Last Updated: May 16, 2026
1. Introduction
24 Basket ("we," "us," or "our") operates a grocery delivery mobile application that enables users to order fresh fruits, dairy products, eggs, beverages, and laundry essentials for home delivery. We are committed to protecting your privacy and handling your personal information responsibly and transparently.
This Privacy Policy explains what personal information we collect, how we use it, with whom we share it, how we protect it, and what rights you have over your data. By downloading, registering, or using the 24 Basket App, you agree to the terms of this Policy. If you do not agree, please discontinue use of the App immediately.
This Policy is drafted in compliance with the Information Technology Act, 2000, the IT (Reasonable Security Practices) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (DPDP Act), Government of India.
2. Information We Collect
We collect only the information that is necessary to provide you with a smooth, secure, and personalised grocery shopping experience. We collect data in the following ways:
2.1 Information You Provide Directly
- Account Registration: When you sign up, we collect your full name, mobile number, email address, and a password. Passwords are encrypted using bcrypt hashing and are never stored in readable form.
- Delivery Address: We collect your complete delivery address including house/flat number, street, landmark, city, state, and PIN code. You may save multiple addresses to your account.
- Order Information: Each time you place an order, we record the products selected, quantities, special instructions, order value, discounts applied, timestamps, and order status history.
- Payment Details: Payments are handled by our PCI-DSS certified third-party payment gateway partners. We never store your full card number, CVV, or net banking credentials. We may retain only the last four digits of your card and card type for your order history reference.
- Customer Support: When you contact our support team, we collect the content of your messages, your contact details, and any attachments you share, solely to resolve your queries.
- User Content: Product reviews, ratings, and photos you submit within the App are collected and may be displayed publicly.
2.2 Information Collected Automatically
- Device Information: We automatically collect your device model, operating system version, unique device identifiers, mobile network information, and app version.
- Usage Data: We collect data about how you interact with the App, including screens viewed, search queries, products browsed, items added to cart, time spent per screen, and button clicks.
- Log Data: Our servers automatically record your IP address, timestamps, crash reports, error messages, and diagnostic data whenever you use the App.
- Location Data: With your explicit permission, we collect your precise GPS location to suggest your delivery address and show accurate delivery times. You may deny location permission and enter your address manually. The App does not collect location data in the background when the App is closed or not actively in use. We do not collect background location data without your knowledge.
2.3 Information from Third Parties
If you register using Google Sign-In, we receive your name, email, and profile picture from Google based on the permissions you grant. Our payment partners share transaction status information with us to confirm or flag payments. Analytics providers may share aggregated, anonymised usage insights with us. The App may use Google Play Services, Firebase Analytics, Firebase Crashlytics, and Firebase Cloud Messaging to improve app functionality, analytics, crash reporting, and notifications.
3. How We Use Your Information
We use your personal data strictly for the following lawful purposes:
- Order Fulfilment: To receive, process, and deliver your grocery orders, and to send you real-time updates via push notifications and SMS about your order status and delivery progress.
- Account Management: To create and maintain your account, authenticate your identity through OTP verification, and allow you to manage your profile, addresses, and preferences. OTP verification may use secure auto-detection technologies provided by Android or Google Play Services without accessing personal SMS content.
- Payment Processing: To initiate and confirm payment transactions through our gateway partners in a secure and reliable manner.
- Personalisation: To analyse your order history and browsing behaviour so we can recommend relevant products, display personalised offers, and tailor your home screen experience.
- Customer Support: To respond to your queries, complaints, and feedback quickly and effectively, and to improve our support processes.
- Fraud Prevention and Security: To detect suspicious account activity, monitor transactions for fraudulent patterns, and protect you and our platform from abuse and unauthorised access.
- Marketing Communications: To send you promotional offers, discount alerts, and loyalty programme updates — but only if you have explicitly opted in. You may withdraw this consent at any time.
- App Improvement: To analyse anonymised, aggregated usage data, run A/B tests on new features, fix bugs, and improve delivery efficiency and product availability based on demand patterns.
- Legal Compliance: To retain financial records as required under Indian tax regulations, respond to lawful government and court requests, and enforce our Terms of Service.
4. Legal Basis for Processing
We process your personal data on the following legal grounds under applicable Indian law:
- Consent: For location access, marketing communications, and storing payment preferences, we rely on your freely given, informed consent. You may withdraw consent at any time.
- Contractual Necessity: Processing your orders and managing your account are necessary to fulfil our service agreement with you.
- Legitimate Interests: Security monitoring, fraud detection, and internal analytics are carried out to protect our business and users, provided these interests do not override your rights.
- Legal Obligation: Retaining financial records, responding to legal requests, and complying with regulatory requirements are mandatory obligations under Indian law.
5. Sharing of Your Information
We do not sell, rent, trade, or share your personal information with third parties for their independent marketing purposes. We share your information only in the following limited and controlled circumstances:
- Delivery Partners: Your name, phone number, and delivery address are shared with our delivery agents solely to complete your order. They are contractually prohibited from using this information for any other purpose.
- Payment Gateway Providers: We share your order amount and reference number with our payment partners (such as Razorpay, Paytm, or PhonePe) to process transactions. These providers are PCI-DSS compliant and operate under their own security standards.
- Technology and Cloud Service Providers: We use trusted cloud hosting providers, SMS delivery services, push notification platforms (Firebase Cloud Messaging), and customer support tools. All providers operate under strict data processing agreements and cannot use your data independently.
- Analytics & Crash Reporting Providers: We use trusted third-party services such as Google Firebase Analytics and Crashlytics to monitor app performance, diagnose crashes, and improve user experience. These services receive only anonymised or pseudonymised technical information and do not receive personally identifiable information in readable form.
- Legal & Regulatory Requirements: We may disclose personal information to courts, law enforcement agencies, government authorities, or regulators when required by applicable law, legal process, or to protect the safety, rights, and security of our users, the public, or our business.
- Business Transfers: In the event of a merger, acquisition, restructuring, financing, or sale of business assets, user information may be transferred to the acquiring entity. If such a transfer occurs, users will be notified in advance along with any applicable rights regarding their personal data.
6. App Permissions
The 24 Basket App requests only the permissions necessary to provide specific features and services.
- Location (Precise) — Optional: Used to automatically detect your delivery address and enable real-time order tracking. If denied, you may manually enter your address.
- Camera — Optional: Used to capture profile photos or upload images for customer support requests.
- Photos & Videos — Optional: Allows you to upload profile images or support-related files from your device gallery.
- Push Notifications — Optional: Used to send order updates, delivery alerts, and promotional notifications if you choose to receive them.
- Internet — Required: Necessary for essential app functionality including browsing products, placing orders, processing requests, and connecting to our servers.
- Vibration — Optional: Used to provide haptic feedback for notifications and certain in-app interactions.
You may revoke optional permissions at any time through your device settings: Settings → Apps → 24 Basket → Permissions. Disabling optional permissions may limit certain features but will not prevent core app usage.
7. Data Storage, Security & Retention
7.1 Security Measures
We implement reasonable technical, administrative, and organisational safeguards to protect personal information against unauthorised access, misuse, loss, alteration, or disclosure.
Security measures include:
- Encryption of data transmitted between the App and our servers using secure communication protocols.
- Password hashing using bcrypt; passwords are never stored in plain text.
- Restricted, role-based access controls for employees and authorised personnel only.
- Regular monitoring and security reviews to help maintain platform integrity.
7.2 Data Retention
We retain personal information only for as long as necessary to fulfil the purposes described in this Privacy Policy or as required by applicable laws.
Retention periods generally include:
- Account & profile information: Retained until account deletion request is processed, plus up to 30 days for operational purposes.
- Order history & payment records: Retained for up to 7 years in accordance with Indian tax and accounting laws.
- Customer support communications: Retained for up to 2 years after issue resolution.
- Crash reports & diagnostics: Retained for up to 90 days.
- Location information: Used only during active sessions and not permanently stored.
7.3 Account Deletion
You may request deletion of your account and associated personal data at any time by contacting us at: info@24basket.com. Upon verification, we will process deletion requests within 30 days. Certain information may be retained where required by law, regulatory obligations, fraud prevention requirements, or dispute resolution purposes.
8. Children’s Privacy
The 24 Basket App is intended for users aged 13 years and above. We do not knowingly collect personal information from children under 13 years of age.
If we become aware that a child has provided personal information without appropriate parental consent, we will promptly delete the related account and data. Parents or guardians who believe their child may have registered on the App may contact us at: info@24basket.com. We will review and resolve such requests as quickly as reasonably possible.
9. Your Privacy Rights
Under applicable Indian laws, including the Digital Personal Data Protection Act, 2023 (“DPDP Act”), you may have the following rights regarding your personal data:
- Right of Access: Request information about the personal data we process and the purposes for which it is used.
- Right to Correction: Request correction or updating of inaccurate or incomplete information.
- Right to Erasure: Request deletion of your personal data, subject to legal obligations and retention requirements.
- Right to Withdraw Consent: Withdraw previously granted consent for optional processing activities such as marketing communications or location access.
- Right to Grievance Redressal: Submit complaints regarding the handling of your personal data.
- Right to Nominate: Nominate another individual to exercise your rights in case of death or incapacity, where applicable under law.
To exercise any of these rights, please contact us at: info@24basket.com with the subject line “Data Rights Request”. We aim to acknowledge requests within 48 hours and respond within 30 days.
10. Marketing Communications & Opt-Out
We send promotional messages, offers, and marketing communications only where permitted by applicable law or with your consent. You may opt out at any time by clicking the “Unsubscribe” link in marketing emails, replying “STOP” to promotional SMS messages, or updating notification preferences within the App settings. Please note that essential service-related communications, such as order confirmations, delivery updates, and account security notifications, cannot be disabled.
11. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our services, legal requirements, or data practices. For significant changes affecting user rights or data processing practices, we will provide advance notice through the App, email, or other appropriate communication channels. Continued use of the App after the updated policy becomes effective constitutes acceptance of the revised Privacy Policy.
12. Grievance Officer
In accordance with applicable Indian laws, including the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, users may contact our Grievance Officer at: info@24basket.com. We aim to acknowledge grievances within 48 hours and resolve them within 30 days.
13. Contact Information
24 Basket Support Team
CIN: U72900RJ2022PTC084116
Email: info@24basket.com
Website: https://24basket.com
Address:
112, Okay Plus, Tonk Road,
Durgapura, Jaipur, Rajasthan – 302018, India