Privacy Policy
Last updated: 6 September 2026
This Privacy Policy explains what information we collect through this platform, how we use it, and the choices you have. It applies to restaurant owners and staff who use our restaurant management software (the "Service"), not to your own customers' data, which you control as described below.
1. Information we collect
When you sign up, we collect your name, email address, restaurant/business details, and billing information. As you use the Service, we store the data you create — menus, orders, staff records, and similar business data. We also record when you sign in and a rough description of the device, so you can see where your account is signed in and sign it out from your account page. We do not track which pages you visit.
2. How we use your information
We use your information to provide and improve the Service, process payments, send account-related notifications (such as trial reminders or billing receipts), and respond to support requests. We do not sell your personal information.
3. Your customers' data
Data about your own restaurant's customers (names, phone numbers, delivery addresses, order history, and similar) belongs to you. We process it only to operate the Service on your behalf and do not use it for our own marketing. If one of your customers asks you what you hold about them, or asks you to erase it, the decision is yours and we will help you carry it out.
4. Guest identity documents
If you use the Hospitality module, the front desk records the government identity document number that the law requires it to keep for each guest. That number is stored encrypted, and only the number — we do not store scans or photographs of the document itself.
5. What we never hold
- Card and UPI details. These are entered on the payment gateway's own screens and never reach our servers or our database.
- Readable passwords. Where an account has a password, only a one-way hash of it is stored. Nobody at RMS Guru can read it, and neither can anyone who steals the database.
- Advertising and tracking. There is no advertising network, no analytics tracker and no third-party pixel anywhere in this Service. The only outside code that runs in your browser is the payment gateway's checkout, on the payment screen.
6. Third-party services
These are the only companies your data reaches, and each receives only what its job needs:
| Who | What they receive | Why |
|---|---|---|
| Supabase | The database, accounts and uploaded files | Where the Service's data lives |
| Cloudflare | Web traffic | Serves the site |
| Razorpay | Payment details, name, contact | Takes payments. Their checkout runs in the browser on the payment screen, so they see that page; card and UPI details are entered on their systems and never reach ours |
| MSG91 | Phone number | Sends the one-time code a customer signs in with |
| Delivery address, for distance only; email and name if "Continue with Google" is used | Works out delivery distance; signs staff in | |
| The email provider in use | Email address and the contents of the message | Sends receipts, invites and sign-in codes. If you connect your own email provider, your customers' emails go through that one instead |
These providers receive only the information needed to perform their function and are bound by their own privacy and security obligations. We do not share personal data for anyone else's advertising.
7. Data storage and security
Data is stored on Supabase's cloud infrastructure. One restaurant's records are separated from another's in the database itself, not only in the application, so a page cannot reach another restaurant's data even if it asks for it. Payment credentials and stored identity document numbers are encrypted, with the key held outside the database, so a stolen copy of the database alone does not reveal them. No method of storage or transmission is completely secure, but these are real measures rather than a promise to be careful.
8. Data retention
- Accounts nobody uses. If an account is not used for a year, it is erased — but only after a warning email, and never sooner than 48 hours after that email goes out. Signing in is enough to stop it.
- Closing an account. Your name, email, phone and saved addresses are erased. Orders and invoices are not: an invoice is the business's tax record, and Indian tax law requires those to be kept for six years. What remains is the money trail with the person taken out of it.
9. Your rights
Under India's Digital Personal Data Protection Act you may ask us to show you the personal data we hold about you, correct it if it is wrong, erase it, or nominate someone to exercise these rights on your behalf if you cannot. The Service has controls for the first three in your account page; write to us if any of them does not do what you need. Some records (such as issued invoices) are kept even after an erasure request, for the tax reason described above.
If you are unhappy with how a request was handled, write to our Grievance Officer at grievance@rmsguru.com. If we still have not put it right, you may complain to the Data Protection Board of India.
10. Cookies and browser storage
Signing in stores a session cookie, which is what keeps you signed in; without it the Service cannot work. Some preferences — the theme, a remembered filter — are stored in your browser and never sent to us. There are no advertising or tracking cookies of any kind, which is why this site does not ask you to accept any.
11. Children's privacy
The Service is intended for business use and is not directed at children. We do not knowingly collect personal information from children.
12. Changes to this policy
We may update this Privacy Policy from time to time. When a change matters, we will say so on this page and tell account holders directly. The date at the top always shows the current version. Continued use of the Service after an update constitutes acceptance of the revised policy.
13. Contact
Questions about this Privacy Policy can be sent to support@rmsguru.com or through our Contact Us page.