Restro IT, a product of Blackshift Technologies LLP, is committed to protecting the privacy of all individuals who interact with our Platform. This Privacy Policy explains how we collect, use, share, and protect personal data in accordance with the Digital Personal Data Protection Act, 2023 (“DPDPA”) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
1. Who This Policy Applies To
- Restaurant Owners / Subscribers who create accounts on the Platform
- End Customers who place food orders through Restaurant-Owner-operated systems powered by Restro IT
- Website Visitors who browse restroit.com
2. Data We Collect
From Restaurant Owners (Subscribers)
- Full name, business name, email address, mobile number
- Restaurant details: name, address, FSSAI number, GST number, cuisine type
- Payment information processed by our Payment Gateway partners — we do not store card numbers or CVV
- Billing address and GST details for invoicing
- Usage data: login times, features accessed, orders processed
- Uploaded content: menu items, food images, restaurant logo
From End Customers (via Restaurant-Owners' systems)
- Name, mobile number (for order notifications)
- Table number or delivery address
- Order details and transaction references
Note: End Customer data is collected on behalf of the Restaurant Owner. Restro IT acts as a Data Processor for End Customer data; the Restaurant Owner is the Data Fiduciary.
Automatically Collected Data
- IP address, browser type, operating system
- Pages visited, time spent, referral URL
- Cookies and similar tracking technologies (see our Cookie Policy)
3. How We Use Your Data
| Purpose | Legal Basis (DPDPA) |
|---|---|
| Providing and operating the Platform | Contract performance |
| Processing payments and issuing GST invoices | Legal obligation |
| Sending transactional emails (OTPs, invoices, receipts) | Contract performance |
| Customer support and grievance resolution | Legitimate interest / Legal obligation |
| Platform analytics and improvement | Legitimate interest |
| Marketing communications (with opt-out) | Consent |
| Fraud prevention and security | Legitimate interest / Legal obligation |
4. Data Sharing
We share data only in the following circumstances:
- Payment Gateways: Payment data is shared with Razorpay, Cashfree, Stripe, PayU, or PhonePe solely to process transactions. Each operates under their own privacy and PCI-DSS compliance frameworks.
- Service Providers: Limited third-party providers for cloud hosting, email/SMS delivery, and analytics (anonymized data only), bound by data processing agreements.
- Legal Disclosure: We may disclose data to government authorities or courts when required by law or court order.
- Business Transfer: In a merger or acquisition, data may transfer to the successor entity with prior notice to affected users.
We do not sell your personal data to any third party for marketing purposes.
5. Data Localization
Personal data of Indian residents is stored on servers located within the territory of India, in compliance with applicable Indian regulations.
6. Data Security
- Encryption: TLS 1.2+ in transit; AES-256 at rest
- Access controls: Role-based access control; only authorized personnel can access personal data
- Password security: All passwords stored as salted hashes using industry-standard algorithms
- Incident response: Breach notification procedures in place per DPDPA requirements
7. Data Retention
| Data Category | Retention Period |
|---|---|
| Active account data | Duration of subscription + 30 days post-termination |
| Billing and GST records | 8 years (Indian tax law requirement) |
| Order data | 2 years from order date |
| Communication logs | 1 year |
8. Your Rights (DPDPA)
Under the Digital Personal Data Protection Act, 2023, you have the right to:
- Access: Request a summary of personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Erasure: Request deletion of your personal data (subject to legal retention requirements)
- Grievance redressal: File a complaint with our Grievance Officer
To exercise these rights, email support@restroit.com from your registered email address. We will respond within 30 days.
9. Children's Privacy
The Platform is not directed at children under 18. We do not knowingly collect personal data from minors. If we become aware of such data, we will delete it promptly.
10. Changes to This Policy
We may update this Policy periodically. Active Subscribers will be notified via email for material changes. The updated Policy is effective from the date posted on our website.
11. Grievance Officer
Blackshift Technologies LLP
Email: support@restroit.com
Working Hours: Monday to Friday, 10 AM – 6 PM IST
Response time: Acknowledgment within 24 hours; resolution within 30 days.
You may also file a complaint with the Data Protection Board of India once constituted under the DPDPA, 2023.