DPDP & Your Data
India's Digital Personal Data Protection Act sets out how personal data must be handled. This page explains our role, your role, and the practical commitments we've built into the product.
Last updated 25 July 2026
Draft notice: this document is written to match how the product actually behaves, but it has not yet been reviewed by a lawyer. Get Indian counsel to review it before you rely on it commercially.
Who plays which role
For your restaurant's own records, you are the Data Fiduciary and we act as a Data Processor on your instructions.
For the account you hold with us — your name, contact details, billing — we are the Data Fiduciary.
Data residency
Operational and personal data for Indian customers is stored on infrastructure located in India.
Built-in commitments
Personal information is consolidated rather than scattered across tables, so an erasure request can be honoured completely and verifiably.
Access is scoped by role: an outlet operator cannot read another outlet's data, and franchisor visibility is limited to what the franchise agreement covers.
Every access path to personal data is logged.
Consent
Where we ask for consent — for example to send you product updates on WhatsApp — the request is specific, and withdrawing it is as easy as giving it.
Breach handling
If a personal data breach occurs, we will notify affected customers and the Data Protection Board as required, with what we know, what we're doing, and what you should do.
Raising a concern
Contact us with any data protection question or request. If you're not satisfied with our response, you have the right to complain to the Data Protection Board of India.