What they may do · DPDP §6(4)
What toing does with your data
Toing (operated by Swiggy) collects device, location, order and app-usage data, shares it with vendors, group companies and ad networks, and lets advertising partners track you across other sites and apps.
-
Shares your data with partners
Passed to group companies, advertisers or analytics firms you never chose.
What this costs you. Your number and habits travel to companies you have never heard of and never agreed to. This is the step where the spam calls start.
Show me where they say that
toing’s own policy says “We may share your information with our vendors, consultants, marketing partners, research firms, and other service providers or business partners, such as payment processing companies, for the purposes listed above.”
Our summary names vendors, consultants, marketing partners, research firms and payment processors as recipients; a separate clause also covers sharing with any present or future member of its Group including affiliates, with partner restaurants/merchants, with academic partners, and with advertisers and advertising networks.
-
Builds an advertising profile of you
They watch what you view, tap and buy, and use it to decide which ads you see.
What this costs you. Your attention gets priced. What you hesitate over becomes a bid — and a profile built to predict you is a profile built to persuade you.
Show me where they say that
toing’s own policy says “These third parties may use cookies, JavaScript, web beacons (including clear GIFs), Flash LSOs and other tracking technologies to measure the effectiveness of their ads and to personalize advertising content to you.”
Our summary states that the network advertisers it works with use cookies and other tracking technologies to personalise advertising content shown to the user.
-
Follows you onto other websites and apps
Their tracking carries on after you leave, through pixels and SDKs embedded elsewhere.
What this costs you. You get recognised on sites that have nothing to do with them. Closing the app does not close the file.
Show me where they say that
toing’s own policy says “These entities may use cookies, web beacons, SDKs and other technologies to identify your device when you visit the Platform and use our Services, as well as when you visit other online sites and services.”
Our summary permits third-party measurement, analytics and advertising firms to identify the user's device both on the Platform and when the user visits other online sites and services.
-
Keeps your records long-term
Held on after you stop using the service.
What this costs you. Years after you delete the app, the record is still sitting there — and every year it sits there is another year it can leak.
Show me where they say that
toing’s own policy says “As a result, our use and disclosure of aggregated and/or de-identified information is not restricted by this Policy, and it may be used and disclosed to others without limitation.”
Our summary once information is anonymised or de-identified, its use and disclosure fall outside this policy's restrictions and may continue without limitation.
What the policy does not mention
These are uses toing’s policy is silent on. Silence is not a promise — it means the document does not say, and we do not infer either way.
- Processes your face or other biometrics
- Trains AI models on your content
toing is one app. How many are on your phone?
Most people carry twenty to forty. Add yours and see the total in one screen — how many share your data, profile you for ads, or follow you across the web. Then take it back from all of them at once.
Manage my data with Saaph.in →Free to check · no account needed · built in India for the DPDP Act
Questions
What does toing do with my personal data?
According to toing's own privacy policy, read on 2026-08-14, it discloses 4 of the six uses we track: shares your data with partners, builds an advertising profile of you, follows you onto other websites and apps, keeps your records long-term.
Can I withdraw my consent from toing?
Section 6(4) of India's Digital Personal Data Protection Act 2023 gives you the right to withdraw consent for processing you agreed to. The Act's substantive provisions commence in stages up to May 2027, so a request made now asks for voluntary compliance and puts the date on record. Processing a company carries out under a legal obligation — such as KYC records the RBI requires — cannot be withdrawn.
Does toing track me for advertising?
Yes — toing's published policy discloses this. The exact sentence it is based on is quoted on this page, with the date we read it and a link to the source.
Every use above is one toing declared in its own published privacy policy, which we
read on 2026-08-14. Quotes are verbatim; the summary beside each one is ours
and is labelled as ours. Nothing here is inferred.
Saaph.in is a DPDP consent and request management platform operated by Ronin Works
Private Limited. It is a communication facilitator, not your legal or authorised
representative. The DPDP Act 2023 commences in stages up to May 2027, so a request
made today asks for voluntary compliance and records the date you asked.
Our privacy policy