Policy

Privacy Policy

Effective 5 September 2026 · Version 1.0 · Applies to the Bento app and createbento.in

This Privacy Policy explains what personal data Bento Ventures (“Bento”, “we”, “us”) collects when you use the Bento mobile app, the Bento website at createbento.in, the Bento partner dashboard and the Bento staff app (together, the “Service”), why we collect it, who we share it with, how long we keep it, and the choices you have.

We are a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (“DPDP Act”). This policy is also published in compliance with the Information Technology Act, 2000 and the rules made under it. By creating an account you consent to the processing described here. You can withdraw consent at any time by deleting your account.

The short version

  • We collect the minimum needed to run a dine-in discovery and rewards service: your phone number, a display name, the content you post, where you are when you ask for nearby places, and what you claim, book, pay and redeem.
  • We never sell personal data. We never hand restaurants your phone number, your name or your visit history. Restaurants see aggregate figures and the fact that a Bento diner redeemed a specific perk.
  • Payments are handled by Cashfree Payments. We never see or store your card number, UPI PIN or bank password.
  • Your data is stored and processed in India.
  • You can see, correct and delete your data from inside the app. Deletion takes effect within 30 days, except where the law requires us to keep a record.
  • You must be at least 18 to use Bento.

1. What we collect

1.1 Information you give us

  • Account. Your mobile number (verified by a one-time code, currently delivered over WhatsApp, so you need a WhatsApp account on that number to sign in), a display name or handle, and optionally a profile photo, a short bio and your food preferences.
  • Content. Videos, photos, captions, restaurant tags, and comments you post. Content you post to the public feed is public.
  • Commercial actions. Perks you claim, Dine Passes and experiences you buy, tables you book, group plans you join, and the offer terms locked at that moment.
  • Bill verification. To release a reward we verify your visit against the restaurant's bill. This may include a photo of the bill or the bill total and time as confirmed by restaurant staff.
  • Payout details (creators only). Bank account or UPI ID in your name, and PAN where tax law requires deduction at source.
  • Support. Messages you send us and the details you include in them.

1.2 Information collected when you use the Service

  • Location. With your permission, your approximate location to show nearby restaurants (“Near Me”, “Tonight”), and your precise location at the moment you check in at a restaurant, to confirm you are there. We do not track your location in the background. You can use most of Bento with location off; check-in may then rely on the table QR code alone.
  • Camera and photo library. Only when you choose to record or upload content, scan a QR code or photograph a bill. We strip location and device metadata from every image before it is stored or shown.
  • Usage events. Which reels you watch and for how long, what you skip, save, share and tap, searches, and the screens you visit. These drive the feed ranking and fraud checks.
  • Device and technical data. Device model, operating system, app version, language, IP address, approximate region derived from the IP, crash reports and performance data, and a device identifier we generate to detect duplicate accounts and abuse.
  • Notifications. If you enable them, a push token for your device so we can tell you when a booking is confirmed, an order is ready or a reward is released.

1.3 Information from others

  • Restaurants confirm your check-in and bill through the staff app. They send us the bill amount and time, not your identity; we already know who you are because you checked in.
  • Cashfree Payments tells us whether a payment succeeded, failed or was refunded, the payment method type (for example UPI or card) and a masked reference. Never the full card or account number.
  • Friends who invite you share your phone number with us so we can credit the referral. We use it for nothing else until you sign up.

We do not collect your contacts list, your precise location in the background, or any biometric data. We do not read your messages.

2. How we use it

PurposeWhat we useLegal basis
Create and secure your account; sign you inPhone number, device dataConsent; performance of our contract with you
Show you relevant, nearby food contentLocation, usage events, preferencesConsent
Complete claims, passes, bookings and paymentsCommercial actions, payment statusPerformance of contract
Verify visits and release rewardsCheck-in location, QR scan, bill verificationPerformance of contract; legitimate use for fraud prevention
Pay creators and issue tax documentsPayout details, PAN, attributed transactionsPerformance of contract; legal obligation
Prevent fraud, duplicate accounts and abuseDevice identifier, IP, usage patterns, redemption historyLegitimate use for security
Notify you about your bookings, orders and rewardsPush token, phone numberPerformance of contract
Send marketing messagesPhone number, push tokenConsent, withdrawable at any time in Settings
Fix crashes and improve the ServiceCrash and performance data, aggregated usageLegitimate use
Comply with law and respond to lawful requestsWhatever the request lawfully requiresLegal obligation

We do not use your data for automated decisions that have legal or similarly significant effects on you. Feed ranking is automated but affects only which reels you see first.

3. Who we share it with

3.1 Restaurants

This is the sharing people worry about most, so here is exactly what a restaurant gets:

  • When you check in, staff see your display name or handle, the perk or pass you hold and its locked terms, and whether it has already been redeemed. They do not see your phone number, your other visits, or your history at other restaurants.
  • In their dashboard, restaurants see aggregate figures: how many Bento diners came, what they spent in total, which reels and creators drove visits, and repeat-visit rates. Where a segment is small enough that it could identify you, it is suppressed.
  • Restaurants can ask us to send you a campaign message. We send it; they do not get your number.

3.2 Creators

Creators see how many verified visits their content produced and the rewards earned. They never see who those diners were.

3.3 Other users

Your public profile (handle, photo, bio) and anything you post publicly are visible to other users. Your food diary is private unless you share an entry. Friends you have connected with can see what you choose to share with friends.

3.4 Service providers (Data Processors)

We use a small number of companies to run the Service. Each processes data only on our instructions and under contract:

ProviderWhat they doData involved
Cashfree Payments India Pvt. Ltd.Payment processing, refunds and settlementsAmount, payment method, masked reference, your phone number or email for the payment receipt
Mux, Inc.Video processing and deliveryVideos you upload; playback quality statistics
Cloudflare, Inc.Content delivery, DDoS protection, image and file storageIP address, requested files, images you upload
Meta Platforms (WhatsApp Business)Delivering one-time sign-in codes (the only sign-in channel at present) and transactional messages you have opted intoPhone number, message content
Cloud hosting provider (servers in India)Running our servers and databaseAll data, encrypted at rest
Functional Software, Inc. (Sentry)Crash and error reportingDevice data, app state at the time of an error; personal identifiers are scrubbed

3.5 Legal and safety

We disclose data when the law requires it, in response to a valid order from a court or a government authority empowered to issue it, to enforce our Terms, or to protect the rights, property or safety of Bento, our users or the public. We tell you when we are allowed to.

3.6 Business transfers

If Bento is acquired or merges with another company, your data may transfer to the new owner under this policy. We will notify you in the app before that happens.

We do not sell personal data, and we do not share it with advertisers or data brokers.

4. Where and how long we keep it

Data is stored on servers located in India, encrypted at rest and in transit. Some processors listed above operate globally; where data leaves India it is protected by contract and processed only for the purpose stated.

DataKept for
Account and profileUntil you delete your account, then removed within 30 days
Content you postedUntil you delete it or your account; copies in backups expire within 90 days
Transactions, payments, rewards and payouts8 years after the financial year of the transaction, as required by Indian tax and company law. Anonymised where possible after account deletion
Bill photosDeleted 90 days after the visit is verified, or immediately if verification fails and no dispute is open
Precise check-in locationReduced to “verified at venue” within 24 hours; the coordinate is discarded
Usage events13 months, then aggregated
Fraud and abuse recordsUp to 5 years, to prevent repeat abuse
Support messages2 years after the ticket closes
Server logs90 days

5. Your rights and choices

Under the DPDP Act you have the right to:

  • Access a summary of the personal data we hold about you and how it has been processed. Request it in Settings → Privacy → Download my data, or by email.
  • Correct inaccurate or incomplete data. Most fields you can edit yourself in Profile.
  • Erase your data by deleting your account. See How to delete your account. We keep only what the law requires us to keep, as listed above.
  • Withdraw consent for any processing that relies on it, as easily as you gave it. Turn off location, notifications or marketing in Settings, or delete your account.
  • Nominate another person to exercise these rights on your behalf if you die or are incapacitated.
  • Grievance redressal through our Grievance Officer (section 9), and if you are not satisfied, to complain to the Data Protection Board of India.

We respond to requests within 30 days. We may need to verify that you are the account holder before acting. We will not discriminate against you for exercising any right.

Other controls: you can block or report any user or piece of content from inside the app. You can make your profile private. You can turn off the personalised feed and see content ranked by distance and time alone.

6. Children

Bento is for adults. You must be at least 18 years old to create an account. We do not knowingly collect personal data from anyone under 18. If you believe a child has an account, tell us at privacy@createbento.in and we will delete it.

7. Security

We protect data with encryption in transit (TLS) and at rest, short-lived access tokens, server-side checks on every privileged action, least-privilege access for staff, audit logs on all money and reward state, and regular security testing. Payment card and bank details are never stored on our systems. No system is perfectly secure; if we discover a breach that affects you we will notify you and the Data Protection Board as the law requires.

8. Cookies and similar technology

The website uses no analytics or advertising cookies. The app and the partner dashboard store a session token on your device so you stay signed in, and a device identifier used for security. That is all.

9. Grievance Officer and contact

Grievance Officer
The Proprietor, Bento Ventures
Email
grievance@createbento.in
Privacy requests
privacy@createbento.in
Business
Bento Ventures, Sole Proprietorship, Mysuru, Karnataka, India
Response time
Acknowledged within 24 hours, resolved within 15 days

10. Changes to this policy

When we change this policy we update the effective date at the top and, for material changes, notify you in the app before they take effect. Earlier versions are available on request. Continuing to use Bento after a change means you accept it; if you do not, delete your account.