Legal

Privacy policy

Last updated: Draft, September 2026

Draft for review. This document is pending review by the RestoStay owner, legal counsel and chartered accountant. It is published for transparency and may change before final approval.

This policy explains how RestoStay (“RestoStay”, “we”) handles information when you use the RestoStay restaurant billing and management software (the “Service”) and this website. The Service is operated by [legal entity name and registered address — owner to confirm].

1. Who is responsible

For information a restaurant enters into the Service about its own business, staff and customers, the restaurant is the data owner and decides how it is used; RestoStay processes it to provide the Service. For account, website enquiry and support information, RestoStay is responsible.

2. Information we handle

  • Account and business information — business and outlet names, GST registration details the restaurant enters, owner and staff names, email addresses, mobile numbers and roles.
  • Restaurant operational data — menus, prices, recipes, tables, printers, stock, suppliers, purchases and settings.
  • Billing data — orders, KOTs, bills, invoices, payments (mode, amount and the reference the restaurant records), refunds, shifts and accounting records.
  • Guest information — the POS does not require guest personal details. An optional order note may contain what staff type into it.
  • Device and terminal information — device identifiers, terminal activation records, app version and build, and sync status.
  • Diagnostics — technical logs needed to keep the Service running and secure.
  • Support information — what you send us, including support bundles you choose to share. Support bundles are designed to exclude passwords, OTPs, access tokens, database keys, recovery passphrases, payment references and guest names.
  • Website enquiries — the details you submit on our contact form, with the time of submission and your browser type. To limit repeated submissions we also keep a temporary one-way hash of your IP address, separately from your enquiry, which deletes itself; we do not store your IP address.

3. How we use information

  • To provide, secure and support the Service, including sync between devices and the cloud.
  • To enforce the restaurant’s own permissions, terminal activation and subscription limits.
  • To respond to enquiries and support requests.
  • To send product updates only if you opted in; you can opt out at any time.

We do not sell personal information. We do not use restaurant data for advertising.

4. Where information is stored

Cloud: the Service stores synced data with Google Cloud / Firebase in the asia-south1 (Mumbai, India) region. On devices: billing terminals keep an encrypted local database of work that has not yet synced and the information they need to operate offline. Dish photos, where used, are stored privately per restaurant.

5. Service providers

We use Google Cloud / Firebase for hosting, authentication, database and file storage. [any other processors — owner to confirm]

6. Cookies and analytics

This website does not use advertising or analytics trackers and does not set cookies. If that changes, this policy will be updated first and consent will be requested where required.

7. Retention

Restaurant data is kept while the restaurant’s account is active and for the period required by law for billing and accounting records. Enquiries are kept for [retention period — owner to confirm]. [deletion/export process on account closure — owner and legal to confirm]

8. Security

Access is limited by role and outlet; sensitive operations are performed only on our servers; corrections leave an audit trail; unsynced data on terminals is encrypted. No system is perfectly secure, and we will notify affected restaurants of a breach as required by law.

9. Your choices and rights

You may ask to access, correct or delete personal information we hold about you, subject to legal retention requirements for billing records. Staff and guests of a restaurant should contact the restaurant first. [grievance officer name and contact under applicable Indian law — owner/legal to confirm]

10. Contact

Questions about this policy: support@restostay.in.