Privacy Policy
How Chefose collects, uses, shares and protects your personal information — for customers and for chefs.
The short version
- We collect only what we need to run bookings, take payments, verify chefs and keep the platform safe.
- We share your details with the chef you book (and vice versa) and with providers like our payment gateway — we never sell your personal data.
- Payments are handled by a PCI-DSS compliant gateway; we don’t store your full card number.
- You can access, correct or delete your data, and opt out of marketing, at any time — see Your rights & choices.
This summary is for convenience only. The full policy below is what applies.
This Privacy Policy explains how Chefose (“Chefose”, “we”, “us” or “our”) handles personal information when you use our website, apps and services (together, the “Platform”) to book a chef, host an event, work as a chef on Chefose, or otherwise interact with us. Please read it alongside our Terms & Conditions.
1. Who we are
Chefose operates a marketplace that connects customers with independent, background-verified chefs for in-home cooking, private dining and event catering. For the purposes of applicable data protection law — including the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 and its rules — Chefose is the data fiduciary (controller) responsible for the personal data described in this policy.
Independent chefs you book are separate service providers. When a chef processes your information for their own purposes (for example, keeping their own records), they are responsible for that use.
2. Information we collect
2.1 Information you give us
- Account details — name, email address, phone number, WhatsApp number, password and profile photo.
- Booking details — the service address and any venue map link or location pin you provide, event date and time, guest count, dietary preferences, occasion, menu and dish selections, and any notes or special requests you add for the chef.
- Payment information — amounts, currency and transaction references. Card, UPI and netbanking details are collected directly by our payment gateway; see Payments & financial data.
- Chefose Wallet — wallet balance, top-ups, credits, refunds and transaction history.
- Reviews & communications — ratings and reviews you post, support tickets, and messages you send us or send through the Platform.
- Chef onboarding information (if you apply to cook on Chefose) — bio, experience, cuisines, languages, sample menu, portfolio images, service areas, availability, rate card and engagement preferences.
- Chef verification information — identity and financial details required by law to verify chefs and pay them; described separately in Chef verification (KYC) data.
2.2 Information we collect automatically
- Device & usage data — IP address, browser and device type, operating system, referring pages, the pages and listings you view, and the dates and times of your visits.
- Approximate location — derived from your IP address or, with your permission, your device, so we can show chefs and pricing relevant to your area.
- Cookies & similar technologies — see Cookies & similar technologies.
2.3 Information from other sources
- Payment gateway — payment status, method type and fraud signals from Razorpay (or another gateway we may use).
- Verification partners — results of identity, bank-account and police/antecedent checks for chefs.
- Other users — for example, a review a chef leaves about a booking, or a booking made on your behalf by someone in your household.
3. How we use your information
We use personal information to:
- create and manage your account, and authenticate you when you sign in;
- take and fulfil bookings — including sharing the details a chef needs to arrive and cook, and the details you need to identify your chef;
- process payments, wallet transactions, payouts to chefs, refunds and coupons;
- verify chefs’ identity, right to work and banking details, and run police/antecedent checks, so customers can trust who enters their home;
- send transactional messages — booking confirmations, reminders, status updates, receipts and security alerts — by email, SMS, WhatsApp or push notification;
- provide customer support and resolve disputes;
- show and moderate ratings and reviews;
- keep the Platform safe — detecting fraud, abuse, and violations of our Terms;
- improve and develop our services, and measure the performance of features and campaigns, usually using aggregated or de-identified data;
- send marketing and offers where you have not opted out (you can opt out at any time); and
- comply with legal obligations and enforce our agreements.
4. Legal bases for processing
Depending on the activity, we rely on one or more of the following legal bases:
- Performance of a contract — to provide the bookings and services you request.
- Consent — for optional cookies, marketing communications, and access to precise device location. You may withdraw consent at any time without affecting processing already carried out.
- Legal obligation — for tax, accounting, KYC and other statutory requirements.
- Legitimate interests — to secure the Platform, prevent fraud, understand how our services are used and improve them, provided your rights do not override those interests.
6. Payments & financial data
Payments are processed through a secure, PCI-DSS compliant payment gateway. When you pay, your card, UPI or netbanking details are provided directly to the gateway and are not stored on Chefose’s servers. We retain only the information needed to recognise a transaction and support it — such as the amount, method type, a masked reference, and the payment status.
Chefose Wallet balances and transactions are stored so we can show your balance and history and apply credits or refunds. Learn more on our Payment Methods page.
7. Chef verification (KYC) data
This section applies if you apply to cook on Chefose. To meet legal requirements and keep customers safe, we collect and verify:
- Identity — PAN (and the name on it), and the last four digits of your Aadhaar for matching. We ask you to upload a clear copy of the relevant document.
- Bank details — account holder name, account number, IFSC and bank name, used solely to pay you, together with a cancelled cheque or equivalent proof.
- Police / antecedent verification — a certificate confirming you have no disqualifying criminal record.
Verification documents are stored encrypted with access restricted to staff who need them for review. Sensitive numbers are masked in our systems wherever full display is not required (for example, only the last four digits of a bank account are shown back to reviewers). We retain this information for as long as you are an active chef and for the period afterwards that law requires.
9. How long we keep data
We keep personal information only for as long as needed for the purpose it was collected, and then for any additional period required to comply with law, resolve disputes and enforce our agreements. In practice:
- Account data — for as long as your account is active, and a limited period after closure.
- Booking, payment and tax records — for the retention period set by applicable tax and accounting law.
- Chef KYC records — for the duration of the engagement plus the statutory retention period.
- Support tickets and reviews — for as long as needed to maintain a useful history and moderate content.
When data is no longer needed, we delete it or irreversibly anonymise it.
10. How we protect your data
We use technical and organisational safeguards appropriate to the risk, including encryption of data in transit, encrypted storage for verification documents, role-based access controls, masking of sensitive identifiers, network protection and monitoring, and regular review of our practices. No method of transmission or storage is completely secure, but we work to protect your information and to notify you and the relevant authority of a significant breach as required by law.
11. Your rights & choices
Subject to applicable law, you can:
- Access a copy of the personal information we hold about you;
- Correct information that is inaccurate or incomplete — most details can be updated directly in your account;
- Delete your account and associated data, subject to records we must keep by law;
- Withdraw consent for optional processing, such as marketing or device location;
- Opt out of marketing at any time using the unsubscribe link in our emails, replying STOP to messages, or updating your preferences; and
- Nominate another individual to exercise your rights in the event of death or incapacity, and complain to the Data Protection Board of India.
To make a request, contact us using the details in Grievance Officer & contact. We may need to verify your identity before we act, and we will respond within the timeframe required by law.
12. Children’s privacy
The Platform is intended for users aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has provided us information, please contact us and we will delete it.
13. Where your data is stored
Your information is primarily stored and processed in India. Some of our service providers may process data in other countries; where they do, we require appropriate safeguards and contractual protections consistent with applicable law and this policy.
14. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you through the Platform or by email. Your continued use of the Platform after an update means you accept the revised policy.
15. Grievance Officer & contact
For any question, request or complaint about this policy or your personal information, contact our Grievance Officer, who is designated in accordance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023:
- Grievance Officer
- Chefose — Privacy & Data Protection
- grievance@chefose.com
- Privacy queries
- privacy@chefose.com
- General support
- Customer Support · Contact form
We aim to acknowledge grievances within 48 hours and resolve them within the period required by law.








