Home/Legal & Compliance/Privacy Policy
Data Privacy & Security

Privacy Policy

How Restros protects restaurant merchant data and dining customer privacy in full compliance with Indian data protection laws.

Entity: Restros (Rohtak, India)
Last Updated: September 2026
Legally Active & Published

1. Overview & Commitment to Privacy

Restros ("we," "our," or "us"), operating from Rohtak, Haryana, India, provides a digital restaurant operating system. We respect the privacy of our merchant subscribers ("Restaurants") and their patrons ("Dining Guests").

This Privacy Policy describes our practices regarding the collection, storage, processing, and protection of personal information in compliance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection (DPDP) Act, 2023.

2. Information We Collect

A. Restaurant Merchant Information

  • Owner Name, Mobile Number, and Business Email Address.
  • Restaurant Name, Physical Outlet Address, City, and State.
  • GSTIN and Permanent Account Number (PAN) for commercial tax billing.
  • Menu catalog, prices, category names, and table configurations.
  • Staff roles and system activity logs.

B. Dining Guest Information

  • Customer Name (for identifying table orders).
  • Mobile Number (for order confirmation SMS and digital GST invoice delivery).
  • Table number and items ordered.
  • Payment method and transaction confirmation reference.

3. The Dining Guest Privacy Boundary (Zero Data Resale)

Our Core Privacy Invariant

We NEVER sell, rent, monetize, or share dining guest contact numbers with third-party advertisers or marketing networks.

Guest mobile numbers are utilized exclusively to fulfill dining orders, display orders to the cashier and kitchen, and deliver electronic tax invoices. Kitchen Display System (KDS) screens and public QR URLs are intentionally engineered with architectural privacy boundaries that never expose guest phone numbers.

4. Purpose of Data Processing

We process collected data solely for the following legitimate purposes:

  • Provisioning and maintaining your cloud-based restaurant workspace and menus.
  • Processing table QR orders, kitchen preparation tickets, and cashier bill settlements.
  • Generating statutory CGST and SGST tax invoices and daily sales summaries.
  • Managing annual software subscriptions via secure payment gateway partners.
  • Providing technical customer support, grievance redressal, and system alerts.
  • Enforcing our single-trial anti-abuse registry (`trial_registry`) via deterministic cryptographic hashes.

5. Data Security & Cloud Storage Standards

Restros applies strict physical, technical, and operational safeguards to protect your records:

  • Cloud Infrastructure: Hosted on Google Cloud / Firebase enterprise infrastructure utilizing ISO 27001 and SOC 2 certified data centers.
  • Encryption in Transit & at Rest: All web requests are protected via TLS 1.3 encryption. Database documents, configuration files, and authentication tokens are encrypted at rest with AES-256.
  • Role-Based Access Control (RBAC): Multi-tenant database security rules strictly isolate each restaurant's data. Staff accounts (KITCHEN, CASHIER, MANAGER) are bounded by least-privilege permissions.
  • Financial Security: Restros never collects, stores, or sees merchant or customer debit/credit card numbers or CVVs. All commercial checkout flows are handled directly by PCI-DSS Level 1 certified gateway partners (Razorpay).

6. Cookies & Local Session Storage

Restros utilizes essential HTTP-only cookies and browser `localStorage` solely for session authentication, tenant identity persistence, and offline caching on Edge operating terminals. We do not use third-party cross-site tracking cookies for targeted behavioral advertising.

7. Merchant Rights & Statutory Invariants

Under the DPDP Act 2023, restaurant subscribers have the right to access their account details, correct menu and identity information, and export order and invoice records.

Tax Record Retention: In compliance with Section 36 of the Indian Central Goods and Services Tax (CGST) Act, 2017, statutory GST tax invoices and accounting records generated by the restaurant are preserved for the mandatory legal period and are not prematurely expunged upon subscription expiration.

8. Grievance Officer & Contact Particulars

In accordance with Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the contact details of our designated Grievance Officer are:

Name: Atul Verma

Designation: Founder & Grievance Officer

Entity: Restros

Physical Address: Rohtak, Haryana, India

Business Phone: +91 7982476087

Grievance Email: connect@restros.in

Personal / Gateway Registered Email: atulverma9728@gmail.com

Complaints are acknowledged within 48 hours and resolved within fifteen (15) calendar days from receipt.