Data Protection

Privacy Policy

Last Updated: August 2026

1. Tenant Data Isolation

RestrauntPro employs strict multi-tenant isolation. Every customer profile, transaction log, menu configuration, and sales metric is isolated using tenant-scoped identifiers (`restaurantId`). No tenant data is shared or accessible across different restaurant accounts.

2. Information We Collect

  • Account Credentials: Hashed password strings (`bcryptjs`), user emails, and role assignments.
  • Operational Data: POS orders, menu items, inventory stocks, tax slabs, and receipt records.
  • Customer CRM Data: Phone numbers, customer loyalty points, visit histories, and marketing consent records.

3. Payment & GST Security

We do not store raw credit/debit card details on our servers. Subscription payments are processed via PCI-DSS compliant payment gateways (Razorpay/Stripe). GSTIN details and sales figures are exclusively used for automated GSTR-1 CSV exports within your authenticated session.

4. Third-Party Integrations

If enabled, automated marketing channels (WhatsApp/SMS via Twilio or Gupshup) and food delivery webhooks (Swiggy/Zomato) process order data securely through encrypted API tokens specified in your tenant settings.

Questions Regarding Data Protection?

Contact our privacy compliance team at privacy@restrauntpro.io.