Skip to main content
Legal

Privacy Policy

How BeanRow collects, uses, stores and protects information when restaurant partners use the BeanRow Admin portal — and what rights you have over that information.

Last updated
Effective from

1. Overview

This Privacy Policy explains how BeanRow Technologies ("BeanRow", "we", "us" or "our") handles information in connection with the BeanRow Restaurant Management System and the partner admin portal at https://app.beanrow.com (together, the "Service").

It applies to restaurant owners, managers and staff who hold a BeanRow account, and to information about diners that reaches us because a restaurant uses BeanRow to take and manage their orders.

Registered office: [ to be completed: registered office address ]. Corporate identity number: [ to be completed: CIN ]. GSTIN: [ to be completed: GSTIN ].

2. Our role: partner data vs. diner data

The Service involves two distinct kinds of information, and our responsibilities differ for each.

Partner account data — we are the data fiduciary

For information about your restaurant, your account and the people on your team, BeanRow decides how and why the information is processed. We are the data fiduciary (controller) and this policy governs directly.

Diner and order data — we are the data processor

When a diner scans a QR code and places an order at your outlet, the resulting information is collected on your behalf. Your restaurant decides how that information is used; BeanRow processes it under your instructions in order to operate the Service. You remain responsible for having a lawful basis to collect it and for your own customer-facing privacy notice.

If you operate a restaurant on BeanRow, you should publish your own privacy notice to diners. BeanRow's policy covers our processing, not yours.

3. Information we collect

Information you give us

  • Account details — name, email address, mobile number, password (stored only as a salted hash) and your role (owner, admin, manager or staff).
  • Business details — outlet and branch names, addresses, contact numbers, operating hours, table layouts, menus, pricing, tax settings and business registration details you enter for invoicing.
  • Team details — the names, contact details, roles and permissions of the staff accounts you create.
  • Support and enquiry content — messages, complaints and attachments you send through the contact form, email, phone or WhatsApp.

Information generated by using the Service

  • Order and transaction records — items ordered, table and queue assignments, kitchen timings, bill amounts, payment status and refund requests.
  • Operational analytics — sales totals, best sellers, staff performance metrics, table utilisation and other reporting derived from your activity.
  • Technical and device data — IP address, browser and device type, operating system, timestamps, pages visited, and error and diagnostic logs.
  • Authentication data — session tokens, sign-in times and the role cookie used to route you to the correct dashboard.

Diner information processed on your behalf

  • Order contents, table number and any notes or preferences a diner submits.
  • Contact details a diner chooses to provide, such as a name or mobile number for order updates or loyalty coins.
  • Reviews, ratings and complaints a diner submits about an order.

BeanRow does not collect or store full card numbers, CVVs or UPI credentials. Payments are handled by PCI-DSS compliant payment gateways — see section 7.

4. How we use information

We use information to:

  • Provide, operate and maintain the Service, including order routing, billing, printing and real-time updates.
  • Authenticate users and enforce role-based access so staff only reach the screens their role permits.
  • Generate the reports, analytics and dashboards you use to run your outlets.
  • Provide partner support, respond to enquiries and investigate complaints.
  • Send service communications — billing notices, security alerts, downtime notifications and material changes to the Service.
  • Bill you for your subscription, issue invoices and comply with tax and accounting obligations.
  • Detect, investigate and prevent fraud, abuse, security incidents and violations of our Terms & Conditions.
  • Improve the Service — diagnosing faults, measuring performance and developing new features, using aggregated or de-identified data wherever practicable.
  • Comply with applicable law and respond to lawful requests from authorities.

We do not sell personal information, and we do not use diner information for our own marketing.

6. When we share information

We share information only in the circumstances below, and only to the extent needed.

  • Within your organisation — account owners and administrators can see the activity, performance data and records of the staff accounts under their outlets.
  • Service providers (sub-processors) — cloud hosting and databases, payment gateways, email, SMS and WhatsApp delivery providers, error monitoring and analytics. They act on our instructions under written agreements and may not use the information for their own purposes.
  • Professional advisers — auditors, lawyers and accountants, under confidentiality obligations.
  • Legal and safety — where disclosure is required by law, court order or a lawful government request, or is necessary to protect the rights, property or safety of BeanRow, our partners or the public.
  • Business transfers — in connection with a merger, acquisition, financing or sale of assets, subject to this policy continuing to apply to the transferred information.

A current list of our sub-processors is available on request from support@beanrow.com.

7. Payment information

Subscription payments and, where enabled, diner payments are processed by third-party payment gateways that are certified to the PCI-DSS standard. Card numbers, CVVs, UPI PINs and net-banking credentials are entered directly with the gateway and are never received or stored by BeanRow.

We receive only the transaction outcome and limited metadata — such as a payment reference, amount, timestamp, status and the last four digits or masked identifier of the instrument — which we use for reconciliation, invoicing and refunds.

Your use of a payment gateway is also governed by that provider's own privacy policy.

8. How long we keep information

We keep personal data only as long as it is needed for the purpose it was collected for, or as long as the law requires.

  • Active accounts — for as long as your subscription is active, plus 90 days after termination so you can export your records.
  • Order, invoice and tax records — for the period required under Indian tax and company law, currently eight financial years for books of account.
  • Technical and security logs — 12 months.
  • Support correspondence — for as long as needed to resolve the matter and to evidence how it was handled.

When a retention period ends, we delete the information or irreversibly de-identify it. Aggregated statistics that can no longer identify anyone may be kept indefinitely.

9. Security

We apply reasonable security safeguards appropriate to the sensitivity of the information, including:

  • Encryption of traffic in transit using TLS, with HTTP Strict Transport Security enforced.
  • Passwords stored only as salted hashes — never in plain text and never recoverable by us.
  • Role-based access control, so staff accounts reach only the functions their role permits.
  • Hardened HTTP security headers, including a content security policy and clickjacking protection.
  • Access to production systems restricted to authorised personnel on a need-to-know basis.
  • Logging and monitoring to detect unusual activity.

No system can be guaranteed completely secure. You are responsible for keeping your credentials confidential, for issuing individual logins rather than sharing one account, and for removing staff accounts promptly when someone leaves.

If we become aware of a personal data breach affecting you, we will notify you and the Data Protection Board of India as required by law. Report a suspected security issue to support@beanrow.com.

10. Your rights

Subject to the Digital Personal Data Protection Act, 2023, you have the right to:

  • Access a summary of the personal data we process about you and how it is processed.
  • Correction of inaccurate or misleading data, and completion or updating of incomplete data.
  • Erasure of personal data that is no longer needed for the purpose it was collected for, unless retention is required by law.
  • Withdraw consent you previously gave, at any time.
  • Nominate another individual to exercise your rights in the event of death or incapacity.
  • Grievance redressal — raise a complaint with us and, if unresolved, escalate to the Data Protection Board of India.

To exercise any of these rights, write to support@beanrow.com from the email address registered on your account. We will respond within 30 days. We may ask you to verify your identity before acting.

If you are a diner and want your information corrected or deleted, contact the restaurant that took your order. They decide how that information is used; we act on their instructions.

11. Cookies and similar technologies

We use a small number of browser storage mechanisms:

  • Strictly necessary cookies — including the authentication role cookie that keeps you signed in and routes you to the correct dashboard. The Service will not function without these.
  • Local storage — used to remember interface preferences and to hold session state in your browser.
  • Analytics and performance — where enabled, used in aggregate to understand which features are used and to diagnose faults.

You can clear or block browser storage through your browser settings, but doing so will sign you out and may prevent parts of the Service from working.

12. Children

The Service is a business tool and is not directed at children. We do not knowingly create accounts for anyone under 18. If we learn that we hold the personal data of a child without verifiable parental consent, we will delete it. Staff accounts must only be issued to individuals lawfully employed by your outlet.

13. Storage and international transfers

Our infrastructure is hosted in asia-south1 (Mumbai), India. Some of our service providers may process limited information outside India.

Where information is transferred outside India, we do so only to countries not restricted by the Central Government and under contractual safeguards requiring a comparable standard of protection.

14. Changes to this policy

We may update this policy as the Service or the law changes. The revision date at the top of this page always reflects the current version.

If a change materially affects how we handle your information, we will give you notice — by email to your registered address or by a prominent notice in the portal — before it takes effect. Continuing to use the Service after that date means you accept the updated policy.

15. Contact and grievance officer

For any question about this policy, or to exercise your rights, contact us:

  • Privacy and data requests: support@beanrow.com
  • General enquiries: hello@beanrow.com
  • Phone: +91 82600 61212 (Monday to Saturday, 9:00 AM to 7:00 PM IST)

Grievance Officer, appointed under the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023: [ to be completed: Grievance Officer name ], [ to be completed: Grievance Officer email ], [ to be completed: registered office address ].

We aim to acknowledge every grievance within 24 hours and resolve it within the period prescribed by law. If you are not satisfied with our response, you may escalate the matter to the Data Protection Board of India.

Questions about this policy?

Our partner support team can walk you through anything here.