Privacy Policy
How Restros protects restaurant merchant data and dining customer privacy in full compliance with Indian data protection laws.
1. Overview & Commitment to Privacy
Restros ("we," "our," or "us"), operating from Rohtak, Haryana, India, provides a digital restaurant operating system. We respect the privacy of our merchant subscribers ("Restaurants") and their patrons ("Dining Guests").
This Privacy Policy describes our practices regarding the collection, storage, processing, and protection of personal information in compliance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection (DPDP) Act, 2023.
2. Information We Collect
A. Restaurant Merchant Information
- Owner Name, Mobile Number, and Business Email Address.
- Restaurant Name, Physical Outlet Address, City, and State.
- GSTIN and Permanent Account Number (PAN) for commercial tax billing.
- Menu catalog, prices, category names, and table configurations.
- Staff roles and system activity logs.
B. Dining Guest Information
- Customer Name (for identifying table orders).
- Mobile Number (for order confirmation SMS and digital GST invoice delivery).
- Table number and items ordered.
- Payment method and transaction confirmation reference.
3. The Dining Guest Privacy Boundary (Zero Data Resale)
Our Core Privacy Invariant
We NEVER sell, rent, monetize, or share dining guest contact numbers with third-party advertisers or marketing networks.
Guest mobile numbers are utilized exclusively to fulfill dining orders, display orders to the cashier and kitchen, and deliver electronic tax invoices. Kitchen Display System (KDS) screens and public QR URLs are intentionally engineered with architectural privacy boundaries that never expose guest phone numbers.
4. Purpose of Data Processing
We process collected data solely for the following legitimate purposes:
- Provisioning and maintaining your cloud-based restaurant workspace and menus.
- Processing table QR orders, kitchen preparation tickets, and cashier bill settlements.
- Generating statutory CGST and SGST tax invoices and daily sales summaries.
- Managing annual software subscriptions via secure payment gateway partners.
- Providing technical customer support, grievance redressal, and system alerts.
- Enforcing our single-trial anti-abuse registry (`trial_registry`) via deterministic cryptographic hashes.
5. Data Security & Cloud Storage Standards
Restros applies strict physical, technical, and operational safeguards to protect your records:
- Cloud Infrastructure: Hosted on Google Cloud / Firebase enterprise infrastructure utilizing ISO 27001 and SOC 2 certified data centers.
- Encryption in Transit & at Rest: All web requests are protected via TLS 1.3 encryption. Database documents, configuration files, and authentication tokens are encrypted at rest with AES-256.
- Role-Based Access Control (RBAC): Multi-tenant database security rules strictly isolate each restaurant's data. Staff accounts (KITCHEN, CASHIER, MANAGER) are bounded by least-privilege permissions.
- Financial Security: Restros never collects, stores, or sees merchant or customer debit/credit card numbers or CVVs. All commercial checkout flows are handled directly by PCI-DSS Level 1 certified gateway partners (Razorpay).
6. Cookies & Local Session Storage
Restros utilizes essential HTTP-only cookies and browser `localStorage` solely for session authentication, tenant identity persistence, and offline caching on Edge operating terminals. We do not use third-party cross-site tracking cookies for targeted behavioral advertising.
7. Merchant Rights & Statutory Invariants
Under the DPDP Act 2023, restaurant subscribers have the right to access their account details, correct menu and identity information, and export order and invoice records.
Tax Record Retention: In compliance with Section 36 of the Indian Central Goods and Services Tax (CGST) Act, 2017, statutory GST tax invoices and accounting records generated by the restaurant are preserved for the mandatory legal period and are not prematurely expunged upon subscription expiration.
8. Grievance Officer & Contact Particulars
In accordance with Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the contact details of our designated Grievance Officer are:
Name: Atul Verma
Designation: Founder & Grievance Officer
Entity: Restros
Physical Address: Rohtak, Haryana, India
Business Phone: +91 7982476087
Grievance Email: connect@restros.in
Personal / Gateway Registered Email: atulverma9728@gmail.com
Complaints are acknowledged within 48 hours and resolved within fifteen (15) calendar days from receipt.
