Privacy Policy
Last updated: 2026-08-22
This Privacy Policy explains how DEVMORE INNOVATIONS ("Mumbai Resto", "we", "us", "our") collects, uses, stores, and protects personal data when you use our platform website (mumbairesto.in), admin dashboard, mobile applications, tenant storefronts, QR ordering interfaces, table booking systems, and related services (collectively, the "Platform").
This policy applies to three categories of users:
- Restaurant Owners/Staff ("Platform Users") — who manage restaurants through the admin dashboard
- Diners/Customers ("End Users") — who browse tenant storefronts, place QR orders, make bookings, or order online
- Platform Administrators — who operate the Platform
Where sections apply only to specific user types, they are clearly marked.
On this page
- Who We Are and Scope
- Information We Collect
- Device Permissions We Request and Why
- How We Use Your Information
- Legal Basis for Processing (India — DPDP Act, 2023)
- How We Share Your Information
- Data Storage, Security, and International Transfer
- Data Retention
- Your Rights and Choices
- Children
- Cookies and Similar Technologies
- Third-Party Links and Payment Apps
- Changes to This Policy
- Grievance Officer
- Contact Us
1. Who We Are and Scope
Mumbai Resto is a restaurant management SaaS platform operated by DEVMORE INNOVATIONS, providing:
- Admin Dashboard — restaurant operations (orders, bookings, menu, staff, tables, branches, kitchen display, analytics)
- Tenant Storefronts — public-facing restaurant websites with menus, galleries, booking widgets, and contact info
- QR Table Ordering — scan-to-order from table QR codes, multi-session carts, live kitchen updates
- Online Bookings — 24/7 table reservations with availability management, confirmations, and reminders
- Payment Integration — UPI, cards, wallets via Razorpay/Stripe; Enterprise plans support custom gateways
- Multi-branch & Multi-tenant — each restaurant (tenant) is a logically isolated data environment
Entity details:
- Data Fiduciary: DEVMORE INNOVATIONS
- Registered Address: Mumbai, Maharashtra, India
- Platform Domain: mumbairesto.in (and tenant subdomains like
{slug}.mumbairesto.in, custom domains) - Grievance Email: grievance@mumbairesto.in
- Support Email: support@mumbairesto.in
2. Information We Collect
2.1 Information You Provide Directly
Platform Users (Restaurant Owners/Staff):
- Account credentials: full name, email address, phone number (for OTP-based login), password hash
- Restaurant business details: name, slug, address, phone, email, cuisine type, operating hours, GSTIN/FSSAI (optional)
- Branch details: name, address, contact info, table layouts, QR codes
- Menu content: categories, items, descriptions, prices, images, dietary tags, allergens
- Staff accounts: names, emails, roles (owner, manager, captain, kitchen, waiter), permissions
- Billing & subscription: plan selection, invoice history, payment method tokens (via processor)
- Settings & customizations: theme, template, domain configuration, notification preferences
- Support communications: tickets, chat messages, email correspondence, attachments
End Users (Diners):
- Booking details: name, phone, email, party size, date/time, special requests, table preferences
- QR Ordering: table/session identifier, cart items, special instructions, dietary preferences
- Online Orders: delivery address, pickup instructions, contact details, order notes
- Reviews/Feedback: ratings, comments, photos (if submitted)
- Wallet/Saved payment methods: tokenized references only (processed by payment partner)
- Marketing preferences: email/SMS consent for promotions, newsletters
All Users:
- Communications you send us: support emails, contact forms, feature requests, bug reports
2.2 Information Collected Automatically
From all Platform interactions:
- Device information: model, OS version, browser type/version, app version, language, timezone, screen resolution
- Network data: IP address, ISP, connection type (Wi-Fi/cellular)
- Usage analytics: pages viewed, features used, session duration, navigation paths, search queries, booking/order funnel events
- Crash/diagnostic data: error traces, device state at crash time, app version (via Sentry/Firebase Crashlytics)
- Location data: only when you grant permission — used for "nearby branches" on storefronts, delivery radius checks, auto-detecting nearest branch for QR ordering. Never collected in background. Optional.
From mobile apps (if applicable):
- Push notification token (Firebase Cloud Messaging) for booking confirmations, order updates, OTPs, reminders
- Camera/photo library access: only when you initiate upload of profile photo, menu images, payment screenshots, or KYC documents
- Biometric/FaceID: optional, for quick app unlock (stored locally on device via OS keychain)
2.3 Payment Information
- We never see or store full card numbers, CVV, UPI PIN, or net-banking credentials.
- Payments are processed by Razorpay Payments India Pvt. Ltd. and/or Stripe Payments India Pvt. Ltd. on their PCI-DSS Level 1 certified infrastructure.
- We receive and store only: order/transaction ID, payment reference/UTR, amount, currency, payment method type (UPI/card/wallet), status (success/failed/pending/refunded), timestamps, and masked instrument details (last 4 digits of card, VPA handle).
- For manual UPI flows (pay-to-owner), we store the UPI reference/UTR you submit and any payment confirmation screenshot you upload for staff verification.
- Refunds: we store refund ID, amount, reason, status, and processing timestamps.
2.4 Information from Third Parties
- Payment status callbacks from Razorpay/Stripe (webhook events)
- SMS/OTP delivery status from providers (Twilio, MSG91, or Firebase Auth)
- Email delivery/engagement metrics from transactional email providers (SendGrid, Resend)
- Domain verification status from DNS providers (for custom domains)
- Social login profile data (if you sign in via Google/Microsoft — only name, email, profile photo)
2.5 Information We Do NOT Collect
- Government IDs (Aadhaar, PAN, passport, driving license) from End Users
- Contacts, call logs, SMS inbox (except OS-level OTP autofill), microphone, background location
- Keystroke logging, screen recording, or clipboard access
- Children's data (see Section 10)
- Biometric data (except optional device-local app unlock)
3. Device Permissions We Request and Why
| Permission | Purpose | Required? | |------------|---------|-----------| | Location (precise/approximate, when-in-use only) | Show nearby branches on storefront; auto-detect nearest branch for QR ordering; validate delivery radius | Optional — features degrade gracefully if denied | | Camera / Photo Library | Upload profile photo, menu dish images, branch photos, payment screenshots, KYC documents | Optional — only when you initiate an upload | | Notifications (Push) | Booking confirmations, order status updates, OTPs, payment receipts, slot reminders, negotiation alerts | Optional — you may miss time-sensitive updates if disabled | | Internet / Network State | Required for all Platform functionality (cloud sync, real-time updates) | Required | | Storage (scoped) | Cache images, generate/share booking receipts PDFs, offline draft orders | Required for full functionality | | Biometric / FaceID | Optional quick unlock for mobile app | Optional — local-only, never leaves device |
We never use any permission for a purpose other than the one stated above. You can revoke permissions anytime via your device OS settings.
4. How We Use Your Information
We process personal data for the following purposes:
| Purpose | Applies To | |---------|------------| | Account creation & authentication (OTP login, session management, role-based access) | Platform Users, End Users | | Restaurant operations (orders, bookings, menu, inventory, staff scheduling, kitchen display, table management) | Platform Users | | Tenant storefront rendering (menus, galleries, booking widget, contact info, SEO) | End Users | | QR table ordering (session management, cart persistence, live order sync to kitchen) | End Users | | Booking management (availability checks, confirmations, reminders, cancellations, waitlists) | End Users, Platform Users | | Payment processing & reconciliation (initiate, verify, refund, settle, issue invoices) | Platform Users, End Users | | Customer communication (transactional SMS/email/push: OTPs, booking confirmations, order status, payment receipts, reminders) | End Users | | Support & dispute resolution (tickets, chat, refund requests, chargeback evidence) | All Users | | Fraud prevention & security (rate limiting, anomaly detection, abuse prevention, audit logs) | All Users | | Analytics & product improvement (aggregate usage, feature adoption, crash fixing, performance monitoring) | All Users | | Legal compliance & tax obligations (GST invoicing, TDS, accounting records, lawful requests) | Platform Users | | Marketing (with consent) — newsletters, feature announcements, promotional offers, webinar invites | Platform Users (opt-in), End Users (opt-in per tenant) |
We do not sell your personal data. We do not use your data for third-party advertising.
5. Legal Basis for Processing (India — DPDP Act, 2023)
| Basis | Applies To | |-------|------------| | Your consent — given at sign-up, when granting device permissions, opting into marketing, or submitting optional data (photos, reviews). You may withdraw consent as described in Section 9. | All Users | | Contractual necessity — processing necessary to perform the services you requested (bookings, orders, payments, dashboard features, tenant storefront). | All Users | | Legitimate uses recognized under the DPDP Act, 2023 — security, fraud prevention, error monitoring, service improvement, enforcement of Terms, compliance with law. | All Users | | Legal obligation — tax invoicing, TDS, GST returns, accounting records, lawful government requests. | Platform Users |
6. How We Share Your Information
6.1 With Your Restaurant (Tenant Context)
- End Users → Restaurant Staff: When you place a booking or QR order, the restaurant's staff (owner, manager, captain, kitchen, waiter) can see your name, phone, booking/order details, special requests, and payment status. This is necessary to fulfil your service.
- Restaurant Staff → End Users: Staff may contact you via Platform messaging or phone for order clarification, booking changes, or delivery coordination.
6.2 Public Content
- Reviews, ratings, and photos you submit on tenant storefronts are publicly visible within that storefront and display your name/initials.
6.3 With Service Providers (Data Processors)
| Provider Category | Examples | Purpose | |-------------------|----------|---------| | Cloud Infrastructure & Database | Google Cloud (Firebase: Auth, Firestore, Storage, Functions, FCM, Analytics, Crashlytics), Turso (libSQL) | Hosting, authentication, real-time data sync, file storage, push notifications, analytics, crash reporting | | Payment Processors | Razorpay Payments India Pvt. Ltd., Stripe Payments India Pvt. Ltd. | Payment processing, refunds, settlements (RBI-regulated payment aggregators) | | Transactional Communications | Twilio, MSG91, SendGrid, Resend, Firebase Auth | SMS/OTP delivery, transactional email, WhatsApp Business API | | Error Monitoring | Sentry | Crash reporting, performance monitoring (if enabled) | | Domain & DNS | Cloudflare, DNS providers | Custom domain provisioning, SSL, DNS verification | | Analytics | Google Analytics (GA4), Firebase Analytics | Aggregate usage analytics (pseudonymized) |
All processors are bound by contractual data processing terms and may only process data to provide services to us. We conduct due diligence on their security practices.
6.4 Legal, Safety, and Business Transfers
- Legal compliance: We may disclose data if required by law, court order, or a government authority with lawful jurisdiction (e.g., police, tax authorities, Data Protection Board).
- Safety & enforcement: To enforce our Terms, protect our rights, prevent fraud, or protect the safety of any person.
- Business transfers: If we merge, are acquired, or sell assets, user data may transfer to the successor entity under this same Policy. You will be notified of any material change.
6.5 Third-Party Integrations You Enable
- If you connect third-party services (e.g., accounting software, POS, delivery aggregators, loyalty programs) via our marketplace or API, those providers receive only the data necessary for the integration. Their privacy policies govern their handling. Review each integration's terms before enabling.
7. Data Storage, Security, and International Transfer
7.1 Storage Locations
- Primary: Google Cloud (Firebase) — data centres in Mumbai (asia-south1) and Singapore for Firestore, Auth, Storage, Functions, Analytics, Crashlytics
- Database: Turso (libSQL) — replicated edge locations; primary region configurable
- Payment Data: Stored exclusively by Razorpay/Stripe on their PCI-DSS infrastructure (India + global regions per their policies)
7.2 Security Measures
- Encryption in transit: TLS 1.2+ (HTTPS) for all API, web, and mobile traffic; HSTS enforced
- Encryption at rest: Google Cloud default encryption (AES-256) for Firestore, Storage, Cloud SQL; Turso encryption
- Access controls: Role-based access (RBAC) in admin dashboard; tenant isolation via logical partitioning (each restaurant's data scoped by
restaurantId); production access restricted to authorised personnel on need-to-know basis - Authentication: OTP-based login (SMS/Email), optional 2FA for Platform Users, session tokens with HMAC-SHA256 signing, 24-hour expiry, revocation list
- API security: Rate limiting, input validation, CORS policies, CSP headers
- Vulnerability management: Dependency scanning, Sentry error monitoring, periodic security reviews
7.3 International Transfers
- Google Cloud and Turso data centres may be located outside India (e.g., Singapore, US, EU). By using the Platform, you consent to this cross-border transfer.
- Transfers are protected by: Google's Standard Contractual Clauses, Turso's DPA, and our processor agreements requiring equivalent protection.
- Payment processors (Razorpay/Stripe) maintain their own international transfer safeguards per RBI and card network rules.
7.4 No Absolute Security
No method of transmission over the Internet or electronic storage is 100% secure. We implement industry-standard measures but cannot guarantee absolute security. In the event of a personal data breach, we will notify affected users and the Data Protection Board of India as required by the DPDP Act, 2023.
8. Data Retention
| Data Category | Retention Period | Notes | |---------------|------------------|-------| | Account & profile data (Platform Users) | While subscription active + 2 years | Then anonymised or deleted | | Account & profile data (End Users) | While account active or last activity + 2 years | Then anonymised | | Bookings, orders, payments, invoices | 8 years from transaction date | Required for GST, Income Tax, accounting compliance under Indian law | | QR ordering sessions & carts | 30 days after session end | Auto-cleaned by scheduled jobs | | Chat messages & negotiations (booking/order chat) | While account active + 1 year | Then deleted | | Reviews & ratings | While tenant active + 2 years | Pseudonymised after account deletion | | Support tickets & communications | 3 years after resolution | For dispute resolution | | Analytics & crash data | Per Firebase defaults (up to 14 months user-level) | Then aggregated/anonymised | | Audit logs (admin actions, config changes) | 3 years | Security & compliance | | Marketing preferences & consent records | While consent valid + 2 years | For compliance evidence |
After account deletion request: Personal data is deleted or irreversibly anonymised within 30 days, except records we must retain by law (payment/tax records, dispute evidence) or for pending legal proceedings.
9. Your Rights and Choices
Under the Digital Personal Data Protection Act, 2023 (DPDP Act) and other applicable laws, you have the right to:
| Right | Description | How to Exercise | |-------|-------------|-----------------| | Access | Request a summary of personal data we hold about you | Email grievance@mumbairesto.in from registered email; or use "Export My Data" in Dashboard (Platform Users) | | Correction | Update inaccurate or incomplete data | Edit profile in Dashboard/App; or email grievance@mumbairesto.in | | Erasure | Request deletion of your account and personal data | Dashboard → Settings → Delete Account (Platform Users); or email grievance@mumbairesto.in with "Delete My Account" subject | | Withdraw Consent | Revoke device permissions (OS settings) and/or marketing consent | OS settings for device permissions; unsubscribe link in emails; Dashboard notification settings | | Data Portability | Receive your data in a structured, machine-readable format | Request via grievance@mumbairesto.in | | Grievance Redressal | Complain to our Grievance Officer; escalate to Data Protection Board if unresolved | See Section 14 | | Nomination | Nominate another individual to exercise rights in case of death/incapacity | Email grievance@mumbairesto.in with nominee details |
Verification: We will verify your identity (registered email/phone OTP) before acting on requests. We respond within 30 days (or as required by law).
Effect of withdrawal: Withdrawing consent for marketing stops promotional emails. Withdrawing device permissions (location, camera, notifications) limits related features but core Platform functionality remains. Withdrawing consent for essential processing (e.g., OTP login, payment processing) may make the service unavailable.
10. Children
- The Platform is a business-to-business service intended for users aged 18 and above.
- End Users (diners) placing orders/bookings must be 18+ or have parental supervision.
- We do not knowingly collect personal data from children under 18 without verifiable parental consent as required by the DPDP Act.
- If you believe a child has provided us data, contact grievance@mumbairesto.in and we will delete it promptly.
11. Cookies and Similar Technologies
| Type | Purpose | Duration | Control |
|------|---------|----------|---------|
| Essential (Authentication) | Session management, CSRF protection, tenant resolution | Session / 24 hours | Cannot be disabled (required) |
| Security | Rate limiting, fraud detection | Session | Cannot be disabled |
| Preferences | Theme, language, branch selection, notification settings | 1 year | Browser settings / Dashboard |
| Analytics (if enabled) | Aggregate usage via GA4, Firebase Analytics | Up to 14 months | Cookie banner / Browser settings / analytics_opt_out flag |
| Third-party | Payment processor checkout (Razorpay/Stripe), maps (Google Maps) | Per provider | Provider's controls |
Web version uses cookies/localStorage. Mobile apps use secure platform storage (iOS Keychain / Android Keystore) for tokens. You can clear cookies via browser settings (will sign you out). Our cookie banner lets you accept/reject non-essential categories.
12. Third-Party Links and Payment Apps
- Payment flows may redirect to Razorpay/Stripe hosted checkout or open your UPI app (Google Pay, PhonePe, Paytm, BHIM, etc.). Those services are governed by their own privacy policies.
- Maps/Location on storefronts may use Google Maps API (governed by Google's privacy policy).
- Social login (Google, Microsoft) shares only name, email, profile photo per your consent.
- Custom domains involve DNS providers and SSL issuers (Let's Encrypt, Cloudflare).
- We are not responsible for the privacy practices of third-party apps, websites, or services linked from the Platform. We encourage you to review their policies.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect:
- Changes in applicable law (DPDP Rules, RBI guidelines, GST)
- New Platform features or data practices
- Changes in subprocessors or international transfer mechanisms
- Security improvements
Notification: Material changes will be communicated via:
- In-app banner/notification (Platform Users)
- Email to registered address (if marketing consent given)
- Updated "Last updated" date at the top of this page
- Tenant storefront notice (for End User affecting changes)
Continued use of the Platform after the effective date constitutes acceptance of the revised Policy.
14. Grievance Officer
As required under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the DPDP Act, 2023:
- Name: [Grievance Officer Name]
- Title: Grievance Officer, Mumbai Resto
- Email: grievance@mumbairesto.in
- Address: DEVMORE INNOVATIONS, Mumbai, Maharashtra, India
- Response Commitment:
- Acknowledgement within 24 hours
- Resolution within 15 days (or as prescribed by Rules)
- Monthly transparency report on grievance categories (internal)
If you are unsatisfied with our resolution, you may escalate to the Data Protection Board of India (dpb.gov.in) once constituted under the DPDP Act.
15. Contact Us
Mumbai Resto — Privacy & Data Protection
- Email: support@mumbairesto.in (general) | grievance@mumbairesto.in (privacy/grievances)
- Address: DEVMORE INNOVATIONS, Mumbai, Maharashtra, India
- Platform: https://mumbairesto.in
Appendix: Tenant Storefront Data Processing Notice
Each restaurant (tenant) on Mumbai Resto acts as an independent Data Fiduciary for the personal data they collect from their diners through:
- Booking widgets on their storefront
- QR table ordering sessions
- Online order forms
- Contact/feedback forms
- Loyalty programs (if enabled)
Mumbai Resto is the Data Processor for this tenant-collected data. We process it solely on the tenant's instructions to provide the Platform service. Tenants are responsible for:
- Providing their own privacy policy to diners (template available in Dashboard → Website → Legal)
- Obtaining lawful consent for marketing communications
- Responding to diner rights requests
- Configuring data retention per their legal obligations
Diners should refer to the restaurant's own privacy policy (linked in their storefront footer) for details on how that specific restaurant handles their data.
Governing Law & Jurisdiction
This Privacy Policy is governed by the laws of India. Courts in Mumbai, Maharashtra shall have exclusive jurisdiction over any dispute arising out of or in connection with this Policy.
This Privacy Policy is part of the Mumbai Resto Terms of Service. By using the Platform, you acknowledge you have read and understood this Policy.