Dormdash Networks Private Limited (“DormDash”, “the Company”, “we”, “us”, or “our”) operates a campus-exclusive delivery, marketplace, and student-services platform available on the Apple App Store, Google Play, and at our associated website (together, the “Platform”). This Privacy Policy explains what personal data we collect through the Platform — including for student accounts, deliveries, the campus marketplace, wallet and payment transactions, delivery partners, and identity verification — why we collect it, who we share it with, and the rights available to you under the Digital Personal Data Protection Act, 2023 (“DPDP Act”). The Platform is restricted to users aged 18 and above. We do not sell personal data, and we do not use it for third-party behavioural advertising.
Contents
- 1. Scope of this Policy
- 2. Age & Eligibility
- 3. Information We Collect
- 4. How We Use Information
- 5. Payments, Payouts & Subscriptions
- 6. Disclosure of Information
- 7. Third-Party Processors
- 8. Retention
- 9. Your Rights
- 10. Security
- 11. Data Storage & Transfer
- 12. Children's Data
- 13. Amendments
- 14. Grievance Redressal
- 15. Governing Law
- 16. App Store Disclosures
1. Scope of this Policy
This Privacy Policy is issued by Dormdash Networks Private Limited (CIN: U63112TS2025PTC208012), having its registered office at F17, Rd Number 17, Muppas Panchavati Colony, Rangareddy, Telangana 500089, India.
This Policy governs the collection, use, storage, processing, disclosure, and protection of personal data of any individual who downloads, installs, registers on, or otherwise accesses the DormDash mobile application on the Apple App Store or Google Play Store, or any associated website (together, the “Platform”). It is the single privacy policy that applies to every distribution of DormDash, whether installed via the Apple App Store or Google Play.
This Policy applies to all categories of individuals who use the Platform, including students who create an account to request a delivery, task, or purchase from the campus marketplace (“Requesters”), students who fulfil a delivery or task as a delivery partner (“Dashers” or “Drivers”), and campus stores, clubs, or organisations that list inventory or purchase promotional placement on the Platform (“Partners”).
This Policy should be read together with our Terms & Conditions. In the event of any conflict between the two on a matter of data protection, this Policy shall prevail.
By registering for or using the Platform, you confirm that you have read, understood, and agree to the practices described in this Policy. If you do not agree, you must not use the Platform.
2. Age & Eligibility
The Platform is available only to individuals who are 18 years of age or older, and who possess the legal capacity to enter into a binding contract under the Indian Contract Act, 1872.
This restriction is a deliberate operational and legal decision. The Platform involves a funded digital wallet, unsupervised in-person handoffs between individuals, and coordination with other verified students. DormDash has determined that these are not activities it will extend to minors, and does not operate the verifiable parental-consent mechanism that Section 9 of the DPDP Act would require to lawfully process a child's personal data.
You are required to self-certify that you are 18 years of age or older during registration. DormDash is entitled to rely on this self-certification, together with the identity and profile details described in Section 3.1, as evidence of your eligibility.
If DormDash determines, at its sole discretion, that a user has misrepresented their age or identity, DormDash reserves the right to immediately suspend the account, withhold or reverse any pending payout, and delete the personal data associated with the account, subject to any retention obligations described in Section 8.
Where DormDash becomes aware that it has inadvertently collected personal data from an individual under 18, it will delete such data as soon as reasonably practicable, save to the extent retention is required to investigate the circumstances or comply with law.
3. Information We Collect
DormDash collects the categories of personal data set out below, corresponding to the records maintained in its production database.
3.1 Identity, profile & verification data
You create a DormDash account by signing in with Google Sign-In or with Sign in with Apple. Where you use Google Sign-In, Google provides DormDash with your full name, profile photograph, and email address. Where you use Sign in with Apple, Apple provides DormDash with your name and the email address you choose to share (which may be a private relay address). DormDash does not collect or store a password for your account.
From within the app, you can add your college email address, college roll number or student ID, current year of study, phone number, hostel tower or block assignment, and, optionally, your gender to your profile. These details help DormDash and other students recognise you as a member of your campus community, and, in the case of gender, to offer the gender-based matching preference described in Section 3.8 and Section 4.
3.2 Wallet and financial records
Your wallet balance and a complete ledger of wallet transactions, including top-ups, debits, withdrawals, and refunds; order-level payment records, including the amount, fee breakdown, and status of each transaction; the UPI ID you provide as a payout destination, whether to receive earnings as a delivery partner or to withdraw your wallet balance; and, where you subscribe to Student Pass, your subscription status, start date, renewal dates, and cancellation date (see Section 5).
3.3 Task, delivery & marketplace data
The content of any task, delivery, or marketplace order you create or accept, including item or task descriptions, pickup and drop-off details, your tower and room number or a Lobby delivery preference, timestamps for each stage of fulfilment, any priority-delivery selection, in-app messages exchanged between a Requester and a delivery partner relating to that task, and any rating or written review given or received on completion. Where you use a screenshot, such as of an order QR code, to help place a task or marketplace order, the image is transmitted to our OCR text-extraction provider, OCR.space, solely to read the order details; the image itself is separately stored by DormDash and shared with your assigned Dasher, to allow them to verify and collect your order at the counter. OCR.space itself does not retain the image after processing (Section 7). Task and delivery completion is confirmed through a one-time OTP exchanged between the Requester and the delivery partner; DormDash does not capture or store photographic proof of delivery.
3.4 Safety and complaint records
Where you submit or are named in a complaint or safety report, we retain the substance of that report, any supporting evidence submitted, the parties involved, and its resolution status.
3.5 Notifications
Your device's push-notification token, issued through Expo's push notification service, and a log of order and safety alerts delivered to you as push notifications through that service.
3.6 University and marketplace Partner data
The university or campus associated with your account. Where you are a marketplace Partner (a campus store, stall, or club), the product catalogue or inventory you list, and details of any promotional placement you purchase. DormDash sells promotional placements directly to campus stores and clubs; it does not operate or integrate any third-party advertising network, and does not share individual user data with Partners for targeting purposes.
3.7 Information collected automatically
| Category | Examples |
|---|---|
| Device & diagnostic data | Device model, operating system, unique device identifiers, IP address, app version, and crash and diagnostic logs, stored in our Supabase database. |
| Usage data | Screens viewed and features used, for the purpose of maintaining and improving the Platform. |
3.8 Location data
DormDash does not collect, track, or store your device location, whether you use the Platform as a Requester or as a Dasher, and including while fulfilling an active delivery. The Platform does not request background or foreground location permission.
4. How We Use Information
- To operate the Platform: to match Requesters with delivery partners, track active deliveries, and process marketplace orders and wallet transactions.
- To offer gender-based matching preferences: where a Requester or Dasher has indicated a same-gender delivery preference, to match and display tasks accordingly, and to offer an alternate drop-off point where a same-gender match is not available and the Requester consents to proceed (Section 3.1).
- To verify identity and eligibility: to confirm that you are 18 or above and a member of your campus community before granting access.
- To maintain safety and trust: to operate the ratings system, investigate complaints and reported incidents, and detect fraudulent or abusive use of the Platform.
- To provide customer support: to respond to queries, complaints, and requests submitted to us.
- To deliver notifications: to send you order updates, safety alerts, and service communications by push notification.
- To maintain and improve the Platform: to diagnose technical issues and understand feature usage.
- To comply with law: to meet record-keeping, taxation, and regulatory obligations, and to respond to lawful requests from courts or government authorities.
- For marketing communications, only where you have separately opted in, and which you may withdraw consent to at any time.
DormDash does not use personal data to construct behavioural advertising profiles, and does not sell personal data to any third party.
5. Payments, Payouts & Subscriptions
The DormDash wallet holds funds in escrow between the time a Requester pays for a task or marketplace order and the time it is confirmed complete.
Wallet top-ups are processed by our payment gateway partner, Juspay Technologies Private Limited, through its HyperSDK, settling via HDFC Bank's SmartGateway. Top-ups may be made using any payment method supported through this gateway, including UPI, debit and credit cards, and net banking. Your card number, CVV, UPI PIN, and net-banking credentials are entered directly with the gateway and are not collected or stored by DormDash.
Payouts and withdrawals are also processed through this gateway, and are made to a UPI ID only. To receive earnings as a delivery partner, or to withdraw your wallet balance, you are required to provide a UPI ID. DormDash stores this UPI ID as a beneficiary record and discloses it only to our payment gateway partner, for the sole purpose of executing the transfer to you. DormDash does not collect or store bank account numbers or IFSC codes.
You may withdraw your available wallet balance to your registered UPI ID at any time, whether you use the Platform as a Requester, as a delivery partner, or as both.
Student Pass is an optional monthly subscription that reduces the Campus Service Fee payable on your orders. Where you subscribe, DormDash records your subscription status and its start, renewal, and cancellation dates. You may cancel Student Pass at any time from within the application; cancellation stops future renewals, and the subscription remains active until the end of the period already paid for.
DormDash retains a record of the amount, date, fee breakdown, and status of every transaction, as described in Section 8.
6. Disclosure of Information
| Recipient | What is disclosed, and why |
|---|---|
| The counterpart on a task | Name, profile photograph, and rating, limited to the duration of that specific task. |
| Juspay Technologies Pvt. Ltd. / HDFC Bank SmartGateway (payments, payouts & withdrawals) | Payment amount, order reference, and your UPI ID, to process wallet top-ups, delivery-partner earnings, and wallet withdrawals (Section 5). |
| Supabase (database & infrastructure) | All data described in Section 3 is stored on our behalf under contract. |
| University or campus administration | Only where required for a safety investigation, legal compliance, or with your specific consent; never wallet or payment details, and never as a matter of routine. |
| Courts, regulators, or law enforcement | Only where legally compelled, such as under a valid court order or statutory request. |
| A successor entity | In the event of a merger, acquisition, or sale of DormDash's business, subject to this Policy continuing to apply until you are notified of any change. |
DormDash does not disclose personal data to advertisers, data brokers, or any third party for their own independent marketing purposes.
7. Third-Party Processors
DormDash engages the following service providers to operate the Platform. Each processes personal data solely on DormDash's instructions and for the purposes set out in this Policy, and each is contractually required to provide a standard of protection for that data equal to the standard set out in this Policy. None of these providers is permitted to sell personal data or to use it for its own purposes. Most process data within India; OCR.space, our OCR text-extraction provider, is headquartered in Germany and processes screenshot images outside India solely to extract order text, and does not retain each image after processing.
| Function | Provider |
|---|---|
| Account creation and sign-in | Supabase Authentication, Google Sign-In, and Sign in with Apple |
| Database & backend infrastructure | Supabase (hosted on AWS ap-south-1, Mumbai) |
| Wallet top-ups, payouts & withdrawals | Juspay Technologies Private Limited (HyperSDK), settling via HDFC Bank SmartGateway |
| Push notifications | Expo Push Notification service |
| OCR text extraction | OCR.space |
8. Retention
- Account and profile data is retained for as long as your account remains active, and for a limited period thereafter to address disputes or suspected fraud.
- Transaction, payment, and payout records are retained for the period required under applicable Indian financial and taxation law, irrespective of account deletion.
- Complaint and safety records are retained for as long as necessary to resolve the matter and for a reasonable period thereafter for pattern-of-conduct review.
- Order-related screenshots are stored by DormDash as part of the order record and shared with your assigned Dasher. The image is separately transmitted to OCR.space for text extraction only; OCR.space does not retain it after processing (Section 3.3).
- Where data is no longer required for the purposes above, DormDash will delete or irreversibly anonymise it.
9. Your Rights
Under the Digital Personal Data Protection Act, 2023, you have the right to:
- Access the personal data DormDash holds about you.
- Correct or update inaccurate or incomplete data.
- Withdraw consent to any processing that relies on it, at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Request erasure of your data, subject to DormDash's retention obligations under Section 8.
- Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
- Lodge a grievance with DormDash's Grievance Officer (Section 14), and thereafter, if unresolved, with the Data Protection Board of India.
Requests may be submitted in-app under Profile, or directly to the Grievance Officer using the contact details in Section 14.
9.1 Account deletion
You may delete your DormDash account at any time. Deletion may be initiated from within the application, under Profile, and may also be requested from outside the application by written request to the Grievance Officer at the address or email in Section 14. On deletion of your account, DormDash will delete the personal data associated with it, other than records it is required to retain under Section 8, principally transaction and payout records retained to satisfy Indian financial and taxation law. Suspension or deactivation of an account is not treated as a substitute for deletion.
10. Security
DormDash employs encryption of data in transit, access controls restricting internal access to personal data on a need-to-know basis, and a double-entry ledger architecture for wallet transactions to ensure that funds and records reconcile automatically. Task and delivery completion is confirmed through a one-time OTP shared between the two parties, rather than photographic evidence. No system of transmission or storage can be guaranteed completely secure; users are advised to report any suspected unauthorised access to their account immediately.
11. Data Storage & Transfer
Personal data is stored on infrastructure provided by Supabase, in the ap-south-1 (Mumbai, India) AWS region, and DormDash does not otherwise transfer personal data outside India. Juspay/HDFC SmartGateway and our other processors each process data solely for the purposes described in this Policy, within India. The one exception is OCR.space, a Germany-headquartered provider: where you use a screenshot to help place an order, that image is transmitted outside India for text extraction; OCR.space does not retain it after processing (Section 3.3).
12. Children's Data
As set out in Section 2, the Platform is not directed at, and is not intended for use by, any individual under 18 years of age. DormDash does not knowingly collect personal data from children. A parent or guardian who believes a child has provided personal data to DormDash may contact the Grievance Officer (Section 14) to request its investigation and deletion.
13. Amendments
DormDash may revise this Policy from time to time to reflect changes in its practices or in applicable law. Material changes will be notified to users through the Platform or by email prior to taking effect. The “Last updated” date at the head of this Policy reflects the most recent version.
14. Grievance Redressal
In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000, DormDash has appointed a Grievance Officer to address concerns regarding the processing of personal data.
- Grievance Officer
- Preetham Sunku
- dormdash.in@gmail.com
- Phone
- +91 63045 88573
- Address
- F17, Rd Number 17, Muppas Panchavati Colony, Rangareddy, Telangana 500089, India
- Acknowledgement period
- Within 24 hours of receipt
- Resolution period
- Within 15 days for general grievances; within 30 days for data-protection complaints under the DPDP Act, 2023
These timelines follow the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
15. Governing Law
This Policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000. Any dispute arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts at Hyderabad, Telangana, India.
16. App Store Disclosures
Both the Apple App Store and Google Play require app privacy details to be shown against each store's own fixed taxonomy of data types. The tables below record DormDash's data collection and sharing against each taxonomy. No data type collected by DormDash is used to track users across other companies' apps or websites, and none is shared for advertising purposes: DormDash sells promotional placements directly to campus stores and clubs and does not integrate any third-party advertising network.
16.1 Apple App Privacy (“Nutrition”) Label
| Apple category | Collected | Linked to the user | Used to track the user |
|---|---|---|---|
| Contact Info: Name | Yes | Yes | No |
| Contact Info: Email Address | Yes, college email address | Yes | No |
| Contact Info: Phone Number | Yes | Yes | No |
| Contact Info: Physical Address | Yes, tower and room number or Lobby delivery location | Yes | No |
| Location: Precise Location | No (Section 3.8) | Not applicable | Not applicable |
| Financial Info: Payment Info | No. Entered directly with our payment gateway partner and not collected by DormDash (Section 5) | Not applicable | Not applicable |
| Financial Info: Other Financial Info | Yes, UPI ID, used for payouts and wallet withdrawals | Yes | No |
| Identifiers: User ID | Yes | Yes | No |
| Identifiers: Device ID | Yes, Expo push notification token | Yes | No |
| User Content: Emails or Text Messages | Yes, in-app messages between a Requester and a delivery partner | Yes | No |
| User Content: Photos or Videos | Yes — an order-related screenshot is stored by DormDash and shared with your assigned Dasher; it is also sent to OCR.space for text extraction, which does not retain it afterward (Section 3.3) | Yes | No |
| User Content: Customer Support | Yes | Yes | No |
| Purchases: Purchase History | Yes, order and task history, and Student Pass subscription records | Yes | No |
| Usage Data: Product Interaction | Yes | Yes | No |
| Diagnostics: Crash Data | Yes, stored in Supabase | Yes | No |
| Other Data: Other Data Types | Yes, gender, collected optionally to offer a same-gender delivery-matching preference (Sections 3.1 and 4) | Yes | No |
16.2 Google Play Data Safety
| Google Play category | Collected | Shared | Purpose |
|---|---|---|---|
| Personal info: Name | Yes | No | App functionality, account management |
| Personal info: Email address | Yes, college email address | No | App functionality, account management |
| Personal info: Phone number | Yes | Yes, with other users on a matched carpooling trip | App functionality |
| Personal info: Address | Yes, tower and room number or Lobby delivery location | No | App functionality |
| Personal info: User IDs | Yes, including college roll number | No | App functionality, account management |
| Personal info: Other info | Yes, gender, collected optionally | No | App functionality (gender-based delivery-matching preference, Sections 3.1 and 4) |
| Location: Approximate/Precise location | No (Section 3.8) | No | Not applicable |
| Financial info: Purchase history | Yes, order and task history | No | App functionality |
| Financial info: Other financial info | Yes, UPI ID, for delivery-partner payouts and wallet withdrawals only | Yes, with Juspay Technologies Pvt. Ltd. (HDFC SmartGateway) | App functionality, processing payouts |
| Messages: In-app messages | Yes, messages between a Requester and a delivery partner | No | App functionality |
| Photos and videos | Yes — stored by DormDash and shared with the assigned Dasher; also shared with OCR.space for text extraction only | Yes, with OCR.space | App functionality; text extraction to help place orders (Section 3.3) |
| App activity: App interactions | Yes | No | Analytics, app functionality |
| App info and performance: Crash logs and diagnostics | Yes, stored in Supabase | No | Analytics, app functionality |
| Device or other IDs | Yes, Expo push notification token | No | App functionality, push notifications |
16.3 Additional Google Play Data Safety declarations
| Declaration | Response |
|---|---|
| Data encrypted in transit | Yes |
| Users may request deletion of their data | Yes, in-app under Profile, or by written request to the Grievance Officer (Sections 9.1 and 14) |
| Commitment to the Play Families Policy | Not applicable. The Platform is restricted to users aged 18 and above and is not directed at children (Section 2) |
| Independent security review completed | No |
| Use of the Unified Payments Interface | Yes, via Juspay HyperSDK / HDFC Bank SmartGateway |
| Background location collected | No (Section 3.8) |