Privacy policy

Desi Global Bites · ABN 48 701 418 671 · Last updated 15 September 2026

This policy explains how Desi Global Bites handles your personal information, and how we meet our obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Online ordering for Desi Global Bites is provided by OrderMint, which stores and processes this information on the shop’s behalf.

What we collect

When you place an order we collect only what is needed to prepare and deliver it:

  • your name;
  • your mobile number, so we can text you order updates;
  • your email address, so we can send your confirmation and tax invoice;
  • your company name, if you give one (catering orders are often for a workplace);
  • your delivery address and suburb, for delivery orders;
  • any notes you add to the order — please include dietary or allergy information here if it is relevant, and nothing more sensitive than that; and
  • the contents, time and total of your order.

If you send us a message or ask for a table, we collect what you put in that form: your name and phone number, your email address if you give one, the date, time and party size for a table request, and whatever you write in the message. We use it to answer you and for nothing else — you are not added to a mailing list, and we do not pass it on to anyone except the service providers listed below that run this site.

We never see or store your card details. Card payments are entered directly into a secure form hosted by Stripe and go straight to Stripe. Your card number never reaches our servers, and we only ever receive confirmation that a payment succeeded.

Why we collect it

To take, prepare, and deliver your order; to contact you about it; to issue a tax invoice as required by Australian tax law; to process a refund if one is due; to find and fix faults in the ordering system; and to keep the business records we are legally obliged to keep.

Who we share it with

We do not sell your personal information, and we do not use it for marketing unless you ask us to. You can ask in two ways: by ticking the box at checkout, or by pressing the button on your order confirmation. If you ask, we keep your email address (and your name, if you gave it with an order) for that purpose until you unsubscribe — every such email carries a one-click unsubscribe link that needs no sign-in, and we act on it immediately. Order confirmations and tax invoices are separate and are not marketing; you receive those because you placed an order. We share it only with the service providers that make ordering work:

  • Stripe — card payment processing (United States and Australia).
  • Twilio — sending order-status text messages (United States).
  • Resend — sending confirmation emails and tax invoices (United States).
  • Neon — database hosting (Sydney, Australia).
  • Fly.io — application hosting (Sydney, Australia).
  • Sentry — error monitoring, so we find out when something breaks (stored in the European Union, in Germany).
  • Integration partners the shop enables — for example KarmasAI, which can answer the shop’s phone and take your order. If you order by phone through such a service, it passes us your name, phone number, delivery address, order and any allergy information you give, and can read back the orders it placed so it can tell you how they are going. It receives nothing about orders you place on the website or at the counter.

Before an error report goes to Sentry we remove your name, mobile number, email address, company, delivery address and order notes, and blank out anything else that looks like an email address or phone number. That removes almost everything, but not always all of it: a piece of personal information can occasionally still appear in the text of an error. Sentry keeps error reports for a limited period (currently 30 days) and is not sent your IP address.

Some of these providers are located overseas, so under APP 8 your information may be disclosed outside Australia — principally to the United States, and to Germany for error reports. We only use providers that commit to protecting it under contractual and legal safeguards.

How we protect it

Your information is encrypted in transit (HTTPS on every page) and encrypted at rest by our database provider. Access to order data is restricted to the shop it belongs to and to authorised OrderMint staff, is protected by individual accounts rather than shared passwords, and administrative actions are recorded in an audit log.

How long we keep it

We keep messages and table requests for twelve months from the date you contact us, after which they are deleted. We keep order records identifying you for two years from the date of your order, after which they are deleted or de-identified. Some records must be retained for longer where tax law requires it; those are kept only for that purpose.

Accessing or correcting your information

Under APP 12 and APP 13 you may ask for a copy of the personal information we hold about you, or ask us to correct it. Email privacy@ordermint.com.au or contact Desi Global Bites directly on 0495 021 313. We will respond within 30 days. You can also ask us to delete your information, and we will do so unless we are required to keep it.

Complaints

If you think we have mishandled your personal information, please tell us first at privacy@ordermint.com.au so we can put it right. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.

Data breaches

If a breach of your personal information occurs that is likely to result in serious harm, we will notify you and the OAIC as required by the Notifiable Data Breaches scheme.

Changes

If we change this policy we will update the date at the top of this page. Material changes will be notified at checkout.

Privacy policy — Desi Global Bites