Short version: We collect what we need to cook, deliver, and communicate about your orders. We do not sell your personal information. You can reach us anytime at support@thefreshdabba.com.

Fresh Dabba (“Fresh Dabba,” “we,” “us”) runs thefreshdabba.com and related tools so you can order vegetarian tiffin, manage weekly plans, and talk to our team. This Privacy Policy describes how we handle personal information. It works together with our Terms of Service.

By using our site or placing an order, you agree to this policy. If you do not agree, please do not use the services.

Who this covers

This policy applies to customers with accounts, guests who checkout without signing up, and anyone who contacts us or visits our public pages. Staff and owner portals are governed by the same principles but may involve additional operational data (for example, route assignments).

What we collect

Information you give us

  • Identity & contact: name, email, phone number, and (for accounts) login credentials managed by our authentication provider — we never store your password in plain text.
  • Orders: meal choices, plan type (one-time, weekly, monthly), delivery dates and windows, spice level, allergy or dietary notes you choose to share, add-ons, and messages you send us.
  • Delivery & payment: street address, unit, ZIP, gate codes or instructions, order history, and payment-related details (for example Zelle references or cash-on-delivery notes you provide).
  • Support: anything you email, text, or submit through feedback forms.

Information collected automatically

  • Technical logs: browser type, device class, IP address, and timestamps — used for security, fraud prevention, and keeping the site reliable.
  • Session data: cookies and local storage needed to keep you signed in or remember checkout steps. You can limit cookies in your browser; some features may stop working if you disable essential cookies.

Optional tools

If you use address autocomplete powered by Google Maps Platform, the text you type may be processed by Google under their policies to suggest U.S. addresses. Google sign-in, if enabled, is also subject to Google's terms.

How we use information

We use personal information to:

  • Create accounts, authenticate you, and operate customer and owner dashboards.
  • Prepare, pack, route, and deliver meals; confirm payments; and resolve delivery issues.
  • Run weekly plans, cutoffs, skip days, change requests, and reminders you enable.
  • Send transactional email or SMS (and WhatsApp where configured) about orders — not unrelated marketing blasts.
  • Improve menus, kitchen planning, and customer experience using aggregated, non-identifying statistics.
  • Detect abuse, protect our team and customers, and comply with law.

Where laws like the GDPR require a legal basis, we rely on contract (delivering your order), legitimate interests (security and service improvement), consent when required (certain optional messages), and legal obligation when applicable.

Who we share with

We do not sell your personal information. We share data only with service providers who help us run the business under confidentiality obligations, including:

  • Supabase — database, authentication, and backend infrastructure for orders and accounts.
  • Vercel — hosting and delivery of our website and application.
  • Resend (or similar) — transactional email when configured.
  • Twilio (or similar) — SMS or WhatsApp when you opt into those channels and we have them enabled.
  • Google — optional sign-in or Maps/Places autocomplete, under Google's policies.

We may also disclose information to professional advisors under confidentiality, to authorities when legally required, or in connection with a business transfer (merger or sale), subject to equivalent privacy protections.

Guest orders & track links

You can place orders without creating an account. For guests we still collect the contact and delivery information needed to fulfill the order. After checkout you may receive a track link with a secure token so you can view status, request certain changes (such as skip or address updates where supported), or bridge to an account later. Treat track links like a password — anyone with the link can access that order's guest tools until the token expires. Do not post track URLs publicly.

Cookies & sign-in

We use essential cookies for authentication and site operation. We do not use invasive cross-site advertising trackers on our ordering flows. Analytics, if added later, will be described in an updated version of this page.

How long we keep data

We keep information while your account is active, while we have an ongoing delivery relationship, and as long as needed for tax, accounting, dispute resolution, and legal compliance. Deleted accounts may leave residual copies in encrypted backups for a limited period.

Your choices

  • Update profile and addresses in your account when the feature is available.
  • Email us to correct or delete account data — some records must be kept where law requires.
  • Opt out of optional marketing; transactional messages about active orders may still be sent.
  • California residents: you may have rights to know, delete, and opt out of certain “sale” or “sharing” as defined by California law. We do not sell personal information for money. Contact us to exercise rights.

Children

Our services are not directed to children under 13. We do not knowingly collect their personal information. If you believe we have, contact us and we will delete it promptly.

Updates

We may revise this policy as our features evolve. The “Last updated” date on this page will change, and material updates may be noted on the site or by email. Continued use after changes means you accept the updated policy.

Contact

Privacy questions or requests: support@thefreshdabba.com. You can also reach us through WhatsApp or the contact details in our site footer. Fresh Dabba operates in Houston, Texas, United States.

Note: This policy is written for transparency. It is not legal advice. Consult a qualified attorney for regulated or high-risk processing.