PrivacyPolicy
Your trust is our foundation. We're committed to protecting your data with the same care and seriousness you put into your business.
Your data is completely yours.
Every order, every sale, every customer insight your business generates belongs entirely to you. We are a tool you use, not a company that profits from your business data.
Never sold
We never sell your data to any third party, ever. No exceptions.
Team access blocked
Our internal team cannot view your sales, stats, or customer data unless you grant them access.
No cross-brand visibility
Your data is never shared with, or visible to, any other brand on this platform.
Your Business Data Belongs to You
restOS is a software platform that you use to run your business (whether that's a restaurant, café, retail store, event venue, or brand). The data generated through your operations (sales numbers, customer lists, order history, revenue figures, analytics) is your proprietary business information. We store and process it on your behalf. We do not own it.
What we guarantee
- Your sales figures, revenue, and growth stats are invisible to our team unless you raise a support ticket that specifically requires access, and only after your consent
- Your customer data (names, phones, emails, order history) is never shared with any other restaurant, brand, or business on this platform
- We do not use your data to train models, build competitive intelligence, benchmark against other brands, or improve services for any other entity
- You can export or delete all your data at any time by contacting us. No lock-in, ever.
What we will never do
- Sell your business data or customer data to any third party
- Share your menu, pricing, or revenue data with competing brands
- Use your customer contacts for marketing on behalf of other businesses
- Access your data for any internal purpose (analytics, product research) without your explicit consent
- Use your data as part of any aggregate or anonymised dataset shared externally
- Transfer your data outside India. All data is stored and processed on India-based servers only.
Indian Law Compliance
restOS is a proudly India-first platform, headquartered in Andhra Pradesh. We operate under and comply with Indian data protection law as our primary legal framework.
Digital Personal Data Protection Act, 2023 (DPDPA)
India's landmark data protection law, the DPDPA 2023, is our primary compliance framework. This Act governs how we collect, store, process, and handle personal data of individuals in India.
- Consent-first: We collect only the personal data you or your customers explicitly consent to provide
- Purpose limitation: Data is used only for the specific purpose for which it was collected
- Data minimisation: We collect only what is necessary and nothing more
- Data Principal rights: Every individual has the right to access, correct, and erase their personal data
- Grievance Redressal: We maintain a designated grievance officer reachable at the contact details below
- Data Breach Notification: In the event of a breach, affected parties and the Data Protection Board of India will be notified as required by law
Information Technology Act, 2000 & IT (Amendment) Act, 2008
We comply with the IT Act and its associated rules including the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, which prescribe security standards for collecting and handling sensitive personal data such as passwords, financial information, and health data.
GST & Financial Data Compliance
Transaction records and invoicing data are retained for a minimum of 7 years as required under Indian GST law. This data is stored securely and is not accessible to any party other than your business and legal authorities with a valid court order.
Grievance Officer (under IT Act & DPDPA): For any data-related grievance or complaint, contact us at privacy@restos.in. We will acknowledge within 48 hours and resolve within 30 days as required by law.
Information We Collect
Account & Personal Information
- •Name, email address, phone number: used for account creation and communication
- •Restaurant or brand details: business name, address, GST number, contact information
- •Staff information: for role management and access control within your account
Your Customers' Data (held on your behalf)
This data belongs to your customers and is collected with their consent through your platform. You are the Data Fiduciary; we act as your Data Processor.
- •Contact information: used for reservations, orders, and communications
- •Order and purchase history: food orders, store purchases, and event tickets
- •Loyalty and rewards data: points balance, redemption history, and tier status
- •Event attendance and ticket information
- •Feedback and reviews
Business Operations Data
- •Menu items, pricing, and inventory
- •Events, ticketing, and attendee data
- •Retail store products and orders
- •Blog and content data
- •Loyalty programme configuration: tiers, points rules, redemption settings
- •Sales data and analytics: visible only to you and your authorised staff
Technical and Usage Data
- •IP address and device information: used for security and fraud prevention
- •Browser type and version: for compatibility optimisation
- •Platform usage patterns: used to improve the product and are never tied to your business identity externally
- •Performance and error logs: used for technical support and debugging
How We Use Your Data
Primary Service Purposes
- Service Delivery: Provide and maintain the platform functionality you subscribed to
- Order & Transaction Processing: Process food orders, store purchases, event ticket bookings, reservations, and pay-bill transactions
- Fulfilling Your Orders & Bookings: When you create an account or submit personal information (such as your name, phone number, or email) to place an order, make a booking, or use a service through a restaurant, brand, outlet, or delivery partner on the platform, that information is collected on their behalf, as the entity you are directly transacting with. We host and power their storefront, but we do not sit between you and them as a separate data recipient. They may use it to contact you to confirm, fulfil, or provide support for that order, booking, or service. By submitting this information and continuing to use the platform, you consent to this contact.
- Loyalty & Rewards: Track and manage loyalty points, tier progression, and reward redemptions for your customers
- Analytics & Reporting: Generate business insights and performance reports visible only to you and your team
Support & Improvement
- Customer Support: Respond to inquiries and provide technical assistance. We access your account data only when you specifically raise a support request.
- Platform Enhancement: Analyse anonymised usage patterns to improve features. This is never tied to your brand's identity.
- Security & Fraud Prevention: Monitor for suspicious activities to protect your account
Legal & Compliance
- Regulatory Compliance: Meet legal obligations under Indian law (DPDPA 2023, IT Act, GST)
- Tax & Financial Reporting: Retain transaction data as required by GST and Indian accounting regulations
Legal Basis (DPDPA 2023): We process data based on your consent, contractual necessity (to deliver the services you signed up for), and legal obligations under Indian law.
Data Sharing & Third Parties
We do NOT share your data with third parties for commercial gain
Your business data (sales, customers, revenue, orders, menu performance) is never sold, licensed, rented, or shared with any external party for commercial purposes. This is a firm commitment, not a policy subject to change for business reasons.
- Not shared with advertisers or marketing agencies
- Not shared with data brokers
- Not shared with restaurants, brands, or businesses you have not interacted with on this platform
- Not used for cross-platform profiling or targeting
Ordering or booking directly from a business is not "sharing"
- You are transacting with them, not us: When you create an account or submit personal information (name, phone, email, etc.) to place an order, make a booking, or use a service through a restaurant, brand, outlet, or delivery partner on the platform, that information is collected directly by that business as the party you're dealing with. We power their storefront; we are not a middleman who then "shares" your data onward to them. It is never passed to any other, unrelated business on the platform.
- Legal requirements only: Beyond that, we disclose data only when compelled by Indian law, a valid court order, or a lawful directive from a government authority, and strictly to the minimum extent required by that order.
That's it. No infra providers, no payment processors, no email tools receive your business data. Infrastructure services we use (hosting, payments, emails) operate at a technical layer only. Your business data, sales, customers, and analytics never leave our environment and are never exposed to any external system.
Data stays in India
All your data (business data, customer data, transaction records) is stored exclusively on India-based servers. We do not transfer your data outside India. No cross-border data transfers. Your data stays in the country, under Indian law, at all times.
Our Team's Access to Your Data
We believe that trust is built through transparency. Here is exactly how our internal team is restricted from accessing your data:
- No access to business stats by default: Our team members do not have routine access to your sales figures, revenue, customer lists, or order volumes. These are visible only to you and your authorised staff.
- Support access only when you allow it: If a support situation requires our team to look at your account, access is only possible after you explicitly grant it from within the platform. No team member can view your data without your active permission.
- Access is logged: Every internal access to production data is audit-logged with timestamps, the team member's identity, and the reason.
- Principle of least privilege: Each team member has access only to what their role specifically requires. Engineers, support staff, and business teams operate in separate access tiers.
- Confidentiality agreements: All team members sign NDAs and data handling agreements before accessing any production systems.
You can request an access log for your account at any time by emailing privacy@restos.in. We'll provide a summary of any internal accesses made to your data.
Data Protection Measures
Technical Security Measures
- 256-bit SSL/TLS Encryption: All data transmissions encrypted end-to-end
- AES-256 Encryption: Data at rest encrypted with industry-standard algorithms
- Secure Data Centres: SOC 2 Type II, ISO 27001 certified infrastructure
- Regular Security Audits: Periodic penetration testing and vulnerability assessments
- Multi-factor Authentication: Required for all administrative access
Access Control & Authentication
- Role-based Access Control: Granular permissions based on job functions
- Principle of Least Privilege: Minimum necessary access for all users
- Session Management: Automatic timeout and secure session handling
- Audit Logging: Comprehensive logging of all access and modifications
Data Integrity & Backup
- Automated Backups: Daily encrypted backups with geographic redundancy
- Data Validation: Input validation and sanitization to prevent corruption
- Disaster Recovery: Comprehensive disaster recovery and business continuity plans
Your Data Rights
Rights Under DPDPA 2023 & Indian Law
- Right to Access: Request a copy of your personal data in a readable format
- Right to Correction: Correct inaccurate or incomplete personal data
- Right to Erasure: Request deletion of your personal data (subject to legal retention obligations)
- Right to Portability: Export your data in a machine-readable format
- Right to Grievance Redressal: Lodge a complaint with our Grievance Officer; escalate to the Data Protection Board of India if unresolved
- Right to Withdraw Consent: Withdraw consent for processing at any time (without affecting prior lawful processing)
- Right to Nominate: Nominate another person to exercise your data rights on your behalf in the event of death or incapacity
How to Exercise Your Rights
- •Email our Grievance Officer at privacy@restos.in with your request
- •We will acknowledge your request within 48 hours
- •We'll resolve it within 30 days as required by the DPDPA 2023
- •No fees for any legitimate request
- •If you are unsatisfied, you may escalate to the Data Protection Board of India
Data Retention Periods
- •Account Data: Retained while your account is active
- •Order & Purchase History: 7 years for GST and legal compliance (food, store, events)
- •Event Ticket Records: Retained for 3 years after the event date
- •Loyalty Data: Retained while your account is active; deleted 1 year after account closure
- •Customer Data: 2 years after last interaction, unless consent renewed
- •Analytics Data: Anonymised after 13 months
Cookies & Tracking Technologies
Types of Cookies We Use
- Essential Cookies: Required for basic platform functionality (login, sessions, security). Cannot be disabled.
- Performance Cookies: Collect anonymous usage data to improve platform performance
- Functional Cookies: Remember preferences and provide personalised features
We do not use advertising or tracking cookies for targeting you or your customers across other websites.
Managing Your Preferences
- •Use your browser settings to block or delete non-essential cookies
- •Manage preferences from your account privacy settings
Children's Privacy
Our platform can be used by individuals of all ages, including children. However, in line with the Digital Personal Data Protection Act, 2023 (DPDPA), children under the age of 8 years are considered minors for the purpose of data collection, and we apply additional protections for their data.
- Parental consent: For users below 8 years of age, personal data is collected only with verifiable parental or guardian consent
- No profiling: We do not profile, track, or use the data of any child for targeted purposes under any circumstances
- Parental deletion right: A parent or guardian may request deletion of their child's data at any time
Contact: For any queries related to a child's data or to request deletion, contact us at privacy@restos.in.
Changes to This Policy
- Regular Updates: We may update this policy to reflect changes in our practices or legal requirements
- Notification: Material changes will be communicated via email and platform notifications at least 14 days before they take effect
- Your choice: If you disagree with a material change, you may close your account and export your data before the change takes effect
Tip: Review this policy periodically. The "Last Updated" date below indicates when changes were last made.
Contact & Grievance Officer
Privacy & Data Requests
privacy@restos.in
General privacy questions, data access/deletion requests
Grievance Officer (DPDPA / IT Act)
privacy@restos.in
Formal complaints. Acknowledged within 48 hrs and resolved within 30 days.
Registered Address
Flikko Technologies
Kakinada – 533 003
Andhra Pradesh, India
Regulatory Compliance
Primary: Indian Law
- • Digital Personal Data Protection Act, 2023 (DPDPA)
- • Information Technology Act, 2000 (& 2008 Amendment)
- • IT (SPDI) Rules, 2011
- • GST Act (data retention requirements)
Security Standards
- • ISO 27001:2022 (Information Security)
- • SOC 2 Type II Compliance
- • PCI DSS 4.0 (Payment Security)
Last Updated: July 8, 2026
Effective Date: July 8, 2026
Next Review: March 30, 2027
