Privacy Policy
Last updated 8 September 2026
This policy explains what LaGo collects, why, who else sees it, and how to have it removed. It covers the LaGo customer app, the LaGo Merchant Partner app, the LaGo Delivery Partner app, and this website.
We do not sell your data and we do not run advertising. There is no advertising network, no analytics service and no tracking library in any LaGo app.
This policy is published under the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. In the language of that first Act, you are the Data Principal and LaGo is the Data Fiduciary — we decide what is collected and we are answerable for it.
1. What everyone gives us
Four things are the same whoever you are, because signing in and reaching you work the same way for all of us.
- Your email address. The only way to sign in. We email you a one-time code, so there is no password for us to store or for anyone to steal.
- Your name. So that the people meeting at a handover know who they are looking for.
- Your phone number. So a delivery can be sorted out by phone when something goes wrong. Who can see it, and for how long, is set out below.
- A notification token from your device. An identifier your phone gives us so order updates can reach it. It identifies the app installation, not you, and it changes if you reinstall.
2. If you order — the customer app
In addition to section 1, we hold:
- Your delivery addresses, to bring the order to you and to check that we deliver to your pincode at all.
- Your location, only if you allow it. Used for one thing: dropping a pin on an address while you are adding it. The app asks only when you tap for it, reads your location only while it is open, and never in the background. We do not track your movement. Declining costs you nothing beyond typing the address yourself.
- Your orders and their history, to show you what is on its way, and because completed orders are financial records we are required to keep.
- Reviews and support messages you write. A review you leave publicly shows your first name to anyone looking at that store.
- A profile photo, if you add one. Shown to you, in your own profile. Stores and delivery partners do not see it.
A store sees your first name and what you ordered — not your phone number, address or email. A delivery partner sees your name, phone number and delivery address, and only for an order they are actually carrying; it stops being visible to them once that order is finished.
3. If you sell — the Merchant Partner app
In addition to section 1, we hold:
- Your business details: store name, description, address and contact numbers. Most of this is shown to customers deciding where to order from.
- Registration and tax identifiers: FSSAI licence, PAN, and GSTIN where you have one. We need them to confirm you may lawfully sell food, and for tax records on what you earn.
- Your bank account number and IFSC, used to pay you what you have earned and for nothing else. Never shown to customers or delivery partners.
- Photographs of those documents, reviewed by our operations team when you join and when something needs renewing. They are stored privately, are never publicly addressable, and each authorised view is time-limited.
- Your orders, menu and settlements: what you sold, what you earned, and what we have paid you.
Customers see your store name, description, address, opening hours, menu and rating. Your documents, bank details and identifiers are never shown to anyone outside our operations team.
4. If you deliver — the Delivery Partner app
In addition to section 1, we hold:
- Your personal details: name, phone number and address, for identity verification and so operations can reach you about a delivery.
- Identity and licence details: your driving licence and its expiry, your PAN, and only the last four digits of your Aadhaar number — never the whole one.
- Your vehicle details: type and registration, so a store and a customer know what to expect at the door.
- Your bank account number and IFSC, used to pay your earnings and for nothing else.
- Photographs of those documents, stored privately, never publicly addressable, and readable only through time-limited access.
- Your deliveries and earnings: which orders you carried, what happened to each, and what you were paid.
We do not track where you are. The delivery app does not ask for location permission and does not read your position, either while you work or afterwards. Orders are offered to whoever is online with a free slot, not to whoever is nearest, and we hold no record of anywhere you have been.
Customers see your first name and rating while you are carrying their order, and your phone number only so the delivery can be completed. Your documents, address and bank details are never shown to a customer or a store.
5. What we deliberately do not collect
- No card, UPI ID or bank detail from customers. LaGo is cash on delivery. You pay the delivery partner at your door, in cash or by scanning our QR code with your own banking app. That payment happens entirely outside LaGo and we never see your payment credentials.
- No live tracking of anyone. We cannot show you a moving dot on a map, because nothing reads a delivery partner's location.
- No advertising identifiers and no cross-app tracking.
- No microphone access and no access to your contacts. Neither permission is requested by any LaGo app.
6. Who else sees your information
We do not sell or rent personal information. It reaches other people in two ways only: the people you are transacting with, as set out in sections 2 to 4, and a small number of service providers who run parts of the service on our behalf.
Those providers fall into four categories:
- A notification service, which delivers order updates to your device.
- An email service, which sends your sign-in code.
- Cloud hosting and storage providers, which run the service and hold verification documents.
- An error-monitoring service, which records technical faults so we can fix them. Sign-in codes, order codes, identity numbers and bank details are removed before anything is sent to it.
Each of them is bound by contract to process information only on our instructions and not for their own purposes. Some are located outside India, and where information is transferred abroad we do so in accordance with the Digital Personal Data Protection Act, 2023. We may also disclose information where the law requires it of us, or to establish or defend a legal claim.
7. How long we keep it
- Used or expired sign-in codes are deleted automatically after 7 days.
- Expired or signed-out sessions are deleted automatically after 30 days.
- Documents uploaded but never submitted are deleted automatically within the hour.
- Orders, payments and payouts are kept for as long as tax and accounting law requires, including after an account is closed.
8. Deleting your account
Every LaGo app can delete your account from inside it, under Profile. There is no email to send and no form to fill in.
When you delete your account we overwrite the personal information on it. Your name, email, phone number, addresses, documents and bank details are replaced, and you can no longer sign in. The order, payout and tax records those details were attached to survive, because we are required to keep them and because the other party to a completed order has a right to their own history. Nothing identifying you remains on them.
You cannot delete an account while an order is still in progress or money is still owed to you. The app will tell you which, and you can delete once it is settled.
9. Your rights under Indian law
Under the Digital Personal Data Protection Act, 2023 you have the following rights, and you can exercise any of them by writing to us at privacy@lagolavasa.com.
- To know what we hold. A summary of your personal data, what we are doing with it, and who we have shared it with.
- To have it corrected or completed. Most of it you can already edit yourself in the app.
- To have it erased, where we are no longer required to keep it. Section 8 explains what survives account deletion and why.
- To nominate someone to exercise these rights on your behalf if you die or become unable to act.
- To complain, first to our Grievance Officer in section 13, and then to the Data Protection Board of India if you are not satisfied with our answer.
We will respond within 30 days. You also have a duty under that Act not to impersonate anyone else and not to file false or frivolous complaints.
Some of what we hold about merchant and delivery partners — bank account details in particular — is Sensitive Personal Data or Information under the 2011 Rules, and is handled accordingly.
10. Keeping it safe
We follow reasonable security practices and procedures as required by the Information Technology Act, 2000 and the rules made under it, appropriate to the sensitivity of what we hold. In particular:
- Everything sent between the apps and our systems is encrypted in transit. Unencrypted connections are refused.
- Verification documents are stored privately and are never publicly addressable. Each time an authorised person views one, the access is time-limited and expires.
- Handover codes are stored in a form that cannot be read back, and each party can see only their own.
- Access to our internal tools is restricted by role, and every action taken in them is recorded.
No system is perfectly secure. If a breach affects you, we will notify you and the Data Protection Board of India as the law requires.
11. Children
The Digital Personal Data Protection Act, 2023 treats anyone under 18 as a child, and requires verifiable parental consent before their data may be processed. LaGo is not intended for children and we do not knowingly collect their information. We do not track children, show them targeted advertising, or process their data in any way likely to harm them. If you believe a child has given us information, write to us and we will remove it.
12. Changes to this policy
If we change this policy we will update the date at the top, and for anything significant we will tell you in the app before it takes effect.
13. Grievance Officer
In accordance with the Information Technology Act, 2000 and the rules made under it, and with the Digital Personal Data Protection Act, 2023, you may raise any complaint about how your information has been handled with our Grievance Officer.
grievance@lagolavasa.com
LaGo · Lavasa, Maharashtra, India
We acknowledge complaints within 48 hours and aim to resolve them within one month of receipt. If you remain dissatisfied, you may approach the Data Protection Board of India.
14. Contact
privacy@lagolavasa.com
LaGo · Lavasa, Maharashtra, India