Privacy Policy

Naira — QR ordering & restaurant management, operated by Naira Menus Private Limited

Effective: 12 August 2026Last updated: 12 August 2026

1. About this Policy

Naira is a software platform for restaurants and cafés. It provides QR-code based digital menus and table ordering for diners, and a management dashboard for restaurant owners covering menu management, billing, receipts, table and staff management, and analytics. This Policy explains what personal data is collected through the Naira platform, why it is collected, with whom it is shared, how long it is retained, and the rights available to data principals.

This Policy is published by Naira Menus Private Limited ("Naira", "we", "us", "our"), a company incorporated in India with its registered office at Erandes Rajhans Residency, S. No. 245 D.P.R. Baner, Aundh, Haveli, Pune 411007, Maharashtra. It applies to our websites and subdomains, including nairamenus.in and its subdomains, and to the Naira mobile-web applications.

This Policy is issued in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the rules made thereunder, and with the Information Technology Act, 2000.

2. Who this Policy covers, and our roles

Three categories of individuals interact with Naira, and our legal role differs between them. This distinction determines whom a data principal should approach to exercise their rights.

CategoryInteraction with NairaOur role
Diners / guestsScan a QR code at a restaurant table to browse the menu or place an order.Data Processor, acting on behalf of the restaurant, which is the Data Fiduciary.
Restaurant owners, managers & partnersHold a Naira account to operate one or more outlets.Data Fiduciary, for the account and business data.
Restaurant staffRecorded by their employer for rostering, attendance and payroll reference.Data Processor, acting on behalf of the employer, which is the Data Fiduciary.

Diners and restaurant staff wishing to access, correct or erase their data should, in the first instance, contact the relevant restaurant, which determines the purpose and manner of collection. We will assist the restaurant in fulfilling such requests. A data principal may also contact us directly using the details in Section 14, and we will route the request appropriately.

3. Personal data we collect

We collect only such personal data as is necessary for the platform to function.

3.1 Diners (restaurant guests)

DataWhen collectedOptional?
NameEntered on the welcome screen prior to browsing the menu.Optional — a "Skip, just browse the menu" option is provided.
Mobile numberEntered on the same welcome screen.Optional — the same option applies.
Order contentsWhen items are added to the cart and an order is placed.Necessary to fulfil the order.
Table number and sessionDerived from the QR code scanned; a temporary access code may be issued.Necessary to route the order to the correct table.
Billing / receipt recordsName, mobile number, items, taxes and total, generated with the bill.Necessary; also a statutory business record.
Delivery detailsName, phone number and delivery address, for delivery orders.Necessary for delivery orders only.
Dietary and allergen filtersWhen menu filters are used.Optional; applied within the browser to filter the displayed menu.
Service requestsWhen a guest calls a waiter or requests the bill — the table, request type and time.Necessary to serve the request.
Session activity recordsWhen items are added to the cart, and when an in-app suggestion is shown or accepted. Recorded against a cart identifier and the table, not against a name or mobile number.Necessary for the restaurant's own operational analytics. See Section 4.1.
Name and mobile number retained by the restaurantWhere supplied with a bill, so a returning guest's name can be recalled at that restaurant on a later visit. Held separately for each restaurant.Optional, and only where the diner supplies them.

Dietary and allergen preferences may indirectly indicate religious belief or health information. Such preferences are not stored as part of a customer record; they are applied only within the diner's browser session to filter the menu display.

3.2 Restaurant owners, managers and partners

DataPurpose
Username and passwordAccount creation and security. Passwords are stored only as a bcrypt hash and are not stored, logged or recoverable in readable form.
Café / outlet name, business addressIdentification of the outlet on customer-facing menus and on bills.
Email addressAccount communications, password reset and two-factor authentication codes.
Phone and WhatsApp numberAccount support, and business contact information shown to diners where the operator elects to display it.
GSTIN and registered business namePrinting of statutory tax details on customer bills, where supplied.
Subscription and billing recordsRecording the Naira plan(s) held and generation of invoices.
Support tickets and correspondenceResponding to support requests raised.
Event listings, where usedEvent name, description, date, venue, contact number, contact email, images and ticket types, published to diners on the customer-facing menu.

3.3 Restaurant staff (recorded by the restaurant)

Where a restaurant uses the staff management module, it may record the following information regarding its employees. Such information is processed solely on the instructions of the relevant restaurant, which determines what is recorded and for what purpose; we exercise no independent discretion over this data.

DataNotes
Name, phone number, email addressBasic identification and contact information.
Role and joining dateRostering and record-keeping.
Salary amount and pay typeFinancial information, visible only to the employing restaurant's authorised account holders.
PhotographWhere uploaded by the restaurant, for staff identification within the dashboard. Stored within the platform database rather than in separate image storage.
Attendance records and leave reasonsA recorded leave reason may reveal health information; restaurants should record only what is necessary.
Free-text notesEntered at the restaurant's discretion.

Restaurants are responsible for providing notice of such processing to their own employees and for obtaining any consent required under the DPDP Act and applicable labour law. Naira makes the relevant functionality available; the employer determines its use.

3.4 Technical data

4. Purpose and basis of processing

Under the DPDP Act, personal data may be processed on the basis of consent, or for certain legitimate uses recognised by the Act.

PurposeData usedBasis
Displaying the menu and taking ordersTable/session identifiers, cart and order contentsPerformance of the requested service
Identifying the guest to staff for order deliveryName, mobile number (where provided)Consent
Recalling a returning diner's name at the same restaurantName, mobile numberConsent
Generating and issuing bills or receiptsName, mobile number, order and tax detailsPerformance of service; statutory record-keeping
Transmitting bills or receipt links via WhatsAppMobile number, bill documentConsent
Responding to table service requestsTable number, request type, timestampPerformance of the requested service
Operational analytics for the restaurantSession identifier, table, order and suggestion-interaction recordsLegitimate business operation of the restaurant
Fulfilling delivery ordersName, phone number, delivery addressPerformance of the requested service
Creating and securing restaurant accountsUsername, password hash, email, phone numberPerformance of contract; security
Two-factor authentication and password resetEmail address, phone number, one-time codesSecurity of the account
Provision of customer supportAccount details, support ticket contentsPerformance of contract
Sales and business analytics for the restaurantAggregated order, item and billing recordsLegitimate business operation of the restaurant
Maintaining the security of the serviceServer logs, IP address, session tokensSecurity; prevention of fraud
Compliance with legal, tax and accounting obligationsBilling and invoice recordsCompliance with law

4.1 Operational analytics — what we record and what we do not

So that a restaurant can understand its own service, the platform records certain operational events during a dining visit: that a cart was started, that an in-app suggestion was shown, and whether it was accepted. These records are held against a cart identifier and a table number only. They carry no name and no mobile number, and they are never combined across restaurants.

Because the cart identifier is stored on the diner's own device, events from a repeat visit using the same device at the same table will carry the same identifier. We do not use this to build a profile of a diner, and no report available to a restaurant presents an individual's history. We describe it here because it means these records are not strictly single-visit, and we would rather state that plainly than imply otherwise. A diner who clears their browser storage starts afresh.

From these records, and from the restaurant's own order history, the dashboard presents that restaurant with summaries such as busiest hours, most-ordered items, and the proportion of carts not completed. These summaries relate to the restaurant's trade, not to identified individuals.

We do not use any of this for advertising, and we do not follow a diner across restaurants, websites or services. See Section 7.

5. Cookies and local storage

Naira uses a limited number of cookies, each of which is strictly necessary for the service to function. No advertising cookies, tracking pixels or third-party analytics cookies are used.

NamePurposeType
ADMIN_TOKENMaintains a restaurant account holder's signed-in session with the dashboard.Strictly necessary. HttpOnly; Secure in production.
OUTLET_TOKENRecords which outlet a multi-outlet owner or manager is currently operating within.Strictly necessary. HttpOnly; Secure in production.
IMPERSONATION_TOKENIssued where authorised support personnel view an account in read-only mode to resolve a support request.Strictly necessary. HttpOnly; Secure in production.
OPS_TOKENMaintains internal operations staff sign-in to the internal console.Strictly necessary. HttpOnly; Secure in production.

A limited amount of information is also stored within the user's own browser and is not transmitted to us as a cookie. "Session storage" is discarded when the browser tab is closed; "local storage" persists until cleared by the user.

Stored itemPurposePersistence
Name and mobile number entered on the welcome screenPre-filling the guest's details during the current visit.Session storage — discarded when the tab is closed.
A record that the guest chose to skip entering detailsNot asking again during the same visit.Session storage.
A record that a guidance prompt was dismissedNot showing the same prompt repeatedly.Session storage.
Cart identifier, per tableKeeping each guest's cart separate at a shared table. See Section 4.1.Local storage — persists until the browser's storage is cleared.
Table access code, per tableAllowing the guest to keep ordering without re-entering the code.Local storage — removed when the dining session ends.
A record that the review link was followedNot asking the same guest to leave a review again.Local storage — persists until the browser's storage is cleared.
Dashboard preferences (notification volume, printer settings)Restaurant users only — remembering interface settings.Local storage.

None of these contain payment details. All may be cleared at any time via the browser's own settings.

6. Disclosure to third parties

We do not sell personal data, nor do we share it for advertising purposes. Personal data is shared only with the service providers set out below, and only to the extent necessary for each to perform its function.

ProviderFunctionData involved
Meta Platforms (WhatsApp Business Cloud API)Delivery of bills, receipt links and account messages via WhatsApp, where this feature is used; and receipt of replies sent by a diner to that WhatsApp number, together with delivery-status notifications.Recipient mobile number; the message or bill document transmitted; the content of any reply received.
CloudflareNetwork ingress, TLS encryption and protection against network attacks.Network traffic in transit, including IP address.
Google LLC (Gmail SMTP)Transmission of account emails, password resets and one-time verification codes.Recipient email address; message contents.
UrbanPiper (optional)Synchronisation of orders from food-delivery aggregators, where a restaurant enables this integration.Order details, and, where supplied by the aggregator, customer name, phone number and delivery address.
DigitalOcean (Managed MySQL)Hosting of the managed database in which platform data resides.All stored platform data.
DigitalOcean (Spaces object storage)Available for image storage; presently configured but not enabled.Uploaded images only, if and when enabled.

Our own personnel. Where a restaurant raises a support request that cannot be resolved otherwise, authorised support personnel may view that restaurant's account in a read-only mode that is technically enforced. Data visible in that mode may include diner names and mobile numbers appearing on bills. Such access is limited to authorised personnel and to the resolution of the request.

Personal data may also be disclosed where required by law, by a court, or by a competent authority, or as necessary to establish or defend a legal claim.

7. What we do not do

8. Storage location and cross-border transfers

Platform data is held in a DigitalOcean Managed MySQL database located in Bangalore, India. Database connections require TLS encryption, which is enforced by the connection configuration rather than merely preferred.

Certain service providers operate internationally, such that personal data may be transferred outside India:

The DPDP Act permits the transfer of personal data outside India save to such territories as the Central Government may restrict by notification. Any such restriction will be complied with, and this Policy will be updated should our arrangements change.

9. Data retention

DataRetention periodReason
Public receipt links issued to diners30 days from issue, expiring automatically thereafterSufficient time for retrieval of the bill
Table ordering sessions and access codes4 hours, expiring automatically thereafterCovers the duration of a single dining visit
One-time passwords and password-reset tokensBetween 10 minutes and one hour, depending on typeSecurity
Diner name and mobile number6 months from the visit to which they relateOrder history and customer service
Session activity records6 months, after which only aggregated monthly totals carrying no identifier are retainedOperational analytics for the restaurant
Order and receipt recordsRetained by the restaurant for the applicable statutory period — 8 yearsLegal and tax obligations
Restaurant account dataFor the duration of the account, deleted or anonymised within 30 days of closurePerformance of contract
Staff recordsDetermined by the employing restaurantThe restaurant is the Data Fiduciary
Server and security logs90 daysSecurity and troubleshooting

Where the DPDP Act or the rules made thereunder prescribe a shorter erasure period for a particular category of Data Fiduciary, the shorter period shall apply.

10. Security measures

No system can be guaranteed to be entirely secure. In the event of a personal data breach, the Data Protection Board of India and affected data principals will be notified in accordance with the DPDP Act and the rules made thereunder.

11. Rights of the data principal

Subject to the conditions set out in the DPDP Act, a data principal has the following rights:

11.1 Exercise of rights

Diners and restaurant staff should, in the first instance, contact the relevant restaurant, which determines the manner in which personal data is used. A data principal may also write to support@nairamenus.in, and the request will be assisted and routed accordingly.

Restaurant account holders may correct most account information directly within the dashboard Settings, or by writing to support@nairamenus.in.

A response will be provided within 30 days of receipt of a verifiable request. Identity verification may be required prior to acting on a request, to prevent disclosure of personal data to an unauthorised party.

11.2 Account closure and deletion

A restaurant account holder may request closure and deletion of an account by writing to support@nairamenus.in. Upon closure, account data will be deleted or irreversibly anonymised within 30 days, save for such records — principally billing and tax records — as we are required by law to retain.

A diner may request deletion of their name and mobile number at any time by writing to the same address, or by asking the restaurant they visited.

12. Children's data

Naira is intended for use by adults. It is not designed for, nor directed at, children, and personal data is not knowingly collected from any individual under the age of 18 as a distinct category of user.

Under the DPDP Act, the processing of a child's personal data requires verifiable consent from a parent or lawful guardian. The DPDP Act further prohibits the tracking or behavioural monitoring of children and targeted advertising directed at them. Naira undertakes no advertising of any kind, no profiling of any user, and no tracking of any user across restaurants, websites or services. The operational records described in Section 4.1 are confined to a single table at a single restaurant and carry no name or mobile number. As explained in that Section, the cart identifier they use is stored on the diner's own device and may recur on a repeat visit to the same table; it is not used to construct a history of an individual, and no such history is presented to a restaurant.

As a diner ordering at a restaurant table may, in practice, be a minor, restaurants are advised not to require personal details from guests who appear to be children. The entry of a name and mobile number is optional throughout, and a guest may browse and order without providing either.

Any person who believes that a child has provided personal data to us without appropriate parental consent should contact support@nairamenus.in, and such data will be deleted.

13. Grievance redressal

A data principal with a concern regarding the handling of personal data may contact the Grievance Officer named below. Each complaint will be investigated and responded to.

NameAshay Gohad
DesignationGrievance Officer
Emailsupport@nairamenus.in
Telephone+91 90210 44469
Postal addressNaira Menus Private Limited, Erandes Rajhans Residency, S. No. 245 D.P.R. Baner, Aundh, Haveli, Pune 411007, Maharashtra, India
Response timeAcknowledgement within 3 working days; resolution within 30 days.

A data principal dissatisfied with our response is entitled to complain to the Data Protection Board of India, established under the DPDP Act.

14. Contact details

EntityNaira Menus Private Limited
Registered officeErandes Rajhans Residency, S. No. 245 D.P.R. Baner, Aundh, Haveli, Pune 411007, Maharashtra, India
General enquiriessupport@nairamenus.in
Privacy enquiriessupport@nairamenus.in
Websitenairamenus.in

15. Amendments to this Policy

This Policy may be revised from time to time to reflect changes to the platform, our service providers, or applicable law. Upon any material revision, the "Last updated" date above will be amended and, where the revision materially affects the use of personal data, notice will be given through the platform or by email. Where a revision requires consent under the DPDP Act, such consent will be obtained before the revision takes effect.

16. Language

This Policy is available in English and Hindi. A data principal may request this notice in any language listed in the Eighth Schedule to the Constitution of India by writing to support@nairamenus.in.