Privacy Policy
Last Updated: [date you publish this]
1. Who We Are
This Privacy Policy explains how RestroPod collects, uses, and protects your information.
RestroPod is a restaurant billing (POS) software, made up of a Windows application, an Android app, and an online service that supports them. It is built and operated by:
Aditya Joshi, an individual based in Indore, Madhya Pradesh, India. RestroPod is not currently a registered company — Aditya operates it independently.
If you run a restaurant and use RestroPod to bill your customers, this policy applies to you. If you are a customer of a restaurant that uses RestroPod, Section 2(G) below explains what happens to your data too.
Any question about this policy, or about your data, can be sent to: info@digiindian.com
2. Data We Collect
We collect different information depending on how you use RestroPod. Here's exactly what, and why.
A. When you sign up for RestroPod (SaaS account)
- Your name, restaurant name, email, phone number
- Password (stored securely, never in plain readable form)
- If you add billing details: GSTIN, billing address, state
We need this to create your account, contact you, and generate valid invoices.
B. When you activate the POS on a device (Windows or Android)
- A unique ID generated from your device's hardware (on Windows: your processor and motherboard serial numbers, turned into a code; on Android: a code your phone's operating system already generates)
- Your device's IP address
- Rough location (city/region/country) worked out from that IP address, using a third-party service called ipapi.co
- The app version you're running
- Your device's clock time (used only to detect tampering, e.g. someone turning their clock back to bypass an expiry)
We need this to activate your license, stop the same license being used on unlimited devices, and detect fraud (like one device pretending to be another restaurant).
C. A recovery phrase for your local database
When you activate your POS, it generates a secret recovery phrase that protects your restaurant's local data on your device. A copy of this phrase is sent to us once, and we store it in encrypted form. You can view it in plain text yourself from your dashboard, using your password. We do not have a way to view it — only you can decrypt it.
D. Payment information
When you pay for a subscription, payment is handled entirely by Razorpay, a licensed Indian payment gateway. We never see or store your card, UPI, or bank details. We only receive confirmation that a payment succeeded or failed, and a transaction reference number.
E. Your restaurant's menu, if you use the QR menu feature
If you turn on the QR code menu feature, your menu (items, categories, prices) is uploaded to our servers so it can be shown on a public web page for your customers to scan and view. This stays on our servers even if you later turn the feature off, unless you ask us to delete it.
F. If you contact us
If you fill out a contact form, ask for support, or email us, we keep your name, contact details, and message, so we can reply and keep a record of the conversation.
G. Your customers' data (people who eat at your restaurant)
If you store your customers' details in RestroPod (name, phone, address, loyalty points), that data is saved only on your own device, inside your encrypted local database. It is not sent to us, and we cannot see it or access it. You are responsible for this data, the same way you're responsible for a paper customer register — RestroPod is just the tool you use to keep it.
3. How We Use Your Data
We use the information above only for these reasons:
- To run your account and let you log in
- To activate and validate your POS license
- To process your subscription payments and generate invoices
- To detect fraud — like someone copying a license onto extra devices
- To send you emails about your account: OTPs, device activity, payment receipts, license status, security alerts
- To respond when you contact us for support
- To show your restaurant's QR menu publicly, if you've turned that feature on
- To fix bugs and improve RestroPod
We do not sell your data. We do not use it for advertising.
4. Who We Share Data With
We only share data with the services that help RestroPod actually work. Each one only gets the specific data it needs to do its job:
- Razorpay — to process your payments. They receive your payment details directly; we never do.
- ipapi.co — to work out the rough location (city/country) of a device from its IP address, for fraud detection.
- Our email provider — to send you account emails (OTPs, receipts, alerts).
We do not share your data with advertisers or data brokers. We may share information if required by Indian law — for example, a valid court order or a request from a government authority.
5. Security
We take reasonable steps to protect your data:
- Your account password is stored in a form that can't be reversed, even by us
- Your local POS database is encrypted on your device
- Your recovery phrase is encrypted on our server, and only you can unlock it — using your account password
- We monitor for suspicious activity, like a device pretending to belong to a different restaurant, or requests trying to tamper with license data
No system is 100% secure, and we can't guarantee absolute security. But we actively watch for and respond to threats.
6. Your Customers' Data — Your Responsibility
If you use RestroPod to store your own customers' details (name, phone, loyalty points, etc.), that data lives only on your device — we never receive it or see it.
This means you are responsible for that data, the same way you would be if you kept it in a notebook or spreadsheet. If one of your customers asks you what data you hold on them, or asks you to delete it, that request is yours to handle — RestroPod gives you the tool to store and manage it, but the legal responsibility for how you collect and use it is yours, not ours.
7. How Long We Keep Your Data
We keep your account and billing data for as long as your account stays active with us.
There is currently no automatic deletion — your data stays until you ask us to remove it. If you want your account and data permanently deleted, email us at info@digiindian.com. Once deletion is done, it cannot be undone.
8. Your Rights
You can:
- Ask us what data we hold about you
- Ask us to correct wrong information (most of this you can already edit yourself from your dashboard)
- Ask us to delete your account and data permanently (see Section 7)
- Withdraw from marketing emails at any time using the unsubscribe link in those emails
To use any of these rights, contact us at info@digiindian.com.
9. Grievance Officer
If you have a complaint about how your data is handled, you can reach our Grievance Officer:
- Name: Aditya Joshi
- Email: info@digiindian.com
- Response time: We aim to acknowledge complaints within [X] days.
Full contact and process details are available on our Grievance Officer page.
10. Changes to This Policy
We may update this policy from time to time — for example, if we add a new feature that changes what data we collect. If we make a significant change, we'll let you know by email or by showing a notice in your dashboard.
11. Governing Law
This policy is governed by the laws of India. Any disputes will be handled in the courts of Indore, Madhya Pradesh.
12. Contact Us
If you have any questions about this Privacy Policy, please contact us via our Contact Page or at info@digiindian.com.