RestaurantOS
Loading...
Legal Agreements

Privacy Policy

Last Updated: July 2026 • Compliant with Digital Personal Data Protection (DPDP) Act, 2023

1. Information We Collect

At RestaurantOS, we value your privacy and are committed to protecting the personal data of both our SaaS subscribers (Restaurant Owners, Managers, and Staff) and their end-users (Diners/Customers visiting the restaurant). This Privacy Policy explains how we collect, use, process, and safeguard personal information in compliance with the Digital Personal Data Protection (DPDP) Act, 2023 (India) and other global data protection standards (GDPR).

Subscriber Data: Full Name, email address, password, billing address, country, and location details (State and City) during registration.

Workspace Data: Restaurant name, slug, restaurant type, cuisine, dietary tags, logo, and active branch details.

Subscription & Payment Data: Transaction status, billing history, subscription plan tier, and payment metadata. (We do not store credit card/bank credentials directly; all payments are processed securely via PCI-DSS compliant third-party gateways like Razorpay).

Diner Data: Table number, session token, cart items, order preferences, and payment status (Cash or Online). If enabled by the subscriber, customer phone number for OTP verification, digital receipt delivery, or loyalty reward points.

2. How We Use the Information

We process personal data only to the extent necessary to deliver the RestaurantOS services:

To authenticate user sessions, secure workspace portals, and prevent unauthorized database access.

To process self-ordering requests, send real-time kitchen notifications, and generate secure table QR codes.

To coordinate billing subscriptions, trigger email receipts, and send operational notifications.

To monitor system uptime, database performance, and prevent fraud.

3. Data Storage & Multi-Tenant Separation

Sacred Database Policy: All data is hosted on highly secure cloud servers with atomic write operations.

Strict Tenant Isolation: Data belonging to your restaurant is strictly segmented. We enforce validation filters at the database level to ensure that no restaurant, cashier, or diner can ever view, modify, or leak data from another workspace.

4. Third-Party Integrations & Data Sharing

We do not sell, rent, or trade your data. We share information only with trusted processors required to run the service:

Razorpay: For processing subscription payments.

Ably Realtime: For synchronizing self-orders and kitchen queues via secure, encrypted websockets.

SMTP Relays (Gmail/Nodemailer): For delivering transactional registration updates and security OTP tokens.

Cloudinary: For hosting and serving restaurant logos and dish images securely.

5. Your Rights Under DPDP Act, 2023

If you are located in India, you hold the following rights:

Right to Access & Rectify: You can correct or update your profile details anytime via the Dashboard Settings.

Right to Consent Withdrawal: You can withdraw your consent for optional data collection.

Right to Erasure: You may request that your account and restaurant branch data be permanently deleted. Contact our support channels for account closure.

6. Grievance Officer & Support Contact

In accordance with the DPDP Act, 2023, if you have any questions, complaints, or grievance requests regarding data processing, please contact our Grievance Officer:

WhatsApp Support: +91 75820 21281

Email Support: restaurantos@navneettechlabs.com / official@navneettechlabs.com

Address: Indore, Madhya Pradesh, India