Who We Are & What This Policy Covers
The Quest Kitchen ("we," "us," "our") is a premium vegetarian food brand based in Indore, Madhya Pradesh, India. We operate a delivery and takeaway food service along with associated digital platforms including our website, blog (The Quest Blog), and CMS.
This Privacy Policy explains how we collect, use, share, retain, and protect personal information when you interact with any of our services — whether you are ordering food, reading our blog, subscribing to our newsletter, or contacting us.
By accessing or using any Quest Kitchen service, you acknowledge that you have read and understood this policy. If you disagree with any part, please discontinue use of our services.
Plain English summary: We collect only what we need to serve you well. We don't sell your data. We don't spam. We protect what you share with the same obsessiveness we apply to our food.
Applicable Law
This policy is governed by the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (DPDP Act) as applicable in India.
Information We Collect
We collect information in three ways: information you provide directly, information collected automatically, and information from third-party platforms through which you order.
Information You Provide
| Category | Examples | When Collected |
|---|---|---|
| Contact Information | Name, email address, phone number | Order placement, contact form, newsletter signup |
| Delivery Information | Delivery address, location coordinates, delivery instructions | Order placement |
| Order Information | Items ordered, special instructions, payment method type | Order placement and processing |
| Account Information | Name, email address, and a one-way hash of your password — we never store the password itself | Account creation |
| Communication Data | Messages, feedback, complaints, reviews | When you contact us via any channel |
| Newsletter Data | Email address, subscription preferences | Newsletter signup |
Information Collected Automatically
| Category | Examples | Purpose |
|---|---|---|
| Device Information | Browser type, operating system, device type, screen size | Optimize website display |
| Usage Data | Pages requested, recorded in the web server log | Diagnosing errors and abuse |
| IP Address | Your internet protocol address | Security, fraud prevention, general location |
| Cookies | One session identifier (PHPSESSID). Your cart is stored on our server, not in your browser | Keeping you signed in and your cart intact |
| Log Data | Server access logs, error logs, admin access logs | Security monitoring |
Information from Third Parties
When you order through Zomato or Swiggy, these platforms share your order and delivery information with us to fulfill your order. Their collection and use of your data is governed by their respective privacy policies. We receive only the information necessary to prepare and deliver your order.
We do NOT collect: Payment card numbers (processed directly by payment gateways), biometric data, caste/religion/political views, or any other sensitive personal information not listed above.
How We Use Your Information
We use your information exclusively to serve you better and to operate our business responsibly. Every use of your data has a clear, legitimate purpose.
| Purpose | Legal Basis | Data Used |
|---|---|---|
| Order fulfillment | Contract performance | Contact, delivery, order data |
| Customer support | Contract performance / Legitimate interest | Contact data, communication records |
| Order history & tracking | Contract performance | Order data, contact data |
| Website functionality | Legitimate interest | Device data, cookies |
| Security & fraud prevention | Legitimate interest / Legal obligation | IP address, log data, device data |
| Marketing communications | Consent | Email, name, preferences |
| Legal compliance | Legal obligation | Any relevant data |
| Blog & newsletter | Consent | Email, name |
Marketing Communications
We will only send you marketing communications (promotional offers, new menu items, blog updates) if you have explicitly opted in. Every marketing email includes a clear, one-click unsubscribe link. We do not engage in unsolicited communications.
Automated Decision-Making
We do not use automated decision-making or profiling that produces significant legal effects concerning you. Our AI tools (used for blog content generation) do not process personal data.
Data Sharing & Disclosure
We do not sell, rent, or trade your personal information to third parties — ever. Full stop. We may share limited data with the following categories of parties only where strictly necessary:
Service Providers
We work with carefully selected third-party service providers who assist us in operating our business. These include delivery logistics partners, payment processors, email service providers, and website hosting. These providers are contractually bound to use your data only to perform services for us and must maintain appropriate security standards.
Delivery Platforms
When you order via Zomato or Swiggy, we receive your order details from them. We do not share additional data back to these platforms beyond what is required for order coordination.
Legal Compliance
We may disclose your information if required by law, court order, government authority, or to protect the safety of our customers, staff, or the public — and only to the minimum extent required by such legal obligation.
Business Transfers
In the event of a merger, acquisition, or sale of assets, customer data may be transferred as part of the transaction. We will provide notice before your personal data is transferred and becomes subject to a different privacy policy.
We will never: Sell your data to advertisers. Share your data for third-party marketing. Use your data in ways not described in this policy without obtaining fresh consent.
Cookies & Tracking
We set exactly one cookie. It is strictly necessary — without it you could not stay signed in or keep a cart.
What we do not use
No advertising cookies. No analytics cookies — we do not run Google Analytics, Meta Pixel, or any heatmap or session-recording tool. No cross-site tracking. We do not sell or rent your data to anyone.
Because the only cookie we set is strictly necessary, there is no consent banner on this site. There is nothing optional to consent to.
Managing Cookies
You can control cookies through your browser settings. Blocking our session cookie will prevent you from signing in, keeping a cart, or placing an order — that is a technical consequence, not a penalty, because the cookie is the only thing linking your requests together. Signing out clears your session immediately.
Our Cookie Policy covers this in more detail.
Data Security
We take data security seriously — with the same obsessive attention we apply to food quality. We implement multiple layers of protection:
Technical Safeguards
HTTPS encryption for all data in transit. Session token authentication with cryptographically random tokens for CMS access. Rate limiting and account lockout after repeated failed login attempts. Access logging — all administrative access is recorded with timestamp, IP address, and action. Secure local storage practices for browser-stored data.
Organisational Safeguards
Minimum access principle: Only personnel who need access to perform their role can access personal data. Staff awareness: All team members are trained on data handling responsibilities. Vendor assessment: Third-party providers are assessed for security practices before engagement.
Breach Response
In the event of a data breach that poses a risk to your rights, we will notify affected individuals and the relevant authorities within 72 hours of becoming aware of the breach, as required under applicable law.
Important: No security system is completely impenetrable. While we do everything reasonable to protect your data, we cannot guarantee absolute security. We encourage you to use strong, unique passwords and to keep your login credentials confidential.
Your Rights
Under the Digital Personal Data Protection Act, 2023 and other applicable laws, you have the following rights regarding your personal data:
How to Exercise Your Rights
To exercise any of the above rights, contact us at thequestkitchenco@gmail.com or through our contact page. We will acknowledge your request within 3 business days and respond substantively within 30 days. We may need to verify your identity before processing certain requests.
Right to Complain
If you believe we have not handled your personal data correctly, you have the right to lodge a complaint with the relevant data protection authority in India.
Children's Privacy
Our services are not directed at children under the age of 18. We do not knowingly collect personal data from anyone under 18 years of age.
If you are a parent or guardian and become aware that your child has provided us with personal information without your consent, please contact us immediately at thequestkitchenco@gmail.com. We will take immediate steps to delete such information from our records.
When ordering food, it is the responsibility of the account holder (who must be 18 or over) to manage their account. Orders placed on behalf of or for minors by adults are entirely permissible.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements.
| Data Type | Retention Period | Reason |
|---|---|---|
| Order Records | 7 years | Legal / Tax compliance (GST requirements) |
| Customer Account Data | Duration of account + 2 years | Service delivery and dispute resolution |
| Contact/Support Queries | 3 years from last interaction | Service history, dispute resolution |
| Marketing Data | Until unsubscribed + 1 year | Compliance with consent records |
| Security/Access Logs | 12 months | Security investigation |
| Session Data | Until browser close, or 2 hours idle | Authentication and cart |
| Failed Login Records | 30 days | Security monitoring |
When data is no longer required, it is securely deleted or anonymized so it can no longer be linked to you.
Third-Party Platforms & Links
Our website and services may contain links to third-party websites, platforms, and services. These include Zomato, Swiggy, social media platforms (Instagram, Twitter/X), and other partners.
We are not responsible for the privacy practices of third-party platforms. When you click a link and leave our site, you are subject to that platform's own privacy policy. We encourage you to review the privacy policies of any third-party services you use.
Zomato & Swiggy
When you order through these platforms, your data is collected and processed by them under their own privacy policies. We receive only the information needed to prepare and deliver your order. We recommend reviewing Zomato's Privacy Policy and Swiggy's Privacy Policy.
We confirm orders and handle support over WhatsApp, which is run by Meta under its own terms and privacy policy. When you message us, Meta processes that conversation. We do not control what it stores.
Google Fonts
Our typefaces are served by Google Fonts. Google sets no cookies when serving a font, but your browser contacts Google's servers, so Google receives your IP address as part of that request.
Google Sign-In
If you choose to sign in with Google, Google sets its own cookies on accounts.google.com under its own policies. We receive only your name, email address and profile picture. We never see your Google password.
Email delivery
Password reset emails are delivered through our email provider, which processes your email address solely to deliver that message.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
When we make changes, we will:
• Update the "Last Updated" date at the top of this policy
• Post a prominent notice on our website for significant changes
• Send an email notification to subscribers for material changes
• Where required by law, seek fresh consent
We encourage you to review this policy periodically. Your continued use of our services after changes are posted constitutes acceptance of the revised policy.
Version History
| Version | Date | Summary of Changes |
|---|---|---|
| v1.0 | 1 January 2025 | Initial Privacy Policy — launch version |
| v1.1 | 1 March 2025 | Added DPDP Act 2023 compliance; updated cookie table |
| v1.2 | 29 August 2026 | Corrected the cookie table to the one cookie the site actually sets; removed claims of analytics and AI processing that were never in use; documented email delivery |
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out. We are committed to responding clearly, promptly, and helpfully.
Privacy Officer
All privacy-related inquiries are handled by our designated Privacy Officer:
| Channel | Details | Response Time |
|---|---|---|
| thequestkitchenco@gmail.com | Within 24 hours | |
| Phone | +91 70000 00000 | Mon–Sun, 11am–11pm IST |
| +91 70000 00000 | Same day during business hours | |
| Contact Form | /contact.php | Within 24 hours |
| Postal Address | The Quest Kitchen, Indore, Madhya Pradesh — 452001, India | Within 15 business days |
We take every privacy inquiry seriously. Our promise: you will always receive a substantive, honest response — never a template. That's the Quest Kitchen way.