Privacy Policy

Last updated 25 August 2026

We, MMS Lifestyle LLP (“Crawford2U”, “the Company”, “we”, “us”), are committed to protecting the privacy and security of your personal information. Your privacy matters to us and keeping your trust is paramount.

This policy explains what information we collect, how we use and disclose it, and the rights you have over it. By using the Crawford2Uapp or this website you consent to it, alongside our Terms & Conditions. If you have any questions, write to us at mmslife22@gmail.com.

1. Applicability and scope#

This policy covers the information we collect through the Crawford2U mobile application and this website, and through email and messages sent in connection with them.

It does not cover information you give directly to a third party — for example, the card details you enter with our payment provider, which never reach us. Those are governed by that provider's own policy, and we encourage you to read it.

If you do not provide the information we ask for, we may not be able to offer you all of the service. An address is needed to deliver to you; a phone number is needed to sign you in.

2. Permissible age#

The service is intended for people aged 18 or over — the age at which a person can enter a binding contract under the Indian Contract Act, 1872, and the age below which the Digital Personal Data Protection Act, 2023 treats someone as a child.

We do not knowingly collect personal information from anyone younger, and we do not market to them. If you believe a child has given us their information, contact us and we will delete it.

The Act separately forbids tracking children, monitoring their behaviour, and advertising to them. We do none of those things to anyone, of any age — there is no advertising or analytics SDK in the app at all, as section 8 explains.

3. Information you give us#

Account details
Your name, mobile number and, if you choose to add one, your email address. A mobile number is required because we sign you in with a one-time password rather than a stored password.
Delivery addresses
The address line, city, state and PIN code, plus house or flat number, floor and landmark, and the name and phone number of whoever is receiving the order.
Order information
What you ordered, the amount, the payment method, the delivery status, and a snapshot of the delivery address as it read when you placed the order.
Payment information
Our payment provider handles your card, UPI or netbanking details directly. We never see or store your card number, UPI PIN or CVV — only the provider’s transaction reference, the amount, and whether it succeeded.
Content you submit
Product reviews and ratings, your cart and wishlist, and anything you write to us for support — including the reason you give if you delete your account.

4. Information collected automatically#

Precise location
Latitude and longitude, stored against each saved delivery address so a rider can be routed to the right door. It comes from the pin you drop on the map or the address you choose in search. We ask for device location only while the app is open, and only to centre that map on you — you can refuse and type the address instead, and everything else still works. We never collect location in the background, when the app is closed, or at any moment you are not adding an address.
Push notification token
An identifier issued by Apple or Google for your device, so we can tell you your order has been dispatched or delivered. It identifies a device, not you, and is deleted when you sign out or delete your account.
Crash diagnostics
When the app fails we receive a crash report: the screen you were on, the error, and your device model and operating system version. We use it to fix faults and nothing else.

5. What we never collect#

The app asks for one permission — location, and only while it is open. Specifically, it does not collect:

  • Your contacts or address book.
  • Your photos, camera, microphone, files or any metadata about them.
  • Your SMS messages. We do not send SMS either — one-time passwords and order updates go by WhatsApp, email and push notification only.
  • Any advertising identifier, and no profile of you is built for advertising.
  • A list of the other applications installed on your phone.
  • Health, biometric, financial-account or government-identifier data.
  • Your location in the background, or at any time the app is not open.

There is no advertising SDK and no analytics SDK inside the app, and nothing in it tracks you across other apps or websites.

6. How we use your information#

  • To create and secure your account, and to sign you in by one-time password.
  • To take payment, place your order, and get it to the right door — which is what the delivery coordinates are for.
  • To keep you informed about that order, by push notification, WhatsApp and email.
  • To handle cancellations, refunds and returns, and to answer your questions.
  • To detect and prevent fraud and abuse of the service.
  • To find and fix crashes, so the app stays usable.
  • To meet our legal obligations, including keeping invoices and tax records.

Our lawful basis is the consent you give when you create an account and place an order, and, for accounting and tax records, compliance with a legal obligation.

We do not use your information to advertise to you, and we do not sell or rent it to anyone.

7. How we share your information#

We share personal information only with the parties that make the service work, and only with what each one needs:

Delivery agents
The recipient’s name, phone number, delivery address and coordinates, and the cash to collect for a cash-on-delivery order. Restricted to the agent assigned to your order.
Payment gateway
Handles the transaction. It receives the amount, the order reference and your contact details, for receipts and for handling chargebacks. It is PCI-DSS compliant.
WhatsApp messaging provider
Your mobile number, to deliver one-time passwords and order updates.
Email provider
Your email address and order details, to send confirmations and receipts.
Apple and Google
Push notification tokens, so notifications reach your device.
Error monitoring
Crash diagnostics from the app, to find and fix faults.
Hosting and infrastructure
Our servers and database are run by third-party hosting providers under contract.
Legal authorities
Where we are required to disclose by law, or to establish, exercise or defend a legal claim, or to investigate fraud or a threat to someone’s safety.
A successor
If the business is sold or merged, customer information may transfer as part of it. This policy continues to apply until you are told otherwise.

Everyone above acts on our instructions and is contractually bound to keep your information confidential and to use it only for the purpose we gave it to them for.

8. Cookies and tracking#

On this website

We use Google Analytics to understand how the site is used — which pages people reach and how they arrive. It sets cookies in your browser and records a truncated version of your IP address. You can block these through your browser settings or a tracker-blocking extension, and the site works normally without them.

In the Crawford2U app

The app uses no cookies, no analytics SDK and no advertising SDK. It stores two things on your own device — the token that keeps you signed in, and your cart — so neither is lost between visits. Both stay on the phone and are removed when you sign out or clear the app's data.

9. How long we keep it#

Account details
While your account is open, then deleted as described below.
Orders and invoices
Eight years from the transaction, because India’s tax and companies legislation requires it. This survives account deletion — see below.
Crash diagnostics
Up to 90 days.
One-time passwords
Minutes. They expire shortly after being issued.
Backups
Copies may persist in backup storage for up to a further 30 days after deletion, until that storage is overwritten on its normal rotation.

10. Your rights#

Under the Digital Personal Data Protection Act, 2023 you may:

  • Ask what personal information we hold about you and how it has been shared.
  • Have anything inaccurate corrected — most of it you can edit yourself in the app.
  • Have your information erased, subject to the retention periods above.
  • Withdraw consent, including by turning off notifications or revoking location permission in your device settings.
  • Nominate someone to exercise these rights on your behalf if you die or become incapacitated.
  • Complain to us, and to the Data Protection Board of India if we do not resolve it.

To exercise any of these, contact our Grievance Officer below. We may need to verify your identity first, usually by confirming control of your registered mobile number.

These rights may be limited where a request is excessive or repetitive, where acting on it would affect someone else's rights or safety, or where the information relates to a legal claim between us.

You cannot opt out of essential messages about an order you have placed — a delivery update is part of the service, not marketing.

11. Deleting your account#

You can delete your account at any time from Profile → Account privacy → Request to delete account in the app, or by writing to mmslife22@gmail.com from the number registered to it.

What is deleted

  • Your name, email address and mobile number.
  • Every saved delivery address, including its coordinates, landmark and receiver details.
  • Your cart, wishlist, saved preferences and product reviews.
  • Push notification tokens for every device, so notifications stop at once.

What is kept, and why

Order and invoice records are retained for eight years, as tax and companies legislation requires. They are held as accounting records, are not used to contact you, and are not used to build any profile of you.

If an order is still on its way, the request is accepted but completes once that delivery finishes. Your account is closed to new orders in the meantime, and you can withdraw the request until it completes. Deletion is permanent — we cannot restore an account or its history afterwards.

12. How we protect your information#

  • All traffic between the app, this website and our servers is encrypted in transit using HTTPS/TLS.
  • Data is held in managed databases with access restricted to authorised staff.
  • We never store your card details — they go directly to a PCI-DSS compliant payment provider.
  • Admin and delivery-agent accounts are individually credentialed, and an agent can only see the orders assigned to them.
  • Signing in requires a one-time password sent to your number, so there is no password of yours for us to lose.

No system is perfectly secure, and we cannot accept responsibility for interception beyond our control. Keep control of your mobile number and your device: anything done through your account is treated as done by you. If a breach affects your personal information we will notify you and the Data Protection Board of India as the law requires.

13. Third-party links and services#

The app and this website may link to services we do not operate. We are not responsible for their content or their privacy practices, and this policy does not cover information you give them. We encourage you to read their policies before sharing anything.

14. Changes to this policy#

We may amend this policy to reflect changes in the law, in our practices, or in the service. The date at the top shows when it last changed. Where a change materially affects your rights we will tell you in the app or by email before it takes effect; continuing to use the service after a change means you accept it.

15. Grievance Officer#

In accordance with the Digital Personal Data Protection Act, 2023 and the Consumer Protection (E-Commerce) Rules, 2020, the officer responsible for complaints and for requests about your personal information is:

Grievance Officer
Juzer Motiwala
Email
mmslife22@gmail.com
Phone
+91 98700 77002
Postal address
92 Sarang Street, Mumbai 400003, Maharashtra, India
Response time
Acknowledged within 48 hours and resolved within 30 days of receipt.