Privacy Policy

Canteen Staff App (com.aveoninfotech.canteenapp)

Effective date: 30 June 2026

This Privacy Policy explains how Aveon Infotech Pvt Ltd (“we”, “us”, or “our”) collects, uses, stores and protects information when you use the Canteen Staff App (the “App”). The App is a canteen and mess management tool provided to staff and members of an institution (a college, company, or similar organisation, the “Institution”) that has licensed our platform. By using the App you agree to this policy.

1. Who is responsible for your data

The App is operated by Aveon Infotech Pvt Ltd on behalf of your Institution. The Institution is the owner (data controller) of the account and transaction records; we operate and host the platform on their behalf (data processor). Questions about your account should be directed to your Institution’s administrator or to us at the contact below.

2. Information we collect

We only collect what is needed to run the canteen/mess service:

  • Account & identity information - your username or employee ID, name and (where applicable) mobile number and email address. These are created or provided by your Institution’s administrator, or by you at sign-in.
  • Authentication data - your password (stored only as a salted hash on our server, never in plain text), one-time passwords (OTP) sent to your mobile number for login and secure session tokens. Session tokens and a randomly generated device identifier are stored in your device’s encrypted secure storage to keep you signed in and to protect your session.
  • Service & transaction data - meal bookings, meal-token QR codes issued to you, wallet balance and transactions and the canteen/mess location you belong to. This is the operational record of the service.
  • Technical data - basic information required to deliver the service over the internet, such as app version and error/diagnostic logs used to keep the App working.

3. What we do NOT collect

  • We do not collect your GPS or precise/physical location.
  • We do not access your camera, contacts, photos, messages, or call logs.
  • We do not use third-party advertising or marketing trackers.
  • We do not sell or rent your personal information to anyone.

4. How we use your information

  • To authenticate you and keep your session secure.
  • To issue, validate and redeem meal tokens and operate the wallet.
  • To maintain accurate canteen/mess records for your Institution.
  • To detect and prevent fraud, abuse and unauthorised access.
  • To diagnose problems and improve the reliability of the App.

We process this data to provide the service you and your Institution have requested, to meet our legitimate interest in operating it securely and where required, with your consent.

5. Device permissions

  • Internet/Network access - the only permission the App requests; required to communicate securely with the service. The App does not request camera, location, storage, or any other device permission.

6. How your information is shared

We share information only as follows:

  • With your Institution - administrators of your Institution can see the account and transaction records relevant to running the canteen/mess.
  • With service providers - the secure cloud hosting and infrastructure used to run the platform on the Institution’s behalf. These providers process data only to host the service and are bound to keep it confidential.
  • For legal reasons - if required by law, regulation, or a valid legal request, or to protect the rights, safety and security of users and the service.

We never sell your data or use it for third-party advertising.

7. Data storage & security

All communication between the App and our servers is encrypted in transit using HTTPS/TLS. Passwords are stored only as salted hashes; session tokens are kept in your device’s encrypted secure storage. Data is hosted on secured servers operated for your Institution. We apply access controls and reasonable technical and organisational measures to protect your information. No method of transmission or storage is 100% secure, but we work to protect your data using industry-standard practices.

8. Data retention

We retain account and transaction data for as long as your account is active and as long as needed to provide the service and meet your Institution’s record-keeping and legal obligations. When data is no longer required, it is deleted or anonymised. Session tokens on your device are cleared when you sign out.

9. Your rights & account/data deletion

Subject to your Institution’s policies and applicable law, you may request to access, correct, or delete your personal data. Because accounts are managed by your Institution, the fastest route is usually your Institution’s administrator. You may also contact us directly:

To request deletion of your account and associated personal data, email support@aveoninfotech.com from your registered email or include your username/employee ID. We will verify the request and delete or anonymise your personal data, except records we are required to retain for legal or accounting purposes, within a reasonable period.

10. Children's privacy

The App is intended for staff and authorised members of an Institution and is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will remove it.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Effective date” above and, where appropriate, through the App. Continued use of the App after changes take effect constitutes acceptance of the updated policy.

12. Contact us

If you have any questions about this Privacy Policy or your data, contact:

Aveon Infotech Pvt Ltd
Email: support@aveoninfotech.com