Details marked to be published are being finalised and will appear here once confirmed.
In short
- Open personal data only when your current task needs it. Every staff action is logged and reviewed.
- Never ask anyone for an OTP, UPI PIN, card CVV or password. Never move money outside the platform.
- Never work on a shop, application or ticket where you, a relative or a close friend has an interest. Declare it and hand it over.
- Keep everything you learn at Stataa confidential, during and after your time with us.
- Report security incidents and mistakes immediately to security@stataa.com. Honest, fast reporting is never punished.
1. Who this applies to
This code applies to everyone with access to Stataa's staff tools: employees, contractors, interns and volunteers, in every staff role (approver, support and super admin). It adds to your employment or contract terms and to our Terms of Use and Privacy Policy. Breaking it can lead to disciplinary action and, in some cases, criminal liability.
2. Access to data
- Need to know. Open a customer's, shop's or colleague's data only when your task needs it, and only as much as the task needs.
- No curiosity. Never look up friends, family, neighbours, famous people or yourself.
- Keep it inside Stataa. Do not download, export, screenshot, print or copy personal data unless an approved process requires it. Never send it to personal email, WhatsApp or other chat apps, or paste it into AI tools or other outside services that Stataa has not approved.
- Your login is yours. Use only the account Stataa gave you, never share it, turn on two-step login wherever it is offered, and lock your screen when you step away.
- Everything is logged. Every staff action is recorded in an audit log that is reviewed regularly. Misusing access is a serious breach. Under Indian law, including the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, it can also be an offence or lead to heavy penalties.
3. Money and payments
- Never ask anyone for an OTP, UPI PIN, card CVV, bank password or login password, for any reason.
- Never move money outside the platform. Never send a refund by personal UPI, bank transfer or cash. Never collect payment from anyone. Never share a personal UPI ID or QR code.
- Refunds go only through the Stataa system, to the customer's original payment method, as the Cancellation & Refund Policy says.
- Seller payout details are stored encrypted. Reveal a full account number or UPI ID only to verify it or to make a payout; every reveal is logged. Changes need fresh verification and a 48-hour hold. Never try to bypass or "speed up" this, whoever asks, and confirm any change with the shop on its verified phone number.
- Watch for pressure. Scammers pretend to be a founder, a shop owner or a bank and demand urgent refunds or payout changes. Check through a second, known channel before acting, and report the attempt to trust@stataa.com.
4. Conflicts of interest
- Do not review an application, handle a ticket, decide a refund or strike, or change settings for a shop that you, a relative or a close friend owns, works at, or has money in. The same applies to your own customer account and those of relatives and close friends.
- "Relative" includes your spouse or partner, parents, children, brothers and sisters, in-laws, and anyone who lives in your household.
- If a conflict comes up, stop, declare it in writing to a super admin, and hand the case over. If you are unsure, declare it anyway.
- Do not accept cash, gifts, free food, discounts or favours from shops, applicants or customers, beyond a trivial courtesy such as a cup of tea during a visit. Report any other offer. No side deals.
5. Rules for each role
Approvers
- Check that the FSSAI licence or registration is valid on FSSAI's official system and matches the business name, address and kind of food.
- Check that the certificate image matches the number, and that shop photos are real and match the address and map pin.
- Record the reason for every approval and rejection. If in doubt, ask for more information or reject. Never approve under pressure or as a favour.
- Approval is not a food-safety inspection. Never tell a shop or customer that it is.
Support
- Identify customers and shops through their signed-in account or ticket reference (like STA-12345), not through claims made by phone or on social media.
- Follow the Cancellation & Refund Policy. Be fair to both sides, and do not promise outcomes you cannot give.
- Escalate reports of illness, allergic reactions or wrong veg marking at once. Always advise medical help first.
- Share only what each side needs. Do not give one person's contact details to another.
- Communicate only through the ticket system and @stataa.com email. Never give out your personal number.
- Keep ticket notes factual and respectful.
Super admins
- Use admin powers only when needed, and record why.
- Change settings such as commission, cancellation cutoff, report window or minimum discount only after a recorded decision.
- Remove access on the day someone leaves or changes role. Review audit logs regularly.
- Use two-person approval for sensitive actions wherever the system supports it.
6. Confidentiality
Confidential information includes users' personal data, shops' business details (sales, payouts, documents), Stataa's plans, code, security settings, credentials, and anything marked confidential.
- Use it only for your work at Stataa.
- Do not disclose it to anyone who does not need it for their Stataa work, during or after your time with Stataa. For personal data and security details, this duty never ends.
- When you leave, return all Stataa devices and delete Stataa data from any device you were allowed to use.
- If the law requires you to disclose something, tell us first if you are allowed to. Nothing in this code stops you from reporting wrongdoing to the authorities.
- Do not post about users, shops or tickets on social media, and do not speak to the media for Stataa without approval.
7. Security incidents and mistakes
Report at once, and within one hour at most, to security@stataa.com if you:
- suspect a data breach or unusual account activity;
- lose a device that has Stataa access;
- clicked a suspicious link or entered your password on a suspicious page;
- sent data to the wrong person, or changed something by mistake.
Speed matters. Stataa may have to report cyber incidents to CERT-In within 6 hours and personal data breaches to the Data Protection Board. We will not punish honest mistakes that are reported quickly. Hiding one is a serious breach.
8. Respect
Treat customers, shops and colleagues with respect. Discrimination or harassment based on caste, religion, gender, sexual orientation, disability, age, region or language is not allowed. Sexual harassment is not tolerated. Complaints are handled under the Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Act, 2013.
9. Speaking up
If you see something wrong, report it to security@stataa.com (data and security) or grievance@stataa.com (anything else). You can also go directly to to be published, to be published. No one will be punished for raising a concern in good faith.
10. Consequences
Breaking this code can lead to loss of access, disciplinary action up to ending your work with Stataa, recovery of losses, and reporting to the police or other authorities where the law requires.
By accepting, you confirm that you have read this code, will follow it, and will ask if anything is unclear.
Questions about this page? Write to hello@stataa.com, or to our Grievance Officer at grievance@stataa.com. How complaints are handled.