Privacy policy

Template — not legal advice. This is written to be honest about what the

software actually does, which is the hard part. A lawyer in your jurisdiction

still needs to read it before you publish it. Fill in every `[BRACKETED]` field.

Last updated: [DATE]

Operator: [COMPANY LEGAL NAME], [ADDRESS], [GSTIN]

Contact: [PRIVACY@YOURDOMAIN]

The short version

If you scan a QR code and order food without signing in, we keep your order and

almost nothing about you. We do not know your name unless you type it. We do not

track you across the internet. There are no advertising cookies, because there

is no advertising.

If you choose to make an account, we keep a bit more, and you can ask for all of

it back or ask us to delete it.

1. What is collected, and why

### If you order without signing in

We do not collect: your location, your contacts, your browsing history,

anything from other apps, or your identity from any third party.

### If you create an account

Additionally:

### Automatically

2. What is not done

Your data is not sold, ever.

Your data is not shared with advertisers. There are no ad networks in

this application.

No third-party analytics that profile you across sites.

Venues see only their own guests' orders. A company operating four cafes

sees those four; it cannot see any other operator's.

3. Who else touches it

Each of these acts on our instructions and cannot use your data for their own

purposes.

4. How long things are kept

Tax records: about 8 years. Section 36 of the CGST Act 2017 requires a

registered business to retain its books and invoices for 72 months from the due

date of the annual return. We cannot delete an invoice on request, and neither

can anyone else. This is the law, not a policy choice.

Everything identifying: 90 days by default. After that, an automatic sweep

strips names, phone numbers, number plates and device identifiers from old

orders. What remains is the bill: what was sold, for how much, and how much tax.

Your account: until you close it.

5. Your rights

Under India's Digital Personal Data Protection Act 2023 — and, if you are in the

EU or UK, the GDPR — you may:

See what we hold. From the app: your account → "Download my data".

Correct it. Edit your profile, or write to us.

Have it deleted. Your account → "Delete my account". This removes your

profile, your points and every link between you and past orders. The orders

themselves become anonymous rather than disappearing, for the tax reason above.

Withdraw consent at any time, by deleting your account.

Complain to the Data Protection Board of India, or your local supervisory

authority.

We answer within [30] days. There is no charge.

6. Children

This service is not directed at children under 18. We do not knowingly collect

their data. A child can, of course, order a sandwich at a table without an

account — that is a transaction, not a profile.

7. Security

All traffic is encrypted in transit (HTTPS).

Every table in the database enforces row-level security, so one venue's data

is unreachable from another venue's session — this is enforced by the

database itself, not by application code that could be bypassed.

Prices, discounts and tax are calculated on the server. Nothing a browser

sends can change what something costs.

Payment card details never reach our servers; they go directly to the payment

provider.

No system is perfectly secure. If there is a breach affecting you, we will tell

you and the Data Protection Board without undue delay.

8. Cookies

We use exactly two kinds of browser storage:

1. A session cookie, if you sign in. It keeps you signed in. It is not used

for tracking.

2. Local storage for your cart and your device identifier, so a refresh does

not lose your order.

There are no advertising or cross-site tracking cookies.

9. Changes

If this policy changes materially we will say so in the app before the change

takes effect.

10. Contact

[PRIVACY@YOURDOMAIN] · [POSTAL ADDRESS]

Grievance Officer (required in India): [NAME], [EMAIL]