Privacy Policy

Template for counsel review before publishing. Square brackets mark values to fill in. This policy covers Okonomi's own customers (restaurant owners and their staff accounts) and visitors to Okonomi websites. Guests of a restaurant are covered by that restaurant's privacy notice, because the restaurant is the Data Fiduciary for guest data. Okonomi processes guest data on the restaurant's behalf under the Data Processing Agreement.

Last updated: [date]

[Okonomi legal entity] ("Okonomi", "we") provides restaurant software. This policy explains what personal data we collect about restaurant owners, managers and staff who use Okonomi, and about visitors to our websites. It also explains how we use that data and the rights you have under India's Digital Personal Data Protection Act, 2023.

What we collect

  • Account details: name, email, mobile number, restaurant name and address, GSTIN, and your role.
  • Sign-in data: password (stored only as a salted hash), floor PIN (stored only as a salted hash), authenticator secret (encrypted) and device identifiers for paired tablets.
  • Billing: subscription plan and invoices. Card or bank details are handled by our billing provider, [provider], not stored by us.
  • Usage and support: product activity logs, audit logs of sensitive actions, and support conversations.
  • Website visitors: basic analytics about pages visited, collected [with / without] cookies. See [cookie notice].

How we use it

We use this data to:

  • provide and secure the service (sign-in, device pairing, fraud and abuse prevention, audit trails);
  • bill your subscription;
  • give support;
  • send service messages;
  • improve the product using aggregated, de-identified data.

With your consent, we also send product news. You can withdraw that consent at any time.

Sharing

We share personal data only with the service providers who help us run Okonomi, listed in the Data Processing Agreement. We also share it when the law requires us to. We do not sell personal data.

Storage and retention

Data is stored in India ([AWS Mumbai region]). Account data is kept while your subscription is active and for [30] days after it ends, so you can export it. After that it is deleted, except records we must keep for tax or legal reasons.

Security

We protect data with encryption in transit and at rest, isolation between customers, role-based access, lockout after repeated wrong sign-in attempts, optional two-step sign-in and audit logging.

Your rights

You can ask to access, correct or erase your personal data, withdraw consent, or nominate someone to act for you. Write to our Grievance Officer: [name], [email], [postal address]. We respond within [7] days. If you are not satisfied, you may complain to the Data Protection Board of India.

Changes

We will post changes here and, for material changes, email account owners [14] days in advance.