Home

Privacy Policy

Last updated: 29 June 2026

Who we are

RestroInvoice ("we", "us") provides restaurant POS and hotel management software. This policy explains what we collect and how we handle it. Contact: [email protected].

What we collect

  • Account data - your name, business name, email, phone, and login credentials.
  • Operational data you enter - menu, orders, invoices, expenses, staff, and guest/customer details (name, phone, email, stay history) recorded while using the platform.
  • Sensitive personal data - where you choose to record them: guest government ID numbers (e.g. Aadhaar/passport) and staff bank account numbers. These are encrypted at rest (AES-256); only a masked form (last 4 digits) is shown for the guest register.
  • Payment data - handled by our payment processor (Razorpay). We do not store your card details.
  • Technical data - a session cookie for authentication, and basic server logs (IP, timestamps) for security and reliability.

Where your data is stored

  • Platform & data storage - reputable, industry-standard cloud infrastructure providers, with your data hosted in secure data centres and encrypted in transit and at rest.
  • Transactional email - a managed email delivery provider (used only to send you service emails such as credentials and receipts).
  • Payments - Razorpay, a PCI-DSS-compliant payment processor. We never see or store your card details.

Each business's data is kept separate from every other business's, and all data travels over encrypted connections. A current list of our infrastructure sub-processors is available on request at [email protected].

How we use it

To provide and operate the service, process subscriptions and payments, send transactional email (e.g. login credentials, receipts), provide support, and keep the platform secure. We do not sell your data.

Sharing

We share data only with the service providers described above - our cloud infrastructure, email delivery and payment processors - strictly to run the service, under appropriate data-protection obligations, and where required by law. We do not sell your data.

Our role (DPDP Act, 2023)

For your business account data, RestroInvoice is the Data Fiduciary. For the guest/customer data you enter into the platform, you (the business) are the Data Fiduciary and RestroInvoice acts as a Data Processor processing it on your instructions to run the service.

Security

  • Encryption in transit (HTTPS/TLS) and at rest (managed database disk encryption).
  • Sensitive identifiers (guest ID numbers, staff bank account numbers) are additionally application-encrypted (AES-256-GCM) before storage.
  • Each business's data is kept fully separate from every other business on the platform. Access within your account follows the roles you assign to your team, and privileged system credentials never leave our servers.

Retention

We keep personal data while your account is active and only as long as needed for the purposes above or as required by law (e.g. GST/tax records are retained for the statutory period). On account closure or an erasure request, personal data is deleted or anonymised; legally-required transactional records (amounts, dates) are retained without personal identifiers.

Your rights under the DPDP Act, 2023

  • Access - obtain a summary/export of your personal data.
  • Correction & completion - fix inaccurate or incomplete data.
  • Erasure - request deletion when no longer required (subject to legal retention).
  • Withdraw consent - for any processing based on consent.
  • Grievance redressal - raise a complaint with our Grievance Officer (below).
  • Nominate - nominate another person to exercise your rights in the event of death or incapacity.

To exercise any right, email [email protected]. If you are a guest of a business using RestroInvoice, please contact that business; we will assist them as their processor.

Grievance Officer

As required by the DPDP Act and IT Rules, you may contact our Grievance Officer for data-protection concerns: [email protected]. We aim to acknowledge within 48 hours and resolve within the timelines prescribed by law.

Data breach

In the event of a personal-data breach, we will take prompt remedial action and notify the Data Protection Board and affected users/businesses as required by the DPDP Act.

Public bill links

When you share a customer e-bill link, anyone with that link can view that single bill (items, total, and any customer name/phone on it). Links use long, unguessable identifiers.