1. Who we are and how to contact us
Shivshakti Kathiyawadi Restaurant operates from 85B John St S, Hamilton, ON L8N 2C2. Questions, access or correction requests, and privacy concerns may be sent to contact@shivshkti.com or made by calling +1 (905) 522-1555.
2. Information collected for pickup-order requests
When you submit a pickup-order request, we collect the full name, phone number, and email address you provide; requested menu items and one-time pickup tiffins; quantities, selected menu options, one overall order-instructions field, requested or scheduled service date and pickup timing, policy acceptance, consent choices, and technical order identifiers.
The restaurant may record order edits, item substitutions or removals, confirmed pickup time, price and tax calculations, customer approval of material changes, internal operational notes, status history, notification delivery results, payment-at-counter status, and completion or cancellation information.
No card, bank, or online-payment information is collected through the website while the payment method is “pay at restaurant.” Payment is completed using the restaurant’s in-store payment system.
3. Why we use order information
We use order information to receive and review a request, validate current menu and pickup-tiffin prices and availability, contact you about changes, obtain approval before a material addition or price increase, accept or reject the request, prepare the accepted order, send transactional emails, identify the correct customer at pickup, collect payment at the restaurant, respond to support concerns, prevent abuse, and maintain necessary business records.
The first “request received” page or email only confirms receipt. The request becomes an accepted pickup order when the restaurant sends an acceptance or updated-order email and the secure order-status page shows it as confirmed.
4. Secure order-status links and browser storage
Order-status emails contain a high-entropy capability link. The raw access token is not stored in the order database; only a one-way hash is retained. Anyone who receives or copies the link may be able to view the limited order status information available through it, so you should not forward it.
The website uses essential local or session storage to preserve the pickup cart, remember secure order and customer-session tokens, prevent duplicate submissions, maintain security state, and remember optional device settings. Clearing browser data may remove the cart or require you to reopen a secure email link or sign in again.
5. Guest checkout and customer accounts
You may submit an order without signing in. When an order is placed, we link it to a private customer record using the normalized order email and may send a secure, time-limited password-setup link. The login activates only after you use that link and set a password.
Passwords and session tokens are stored as one-way hashes rather than readable text. After activation, the account lets you view current tracking and order history associated with the same verified email. Signing in is optional and does not control promotional consent.
6. Promotional-email consent
Consent to receive offers and restaurant updates is optional, separate from ordering and account creation, and not selected by default. If you opt in, we record the email address, name, consent date, source, and consent-text version needed to manage that choice.
You may withdraw promotional consent at any time. Transactional communications—including request received, order accepted or edited, ready-for-pickup, cancellation, account setup, privacy, security, and customer-service messages—may still be sent when necessary to provide the service you requested.
7. Administrative access, kitchen display, and reports
Authorized restaurant administrators may view customer contact details and combined food-and-tiffin order records in protected dashboard, order-review, notification, and kitchen interfaces when required for their role. Staff should access only the information needed for restaurant operations.
The system may create monthly CSV order reports containing order and customer contact records. These files are stored privately and shared with configured administrative recipients through expiring signed download links. Administrators are instructed to protect downloaded copies and remove them when no longer required.
8. Technical and security information
We may process limited device, browser, network, IP-derived abuse-prevention hashes, timestamps, security logs, error information, and notification records. These help operate the website, prevent duplicate or fraudulent requests, protect accounts, investigate failures, and maintain an audit trail.
Safeguards include restricted administrative access, one-way password and capability-token hashing, server-side menu and price validation, input limits and sanitization, rate limits, duplicate-submission protection, protected data entities, expiring report links, audit events, and separation of public and privileged backend functions. No internet service can guarantee absolute security.
9. Service providers and processing locations
We use service providers to operate the website and restaurant workflows. These may include Base44 for application infrastructure and private file storage, transactional email delivery services, Google for maps and optional business-hours synchronization, and the restaurant’s in-store payment provider.
Providers process information under their own contractual and privacy obligations. Information may be processed or stored outside Ontario or Canada and may be subject to the laws of the jurisdiction where it is processed.
10. Retention and disposal
We retain information only for as long as reasonably necessary for order fulfilment, customer service, accounting and tax records, consent management, operational reporting, dispute handling, abuse prevention, security investigation, and legal obligations. Retention periods may differ by record type.
When information is no longer reasonably required, we take appropriate steps to delete, anonymize, overwrite, or securely dispose of it. A request to delete information may be limited where records must be retained for legal, accounting, security, or dispute purposes.
11. Access, correction, and withdrawal requests
You may ask whether we hold personal information about you, request access to information we can lawfully provide, request correction of inaccurate information, withdraw promotional-email consent, or ask questions about your customer account. We may require reasonable identity verification before responding.
Email contact@shivshkti.com with the subject “Privacy Request,” or call +1 (905) 522-1555.
12. Changes to this policy
We may update this policy when ordering, reporting, account, security, service-provider, or legal requirements change. The current version and update date will be published here.
