LEGAL
Privacy Policy
Last updated: May 2026
Bhojanam Inc. ("Bhojanam","we", "our", or "us") is committed to protecting your personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) of Canada. This Privacy Policy explains how we collect, use, and protect your information when you use our website at bhojanamfoods.com.
1. Information We Collect
When you place an order or create an account, we collect:
- Personal identifiers — your full name, email address, and phone number
- Delivery information — your delivery address, including any saved default address on your profile
- Order history — details of items ordered, quantities, order totals, order status, timestamps, and any help queries or messages exchanged with our team regarding your orders
- Account information — username and password (stored securely and never in plain text), and where applicable, your Google account name and email if you sign in via Google
- Referral information — your referral code and, where applicable, who referred you to Bhojanam
- Reservation and catering details — date, time, party size, and contact information provided when making table reservations or catering enquiries
- Meal plan information — your selected meal plan tier and subscription details if you subscribe to a Bhojanam meal plan
- Wallet information — your wallet balance and full transaction history including credits issued from meal plan modifications and debits applied at checkout. This data is tied to your account and retained for the duration of your account's activity.
- Reviews and feedback — star ratings and written reviews you submit through our website, linked to your account and verified order. Reviews are subject to admin approval before being published.
- Membership and loyalty data — your membership tier (Bronze, Silver, Gold), points balance, lifetime spend, and points transaction history accrued through delivered orders
We do not collect or store credit card numbers, banking details, or any financial payment information. Orders are settled via cash on delivery, pickup, or Interac e-Transfer. No payment processing data is stored on our servers.
2. How We Use Your Information
We use your information to:
- Process and fulfil your food orders
- Send you order confirmation and status update emails
- Respond to your help queries and support requests
- Improve our menu, services, and website experience
- Contact you regarding changes to your order if required
We do not sell, rent, or share your personal information with third parties for marketing purposes.
Transactional emails (order confirmations, status updates, subscription approvals) are sent as part of our service and are exempt from consent requirements under the Canadian Anti-Spam Legislation (CASL). We do not send marketing emails without your explicit consent.
3. How We Store and Protect Your Information
Your data is stored securely on Railway cloud servers located in the United States. We use industry-standard security measures including:
- HTTPS encryption for all data transmitted to and from our website
- Secure password hashing — we never store passwords in plain text
- Secure HTTP cookies with CSRF protection
- Access controls limiting who can view your data
4. How Long We Keep Your Information
We retain your personal information for as long as your account is active or as needed to provide our services. Order records are kept for a minimum of 2 years for operational and legal compliance purposes. You may request deletion of your account and associated data at any time (see Section 6).
5. Cookies
We use essential cookies only — these are required for the website to function (login sessions, cart, CSRF security). We do not use advertising or tracking cookies. You can disable cookies in your browser settings, but this may affect website functionality.
6. Your Rights Under PIPEDA
As a Canadian resident, you have the right to:
- Access — request a copy of the personal information we hold about you
- Correction — request correction of inaccurate information
- Deletion — request deletion of your account and personal data
- Withdraw consent — opt out of non-essential communications
To exercise any of these rights, contact us using the details in Section 8.
7. Third-Party Services
We use the following trusted third-party services to operate our website:
- Railway — cloud hosting and database
- Cloudinary — image storage
- Resend — transactional email delivery
- Google OAuth — optional sign-in via Google account
Each of these services has their own privacy policy. We only share the minimum information necessary for these services to function.
8. Contact Us
For any privacy-related questions, requests, or concerns, please contact us:
- Email: connect@bhojanamfoods.com
- Contact form: bhojanamfoods.com/about
- Business location: Ontario, Canada
We will respond to all privacy requests within 30 days as required by PIPEDA.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of our website after changes constitutes acceptance of the updated policy.