Privacy Policy
Naira — QR ordering & restaurant management, operated by Naira Menus Private Limited
Effective: 12 August 2026Last updated: 12 August 2026
1. About this Policy
Naira is a software platform for restaurants and cafés. It provides QR-code based digital menus and table ordering for diners, and a management dashboard for restaurant owners covering menu management, billing, receipts, table and staff management, and analytics. This Policy explains what personal data is collected through the Naira platform, why it is collected, with whom it is shared, how long it is retained, and the rights available to data principals.
This Policy is published by Naira Menus Private Limited ("Naira", "we", "us", "our"), a company incorporated in India with its registered office at Erandes Rajhans Residency, S. No. 245 D.P.R. Baner, Aundh, Haveli, Pune 411007, Maharashtra. It applies to our websites and subdomains, including nairamenus.in and its subdomains, and to the Naira mobile-web applications.
This Policy is issued in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the rules made thereunder, and with the Information Technology Act, 2000.
2. Who this Policy covers, and our roles
Three categories of individuals interact with Naira, and our legal role differs between them. This distinction determines whom a data principal should approach to exercise their rights.
| Category | Interaction with Naira | Our role |
|---|---|---|
| Diners / guests | Scan a QR code at a restaurant table to browse the menu or place an order. | Data Processor, acting on behalf of the restaurant, which is the Data Fiduciary. |
| Restaurant owners, managers & partners | Hold a Naira account to operate one or more outlets. | Data Fiduciary, for the account and business data. |
| Restaurant staff | Recorded by their employer for rostering, attendance and payroll reference. | Data Processor, acting on behalf of the employer, which is the Data Fiduciary. |
Diners and restaurant staff wishing to access, correct or erase their data should, in the first instance, contact the relevant restaurant, which determines the purpose and manner of collection. We will assist the restaurant in fulfilling such requests. A data principal may also contact us directly using the details in Section 14, and we will route the request appropriately.
3. Personal data we collect
We collect only such personal data as is necessary for the platform to function.
3.1 Diners (restaurant guests)
| Data | When collected | Optional? |
|---|---|---|
| Name | Entered on the welcome screen prior to browsing the menu. | Optional — a "Skip, just browse the menu" option is provided. |
| Mobile number | Entered on the same welcome screen. | Optional — the same option applies. |
| Order contents | When items are added to the cart and an order is placed. | Necessary to fulfil the order. |
| Table number and session | Derived from the QR code scanned; a temporary access code may be issued. | Necessary to route the order to the correct table. |
| Billing / receipt records | Name, mobile number, items, taxes and total, generated with the bill. | Necessary; also a statutory business record. |
| Delivery details | Name, phone number and delivery address, for delivery orders. | Necessary for delivery orders only. |
| Dietary and allergen filters | When menu filters are used. | Optional; applied within the browser to filter the displayed menu. |
| Service requests | When a guest calls a waiter or requests the bill — the table, request type and time. | Necessary to serve the request. |
| Session activity records | When items are added to the cart, and when an in-app suggestion is shown or accepted. Recorded against a cart identifier and the table, not against a name or mobile number. | Necessary for the restaurant's own operational analytics. See Section 4.1. |
| Name and mobile number retained by the restaurant | Where supplied with a bill, so a returning guest's name can be recalled at that restaurant on a later visit. Held separately for each restaurant. | Optional, and only where the diner supplies them. |
Dietary and allergen preferences may indirectly indicate religious belief or health information. Such preferences are not stored as part of a customer record; they are applied only within the diner's browser session to filter the menu display.
3.2 Restaurant owners, managers and partners
| Data | Purpose |
|---|---|
| Username and password | Account creation and security. Passwords are stored only as a bcrypt hash and are not stored, logged or recoverable in readable form. |
| Café / outlet name, business address | Identification of the outlet on customer-facing menus and on bills. |
| Email address | Account communications, password reset and two-factor authentication codes. |
| Phone and WhatsApp number | Account support, and business contact information shown to diners where the operator elects to display it. |
| GSTIN and registered business name | Printing of statutory tax details on customer bills, where supplied. |
| Subscription and billing records | Recording the Naira plan(s) held and generation of invoices. |
| Support tickets and correspondence | Responding to support requests raised. |
| Event listings, where used | Event name, description, date, venue, contact number, contact email, images and ticket types, published to diners on the customer-facing menu. |
3.3 Restaurant staff (recorded by the restaurant)
Where a restaurant uses the staff management module, it may record the following information regarding its employees. Such information is processed solely on the instructions of the relevant restaurant, which determines what is recorded and for what purpose; we exercise no independent discretion over this data.
| Data | Notes |
|---|---|
| Name, phone number, email address | Basic identification and contact information. |
| Role and joining date | Rostering and record-keeping. |
| Salary amount and pay type | Financial information, visible only to the employing restaurant's authorised account holders. |
| Photograph | Where uploaded by the restaurant, for staff identification within the dashboard. Stored within the platform database rather than in separate image storage. |
| Attendance records and leave reasons | A recorded leave reason may reveal health information; restaurants should record only what is necessary. |
| Free-text notes | Entered at the restaurant's discretion. |
Restaurants are responsible for providing notice of such processing to their own employees and for obtaining any consent required under the DPDP Act and applicable labour law. Naira makes the relevant functionality available; the employer determines its use.
3.4 Technical data
- Authentication session tokens, held in secure cookies (see Section 5).
- A cart identifier generated by the diner's own browser, so that each guest at a shared table has a private cart. It is stored on the device against the table concerned and, unless the diner clears their browser storage, is reused if the same device is used at the same table again. It contains no name, number or device information and is not readable by any other restaurant.
- Server logs generated in the ordinary course of use, which may include IP address, browser type, endpoints accessed and timestamps, used for security, fraud prevention, debugging and service reliability. Mobile numbers are masked before they are written to these logs, so that no contact detail is retained in them.
- Images uploaded by restaurants, including menu item photographs, category artwork, banners, logos and staff photographs where applicable.
4. Purpose and basis of processing
Under the DPDP Act, personal data may be processed on the basis of consent, or for certain legitimate uses recognised by the Act.
| Purpose | Data used | Basis |
|---|---|---|
| Displaying the menu and taking orders | Table/session identifiers, cart and order contents | Performance of the requested service |
| Identifying the guest to staff for order delivery | Name, mobile number (where provided) | Consent |
| Recalling a returning diner's name at the same restaurant | Name, mobile number | Consent |
| Generating and issuing bills or receipts | Name, mobile number, order and tax details | Performance of service; statutory record-keeping |
| Transmitting bills or receipt links via WhatsApp | Mobile number, bill document | Consent |
| Responding to table service requests | Table number, request type, timestamp | Performance of the requested service |
| Operational analytics for the restaurant | Session identifier, table, order and suggestion-interaction records | Legitimate business operation of the restaurant |
| Fulfilling delivery orders | Name, phone number, delivery address | Performance of the requested service |
| Creating and securing restaurant accounts | Username, password hash, email, phone number | Performance of contract; security |
| Two-factor authentication and password reset | Email address, phone number, one-time codes | Security of the account |
| Provision of customer support | Account details, support ticket contents | Performance of contract |
| Sales and business analytics for the restaurant | Aggregated order, item and billing records | Legitimate business operation of the restaurant |
| Maintaining the security of the service | Server logs, IP address, session tokens | Security; prevention of fraud |
| Compliance with legal, tax and accounting obligations | Billing and invoice records | Compliance with law |
4.1 Operational analytics — what we record and what we do not
So that a restaurant can understand its own service, the platform records certain operational events during a dining visit: that a cart was started, that an in-app suggestion was shown, and whether it was accepted. These records are held against a cart identifier and a table number only. They carry no name and no mobile number, and they are never combined across restaurants.
Because the cart identifier is stored on the diner's own device, events from a repeat visit using the same device at the same table will carry the same identifier. We do not use this to build a profile of a diner, and no report available to a restaurant presents an individual's history. We describe it here because it means these records are not strictly single-visit, and we would rather state that plainly than imply otherwise. A diner who clears their browser storage starts afresh.
From these records, and from the restaurant's own order history, the dashboard presents that restaurant with summaries such as busiest hours, most-ordered items, and the proportion of carts not completed. These summaries relate to the restaurant's trade, not to identified individuals.
We do not use any of this for advertising, and we do not follow a diner across restaurants, websites or services. See Section 7.
5. Cookies and local storage
Naira uses a limited number of cookies, each of which is strictly necessary for the service to function. No advertising cookies, tracking pixels or third-party analytics cookies are used.
| Name | Purpose | Type |
|---|---|---|
| ADMIN_TOKEN | Maintains a restaurant account holder's signed-in session with the dashboard. | Strictly necessary. HttpOnly; Secure in production. |
| OUTLET_TOKEN | Records which outlet a multi-outlet owner or manager is currently operating within. | Strictly necessary. HttpOnly; Secure in production. |
| IMPERSONATION_TOKEN | Issued where authorised support personnel view an account in read-only mode to resolve a support request. | Strictly necessary. HttpOnly; Secure in production. |
| OPS_TOKEN | Maintains internal operations staff sign-in to the internal console. | Strictly necessary. HttpOnly; Secure in production. |
A limited amount of information is also stored within the user's own browser and is not transmitted to us as a cookie. "Session storage" is discarded when the browser tab is closed; "local storage" persists until cleared by the user.
| Stored item | Purpose | Persistence |
|---|---|---|
| Name and mobile number entered on the welcome screen | Pre-filling the guest's details during the current visit. | Session storage — discarded when the tab is closed. |
| A record that the guest chose to skip entering details | Not asking again during the same visit. | Session storage. |
| A record that a guidance prompt was dismissed | Not showing the same prompt repeatedly. | Session storage. |
| Cart identifier, per table | Keeping each guest's cart separate at a shared table. See Section 4.1. | Local storage — persists until the browser's storage is cleared. |
| Table access code, per table | Allowing the guest to keep ordering without re-entering the code. | Local storage — removed when the dining session ends. |
| A record that the review link was followed | Not asking the same guest to leave a review again. | Local storage — persists until the browser's storage is cleared. |
| Dashboard preferences (notification volume, printer settings) | Restaurant users only — remembering interface settings. | Local storage. |
None of these contain payment details. All may be cleared at any time via the browser's own settings.
6. Disclosure to third parties
We do not sell personal data, nor do we share it for advertising purposes. Personal data is shared only with the service providers set out below, and only to the extent necessary for each to perform its function.
| Provider | Function | Data involved |
|---|---|---|
| Meta Platforms (WhatsApp Business Cloud API) | Delivery of bills, receipt links and account messages via WhatsApp, where this feature is used; and receipt of replies sent by a diner to that WhatsApp number, together with delivery-status notifications. | Recipient mobile number; the message or bill document transmitted; the content of any reply received. |
| Cloudflare | Network ingress, TLS encryption and protection against network attacks. | Network traffic in transit, including IP address. |
| Google LLC (Gmail SMTP) | Transmission of account emails, password resets and one-time verification codes. | Recipient email address; message contents. |
| UrbanPiper (optional) | Synchronisation of orders from food-delivery aggregators, where a restaurant enables this integration. | Order details, and, where supplied by the aggregator, customer name, phone number and delivery address. |
| DigitalOcean (Managed MySQL) | Hosting of the managed database in which platform data resides. | All stored platform data. |
| DigitalOcean (Spaces object storage) | Available for image storage; presently configured but not enabled. | Uploaded images only, if and when enabled. |
Our own personnel. Where a restaurant raises a support request that cannot be resolved otherwise, authorised support personnel may view that restaurant's account in a read-only mode that is technically enforced. Data visible in that mode may include diner names and mobile numbers appearing on bills. Such access is limited to authorised personnel and to the resolution of the request.
Personal data may also be disclosed where required by law, by a court, or by a competent authority, or as necessary to establish or defend a legal claim.
7. What we do not do
- Personal data is not sold or rented to any party, for any purpose.
- No third-party analytics or tracking is used. The platform contains no Google Analytics, Meta Pixel, tag manager, advertising SDK or any other third-party behavioural tracking. No diner data is transmitted to any analytics provider. The operational analytics we do perform are first-party only, session-scoped, and described in Section 4.1.
- No card or bank details are processed. The platform has no payment-gateway integration. Payment between a diner and a restaurant occurs outside Naira; no card number, UPI credential or bank detail is collected or stored by the platform.
- Personal data is not used for advertising, nor to profile a data principal across other websites or services, nor to follow a diner between restaurants or between visits.
- Diner data is not used for our own commercial purposes. Orders, bills, contact details and session records are held separately for each restaurant and are processed solely for the benefit of the restaurant visited. A name or mobile number given at one restaurant is not visible to, and is never used by, any other restaurant on the platform.
8. Storage location and cross-border transfers
Platform data is held in a DigitalOcean Managed MySQL database located in Bangalore, India. Database connections require TLS encryption, which is enforced by the connection configuration rather than merely preferred.
Certain service providers operate internationally, such that personal data may be transferred outside India:
- Meta Platforms processes WhatsApp messages on infrastructure located outside India.
- Google LLC transmits account and verification emails via infrastructure located outside India.
- Cloudflare routes traffic through a global network of edge locations.
- DigitalOcean Spaces, if enabled, is configured for the Singapore (SGP1) region.
The DPDP Act permits the transfer of personal data outside India save to such territories as the Central Government may restrict by notification. Any such restriction will be complied with, and this Policy will be updated should our arrangements change.
9. Data retention
| Data | Retention period | Reason |
|---|---|---|
| Public receipt links issued to diners | 30 days from issue, expiring automatically thereafter | Sufficient time for retrieval of the bill |
| Table ordering sessions and access codes | 4 hours, expiring automatically thereafter | Covers the duration of a single dining visit |
| One-time passwords and password-reset tokens | Between 10 minutes and one hour, depending on type | Security |
| Diner name and mobile number | 6 months from the visit to which they relate | Order history and customer service |
| Session activity records | 6 months, after which only aggregated monthly totals carrying no identifier are retained | Operational analytics for the restaurant |
| Order and receipt records | Retained by the restaurant for the applicable statutory period — 8 years | Legal and tax obligations |
| Restaurant account data | For the duration of the account, deleted or anonymised within 30 days of closure | Performance of contract |
| Staff records | Determined by the employing restaurant | The restaurant is the Data Fiduciary |
| Server and security logs | 90 days | Security and troubleshooting |
Where the DPDP Act or the rules made thereunder prescribe a shorter erasure period for a particular category of Data Fiduciary, the shorter period shall apply.
10. Security measures
- Passwords are stored only as bcrypt hashes and are never stored, transmitted or logged in readable form, nor are they recoverable by us — only reset.
- All traffic to and from the platform is encrypted in transit by means of TLS; database connections likewise require TLS.
- Session tokens are held in HttpOnly cookies, which cannot be read by browser scripts, and are marked Secure in production.
- Each restaurant's orders, menus, bills, diner contact details, staff records and analytics are logically separated, and every request is verified against the account to which it belongs.
- Public receipt links use an unguessable random token and expire automatically, so that a link cannot be enumerated or reused indefinitely.
- Optional two-factor authentication by email is available for restaurant accounts.
- Where support personnel require access to an account to resolve a support request, such access is read-only and is technically enforced.
- Access to production systems is restricted to authorised personnel.
No system can be guaranteed to be entirely secure. In the event of a personal data breach, the Data Protection Board of India and affected data principals will be notified in accordance with the DPDP Act and the rules made thereunder.
11. Rights of the data principal
Subject to the conditions set out in the DPDP Act, a data principal has the following rights:
- Right to access information — to obtain a summary of the personal data processed, the processing activities undertaken, and the identities of any parties with whom it has been shared.
- Right to correction and erasure — to have inaccurate or misleading data corrected, incomplete data completed, and data erased where no longer necessary for the purpose for which it was collected.
- Right to withdraw consent — where processing is based on consent, such consent may be withdrawn at any time, with withdrawal being no more difficult than the giving of consent. Withdrawal does not affect processing already undertaken.
- Right to grievance redressal — to lodge a complaint and receive a response prior to approaching the Data Protection Board.
- Right to nominate — to nominate another individual to exercise these rights in the event of the data principal's death or incapacity.
11.1 Exercise of rights
Diners and restaurant staff should, in the first instance, contact the relevant restaurant, which determines the manner in which personal data is used. A data principal may also write to support@nairamenus.in, and the request will be assisted and routed accordingly.
Restaurant account holders may correct most account information directly within the dashboard Settings, or by writing to support@nairamenus.in.
A response will be provided within 30 days of receipt of a verifiable request. Identity verification may be required prior to acting on a request, to prevent disclosure of personal data to an unauthorised party.
11.2 Account closure and deletion
A restaurant account holder may request closure and deletion of an account by writing to support@nairamenus.in. Upon closure, account data will be deleted or irreversibly anonymised within 30 days, save for such records — principally billing and tax records — as we are required by law to retain.
A diner may request deletion of their name and mobile number at any time by writing to the same address, or by asking the restaurant they visited.
12. Children's data
Naira is intended for use by adults. It is not designed for, nor directed at, children, and personal data is not knowingly collected from any individual under the age of 18 as a distinct category of user.
Under the DPDP Act, the processing of a child's personal data requires verifiable consent from a parent or lawful guardian. The DPDP Act further prohibits the tracking or behavioural monitoring of children and targeted advertising directed at them. Naira undertakes no advertising of any kind, no profiling of any user, and no tracking of any user across restaurants, websites or services. The operational records described in Section 4.1 are confined to a single table at a single restaurant and carry no name or mobile number. As explained in that Section, the cart identifier they use is stored on the diner's own device and may recur on a repeat visit to the same table; it is not used to construct a history of an individual, and no such history is presented to a restaurant.
As a diner ordering at a restaurant table may, in practice, be a minor, restaurants are advised not to require personal details from guests who appear to be children. The entry of a name and mobile number is optional throughout, and a guest may browse and order without providing either.
Any person who believes that a child has provided personal data to us without appropriate parental consent should contact support@nairamenus.in, and such data will be deleted.
13. Grievance redressal
A data principal with a concern regarding the handling of personal data may contact the Grievance Officer named below. Each complaint will be investigated and responded to.
| Name | Ashay Gohad |
|---|---|
| Designation | Grievance Officer |
| support@nairamenus.in | |
| Telephone | +91 90210 44469 |
| Postal address | Naira Menus Private Limited, Erandes Rajhans Residency, S. No. 245 D.P.R. Baner, Aundh, Haveli, Pune 411007, Maharashtra, India |
| Response time | Acknowledgement within 3 working days; resolution within 30 days. |
A data principal dissatisfied with our response is entitled to complain to the Data Protection Board of India, established under the DPDP Act.
14. Contact details
| Entity | Naira Menus Private Limited |
|---|---|
| Registered office | Erandes Rajhans Residency, S. No. 245 D.P.R. Baner, Aundh, Haveli, Pune 411007, Maharashtra, India |
| General enquiries | support@nairamenus.in |
| Privacy enquiries | support@nairamenus.in |
| Website | nairamenus.in |
15. Amendments to this Policy
This Policy may be revised from time to time to reflect changes to the platform, our service providers, or applicable law. Upon any material revision, the "Last updated" date above will be amended and, where the revision materially affects the use of personal data, notice will be given through the platform or by email. Where a revision requires consent under the DPDP Act, such consent will be obtained before the revision takes effect.
16. Language
This Policy is available in English and Hindi. A data principal may request this notice in any language listed in the Eighth Schedule to the Constitution of India by writing to support@nairamenus.in.