Privacy Policy
Resto Platform ("we") provides software that restaurants, shops and rental businesses ("businesses") use to run their menu, orders, bookings, point of sale and reports, and that their customers use to order and book. This policy explains what data the platform handles and why.
1. Who is responsible
For customer orders and bookings, the business you order from decides how your data is used, and we process it on their behalf. For business accounts (owners and staff), we are responsible. Contact us on WhatsApp at +968 9335 9117.
2. Data we handle
- Business accounts: name, email, phone, business name, address and settings, staff accounts and their roles, subscription and payment records.
- Customers: phone number (verified by SMS when you log in), name, delivery address and car plate if you give them, your orders and bookings, and loyalty points if the business uses them.
- Identity documents (rental businesses only): the document number and photos you upload, so you do not need to upload them again next time.
- Payments: online card payments are handled by the payment provider (for example Thawani). We never see or store your card number; we only store whether the payment succeeded and its reference.
- Technical data: error reports from the web pages (the error message, page address and browser type) so we can fix crashes, security logs of sign-in attempts, and a hashed form of your IP address used only to stop abuse (kept for about an hour).
- Notification tokens for the staff mobile app, used to alert staff about new orders.
3. Why we use it
- To take, prepare, deliver and bill your order or booking.
- To let businesses see their sales, expenses and reports.
- To prevent fraud and abuse (SMS verification, reCAPTCHA, rate limits, audit logs of refunds and cancellations).
- To keep the service working and fix errors.
We do not sell personal data and we do not use it for advertising.
4. AI features
Businesses on the Gold plan can use AI tools (menu translation, reading invoices, sales insights). For these, menu text, invoice photos the business uploads, or totals of sales and expenses are sent to OpenAI for processing. Customer names, phone numbers and addresses are never sent.
5. Service providers
- Google Firebase / Google Cloud (United States): hosting, database, sign-in, SMS verification, file storage, backups.
- Google reCAPTCHA: protection against automated orders.
- Payment providers chosen by the business, such as Thawani.
- OpenAI: only for the AI features described above.
- Email delivery (Resend): order confirmations for shops that turn them on.
6. How long we keep data
Order, bill and audit records are kept while the business account is active, because businesses need them for accounting and tax. Error reports are deleted 30 days after they were last seen. Daily database backups are kept for up to 30 days. When a business account is closed, its data is deleted.
7. Security
Data is encrypted in transit and at rest. Each business can only access its own data, staff access depends on their role, and refunds, cancellations and price changes are recorded in a log that cannot be edited.
8. Your rights
You can ask to see, correct or delete your personal data, or withdraw consent. Customers can ask the business they ordered from, or contact us and we will pass the request on. Some records (paid bills) may need to be kept for legal or tax reasons.
9. Changes
If we change this policy we will update the date above. Important changes will be shown in the admin panel.