Privacy Policy
Last updated: 27 September 2026
This policy explains what information the RestoPay app and restopay.in (“RestoPay”, “we”) collect, why, and how it is protected. RestoPay is used by restaurants (“customers”) and their staff; guests of those restaurants may use table QR codes.
Information we collect
- Staff accounts: mobile number (used for OTP login), name and role (owner, counter, captain, kitchen).
- Restaurant data: restaurant details, floors and tables, menu, orders, KOTs, bills, payments recorded in the app and bill settings such as GST details and logo.
- Device data: a push notification token so staff phones can receive table alerts, and the printer connections you set up.
- Guests using a table QR: we do not ask for a name, phone number or login. We record the request (for example “Call Captain” for Table 4) and a one-way hash of the IP address, used only to prevent spam.
How we use it
- To run the service: show tables and orders, send KOTs, print bills and deliver table alerts.
- To keep accounts and QR codes secure and to prevent abuse.
- To provide support when a restaurant asks for it.
We do not sell personal data and we do not use it for advertising.
Where data is stored
RestoPay runs on Google Firebase. Restaurant data is stored in Google Cloud’s Mumbai region (asia-south1) and protected by access rules so each restaurant’s staff can only see their own restaurant’s data.
Sharing
Restaurant data is visible to that restaurant’s owner and staff. We share data with service providers only as needed to run RestoPay (Google Firebase for hosting and notifications, and 2Factor.in for login OTP SMS), or when required by law.
Retention and deletion
Data is kept while the restaurant uses RestoPay. A restaurant owner can ask us to export or delete their restaurant’s data, and staff can ask for their account to be removed, by writing to us.
Contact
Questions or requests: hello@restopay.in.