DIGITAL PERSONAL DATA PROTECTION ACT, 2023 COMPLIANT

Privacy Policy & Data Governance

Last Updated: September 19, 2026Effective Date: ImmediateJurisdiction: Republic of India

This Privacy Policy constitutes a legally binding document governing the collection, processing, storage, disclosure, and protection of digital personal data by MENU.IND.IN (hereinafter referred to as “Platform”, “We”, “Us”, or “Our”) in full compliance with the Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Consumer Protection (E-Commerce) Rules, 2020.

Core Privacy Guarantees at a Glance

  • Zero Ad Selling: We never sell, rent, or trade your guest data to external third-party advertisers.
  • Zero-Knowledge Secrets: Payment gateway keys are encrypted via AES-256-GCM. We never see plaintext secrets.
  • No Forced Guest Login: Customers view menus without being forced to download mobile apps or register.
  • Indian Domestic Storage: All primary database records are hosted in data facilities located within India.

1. Statutory Definitions & Parties

For the purposes of this Privacy Policy, capitalized terms shall have the respective meanings assigned to them below under the DPDP Act 2023:

  • “Data Fiduciary”: Refers to any person or entity who alone or in conjunction with other persons determines the purpose and means of processing personal data. In the context of customer dine-in orders, the respective Restaurant Establishment acts as the primary Data Fiduciary, and MENU.IND.IN operates as a Data Processor. In respect of registered Restaurant Owner accounts, MENU.IND.IN acts as the Data Fiduciary.
  • “Data Principal”: Refers to the natural person to whom the personal data relates, including dining customers, restaurant operators, and platform visitors.
  • “Personal Data”: Refers to any data about an individual who is identifiable by or in relation to such data.
  • “Processing”: Means a wholly or partly automated operation or set of operations performed on digital personal data, including collection, recording, organisation, structuring, storage, retrieval, use, disclosure, or erasure.

2. Categories of Personal Data Collected

We restrict data collection strictly to what is necessary for facilitating hospitality operations and orders:

A. Restaurant Operator & Tenant Data (Account Creation & KYC)

  • Full legal name, business trade name, and unique subdomain slug.
  • Commercial contact email address and encrypted password hash (via bcrypt with 10 salt rounds).
  • Restaurant physical address, telephone number, official WhatsApp business handle, and Google Maps location URL.
  • FSSAI License registration number and Goods & Services Tax Identification Number (GSTIN), where applicable.
  • Payment gateway public API Key ID (encrypted secret keys are stored exclusively using authenticated AES-256-GCM encryption).

B. Dining Guest & Customer Order Data (Dine-In & Takeaway)

  • Table identifier or takeaway token associated with the specific order session.
  • Customer full name and telephone number (optionally provided by the customer for digital bill receipt dispatch and order status notifications via SMS/WhatsApp).
  • Ordered food items, quantities, dietary specifications, and special kitchen instructions.
  • Transaction payment mode (Cash at Counter vs. Online UPI/Card) and associated payment aggregator order identification reference.
  • Optional GPS Geofencing coordinates (latitude/longitude), queried strictly client-side to verify physical presence within the restaurant premises, and never retained permanently in tracking databases.

C. Automated Technical Telemetry & Device Logs

  • Internet Protocol (IP) address, mobile device operating system, browser user agent, and QR scan event timestamp.
  • Essential HTTP session cookies utilized to maintain table binding and cart states across browser refreshes.

3. Lawful Grounds & Purpose Limitation

In adherence to Section 6 of the DPDP Act 2023, personal data is processed solely under the following lawful grounds:

  • Consent of the Data Principal: Explicitly obtained when restaurant owners register an account or when guests voluntarily enter their mobile number for digital receipt delivery.
  • Certain Legitimate Uses: As stipulated under Section 7 of the DPDP Act, including the fulfillment of service requests initiated by the guest (e.g., relaying food preparation requests to the kitchen, processing UPI payments, printing thermal invoices).
  • Legal & Regulatory Compliance: Maintaining audit records required under the Information Technology Act, 2000, and GST invoicing regulations.

4. Payment Processing & Zero-Escrow Architecture

MENU.IND.IN does not operate as a payment intermediary, wallet, or escrow entity. Online payment transactions initiated by dining customers are processed directly through Reserve Bank of India (RBI) authorized Payment Aggregators (such as Razorpay Software Private Limited, PhonePe Private Limited, or PayU Payments Private Limited) configured by the respective restaurant merchant.

MENU.IND.IN never intercepts, stores, logs, or views customer credit card numbers, CVVs, debit card PINs, or UPI MPINs. All sensitive transactional data is transmitted directly to the RBI-regulated gateway over bank-grade TLS 1.3 encrypted conduits. Funds flow straight into the restaurant merchant's verified bank account.

5. Rights of the Data Principal under DPDP Act 2023

Every individual whose personal data is processed by MENU.IND.IN enjoys the statutory rights guaranteed under Chapter III of the DPDP Act 2023:

Right to Access Information
The right to obtain a summary of personal data being processed, identity of third parties with whom data has been shared, and any other information prescribed.
Right to Correction & Erasure
The right to request correction of inaccurate data, completion of incomplete data, and erasure of personal data that is no longer necessary for the purpose collected.
Right of Grievance Redressal
The right to have grievances addressed by our statutory Grievance Officer within thirty (30) days from the date of submission.
Right to Nominate
The right to nominate any other individual who shall, in the event of death or incapacity of the Data Principal, exercise these rights on their behalf.

6. Technical & Organizational Security Safeguards

In compliance with Section 8(5) of the DPDP Act 2023 and the Reasonable Security Practices Rules 2011, MENU.IND.IN implements comprehensive multi-layer security measures:

  • Encryption in Transit: 100% of data transmissions are protected using TLS 1.3 cryptographic protocols with modern cipher suites and Strict-Transport-Security (HSTS) headers.
  • Encryption at Rest: Database backups and sensitive credentials are encrypted using industry-standard AES-256 cipher specifications.
  • Session Security: Authentication credentials and tokens utilize secure HTTP-only cookies equipped with strict SameSite=Lax boundaries to safeguard against Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF).
  • Regular Vulnerability Audits: Continuous vulnerability scans, dependency audits, and strict role-based access control (RBAC) ensuring only authorized administrative personnel can access server telemetry.

7. Data Retention Protocol

We retain customer order history records for a period of up to twelve (12) months for accounting, tax auditing, and dispute resolution purposes. Restaurant account credentials remain active until the restaurant operator requests formal account deactivation or termination. Upon validated deletion requests, personal data is purged or irrevocably anonymized within thirty (30) calendar days, barring records required to be retained by statutory tax mandates.

8. Statutory Grievance Redressal Officer

In accordance with the Information Technology Act, 2000, Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the DPDP Act 2023, the details of our designated Grievance Officer are set forth below:

Designated Grievance & Data Protection Officer
Name: Mr. Shoaib Khan
Designation: Head of Compliance & Grievance Redressal
Entity: MENU.IND.IN SaaS Technologies
Registered Address: Inner Circle, Connaught Place, New Delhi, Delhi 110001, Republic of India
Direct Grievance Email: grievance@menu.ind.in
Customer Support Phone: +91 98765 43210
Response Timeframe: Acknowledgment within twenty-four (24) hours; resolution within fifteen (15) working days.