Legal

Privacy Policy

We collect what is needed to get food to your door and to let a vendor run their deliveries. We hold no card or bank details, we run no advertising or analytics trackers, and we never sell your data.

Last updated 19 August 2026

1. Who is responsible

The operator of nearsubs.com is the Data Fiduciary for the personal data described here, within the meaning of the Digital Personal Data Protection Act 2023.

2. What we collect

If you are a customer

WhatWhy
Email addressSigning in (a six-digit code), and sending you subscription and bill notices
Name, mobile numberSo the vendor delivering to you knows who to look for and can call
Delivery address - house and street, area, city, pincode, landmarkGiven to the vendor you subscribe to, so they can find you
Subscriptions, pauses, delivery historyRunning the service and showing you what you have taken
Bill records and payment screenshots you choose to uploadSo a vendor can match your payment to the right month. See what we do not hold

If you are a vendor

Your business name and owner name, email, phone, category, city, delivery areas, address, website and social handles, plan and price details, photographs you upload, and your UPI ID and QR image. Most of this is deliberately public - it is your storefront.

If you join the waitlist

Email, and optionally name, phone, city and the services you want. We use it to decide which city to open next and to tell you when we arrive.

Technical

Our servers log the usual request information - IP address, browser user agent, the page requested, the time - for security and diagnostics. Sessions record the IP and user agent they were created from, so you can recognise a session that is not yours.

3. What we deliberately do not collect

  • No card, bank or UPI credentials. There is no payment gateway on this platform. Customers pay vendors directly, and that money never passes through us. A vendor's UPI ID is stored because it is printed on their own storefront; a customer's payment credentials are never seen by us at all.
  • No advertising or analytics trackers. No Google Analytics, no pixels, no third-party tags, no session recording. See cookies below.
  • No location tracking. We know the address you typed. We do not follow a device.
  • No profiling or automated decisions that produce legal or similarly significant effects.

4. Why we are allowed to hold it

Under the DPDP Act 2023 we rely on your consent, given when you create an account, place a subscription request or submit a form; and on certain legitimate uses, such as keeping records we are legally required to keep and preventing fraud or misuse. You may withdraw consent at any time - see your rights.

5. Who else sees it

  • The vendor you subscribe to. They see your name, phone, delivery address, plan, delivery days, pauses and what you owe them. They have to: they are bringing it to your door. They see nothing about your subscriptions with any other vendor.
  • Brevo (Sendinblue), our email provider, which delivers your sign-in codes and notices. It receives your email address and the content of those messages.
  • Our hosting provider, on servers in India, which stores the database and uploaded images.
  • Our own operators, for support and for keeping the marketplace honest. Customer contact details are masked by default in the operator console and can only be revealed by a senior operator through an action that is logged before the data is shown.
  • Authorities, where we are required by law to disclose something.

We do not sell personal data, and we do not share it with advertisers.

6. Cookies

We set five cookies, and every one of them is strictly necessary - remove any and you cannot sign in or stay signed in:

NameWhat it doesLasts
ns_customer_session
ns_vendor_session
Keeps you signed in. Holds a random token, not your details, and is readable only by the server rather than by JavaScript.30 days
ns_admin_sessionThe same for a NearSubs operator. Set only on our operator host, and never sent to nearsubs.com.12 hours
ns_csrf
ns_admin_csrf
A random value the page echoes back with every change you make, so another site cannot make that change on your behalf while you are signed in.Session

There are no analytics or advertising cookies and no third-party tags, which is why you are not asked to consent to any. If that ever changes we will ask first, and this page will say so.

We also keep one item in your browser's own storage, nearsubs.city, holding the city you last browsed so the site does not ask again on every page. It is never sent to our servers, and clearing your browser data removes it.

Your browser can block or delete cookies under its privacy settings. Because ours hold your session, blocking them means you cannot sign in - everything you can do without an account still works.

7. How long we keep it

  • Account and subscription records: while your account is open.
  • Delivery and billing records: retained after a subscription ends, because they are the vendor's book of account and may be needed for tax and dispute purposes - ordinarily up to eight years.
  • Payment screenshots: until the bill is settled, or until you remove them.
  • Sign-in codes: ten minutes, and single-use.
  • Waitlist entries: until we open your city, or until you ask us to remove you.
  • Server logs: kept only while they are useful for security and debugging, and never used to build a profile of you.

8. How it is protected

  • Everything is served over HTTPS.
  • There are no customer or vendor passwords to steal - sign-in is a six-digit code, hashed before it is stored, valid for ten minutes, single-use, and rate limited.
  • Session tokens are stored only as a hash, so a copy of our database cannot be replayed as a login.
  • The operator console is on a separate host with its own host-only session, password plus an authenticator app, and every cross-account action writes an audit record naming the operator.
  • Every query for your data is scoped to your own account on the server, not filtered in the browser.

No system is perfectly secure. If a breach affects you, we will inform you and the Data Protection Board as the DPDP Act requires.

9. Your rights

Under the DPDP Act 2023 you may ask us to:

  • tell you what personal data we hold about you and who we have shared it with;
  • correct anything inaccurate, or complete anything incomplete;
  • erase it, where we are not required to keep it - note that a vendor's billing record of a delivery already made is generally something they must keep;
  • withdraw a consent you previously gave;
  • nominate someone to exercise these rights if you die or become incapacitated.

Much of this you can do yourself: your name, phone, addresses and subscriptions are all editable from your account. For anything else, write to us below.

10. Children

NearSubs is not for anyone under 18, and we do not knowingly collect data about children. If you believe we hold data about a child, tell us and we will delete it.

11. Changes

We will update this page when what we do changes, and change the date at the top. Where a change is significant we will tell registered users by email.

Contact and grievances

Write to support@nearsubs.com for anything about your account, your data or a vendor.

In line with the Consumer Protection (E-Commerce) Rules 2020 and the Information Technology (Intermediary Guidelines) Rules 2021, our Grievance Officer is:

grievance@nearsubs.com

We acknowledge a complaint within 48 hours and aim to resolve it within 30 days of receipt.