Skip to content

Your data and your customers' data

What the product holds, who is responsible for what, what the assistant is and is not told, how to get your data out, and what closing an account really does.

Updated 11 September 20264 minApplies to: Back office, Help centre

Who is responsible for what

Two different responsibilities sit in one product, and telling them apart answers most of what follows.

We are responsible for your account and your business's records — the email you sign in with, your business identifiers, your team's details, and the operational history the product produces.

You are responsible for your customers' data. The names and phone numbers you or your staff type in for a credit account, a loyalty card or an e-bill belong to your business. We hold them on your instructions, we never sell them, and we never contact your customers except to deliver something you asked us to send. If a guest asks a restaurant to erase them, the restaurant answers; we help.

Your data is held in a managed database in the Mumbai region, isolated per business at the database itself rather than by application code — one business cannot read another's rows even if a query tried. The full list of the services involved, by name, is in the privacy policy.

What the assistant is told

The assistant is optional and the product works fully with it off. When you do use it, the text needed to answer goes to the model provider — your question, and dish or ingredient names where the question is about them.

Two limits are built in rather than promised:

  • The screen's address is sent; what you typed into a search box is not. The pathname you asked from goes along so the answer can be about the screen in front of you, and a short list of that page's own state — a date range, a tab, a month. Everything else in the address is dropped, not shortened, because a search box on the customers screen routinely holds a person's name or phone number.
  • The assistant never writes. It proposes, you approve, and the approval runs the same action a person would have used. Nothing it produces reaches your records on its own.

The notes it remembers about your business, if you use that feature, hold no money figures at all by design.

If the guest-conversation module is switched on, its recording policy and an append-only log of who has looked at what are on their own settings page, shown to you rather than hidden.

Getting your data out

Today the way out is the Exports screen: your GST returns, an accounting export your accountant can file from, and CSVs of your items and reports. The Items list also exports whatever you have filtered it to.

There is no single "download everything" button yet. For anything the exports do not cover, write to us and ask — that is a request we answer, not a feature you are waiting for.

Removing the sample data

A new account starts with sample orders so the screens are not empty while you set up. Business settings has a control to remove them, owner-only, with your business name typed to confirm and a recent second step.

It removes the sample history. It deliberately does not touch the sample menu, because dishes carry no marker distinguishing them and real bills already reference some of those names — deleting by name would orphan real orders. Remove sample dishes one at a time from the menu instead.

Closing an account, and what "delete" means

Before you start: a sole owner cannot close their own account. A business with no owner cannot be recovered from inside the product, and the database refuses to reach that state. Hand the business to a teammate first, or ask us to close the business itself.

Where you can close it, asking starts a week's cooling-off period, and one tap cancels it during that week. Cancelling is one tap on purpose; making it as hard to stop as to start would be the wrong symmetry.

Be clear-eyed about what runs at the end of it. Closing removes the personal details from your membership records; it does not instantly erase the business's books. Your orders, bills, payments and the journal derived from them are records Indian tax law expects to be kept, and they are kept for as long as the law asks and then no longer. The privacy policy states the retention position, and you can ask for erasure sooner in writing.

Your rights, and how to use them

Under the Digital Personal Data Protection Act you can ask us what personal data of yours we hold, ask us to correct it, ask us to erase it where the law does not require us to keep it, and raise a grievance.

Write to the Grievance Officer at the address in the privacy policy. Every grievance is acknowledged within three working days and answered substantively within thirty, and we keep a record of when each one arrived and how it was resolved.

Cookies: the app sets them only to keep you signed in and remember your language. The public site sets no advertising or cross-site tracking cookies.

Still stuck?

Beta