PRIVACY POLICY
Last updated : 04/09/2026
This Privacy Policy ("Policy") is published by Prayosha Food Services Private Limited, a company incorporated under the laws of India ("Petpooja", "Stepwise", "we", "us", or "our"), and describes how we collect, use, share, retain and protect the Personal Information of Users of the Stepwise mobile application, available on the Google Play Store and Apple App Store etc, together with any associated web dashboards or services (collectively, the "App" or the "Service").
This Policy governs only the Personal Information relating to Users that is collected through the App. It does not apply to any other data, including business, operational, aggregated or anonymised data, which is instead governed by the Stepwise Terms of Service ("Terms"). Please read this Policy together with the Terms.
By accessing or using the App, or by clicking "I Agree" or checking the acceptance box presented at sign-up, you confirm that you have read, understood and consented to this Policy. If you do not agree with this Policy, please do not use the App.
1. Introduction
Petpooja operates Stepwise, a task and checklist management application designed for businesses such as restaurant chains, retail stores, salons and hotels (each, a "Customer") to assign, track and verify the daily tasks, checklists and work of their teams. This Policy explains what Personal Information we collect from Users, why we collect it, how it is used and shared, and the rights available to Users under applicable law.
We are committed to processing Personal Information fairly, lawfully and transparently, in accordance with the Digital Personal Data Protection Act, 2023 ("DPDPA"), the rules made thereunder, the Information Technology Act, 2000 and applicable rules (together, "Indian Data Protection Law"), and other applicable law.
2. Definitions
The following terms have the meanings given to them below wherever they appear in this Policy, in addition to any terms already defined in the preamble above:
- "App / Service" – the Stepwise mobile application, available on the Google Play Store and Apple App Store, together with any associated web dashboards, APIs, features and support offered by Petpooja.
- "Applicable Law" – Indian Data Protection Law, together with any other law, regulation, direction or judicial/regulatory order applicable to the collection, use, sharing or protection of Personal Information under this Policy, including the law of any other jurisdiction referred to in Section 3.
- "Board / Data Protection Board" – the Data Protection Board of India, established under the DPDPA, before which a Data Principal may raise a grievance after following the process described in Section 18.
- "Consent" – a Data Principal's free, specific, informed, unconditional and unambiguous indication of agreement to the processing of their Personal Information for the specified purpose, signified by a clear affirmative action, as required under the DPDPA.
- "Customer" – the business (such as a restaurant chain, retail chain, salon, hotel or similar organisation) that registers for or subscribes to the Service to manage the tasks, checklists and work of its team.
- "Data Fiduciary" – the person who, alone or with others, determines the purpose and means of processing Personal Information, as defined under the DPDPA (see Section 4 for how this role applies between Petpooja and a Customer).
- "Data Principal" – the individual to whom certain Personal Information relates — ordinarily, a User.
- "Data Processor" – a person who processes Personal Information on behalf of, and under the instructions of, a Data Fiduciary.
- "DPDPA" – the Digital Personal Data Protection Act, 2023, together with the rules, regulations, notifications and circulars issued or made thereunder, as amended or replaced from time to time.
- "Personal Information / Personal Data" – as information identifiable to an individual.
- "Policy" – this Privacy Policy, as amended, updated or replaced from time to time in accordance with Section 23.
- "Processing" – any operation or set of operations performed on Personal Information, whether by automated means or otherwise, including collection, recording, storage, use, sharing, disclosure, erasure or destruction.
- "Sensitive Personal Data or Information (SPDI)" – categories of Personal Information historically classified as sensitive under the IT Act (such as financial information, health records or biometric data), which Petpooja processes only to the extent, and for the purposes, described in this Policy.
- "Service Provider / Third Party" – any vendor, contractor, sub-processor or other entity engaged by Petpooja to support the provision of the Service, as described in Section 9.
- "Terms" – the Stepwise Terms of Service / Terms and Conditions applicable to use of the App, which govern all data other than the Personal Information covered by this Policy.
- "User" – any individual who accesses or uses the App, whether as an owner, administrator, manager, supervisor, employee, worker, consultant, contractor or other personnel of a Customer, or any other individual enrolled on the App at the request or instruction of a Customer/ Customer themselves.
- "You / Your" – the User reading and accepting this Policy.
Capitalised terms used but not defined in this Policy have the meaning given to them in the Terms.
3. Scope and Applicability
- This Policy applies to Personal Information of Users collected through the App.
- If you are located outside India and believe the DPDPA does not apply to your use of the Service by virtue of your jurisdiction, or if any other data protection law applies to you (such as the GDPR or a similar law), you are requested to inform us promptly at the contact details in Section 25, so that we may apply any additional safeguards required under such law.
- This Policy does not cover data, business records, or other information that does not constitute Personal Information, which shall be governed by the Terms.
4. Relationship Between Petpooja and the Customer
Because Stepwise is used by a Customer to manage its own team, the roles of "Data Fiduciary" and "Data Processor" under the DPDPA may be shared between the Customer and Petpooja depending on the purpose of processing:
- Customer as Data Fiduciary: For purposes that the Customer determines — such as deciding which Users to enrol, what tasks or checklists to assign, employment terms, role hierarchy, performance evaluation, or disciplinary action — the Customer is ordinarily the relevant Data Fiduciary, and Petpooja processes the relevant Personal Information as a Data Processor acting on the Customer's instructions to provide the Service.
- Petpooja as Data Fiduciary: For purposes that Petpooja itself determines — such as account creation and sign-in, OTP verification and fraud prevention, App security, product analytics and improvement, and Petpooja's own legal and regulatory compliance — Petpooja acts as the Data Fiduciary in its own right for that limited processing.
Users are encouraged to also review any internal privacy notice, HR policy or employment terms provided by their Customer, since the Customer may independently process Personal Information outside the App for its own business purposes.
5. Personal Information We Collect
We collect the following categories of Personal Information about Users:
(a) Identity and Contact Information
- Name
- Mobile number and country code
- Email address
- Address / location details provided by you
(b) Account and Sign-Up Information
- Sign-up source
- IP address (retained only to detect and prevent misuse of our OTP / sign-up process)
- Preferred language
(c) Employment and Role Information
- Job title / description and other employment-related details shared by the Customer
- Outlet, team, role and reporting hierarchy assigned by the Customer
(d) Device and Technical Information
- Push notification token, device ID, platform (Android/iOS) and app version
- Notification preferences
(e) Location Information
- Precise or approximate location, collected only where a specific task or checklist step requires location confirmation
(f) Content Provided as Proof of Work
- Profile photo, if you choose to upload one
- Photographs, files and typed answers or readings submitted as proof that a task has been completed
- Voice recordings, captured only when you use voice input to create tasks or request reports, and the text generated from converting such speech
(g) Usage and Communication Information
- Your activity on the App (e.g., tasks viewed, completed, or interacted with)
- Chat history within the App
We do not collect financial or payment card details. Please see Section 8 (Payment Information) below.
6. Why we collect Your Personal Information and how we use it
We use Personal Information to provide, maintain and improve the Service, including, but not limited to:
- Name and mobile number – to identify you, send your sign-in code, and show whose task is whose.
- Mobile number – to deliver invites and notifications, and, in hashed form, to measure the effectiveness of our advertising.
- Push token and device details – to deliver notifications to the correct device.
- Role, outlet and team information – to determine who receives which work and what they can see or access.
- Photos, files and typed answers – to serve as proof that work was completed, for the Customer's manager or administrator to review.
- Location – to confirm that a step occurred at the right place, only where the relevant task requests it.
- Timings and scores – to show the Customer what work is on time, late, or missed.
- IP address – to stop OTP/sign-up abuse, and for advertising/ad-matching with partners such as Meta and Google.
- Preferred language – to display the App in the language you understand.
- In-app behaviour – to improve our product and provide you with better services.
- AI-assisted features – as described in Section 7 below.
We may also use Personal Information for: providing customer support; enforcing our Terms; detecting, investigating and preventing fraud, abuse or security incidents; complying with applicable law, legal process or regulatory requirements; and exercising or defending legal claims.
7. AI-Assisted Features
Where AI-assisted functionality is enabled on the App, we may process the relevant task proof, photo, text or voice input to generate an opinion, summary, task, checklist or other output. For example:
- A submitted proof photo may be analysed to determine whether it appears to show what the task requested.
- Your speech may be converted to text to help you create tasks or checklists, or to generate reports, by speaking instead of typing.
- The App may generate summaries or answer questions about the Customer's own business data.
AI outputs may be incorrect or incomplete. You should review AI outputs and must not treat them as definitive factual, legal, HR, safety or compliance determinations. The Customer remains responsible for any decision it makes based on an AI-assisted output.
Responsible use: When using AI features (including voice-to-text and photo-based features), you must not input, upload or dictate any Personal Information of a third party that is sensitive in nature — such as financial account details, health records, government-issued identity numbers, or information relating to a child — unless you are legally authorised to do so and have obtained all consents required under applicable law. You remain solely responsible for the content you provide to AI-assisted features.
We will identify AI-assisted features within the App interface as they are implemented. The underlying data flows and third-party AI providers may vary by feature and will be updated in this Policy or in applicable in-app notices as necessary.
8. Payment Information
We do not collect or store any financial or payment card details. If you or your Customer choose to make a payment (for example, to subscribe to the Service), such payment will be processed by a third-party payment gateway or financial institution, and your payment information will be collected and stored by that third party, not by us. We request that you review the privacy policy of the relevant payment gateway or institution, and continue only if you agree with it.
9. Sharing and Disclosure of Personal Information
We may share Personal Information with third parties only to the extent reasonably required to provide the Service, including with:
- Cloud hosting and infrastructure providers who store and process data on our behalf
- Communication service providers (for SMS, OTP, email, push notifications and similar communications)
- Analytics and advertising partners, such as Meta and Google (see Section 11 below)
- Professional advisors (such as auditors, legal and compliance consultants), where necessary
- Government, regulatory or law enforcement authorities, where required by law (see Section 22)
- A successor entity, in connection with a merger, acquisition, restructuring or sale of assets
- Customer administrators, who may view certain Users' content based on the organisation's internal hierarchy on the App
Such third parties may be located in India or outside India. We require our service providers to protect Personal Information in a manner consistent with this Policy and applicable law, through appropriate contractual and technical safeguards.
10. Cross-Border Transfer of Personal Information
Personal Information may be stored, processed or transferred to servers or service providers located in India and, where applicable, in other countries where our infrastructure and third-party service providers operate. Such transfers, where they occur, are made subject to contractual and technical safeguards intended to protect your Personal Information, and in accordance with any restrictions notified by the Government of India under the DPDPA from time to time.
11. Advertising Identifiers, Analytics and Tracking
The App may use Meta and Google SDKs for event tracking, marketing and optimisation. Depending on your device and configuration, these SDKs may collect mobile advertising or device-related identifiers such as GAID, IDFA or similar identifiers, and may use your mobile number (in hashed form) for advertising measurement.
The App may also send events and usage data to Petpooja's servers, which may be used for analytics, product improvement, advertising measurement, attribution and related business purposes. Such data points may include app open, first app open, outlet added, team created, user added, onboarding completed, and other similar interaction events described in this Policy. We do not intend to use unrelated screen activity or inspect other applications on your device.
Platform-level permissions and controls offered by Android or iOS (such as "Limit Ad Tracking" or App Tracking Transparency) may affect the availability of certain identifiers or analytics functionality, and you may adjust these through your device settings.
12. Cookies and Similar Technologies
What are cookies? Cookies are small text files placed on your device when you visit a website, which help remember your preferences and understand how the application/ website is used. Our website/ application(where this Policy is published) may use cookies for essential functionality, analytics and, where applicable, advertising measurement. Within the App itself, similar functions are performed by the device and SDK identifiers described in Section 11 above, rather than browser cookies.
You can manage or disable cookies through your browser settings, and manage mobile advertising identifiers through your device's privacy settings. Disabling certain cookies or identifiers may affect the functionality of our website or certain features of the App.
13. Consent
By using the App and accepting this Policy (including by clicking "I Agree" or checking the applicable box), you consent to the collection, use, sharing and other processing of your Personal Information as described in this Policy, in accordance with the DPDPA and other applicable law.
Where a Customer provides us with Personal Information of its Users (such as name, mobile number, or employment details), the Customer represents and warrants that it has a valid legal basis to collect and share such Personal Information with us (whether through consent, the employment relationship, or otherwise), and that it has informed the relevant Users accordingly.
You may withdraw your consent at any time by contacting us at the details in Section 25, subject to: (a) the lawfulness of any processing carried out prior to withdrawal; and (b) the consequence that certain features of the App may no longer be available to you following withdrawal.
14. Users Below the Age of 18
The App is designed primarily for adult Users. However, we recognise that a Customer's workforce may, in limited and lawful circumstances (such as interns or apprentices), include individuals below the age of 18.
- Guardian consent required: Where a Customer wishes to enrol a User who is below 18 years of age, the Customer must first obtain verifiable consent from that User's parent or lawful guardian, in accordance with the DPDPA, before granting the User access to the App. The Customer must retain evidence of such consent and provide it to us upon request.
- No harmful processing of children's data: We do not knowingly undertake tracking, behavioural monitoring, or targeted advertising directed at Users identified as being below 18 years of age, and we do not process such Users' Personal Information in a manner likely to cause detrimental effect to their wellbeing, in accordance with Section 9 of the DPDPA.
- Customer's undertaking: Where a Customer shares the Personal Information of any User below 18 years of age with us, the Customer undertakes and warrants that it has obtained the necessary consent of that User's parent or lawful guardian, and shall indemnify Petpooja against any claim arising from a breach of this undertaking.
- Self-identification: If you are a User below the age of 18 and are using the App without the knowledge of your Customer having followed the process above, please inform us immediately at the contact details in Section 25 so that we can take appropriate action.
15. Retention
We retain Personal Information for as long as reasonably necessary for the purposes for which it was collected, for the duration of the Customer's relationship with us, and thereafter for the periods required or permitted by law, legitimate business needs, security, dispute resolution, fraud prevention, backup cycles and enforcement of legal rights.
- For trial accounts that do not convert to a paid subscription, data may be retained for up to one (1) year after trial expiry, unless the Customer requests deletion and such deletion is legally permissible.
- After subscription expiry or account closure, data may similarly be retained for up to one (1) year, unless deletion is requested, subject to legal or legitimate retention requirements.
- Where we receive a valid deletion request, we intend to delete the relevant Personal Information within thirty (30) days of receiving the request, subject to data that must be retained by law or that is reasonably necessary for security, fraud prevention, dispute resolution, or legal claims. Backup copies may persist until overwritten in the normal backup cycle.
16. Security Measures
We use reasonable technical and organisational measures designed to protect Personal Information, including encryption and access controls as implemented in our Service environment.
No security system is completely secure, and we do not guarantee that Personal Information will never be accessed, disclosed, altered or destroyed by an unauthorised third party. Users and Customers are responsible for protecting their own devices, SIM cards, passwords, OTPs, authentication codes and administrator credentials. We are not responsible for unauthorised use resulting from credentials or devices that a User or Customer failed to secure.
Further, we shall not be liable for any breach or loss of data that may occurred to you due failure of any third-party service providers. Such third party shall process your Personal Information in accordance with their policies and hence, it is advised that you go through their policies.
17. Your Rights as a Data Principal
Subject to applicable law and the date from which the relevant statutory provision comes into force, you (as a Data Principal) may have the right to:
- Obtain information about your Personal Information and how it is processed;
- Request correction and updating of inaccurate or incomplete Personal Information;
- Request erasure of your Personal Information, where applicable and subject to lawful retention requirements;
- Withdraw consent, where processing is based on consent, subject to the lawfulness of processing already undertaken and the consequences of withdrawal;
- Seek grievance redressal from us and, where permitted by law and after following the required grievance process, approach the Data Protection Board of India;
- Nominate another individual to exercise your rights in the event of your death or incapacity, where such a right is available under applicable law; and
- Exercise any additional rights conferred by amendments, rules, notifications or other applicable law.
As a Data Principal, you also have certain duties under applicable law, including to provide truthful and accurate information, not impersonate another person, not file frivolous grievances or complaints, and comply with applicable law when exercising your rights.
Requests should be sent to the contact details in Section 25. We may need to verify your identity, authority and Customer relationship before acting on a request. Where the Customer is the relevant Data Fiduciary for workforce data, we may forward your request to the Customer, or request the Customer's assistance to determine the appropriate response.
18. Grievance Redressal
Questions, complaints or privacy grievances concerning our own processing may be sent at the contact details in Section 25. We intend to provide a reasonable mechanism to acknowledge, investigate and resolve grievances in accordance with applicable law.
19. Communications From Us
We may contact Users and Customers through SMS, email, push notification, WhatsApp, in-app messages for purposes including:
- Sending OTPs and verifying your account;
- Transactional, service and account-related updates (such as task assignments, reminders and reports);
- Security alerts and notices regarding suspicious activity;
- Legal notices and updates to our Terms or this Policy;
- Feature announcements and product updates; and
- Where permitted by applicable law, marketing or promotional communications (see Section 20 below).
By registering on the App, you consent to receive the above communications on your registered mobile number and email address. Transactional, security, account, service and legal communications are necessary for us to provide the Service and cannot be opted out of. You may update your communication preferences, where an opt-out is available, by contacting us at the details in Section 25.
20. Marketing and Promotional Communications
We may send operational updates and, where permitted by applicable law, marketing or promotional communications based on your account status, sign-up information and relevant activity.
Where applicable, you can opt out of marketing communications by writing us on details given in Section 25. Transactional, security, account, service, legal and other essential communications may continue, as they are necessary to provide the Service or to comply with law.
Where communications are made through telecom channels, we and the Customer will use applicable telecom and commercial-communication mechanisms and preferences. The Customer is responsible for the lawfulness of any business communications it initiates on its own behalf through the Service.
21. User Content and Workplace Communications
Stepwise allows Users to upload content as proof of work and, where enabled, to leave task-specific comments. Users must not upload content that is unlawful, abusive, defamatory, discriminatory, obscene, sexually explicit, indecent, threatening, harassing, invasive of another person's privacy, or otherwise prohibited by the Terms.
Customer administrators may view certain Users' content based on the organisation's hierarchy within the App. The Customer is responsible for ensuring that such access is used lawfully and only for legitimate business purposes.
22. Legal, Regulatory and Government Disclosures
We may disclose Personal Information where required by law, legal process, or a governmental or regulatory direction, or where reasonably necessary to protect the rights, safety, property or security of Petpooja, Users, the Customer, or the public.
We may also preserve or disclose information to establish, exercise or defend legal claims, enforce our Terms, investigate fraud or abuse, or protect the Service.
23. Changes to this Privacy Policy
We may update this Policy to reflect product changes, vendor changes, legal requirements, security improvements, new features, or changes in our data practices. The updated Policy will be published, or otherwise made available, through reasonable notice mechanisms (such as an in-app notice or updated "Effective Date").
Where a change materially affects the legal basis, purpose or nature of processing, and applicable law requires fresh notice or consent, we will implement the required mechanism before commencing the affected processing.
24. Governing Law and Jurisdiction
This Policy shall be governed by the laws of India. Subject to the dispute resolution provisions (if any) in the Terms, the courts at Ahmedabad shall have exclusive jurisdiction over any disputes arising out of or in connection with this Policy.
25. Contact Us
Privacy requests, complaints and questions should be sent to us at:
https://api.gostepwise.ai/support or at sahil.malhotra@petpooja.com. The Customer should also provide its own internal privacy or grievance contact information to its Users where the Customer acts as the relevant Data Fiduciary for a particular matter.
26. Acceptance
This Policy is published on our website and forms part of the sign-up process for the App. By clicking "I Agree" or checking the acceptance box presented during registration, you confirm your acceptance of this Policy and consent to the processing of your Personal Information as described herein.