may process information according to its own technical functionality and privacy documentation.

52. Payment Service Providers

Where available, payment processing may involve third-party providers.

The provider may process:

  • Transaction information;
  • Payment identifiers;
  • Amount;
  • Payment status;
  • Refund information.

Users should review the relevant payment provider's privacy policy where appropriate.

Hungry Hetauda will not claim that a specific payment provider is used unless that provider is actually integrated into the application.

53. Mapping and Location Providers

If mapping functionality is implemented, the application may use third-party mapping services to:

  • Display maps;
  • Locate delivery addresses;
  • Calculate routes;
  • Assist delivery operations.

Only the information necessary for the relevant mapping feature should be transmitted.

54. Push Notifications

Hungry Hetauda may use push-notification infrastructure to send:

  • Order updates;
  • Delivery updates;
  • Payment notifications;
  • Security alerts;
  • Promotional notifications where permitted.

A device/application notification token may be processed to deliver notifications.

Such tokens should not be treated as a substitute for unnecessary personal information.

55. Email and SMS Providers

Where email or SMS notifications are provided, customer contact information may be processed by communication providers for purposes such as:

  • OTP;
  • Order confirmation;
  • Delivery updates;
  • Password recovery;
  • Account security;
  • Transaction notifications.

56. Social Login

If social login is implemented, we may receive limited information permitted by the selected authentication provider.

Examples may include:

  • Name;
  • Email;
  • Provider account identifier;
  • Profile information permitted by the provider.

We will not claim to use social login if the feature is not implemented.

57. Advertising

The standard food-ordering service does not require personalized advertising.

If advertising or advertising SDKs are introduced in the future, Hungry Hetauda will update applicable disclosures and Google Play Data Safety information to accurately reflect:

  • Advertising identifiers;
  • Advertising data;
  • Personalization;
  • Data sharing;
  • Opt-out mechanisms.

58. Children's Privacy

Hungry Hetauda is a general food-ordering service and is not specifically designed as a child-directed application.

We do not knowingly design the service to collect unnecessary personal information from children.

If the application is ever intentionally directed toward children or includes children in its declared target audience, Hungry Hetauda will comply with applicable Google Play Families requirements and applicable child-privacy laws.

Google requires accurate Target Audience declarations and additional requirements where children are included in the target audience.

59. Children's Data

We will not knowingly use children's personal information for unrelated purposes.

Where child-related data is collected in a legally permitted context, appropriate safeguards will be applied.

Parents or legal guardians who believe that a child has provided personal information to us may contact:

[**contact@hungryheatauda.com**](mailto:contact@hungryheatauda.com)

We will review the request and take appropriate action consistent with applicable law.

60. Sensitive Personal Information

Hungry Hetauda does not require users to provide sensitive personal information merely to order food.

Users should not submit sensitive information unnecessarily through:

  • Reviews;
  • Support messages;
  • Order instructions;
  • Public comments.

If sensitive information is voluntarily submitted, we will handle it according to applicable law and this Privacy Policy.

61. Dietary and Allergy Information

If users voluntarily provide dietary preferences or allergy information, such information may be associated with their account or order.

Examples include:

  • Vegetarian preference;
  • Vegan preference;
  • Food allergies;
  • Dietary restrictions.

Such information should be provided only when necessary.

Because food allergies may involve health-related information, users should avoid providing unnecessary medical details.

Hungry Hetauda will use information provided for food-ordering purposes only to the extent reasonably necessary for the relevant service.

62. User-Generated Content

If customers upload reviews, photographs, or feedback:

  • The content may be associated with their account;
  • Public reviews may be visible to other users;
  • We may moderate content;
  • We may remove prohibited content;
  • We may retain content as necessary for legitimate business or legal purposes.

Users should not post another person's private information.

63. Public Reviews

Where a customer voluntarily publishes a review, the review may be publicly visible.

Customers should understand that information voluntarily made public may be copied or viewed by other people.

Customers should avoid including:

  • Phone numbers;
  • Home addresses;
  • Payment information;
  • Government identification numbers;
  • Passwords;
  • Sensitive personal information.

64. Fraud Prevention

We may process technical and transactional information to detect:

  • Fake orders;
  • Payment fraud;
  • Account takeover;
  • Promotion abuse;
  • Refund abuse;
  • Automated attacks;
  • Suspicious transactions.

Fraud-prevention records may be retained where reasonably necessary to protect customers and the platform.

65. Security Logs

Security systems may generate technical logs containing information such as:

  • IP address;
  • Timestamp;
  • Account identifier;
  • Device information;
  • Request information;
  • Error information.

Security logs may be retained for an appropriate period for:

  • Security;
  • Troubleshooting;
  • Fraud prevention;
  • Incident investigation;
  • Legal compliance.

66. International Data Processing

Some service providers may operate infrastructure outside Nepal.

Where personal information is processed outside Nepal, we will seek to use appropriate safeguards consistent with applicable requirements.

Users acknowledge that cloud infrastructure and service providers may operate in multiple countries.

67. Data Storage

Customer information may be stored using secure hosting and database infrastructure.

The actual storage location may vary depending on:

  • Hosting provider;
  • Cloud region;
  • Backup infrastructure;
  • Service provider architecture.

We will not claim that all information is physically stored in Nepal unless that is technically true.

69. Business Transfers

If Hungry Hetauda is involved in:

  • Merger;
  • Acquisition;
  • Sale;
  • Restructuring;
  • Investment transaction;
  • Transfer of business assets;

customer information may form part of the transferred business assets where legally permitted.

We will take reasonable steps to ensure continued protection of personal information.

71. Government and Law Enforcement

Where legally required, Hungry Hetauda may provide relevant information to competent authorities.

We will seek to limit disclosures to information reasonably necessary for the relevant lawful purpose.

72. Data Breach Response

If we identify a personal-data security incident, we will take reasonable steps to:

  1. Identify the incident;
  2. Contain the incident;
  3. Investigate the incident;
  4. Assess affected data;
  5. Restore affected systems;
  6. Implement corrective measures;
  7. Comply with applicable notification obligations.

Where notification is legally required, we will notify relevant parties in the manner and timeframe required by applicable law.

73. User Security Responsibilities

Users should:

  • Use strong passwords;
  • Keep passwords confidential;
  • Avoid sharing account credentials;
  • Keep devices secure;
  • Install application updates;
  • Avoid suspicious links;
  • Report unauthorized account activity;
  • Use official Hungry Hetauda communication channels.

Hungry Hetauda will never intentionally request a customer's password through an unsolicited message.

74. Data Minimization

We aim to limit collection to information reasonably necessary for the relevant feature.

For example:

  • Food delivery requires an address;
  • Order communication requires contact information;
  • Payment processing requires transaction information;
  • Location-based features may require location permission.

We do not intend to collect unrelated information merely because the device makes it technically available.

75. Privacy by Design

Where practical, Hungry Hetauda seeks to incorporate privacy considerations into:

  • Application design;
  • Database architecture;
  • Access control;
  • Feature development;
  • Third-party integrations;
  • Security processes;
  • Data retention.

76. Employee and Contractor Confidentiality

Personnel who have access to customer information should be subject to appropriate confidentiality and security requirements.

Access should be limited according to job responsibilities.

77. Data Processing by Service Providers

Where third parties process information on our behalf, we seek to use providers appropriate for the relevant service and to limit their access to information reasonably necessary for that service.

Examples may include:

  • Cloud hosting;
  • Payment processing;
  • SMS;
  • Email;
  • Push notifications;
  • Analytics;
  • Customer support;
  • Mapping.

78. Privacy Requests

For privacy-related requests, contact:

Email: [contact@hungryheatauda.com](mailto:contact@hungryheatauda.com)

Suggested subject lines:

  • `Privacy Inquiry`
  • `Data Access Request`
  • `Data Correction Request`
  • `Account Deletion Request`
  • `Data Deletion Request`
  • `Privacy Complaint`
  • `Security Concern`

We may request reasonable identity verification before processing requests involving personal information.

79. Response to Privacy Requests

We aim to respond to privacy-related requests within a reasonable period.

The response time may depend on:

  • Complexity of the request;
  • Amount of information requested;
  • Identity verification;
  • Applicable legal requirements;
  • Technical limitations;
  • Legal exceptions.

Where applicable law provides a specific response period, that requirement will apply.

80. Fraudulent Privacy Requests

To protect users, we may refuse or delay requests where we reasonably believe the request:

  • Is fraudulent;
  • Was submitted by an unauthorized person;
  • Attempts to obtain another person's information;
  • Could compromise account security.

81. Changes to This Privacy Policy

We may update this Privacy Policy from time to time.

Changes may occur due to:

  • New application features;
  • New payment methods;
  • New technology;
  • New service providers;
  • Changes in law;
  • Changes in Google Play requirements;
  • Changes in data-processing practices;
  • Security improvements.

The updated policy will display a revised "Last Updated" date.

82. Material Changes

Where changes materially affect how personal information is collected or used, we may provide additional notice where appropriate.

Notice may be provided through:

  • Application notification;
  • Website notice;
  • Email;
  • Other reasonable communication methods.

83. Google Play Compliance

Hungry Hetauda intends to maintain compliance with applicable Google Play policies concerning user data and privacy.

This includes, where applicable:

  • User Data Policy;
  • Data Safety requirements;
  • Account deletion requirements;
  • Permission requirements;
  • Sensitive-data requirements;
  • Privacy Policy requirements;
  • SDK-related requirements;
  • Target audience requirements.

Google Play requires the Privacy Policy to be accessible from the app and Play Store listing and to comprehensively explain how user data is collected, used, and shared.

Our Google Play Data Safety disclosures should be reviewed whenever the application adds, removes, or changes:

  • SDKs;
  • Analytics;
  • Advertising;
  • Payment integrations;
  • Location functionality;
  • Authentication;
  • Data collection;
  • Data sharing;
  • Account deletion behavior.

84. Accuracy of Data Safety Disclosure

Hungry Hetauda will make reasonable efforts to ensure that information stated in:

  • This Privacy Policy;
  • Google Play Data Safety form;
  • In-app privacy disclosures;
  • Permission explanations;

matches the actual production application's behavior.

The actual application's SDKs and permissions must always take priority over generic examples in this document.

85. Permission Principles

The application will request permissions only when necessary for a feature.

Examples may include:

Location

For delivery/address functionality where required.

Camera

For features that allow users to capture or upload images, if implemented.

Photos/Media

For selecting images for reviews or complaints, if implemented.

Notifications

For order and service updates, where applicable.

Permissions should not be requested merely because they are technically available.

86. Prominent Disclosure for Sensitive Data

Where Google Play requires a prominent in-app disclosure before requesting access to personal or sensitive information, Hungry Hetauda will provide that disclosure before the relevant permission request.

Google's User Data policy requires clear, prominent disclosure and affirmative consent for certain personal or sensitive data practices outside reasonable user expectations.

87. Location Permission Disclosure

Where location permission is requested, the application should clearly explain:

  • That location information will be accessed;
  • Why location is needed;
  • Which feature uses the location;
  • Whether the location is used only while the application is in use;
  • Whether any background access is involved.

The disclosure should be presented before the relevant runtime permission request where required.

88. Account Deletion and Google Play

Hungry Hetauda acknowledges that Google Play requires an app that allows users to create accounts to also provide an in-app account-deletion path.

The deletion process should address the associated user data and should not merely disable login.

The developer must also complete the relevant Data Safety/Data Deletion declarations in Play Console.

89. Privacy Policy Availability

This Privacy Policy should be available:

  1. On a publicly accessible website URL;
  2. From the Google Play Store listing;
  3. Inside the Hungry Hetauda application;
  4. From an easily accessible privacy/legal section of the application.

Google's requirements specifically call for an active, accessible Privacy Policy URL rather than a PDF-only privacy policy for relevant Play disclosures.

90. Privacy Policy URL Requirements

The published Privacy Policy webpage should:

  • Be publicly accessible;
  • Not require login;
  • Not require payment;
  • Clearly identify Hungry Hetauda;
  • Clearly identify the application;
  • Be titled "Privacy Policy";
  • Explain data collection and use;
  • Explain data sharing;
  • Explain security;
  • Explain retention/deletion;
  • Provide contact information.

The production URL should be used in Google Play Console.

91. No Misrepresentation

Hungry Hetauda will not intentionally provide misleading information regarding:

  • Data collection;
  • Data sharing;
  • Security;
  • Account deletion;
  • Permissions;
  • Advertising;
  • Payment processing;
  • Location access.

The Privacy Policy should always be updated when material data practices change.

92. User Rights

Subject to applicable law, users may have rights concerning:

  • Access;
  • Correction;
  • Deletion;
  • Withdrawal of consent;
  • Marketing opt-out;
  • Permission controls;
  • Account closure;
  • Privacy complaints.

The availability and scope of individual rights may vary depending on the user's location and applicable law.

93. No Guarantee of Absolute Security

We use reasonable safeguards but cannot guarantee that:

  • The internet is completely secure;
  • No unauthorized person will ever access information;
  • Third-party services will never experience security incidents;
  • Every security threat can be prevented.

Users acknowledge the inherent risks of internet-based services.

94. Privacy Complaints

If you have a concern regarding our privacy practices, contact:

Hungry Hetauda Private Limited

Email: [contact@hungryheatauda.com](mailto:contact@hungryheatauda.com)

Please include sufficient information for us to investigate the issue.

We will review legitimate privacy complaints and take reasonable corrective action where appropriate.

96. Changes in Applicable Law

If applicable privacy or technology laws change, Hungry Hetauda may update its systems and this Privacy Policy as reasonably necessary.

97. Severability

If any portion of this Privacy Policy is determined to be invalid or unenforceable, the remaining provisions will continue to apply to the extent permitted by law.

98. No Waiver

Failure to enforce a provision of this Privacy Policy does not constitute a waiver of our right to enforce it later.

101. Final Privacy Commitment

Hungry Hetauda is committed to:

  • Respecting customer privacy;
  • Collecting only reasonably necessary information;
  • Using information for legitimate and disclosed purposes;
  • Protecting customer information;
  • Not selling personal information for third-party marketing;
  • Providing account deletion;
  • Providing appropriate privacy controls;
  • Maintaining accurate Google Play disclosures;
  • Reviewing third-party SDK data practices;
  • Improving security continuously;
  • Responding to legitimate privacy requests.

Privacy Policy Acknowledgment

By using the Hungry Hetauda application or Services, you acknowledge that you have had an opportunity to review this Privacy Policy and understand how information may be collected, used, stored, disclosed, protected, and deleted as described above.

Hungry Hetauda Private Limited

Hetauda, Makwanpur, Nepal

Phone: +977 980-2501461

[**contact@hungryheatauda.com**](mailto:contact@hungryheatauda.com)