Privacy Policy
Last updated: June 13, 2026
1. Who we are
Scanmyfood ("we", "us") is a QR menu and ordering platform for Indian restaurants. This Privacy Policy explains what information we collect, how we use it, and the choices you have.
2. Information we collect
From restaurant owners and staff: name, email address, password (stored hashed), restaurant name, GSTIN (if provided), UPI ID, table layout, menu content, expense entries, and basic device/browser information.
From customers using the QR menu: the table you scanned, the display name you enter for the group order, the items you add to your cart, the order itself, and basic device information needed to keep your session active.
We do not collect government identity numbers, card numbers, or bank account details. Payments via UPI happen directly between the customer and the restaurant.
3. How we use information
- To deliver the core Service — showing menus, taking orders, printing receipts, generating bills and powering analytics.
- To keep the Service secure, prevent abuse, and debug issues.
- To send transactional emails (e.g. password reset, order receipts when you opt in).
- To improve the Service based on aggregate, non-identifying usage patterns.
We do not sell your personal information, and we do not show third-party advertising on the platform.
4. Sharing your information
We share information only with:
- Service providers who help us operate the platform (hosting, database, email delivery, analytics). They are bound by confidentiality and security commitments.
- The restaurant you ordered from — order details, table number, notes and your display name are visible to the restaurant's authorised staff.
- Authorities when required by law, court order, or to protect the rights and safety of our users.
5. Data retention
Order, menu and expense data is retained for as long as your restaurant account is active and for a reasonable period after closure to support reconciliation, accounting and legal obligations. Customer session data (cart, order history for that table) is retained for the duration of the dining session and then archived as part of the restaurant's order history.
6. Security
We use industry-standard measures including TLS in transit, encryption at rest, role-based access controls, and per-restaurant database isolation via row-level security. No system is 100% secure — please contact us immediately if you suspect any unauthorised access.
7. Your rights
You can:
- Access and update your account information from the settings page.
- Request a copy of your data, or ask us to delete it, by emailing us.
- Withdraw consent for non-essential communications at any time.
We will respond to verified requests within 30 days, subject to legal record-keeping obligations.
8. Cookies and local storage
We use cookies and browser local storage to keep you signed in, remember your menu drafts, cache content for performance, and measure aggregate usage. You can clear these from your browser at any time, though this may sign you out and clear locally saved drafts.
9. Children's privacy
The Service is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us and we will delete it.
10. Changes to this policy
We may update this policy from time to time. Material changes will be communicated by email or via an in-app notice prior to taking effect.
11. Contact us
Questions, requests or concerns? Email hello@scanmyfood.in and we'll get back to you.