Privacy policy
Template — not legal advice. This is written to be honest about what the
software actually does, which is the hard part. A lawyer in your jurisdiction
still needs to read it before you publish it. Fill in every `[BRACKETED]` field.
Last updated: [DATE]
Operator: [COMPANY LEGAL NAME], [ADDRESS], [GSTIN]
Contact: [PRIVACY@YOURDOMAIN]
The short version
If you scan a QR code and order food without signing in, we keep your order and
almost nothing about you. We do not know your name unless you type it. We do not
track you across the internet. There are no advertising cookies, because there
is no advertising.
If you choose to make an account, we keep a bit more, and you can ask for all of
it back or ask us to delete it.
1. What is collected, and why
### If you order without signing in
We do not collect: your location, your contacts, your browsing history,
anything from other apps, or your identity from any third party.
### If you create an account
Additionally:
### Automatically
2. What is not done
• Your data is not sold, ever.
• Your data is not shared with advertisers. There are no ad networks in
this application.
• No third-party analytics that profile you across sites.
• Venues see only their own guests' orders. A company operating four cafes
sees those four; it cannot see any other operator's.
3. Who else touches it
Each of these acts on our instructions and cannot use your data for their own
purposes.
4. How long things are kept
Tax records: about 8 years. Section 36 of the CGST Act 2017 requires a
registered business to retain its books and invoices for 72 months from the due
date of the annual return. We cannot delete an invoice on request, and neither
can anyone else. This is the law, not a policy choice.
Everything identifying: 90 days by default. After that, an automatic sweep
strips names, phone numbers, number plates and device identifiers from old
orders. What remains is the bill: what was sold, for how much, and how much tax.
Your account: until you close it.
5. Your rights
Under India's Digital Personal Data Protection Act 2023 — and, if you are in the
EU or UK, the GDPR — you may:
• See what we hold. From the app: your account → "Download my data".
• Correct it. Edit your profile, or write to us.
• Have it deleted. Your account → "Delete my account". This removes your
profile, your points and every link between you and past orders. The orders
themselves become anonymous rather than disappearing, for the tax reason above.
• Withdraw consent at any time, by deleting your account.
• Complain to the Data Protection Board of India, or your local supervisory
authority.
We answer within [30] days. There is no charge.
6. Children
This service is not directed at children under 18. We do not knowingly collect
their data. A child can, of course, order a sandwich at a table without an
account — that is a transaction, not a profile.
7. Security
• All traffic is encrypted in transit (HTTPS).
• Every table in the database enforces row-level security, so one venue's data
is unreachable from another venue's session — this is enforced by the
database itself, not by application code that could be bypassed.
• Prices, discounts and tax are calculated on the server. Nothing a browser
sends can change what something costs.
• Payment card details never reach our servers; they go directly to the payment
provider.
No system is perfectly secure. If there is a breach affecting you, we will tell
you and the Data Protection Board without undue delay.
8. Cookies
We use exactly two kinds of browser storage:
1. A session cookie, if you sign in. It keeps you signed in. It is not used
for tracking.
2. Local storage for your cart and your device identifier, so a refresh does
not lose your order.
There are no advertising or cross-site tracking cookies.
9. Changes
If this policy changes materially we will say so in the app before the change
takes effect.
10. Contact
[PRIVACY@YOURDOMAIN] · [POSTAL ADDRESS]
Grievance Officer (required in India): [NAME], [EMAIL]