Privacy Policy
Last updated: 24 August 2026 · Applies to the NamastePOS mobile app, web dashboard, and namastepos.in
NamastePOS ("we", "us") is a point-of-sale and restaurant-management platform built in India for Indian food businesses. This policy explains what data we collect, why, and the rights you have under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and other applicable Indian law.
1. Who this policy covers
It covers two kinds of people: business users (owners, managers, and staff of restaurants that subscribe to NamastePOS) and end customers (diners whose orders, bills, or loyalty points are processed by a restaurant using NamastePOS). For end-customer data, the restaurant is the data fiduciary and we act on its instructions as a processor.
2. Data we collect
Account data — name, email address, and profile photo when you sign in with Google or register with an email and password; phone number if you sign in via SMS OTP.
Business data — restaurant name, address, GSTIN, menu, prices, orders, invoices, staff names and roles, and settings you configure.
End-customer data — where a restaurant chooses to record it: customer name, phone number, order history, and loyalty balance. QR/online orders may include a delivery address.
Payment data — subscription payments are processed by Razorpay. We receive payment status and invoice metadata; we never see or store your card number, UPI PIN, or banking credentials.
Technical data — device type, app version, IP address, and crash/error reports (via Sentry) used to keep the service reliable. Crash reports are scrubbed of emails, phone numbers, and tokens before they leave your device.
3. Why we use it
To operate the POS (orders, billing, kitchen display, printing), generate GST-compliant invoices, send transactional messages (order updates, OTPs, invoices via SMS/WhatsApp where enabled), bill your subscription, provide support, secure the platform against fraud and abuse, and improve reliability. We do not sell personal data, and we do not use your business's data to advertise to your customers.
4. Who we share it with
Only service providers needed to run NamastePOS: Razorpay (subscription payments), Google (sign-in), MSG91 (SMS OTP), Twilio (WhatsApp messages, where enabled), Sentry (crash reporting), and our hosting providers. Each receives only what its function requires. We may disclose data where required by law or a competent authority.
5. Retention
Business records that Indian tax law requires (invoices, GST records) are retained for the statutory period even after account closure. Other personal data is deleted or anonymised when no longer needed, and end-customer data is deleted on verified request or on the restaurant's instruction.
6. Your rights (DPDP Act 2023)
You may access a copy of your personal data, correct it, request erasure, withdraw consent, and nominate a person to exercise your rights. Business users can do this from Privacy in the dashboard or app; end customers can use the privacy page linked on their bill or contact the restaurant. We respond to verified requests within the timelines prescribed by law.
7. Security
Data is encrypted in transit (TLS), access is role-based and tenant-isolated, passwords are hashed with bcrypt, staff PINs are rate-limited with persistent lockout, and administrative access requires two-factor authentication. No system is perfectly secure; if a breach affecting you occurs we will notify you and the Data Protection Board of India as required.
8. Children
NamastePOS is a business tool and is not directed at children. We do not knowingly process children's personal data.
9. Grievance Officer
For privacy questions, requests, or complaints, contact our Grievance Officer at [email protected]. If unsatisfied with our response, you may escalate to the Data Protection Board of India.
10. Changes
We will post updates to this policy here and, for material changes, notify you in the app or by email. Continued use after the effective date constitutes acceptance.