Privacy Policy

Last updated: April 27, 2026

This Privacy Policy describes how OrderIt ("we," "us," or "our") collects, uses, stores, and protects information when you use our restaurant management platform available at orderitnow.in (the "Service"). By using OrderIt, you agree to the practices described in this policy.

1. Information We Collect

A. Account Information

When you create an account or sign up for OrderIt, we collect:

  • Full name
  • Email address
  • Phone number
  • Password (stored in encrypted form via Firebase Authentication)
  • Google account information (if you sign in with Google OAuth)
  • Email verification status and OTP verification records

B. Restaurant Information

When you set up your restaurant on the platform (including during onboarding), we collect:

  • Restaurant name, address, and contact details
  • Menu items, categories, pricing, dish variants, and stock status
  • Restaurant logo, cover images, gallery photos (stored as base64-encoded data)
  • Table configurations, zones, labels, and capacities
  • Tax configuration — tax names, percentages, and enabled/disabled status (e.g., CGST, SGST, Service Charge)
  • Invoice settings — GST number, FSSAI number, custom invoice fields
  • Public profile settings, website template choice, hero/about content, social media links, and special offers
  • Operating hours and reservation settings
  • Delivery settings including delivery charge slabs
  • Feature toggle preferences (which features are enabled/disabled)
  • Onboarding completion status

C. Payment Information

We collect and store your payment configuration for customer-facing transactions:

  • UPI ID (e.g., yourname@upi)
  • Payment contact phone number
  • UPI QR code image (stored as base64-encoded data on our servers)

For your OrderIt subscription payments processed through Cashfree, we collect subscription plan details, billing cycle, and payment status. We do not store your full credit card, debit card, or bank account numbers — these are handled securely by Cashfree.

D. Order and Transaction Data

We collect data related to orders placed through your restaurant, including:

  • Order details — items, quantities, prices, special instructions, order type (dine-in, pack, delivery)
  • Table numbers, table session data, and session billing
  • Payment method selected (UPI or counter) and payment confirmation status
  • Order status history and timestamps
  • Delivery addresses and contact details (for delivery orders)
  • Tax calculations and invoice data generated for each order

E. Customer (Diner) Data

When customers interact with your restaurant through our Service (QR ordering, reservations, delivery), we may collect:

  • Customer name (for reservations and delivery orders)
  • Phone number (for delivery orders and reservations)
  • Delivery address (for delivery orders)
  • Order preferences and waiter call notes
  • Reservation details — date, time, party size, room preference, special requests

We do not require diners to create accounts to place dine-in or takeaway QR orders. Delivery and reservation flows collect minimal contact information necessary to fulfill the service.

F. Staff Access Data

When you generate Staff Links (kitchen display, delivery panel, waiter panel, waiter handheld), we store:

  • Token identifiers for each generated link
  • Waiter names associated with handheld kiosk links
  • Waiter profiles — names, phone numbers, assignment status
  • Waiter call history — table, notes, acknowledgment and completion timestamps

G. Geolocation Data

OrderIt uses your device's GPS location in two specific scenarios, only when you explicitly grant permission:

  • Table Ordering Geofence (Restaurant Owners) — When you detect your restaurant's location in Table Management, your GPS coordinates are saved to your restaurant profile. This is used to verify that customers scanning table QR codes are physically present at your restaurant (within a 10m–100m radius you configure).
  • Table Ordering Geofence (Customers) — When a customer scans a table QR code at a restaurant that has geofencing enabled, their browser requests location access. The customer's coordinates are compared against the restaurant's saved location on the customer's device only — we do not store or transmit customer GPS coordinates to our servers.
  • Delivery Area Geofence (Customers) — When a customer selects "Delivery" on the ordering page, their browser requests location access to check if they are within the restaurant's delivery radius (500m–10km). This check happens entirely on the customer's device — we do not store or transmit customer GPS coordinates.

Location permission is always optional. If a customer denies location access or if geolocation fails, the order is still allowed through. Restaurant owners can recapture their GPS coordinates at any time.

H. Usage and Technical Data

We automatically collect:

  • IP address and approximate location
  • Browser type, device type, and operating system
  • Pages visited, features used, and session duration
  • Error logs and performance data

I. Locally Stored Data

Certain data is stored only in your browser's localStorage and is never transmitted to our servers:

  • Thermal printer configuration — paper width, auto-cut preference, enabled state, connected device info
  • Session verification tokens (OTP verification status)

2. How We Use Your Information

We use the collected information to:

  • Provide, maintain, and improve the OrderIt platform and all its features
  • Process your restaurant's orders, manage table sessions, and handle delivery operations
  • Generate your public restaurant profile page and website
  • Generate invoices, eBills, and thermal receipts with your configured branding
  • Calculate and display taxes on orders based on your tax configuration
  • Process subscription payments and manage billing cycles
  • Send account verification emails, OTP codes, and password reset links
  • Provide real-time order notifications, waiter call alerts, and payment notifications
  • Generate analytics reports — revenue, order trends, payment breakdowns, best sellers
  • Manage reservation bookings and send booking status updates
  • Facilitate bulk menu imports from uploaded Excel/CSV files
  • Provide customer support and respond to inquiries
  • Detect, prevent, and address fraud, abuse, or technical issues
  • Comply with legal obligations

3. Data Storage and Security

Your data is stored on secure cloud infrastructure. We use industry-standard security measures including:

  • Encrypted data transmission (HTTPS/TLS) for all connections
  • Firebase Authentication for secure user authentication with email verification
  • Hashed and salted passwords (managed by Firebase)
  • Rate limiting and request throttling to prevent abuse and brute-force attacks
  • JWT-based authentication tokens for API access
  • Token-based access control for Staff Links with revocable tokens
  • Security headers (X-Content-Type-Options, X-Frame-Options, X-XSS-Protection, Referrer-Policy)
  • Input validation and sanitization on all API endpoints
  • Regular security updates and monitoring

Images (logos, QR codes, cover photos, gallery images) are stored as base64-encoded strings in our database. We enforce size limits on uploaded images to prevent abuse.

While we implement appropriate security measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security of your data.

4. Data Sharing

We do not sell, rent, or trade your personal information. We may share data with:

  • Cashfree — to process subscription payments securely
  • Firebase / Google — for authentication, email verification, and infrastructure services
  • Hosting and database providers — for platform infrastructure (MongoDB Atlas, Vercel, cloud hosting)
  • Email services (SMTP) — for sending OTP verification codes, password reset links, and system notifications
  • Legal authorities — when required by law, court order, or to protect our rights and the safety of our users

Your restaurant's public profile information (name, menu, photos, address, phone, operating hours, social links, special offers) is visible to anyone who visits your public profile page. You control what information appears publicly through your Website Builder settings. Disabling the public profile immediately hides all public-facing content.

Your UPI QR code and UPI ID are shown to customers during the payment process. This is necessary for facilitating payments and is controlled by your payment settings.

5. Data Retention

We retain your account and restaurant data for as long as your account is active or as needed to provide services. Specific retention periods:

  • Account data: Retained while your account is active. Deleted within 30 days of account deletion request.
  • Order history: Retained for the lifetime of your account for analytics and reporting. May be retained in anonymized form after account deletion.
  • Uploaded images: Deleted along with your account data.
  • OTP records: Automatically expire after 10 minutes.
  • Subscription records: Retained for legal and accounting compliance for up to 7 years.
  • Locally stored data: Thermal printer settings remain in your browser until you clear browser data. We have no access to this data.

6. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete information through the Settings page
  • Delete your account and associated data
  • Export your data in a commonly used format (contact support for data export)
  • Withdraw consent for optional data processing
  • Object to data processing based on legitimate interests
  • Disable public profile to remove all publicly accessible restaurant information
  • Revoke Staff Links to immediately cut off staff access to operational features
  • Clear local data — thermal printer settings and browser cache can be cleared through your browser settings at any time

To exercise any of these rights, contact us at support@orderitnow.in.

7. Cookies and Local Storage

OrderIt uses essential cookies and local storage to maintain your login session and remember your preferences. Specifically:

  • Authentication cookies — to keep you signed in (managed by Firebase)
  • Session storage — to track OTP verification status during the current session
  • Local storage — to store thermal printer configuration (paper width, auto-cut, device info)

We do not use advertising cookies, third-party tracking cookies, or any cookies for ad targeting purposes.

8. Third-Party Services

OrderIt integrates with the following third-party services, each governed by their own privacy policies:

  • Firebase (Google) — Authentication, email verification, and analytics
  • Cashfree — Subscription payment processing
  • MongoDB Atlas — Database hosting and storage
  • Vercel — Application hosting and CDN
  • SMTP Email Service — Sending OTP codes, verification emails, and notifications

UPI payment apps (Google Pay, PhonePe, Paytm, etc.) used by your customers are third-party services. We redirect customers to these apps using standard UPI deep links. We do not receive or store any UPI transaction details — payment verification is your responsibility.

9. WebUSB and Device Access

When you use the thermal printing feature, the Service accesses your USB thermal printer via the WebUSB browser API. This access:

  • Requires explicit browser-level permission that you grant through the device picker dialog
  • Is limited to sending print data (ESC/POS commands) to the selected printer
  • Does not access any other USB devices connected to your computer
  • Can be revoked at any time through your browser's site settings
  • Does not transmit any device information to our servers — all communication happens locally between your browser and the printer

10. Children's Privacy

OrderIt is a business tool intended for restaurant owners and operators. Our Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.

11. International Data

OrderIt is based in India and primarily serves restaurants in India. Your data is stored on servers that may be located in various regions. By using the Service, you consent to the transfer and processing of your data in accordance with this policy.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, features, or legal requirements. The updated policy will be posted on this page with a revised "Last updated" date. We encourage you to review this page periodically. Continued use of the Service after changes constitutes acceptance of the updated policy.

13. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, contact us at:

OrderIt

Email: support@orderitnow.in

Website: orderitnow.in