Privacy Policy

Last updated: 3/2/2026

Privacy Policy

This Privacy Policy explains how Orders Free ("we", "us", "our") collects, uses, discloses and protects your Personal Data when you use our website, mobile application and related services (collectively, the "Services"). Please read this Policy carefully. By using the Services you consent to the collection and use of your data as described herein. If you do not accept this Policy, do not use the Services.

1. Scope & Applicability

This Policy applies to personal data collected through Orders Free Services (website, mobile apps, browser extensions, admin portals and APIs). It describes our practices for the handling of personal and non-personal information of Users, customers, visitors and business partners. By using the Services, you agree that Orders Free may process your data as described in this Policy.

2. Types of Data We Collect

We collect the following types of information (collectively "Data"):

  • Identity Data: name, username, profile picture, date of birth (if provided), gender (optional).
  • Contact Data: email address, mobile number, postal address.
  • Account Data: login credentials (hashed), settings, preferences, watchlists, saved addresses, shipping preferences.
  • Payment & Wallet Data: payment method identifiers (tokenized), transaction IDs, wallet balance (stored with payment partners). Note: We do not store full card PAN/CVV unless tokenized by payment partners.
  • Linked Account Data: order history, order IDs, tracking details, addresses, offers, coupons available in linked merchant accounts (from Amazon/Flipkart etc.) when you authorize via OAuth or approved flows.
  • Device & Usage Data: IP address, device identifiers, browser user-agent, OS, device model, screen size, app version, pages visited, clicks, interactions and session logs.
  • Behavioural & Preference Data: search queries, product views, category preferences, saved items, purchase intent signals.
  • Support & Communications: chat transcripts, email correspondence, call logs when you contact support (recorded only where explicitly stated).
  • Analytics & Aggregated Data: aggregated, non-identifying statistics used for improving Services.
  • Sensitive Data: we request users not to submit sensitive personal data (e.g. religious, health, biometric). If such data is submitted inadvertently, we will take reasonable steps to delete or limit processing subject to legal obligations.

3. How We Collect Data

We collect Data via the following sources:

  • Directly from you: when you register, update profile, connect accounts, configure auto-orders, add wallet funds, contact support, upload reviews/photos or use features.
  • From linked third-party accounts: when you authorize Orders Free via OAuth or approved partner flows, we receive permitted scopes of your merchant account data (orders, addresses, offers) as allowed by the third-party provider.
  • Automatically: via cookies, log files, analytics tools and SDKs embedded in our app/website.
  • From partners: marketing partners, affiliate networks, analytics providers and other service providers that you have engaged.
  • From public sources: public directories or social networks if you authorize or make public your information.

4. Purposes of Processing & Legal Basis

We use Data for the following purposes. Where applicable, we state typical legal bases (consent, contract performance, legitimate interests, legal compliance):

  • Provide & maintain Services: deliver core features (search, compare, watchlist, auto-order). Legal basis: contract performance / user consent for certain features.
  • Order facilitation: place orders on behalf of users (if auto-order enabled) and reconcile transactions. Legal basis: contract performance & user authorization.
  • Payment processing & wallet operations: to process top-ups, refunds and payouts using payment partners. Legal basis: contract performance & regulatory compliance.
  • Authentication & fraud prevention: secure accounts, detect abuse and prevent fraudulent activity. Legal basis: legitimate interests & legal compliance.
  • Personalization & recommendations: provide personalized product suggestions and offers. Legal basis: consent / legitimate interests.
  • Analytics & product improvement: analyze usage patterns to improve features. Legal basis: legitimate interests.
  • Customer support: handle tickets, disputes, refunds and user inquiries. Legal basis: contract performance & legitimate interests.
  • Regulatory & legal obligations: maintain records for tax, audit, law enforcement requests. Legal basis: legal compliance.
  • Marketing & communications: sending promotional messages, offers and updates where permitted. Legal basis: consent (for marketing) or legitimate interest for transactional messages.

5. Cookies, Local Storage & Tracking Technologies

We use cookies and similar technologies to operate the Services and improve your experience. Cookies can be session-based or persistent and are used for:

  • Essential platform functionality (login, security).
  • Preference storage (language, currency).
  • Analytics (understanding usage and performance).
  • Marketing & retargeting (with your consent where required).

Visit the Cookie Table (Annex) below for examples of cookies we use. You may control cookie preferences through your browser settings or our cookie consent banner. Blocking certain cookies may affect functionality.

6. When We Share Data

We share Data in the following limited circumstances:

  • Service providers: payment gateways, cloud hosting, analytics providers, messaging and email services, fraud prevention and KYC vendors — under contract and confidentiality obligations.
  • Merchant partners: to complete orders (merchant receives required order details for fulfillment).
  • Affiliates & advertisers: for monetization and campaign delivery, subject to user consent for marketing purposes.
  • Legal & regulatory: where required by law, regulation or court order, or to protect legal rights, safety or property.
  • Business transfers: in connection with a merger, acquisition or sale of assets (users will be notified and data handled under this Policy).
  • Aggregated / anonymized data: shared with third parties for research and analytics where individuals cannot be identified.

7. Third-Party Apps, APIs & Links

Orders Free integrates with third-party services (Amazon, Flipkart, Razorpay, Cashfree, Google, Facebook etc.). These third-party services have their own privacy policies. When you link accounts, those providers may share data with us per their terms. We recommend reviewing their privacy policies in addition to ours. We are not responsible for their policies or practices.

8. Data Security & Retention

Security measures:

  • We use encryption in transit (TLS/HTTPS) and standard encryption at rest for sensitive fields where possible.
  • Access to production data is role-based and logged; only minimal personnel have access for operations.
  • We conduct periodic security assessments and vulnerability scans; third-party SOC2/ISO audits may be performed for partners.

Retention:

  • We retain account and transactional data for as long as needed to provide Services, comply with legal obligations, resolve disputes, and enforce agreements.
  • When an account is deleted, we will anonymize or securely delete data unless retention is required by law or for legitimate business reasons (e.g., tax records).

Data Breaches:

In case of a confirmed data breach, Orders Free will follow applicable law and promptly notify affected users and regulators as required, and take remediation steps to contain and mitigate the breach.

9. Your Rights & Choices

As a user you have the following rights (subject to local law and verification):

  • Access & Portability: Request access to a copy of your personal data in machine-readable format.
  • Rectification: Correct inaccurate or incomplete data.
  • Deletion: Request deletion of your account and personal data (subject to legal retention obligations).
  • Restrict Processing: Request limitation of how your data is processed in certain circumstances.
  • Object to Processing: Object to processing based on legitimate interests, including profiling for direct marketing.
  • Withdraw Consent: If processing is based on consent (e.g., marketing), you may withdraw at any time without affecting prior processing.

To exercise these rights, contact support@ordersfree.com or use the in-app data request form. We will verify identity before fulfilling sensitive requests. We may refuse manifestly unfounded or excessive requests, but will explain reasons for refusal and appeal options.

10. Children

Our Services are not directed to children under 18. We do not knowingly collect personal data from children under 18. If we become aware that a child has provided personal data without parental consent, we will take steps to remove such data. If you believe we have collected data of a child, contact support@ordersfree.com.

11. International Transfers

Data may be processed and stored outside your jurisdiction (including India and other countries) where our service providers and partners operate. We take appropriate safeguards (standard contractual clauses, vendor assessments) to ensure adequate protection for transfers. By using the Services you consent to such transfers.

12. Grievance Officer & Contact

If you have any questions, concerns, privacy requests or grievances, contact:

Grievance Officer: [Team Orders Free]
Email: support@ordersfree.com

We will acknowledge privacy requests within 5 business days and provide a substantive response within 30 days unless a longer period is required by law or verification procedures.

13. Changes to this Privacy Policy

We may update this Policy from time to time. For material changes we will provide advance notice via email or an in-app banner. Continued use after modifications implies acceptance. Keep a copy of "Last Updated" date for reference.

14. Annex: Cookie & Tracking Example Table

The following is an illustrative list of cookies and similar technologies we use (subject to change):

Cookie name / Technology Purpose Type Retention
session_id Maintain session & auth Essential (First-party) Session
_ga (Google Analytics) Usage analytics & performance Analytics (Third-party) 2 years
consent_preferences Store cookie consent choices Essential (First-party) 1 year
affiliate_id Track affiliate referrals Marketing (First/Third) 90 days

You can manage cookies through browser settings or our cookie banner. Disabling non-essential cookies may impact functionality and personalization.

16. Payment Data Security

Payment processing is handled by certified partners like Razorpay. We do not store complete payment card details. Tokenized payment information is stored securely with PCI DSS compliant providers. All payment transactions are encrypted and monitored for fraud prevention.

17. Detailed Cookie Policy

We use essential cookies for login and security, analytics cookies to understand usage patterns, and marketing cookies for personalized advertising (with consent). Users can manage cookie preferences through browser settings or our cookie consent tool.

18. Data Breach Notification

In case of a data breach affecting personal information, we will notify affected users within 72 hours via email and take immediate steps to secure data and prevent further breaches.

19. Acknowledgement

By using Orders Free, you acknowledge that you have read and understood this Privacy Policy and consent to the processing of your Data in accordance with it. For further clarifications, contact support@ordersfree.com.