1. Overview
This Privacy Policy explains how BeanRow Technologies ("BeanRow", "we", "us" or "our") handles information in connection with the BeanRow Restaurant Management System and the partner admin portal at https://app.beanrow.com (together, the "Service").
It applies to restaurant owners, managers and staff who hold a BeanRow account, and to information about diners that reaches us because a restaurant uses BeanRow to take and manage their orders.
Registered office: [ to be completed: registered office address ]. Corporate identity number: [ to be completed: CIN ]. GSTIN: [ to be completed: GSTIN ].
2. Our role: partner data vs. diner data
The Service involves two distinct kinds of information, and our responsibilities differ for each.
Partner account data — we are the data fiduciary
For information about your restaurant, your account and the people on your team, BeanRow decides how and why the information is processed. We are the data fiduciary (controller) and this policy governs directly.
Diner and order data — we are the data processor
When a diner scans a QR code and places an order at your outlet, the resulting information is collected on your behalf. Your restaurant decides how that information is used; BeanRow processes it under your instructions in order to operate the Service. You remain responsible for having a lawful basis to collect it and for your own customer-facing privacy notice.
If you operate a restaurant on BeanRow, you should publish your own privacy notice to diners. BeanRow's policy covers our processing, not yours.
3. Information we collect
Information you give us
- Account details — name, email address, mobile number, password (stored only as a salted hash) and your role (owner, admin, manager or staff).
- Business details — outlet and branch names, addresses, contact numbers, operating hours, table layouts, menus, pricing, tax settings and business registration details you enter for invoicing.
- Team details — the names, contact details, roles and permissions of the staff accounts you create.
- Support and enquiry content — messages, complaints and attachments you send through the contact form, email, phone or WhatsApp.
Information generated by using the Service
- Order and transaction records — items ordered, table and queue assignments, kitchen timings, bill amounts, payment status and refund requests.
- Operational analytics — sales totals, best sellers, staff performance metrics, table utilisation and other reporting derived from your activity.
- Technical and device data — IP address, browser and device type, operating system, timestamps, pages visited, and error and diagnostic logs.
- Authentication data — session tokens, sign-in times and the role cookie used to route you to the correct dashboard.
Diner information processed on your behalf
- Order contents, table number and any notes or preferences a diner submits.
- Contact details a diner chooses to provide, such as a name or mobile number for order updates or loyalty coins.
- Reviews, ratings and complaints a diner submits about an order.
BeanRow does not collect or store full card numbers, CVVs or UPI credentials. Payments are handled by PCI-DSS compliant payment gateways — see section 7.
4. How we use information
We use information to:
- Provide, operate and maintain the Service, including order routing, billing, printing and real-time updates.
- Authenticate users and enforce role-based access so staff only reach the screens their role permits.
- Generate the reports, analytics and dashboards you use to run your outlets.
- Provide partner support, respond to enquiries and investigate complaints.
- Send service communications — billing notices, security alerts, downtime notifications and material changes to the Service.
- Bill you for your subscription, issue invoices and comply with tax and accounting obligations.
- Detect, investigate and prevent fraud, abuse, security incidents and violations of our Terms & Conditions.
- Improve the Service — diagnosing faults, measuring performance and developing new features, using aggregated or de-identified data wherever practicable.
- Comply with applicable law and respond to lawful requests from authorities.
We do not sell personal information, and we do not use diner information for our own marketing.
5. Legal basis and consent
We process personal data under the Digital Personal Data Protection Act, 2023 and other applicable Indian law. Depending on the information, our basis is one of the following:
- Consent — given when you create an account, submit an enquiry, or when a diner chooses to share their details while ordering.
- Performance of our contract with you — everything necessary to deliver the subscription you have purchased.
- Legitimate uses recognised by law — including security, fraud prevention and responding to your own requests.
- Legal obligation — retention of invoices and tax records, and responses to lawful government requests.
Where we rely on consent, you may withdraw it at any time using the contact details in section 15. Withdrawing consent does not affect processing already carried out, and may mean we can no longer provide parts of the Service.
7. Payment information
Subscription payments and, where enabled, diner payments are processed by third-party payment gateways that are certified to the PCI-DSS standard. Card numbers, CVVs, UPI PINs and net-banking credentials are entered directly with the gateway and are never received or stored by BeanRow.
We receive only the transaction outcome and limited metadata — such as a payment reference, amount, timestamp, status and the last four digits or masked identifier of the instrument — which we use for reconciliation, invoicing and refunds.
Your use of a payment gateway is also governed by that provider's own privacy policy.
8. How long we keep information
We keep personal data only as long as it is needed for the purpose it was collected for, or as long as the law requires.
- Active accounts — for as long as your subscription is active, plus 90 days after termination so you can export your records.
- Order, invoice and tax records — for the period required under Indian tax and company law, currently eight financial years for books of account.
- Technical and security logs — 12 months.
- Support correspondence — for as long as needed to resolve the matter and to evidence how it was handled.
When a retention period ends, we delete the information or irreversibly de-identify it. Aggregated statistics that can no longer identify anyone may be kept indefinitely.
9. Security
We apply reasonable security safeguards appropriate to the sensitivity of the information, including:
- Encryption of traffic in transit using TLS, with HTTP Strict Transport Security enforced.
- Passwords stored only as salted hashes — never in plain text and never recoverable by us.
- Role-based access control, so staff accounts reach only the functions their role permits.
- Hardened HTTP security headers, including a content security policy and clickjacking protection.
- Access to production systems restricted to authorised personnel on a need-to-know basis.
- Logging and monitoring to detect unusual activity.
No system can be guaranteed completely secure. You are responsible for keeping your credentials confidential, for issuing individual logins rather than sharing one account, and for removing staff accounts promptly when someone leaves.
If we become aware of a personal data breach affecting you, we will notify you and the Data Protection Board of India as required by law. Report a suspected security issue to support@beanrow.com.
10. Your rights
Subject to the Digital Personal Data Protection Act, 2023, you have the right to:
- Access a summary of the personal data we process about you and how it is processed.
- Correction of inaccurate or misleading data, and completion or updating of incomplete data.
- Erasure of personal data that is no longer needed for the purpose it was collected for, unless retention is required by law.
- Withdraw consent you previously gave, at any time.
- Nominate another individual to exercise your rights in the event of death or incapacity.
- Grievance redressal — raise a complaint with us and, if unresolved, escalate to the Data Protection Board of India.
To exercise any of these rights, write to support@beanrow.com from the email address registered on your account. We will respond within 30 days. We may ask you to verify your identity before acting.
If you are a diner and want your information corrected or deleted, contact the restaurant that took your order. They decide how that information is used; we act on their instructions.
12. Children
The Service is a business tool and is not directed at children. We do not knowingly create accounts for anyone under 18. If we learn that we hold the personal data of a child without verifiable parental consent, we will delete it. Staff accounts must only be issued to individuals lawfully employed by your outlet.
13. Storage and international transfers
Our infrastructure is hosted in asia-south1 (Mumbai), India. Some of our service providers may process limited information outside India.
Where information is transferred outside India, we do so only to countries not restricted by the Central Government and under contractual safeguards requiring a comparable standard of protection.
14. Changes to this policy
We may update this policy as the Service or the law changes. The revision date at the top of this page always reflects the current version.
If a change materially affects how we handle your information, we will give you notice — by email to your registered address or by a prominent notice in the portal — before it takes effect. Continuing to use the Service after that date means you accept the updated policy.
15. Contact and grievance officer
For any question about this policy, or to exercise your rights, contact us:
- Privacy and data requests: support@beanrow.com
- General enquiries: hello@beanrow.com
- Phone: +91 82600 61212 (Monday to Saturday, 9:00 AM to 7:00 PM IST)
Grievance Officer, appointed under the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023: [ to be completed: Grievance Officer name ], [ to be completed: Grievance Officer email ], [ to be completed: registered office address ].
We aim to acknowledge every grievance within 24 hours and resolve it within the period prescribed by law. If you are not satisfied with our response, you may escalate the matter to the Data Protection Board of India.
Questions about this policy?
Our partner support team can walk you through anything here.