Bhojanam

LEGAL

Privacy Policy

Last updated: August 2026

Bhojanam Inc. ("Bhojanam","we", "our", or "us") is committed to protecting your personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) of Canada. This Privacy Policy explains how we collect, use, and protect your information when you use our website at bhojanamfoods.com.


1. Information We Collect

When you place an order or create an account, we collect:

  • Personal identifiers — your full name, email address, and phone number
  • Delivery information — your delivery address, including any saved default address on your profile
  • Order history — details of items ordered, quantities, order totals, order status, timestamps, and any help queries or messages exchanged with our team regarding your orders
  • Account information — username and password (stored securely and never in plain text), and where applicable, your Google account name and email if you sign in via Google
  • Referral information — your referral code and, where applicable, who referred you to Bhojanam
  • Catering details — date, time, and contact information provided when submitting a catering enquiry
  • Meal plan information — your selected meal plan tier and subscription details if you subscribe to a Bhojanam meal plan
  • Wallet information — your wallet balance and full transaction history including credits issued from meal plan modifications and debits applied at checkout. This data is tied to your account and retained for the duration of your account's activity.
  • Reviews and feedback — star ratings and written reviews you submit through our website, linked to your account and verified order. Reviews are subject to admin approval before being published.
  • Membership and loyalty data — your membership tier (Bronze, Silver, Gold), points balance, lifetime spend, and points transaction history accrued through delivered orders
  • Marketing preferences — whether you have opted in to receive marketing emails (and when), and whether you have unsubscribed. See Section 3, "How We Comply with CASL," for details.

We do not require or intentionally collect payment card numbers, banking details, or e-transfer confirmation screenshots. Orders are settled via cash on delivery, pickup, or Interac e-Transfer, and no payment processing data is stored in our database. If a customer voluntarily shares payment confirmation information with us (for example, via email or WhatsApp) as a matter of personal practice, we may retain that communication as part of normal customer correspondence records.


2. How We Use Your Information

We use your information to:

  • Process and fulfil your food orders
  • Send you order confirmation and status update emails
  • Respond to your help queries and support requests
  • Improve our menu, services, and website experience
  • Contact you regarding changes to your order if required
  • Notify you in advance if your reward points are about to expire due to 12 months of account inactivity

We do not sell, rent, or share your personal information with third parties for marketing purposes.

Order confirmations and delivery/pickup status updates are service messages necessary to fulfil your order, and are exempt from consent requirements under the Canadian Anti-Spam Legislation (CASL). Points-expiry notices and similar account messages may, depending on their content, be treated as commercial electronic messages under CASL — where that applies, we follow CASL's consent, identification, and unsubscribe requirements for them. Marketing or promotional emails are different — we only send those to customers who have given valid consent, and every one includes an unsubscribe link. See the next section for how this works in practice.


3. How We Comply with CASL

Canada's Anti-Spam Legislation (CASL) requires consent before sending any marketing or promotional email, along with clear sender identification and a working unsubscribe mechanism in every message. Here's how we meet each of those requirements:

  • Consent — we only send marketing emails to a customer if either: (a) you explicitly checked the "send me marketing emails" box at signup — this consent is durable and does not expire on its own — or (b) you have an active business relationship with us through a recent order or subscription, which gives us implied consent under CASL for approximately 2 years from your last order or subscription. This implied consent basis expires automatically after that window if you have not also opted in and have not ordered again — no action is required on your part, and it simply stops on its own. We keep records of how and when consent was given, and you may withdraw express consent at any time
  • Sender identification — every marketing email clearly identifies Bhojanam Inc. along with our contact email, phone number, and mailing address
  • Unsubscribing — every marketing email includes an unsubscribe link. Clicking it takes you to a confirmation page — nothing is changed until you actively confirm, which protects against an accidental click or an email security scanner automatically opening the link on your behalf. Once confirmed, you are excluded from all future marketing emails immediately. We process unsubscribe requests within 10 business days, as required by CASL
  • Transactional emails are separate — unsubscribing from marketing emails never affects order confirmations, subscription status updates, or any other service email about your own account — those are not marketing and are unaffected
  • Re-subscribing — if you've unsubscribed and later want to receive marketing emails again, we require your renewed, genuine consent (for example, replying to confirm, or opting in again) before resuming — we do not simply re-enable it internally without hearing from you first

4. How We Store and Protect Your Information

Your data is stored securely on Railway cloud servers located in the United States, and may therefore be subject to United States law. We protect your data using:

  • HTTPS encryption for all data transmitted to and from our website
  • Secure password hashing — we never store passwords in plain text
  • Secure HTTP cookies with CSRF protection
  • Access controls limiting who can view your data

5. Privacy Breaches

We maintain procedures for detecting, containing, investigating, and responding to privacy breaches. Where required by law, we will report breaches to the Office of the Privacy Commissioner of Canada and notify affected individuals. We keep records of privacy breaches as required under PIPEDA.


6. How Long We Keep Your Information

We retain your personal information only for as long as necessary for the purposes described in this policy, or as required by law:

  • Account information — retained while your account is active; deleted or anonymized after you close your account, except where retention is required below
  • Order and payment records — retained for a minimum of 6 years, in line with Canada Revenue Agency (CRA) record-keeping requirements for tax and accounting purposes
  • Marketing consent records — retained for 2 years from your last interaction, or until you withdraw consent
  • Reviews and feedback — retained for 2 years, or until removed at your request
  • Support messages and correspondence — retained for 2 years

You may request account closure at any time (see Section 8).


7. Cookies

We use only essential cookies required for the website to function:

  • sessionid — keeps you logged in during your visit
  • csrftoken — protects against cross-site request forgery attacks
  • Google's own cookies during the Google sign-in flow, if you choose to sign in with Google

We do not use advertising, tracking, or analytics cookies. You can disable cookies in your browser settings, but this may affect website functionality.


8. Your Rights Under PIPEDA

As a Canadian resident, you have the right to:

  • Access — request a copy of the personal information we hold about you
  • Correction — request correction of inaccurate information
  • Account closure — request that we close your account and delete or anonymize personal information that we no longer need. We may retain information where required or reasonably necessary for legal, accounting, fraud-prevention, dispute-resolution, or other legitimate purposes (see Section 6 for specific retention periods)
  • Withdraw consent — opt out of non-essential communications

To exercise any of these rights, contact us using the details in Section 10.


9. Third-Party Services

We use the following trusted third-party services to operate our website, and share only the minimum information each needs to function:

  • Railway — our cloud hosting and database provider. As our core infrastructure, Railway stores the information described in Section 1.
  • Cloudinary — image storage. Receives images uploaded through our platform, including menu and event photography, and delivery proof-of-delivery photos.
  • Resend — transactional email delivery. Receives your name, email address, and the content of emails we send you (for example, order confirmations).
  • Google OAuth — optional sign-in via Google account. Only receives your name and email address, and only if you choose to sign in with Google rather than creating a Bhojanam account directly.

Delivery: our own in-house delivery staff can see your delivery address, phone number, and delivery instructions in order to complete your delivery. We do not currently use third-party courier services (such as Uber Eats or DoorDash); if this changes in future, we will update this policy accordingly.

Each third-party service listed above has its own privacy policy governing how it handles information on our behalf.


10. Contact Us

For any privacy-related questions, requests, or concerns, please contact our Privacy Officer:

We will normally respond to access requests within 30 days, subject to any permitted legal extension. We will respond to other privacy requests within a reasonable period.

If you are not satisfied with our response, you may also contact the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca or by phone at 1-800-282-1376.


11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of our website after changes constitutes acceptance of the updated policy.