Privacy Policy
Last updated: 3 October 2026
Syed Qasim, trading as SYQAVO, Hyderabad, Telangana, India ("we", "us"), runs SYQAVO, software that restaurants use for table ordering, billing and payments. This policy explains what personal data the service handles, why, and your rights. It is written with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000 in mind.
1. Who is responsible for your data
- If you are a guest at a restaurant: the restaurant decides why your data is collected and is the Data Fiduciary for it. We process
it on the restaurant's behalf (as its Data Processor) to run the ordering and billing service. You can contact the restaurant, or us, about your data.
- If you are a restaurant owner or staff member, or you contact us: we are the Data Fiduciary for your account data.
2. What we handle, and why
| Whose data | What | Why | Basis |
|---|---|---|---|
| Guests | Mobile number (optional), name (optional), the table and restaurant, what you ordered, your share of the bill and payments | To take your order, show it to the kitchen and your table, split and settle the bill, send a receipt, and let you return to your seat if you close the page | Your consent (given on the welcome screen) and the restaurant's legitimate business use |
| Guests | A one-time login code sent to your number (only where the restaurant verifies numbers; not switched on yet) | To confirm the number is yours | Consent |
| Guests | Your device's IP address and session details | Security, fraud prevention, rate limiting | Legitimate uses permitted by law |
| Restaurant staff | Name, email, role, branch, sign-in times, actions taken | Account access, permissions, the restaurant's audit trail | Performance of the contract with the restaurant |
| Restaurant owners | Business and contact details, GSTIN, billing records | Providing and billing the subscription, tax compliance | Contract and legal obligation |
Payments. Online payment is not switched on yet. When it is, card and UPI details are entered on the payment gateway's page and are handled under the gateway's own privacy policy, and the money goes straight into the restaurant's own account. We receive only the payment result and a transaction reference; we never see or store card numbers or UPI PINs.
We do not sell personal data, use it for advertising, or build profiles of guests across different restaurants.
3. How we protect it
Guest mobile numbers are stored encrypted. Each restaurant's data is separated at the database level so one restaurant cannot see another's. Access is limited by role, every sensitive action is recorded in a tamper-evident audit trail, connections are encrypted (HTTPS), and backups are taken daily. No system is perfectly secure; if a breach affects you we will notify you and the Data Protection Board of India as the law requires.
4. Who we share it with
Only with service providers who help us run the service, under terms that require them to protect it. Today that is Cloudflare, Inc., which carries the encrypted connection between your device and our servers; the data itself is stored on our servers in India. No payment gateway, SMS provider or email provider receives personal data today; before one does, it will be named here. We may disclose data where required by law or to protect rights and safety. Guest data is visible to the restaurant you ordered at; your name (not your number) is visible to others at your table.
5. How long we keep it
- Guest session and ordering data: for as long as the restaurant uses the service, plus the periods below.
- Bills, payments and tax records are kept for as long as Indian tax law requires (generally at least six years), even if the
restaurant leaves the service; they are taken out of use and then erased.
- Remembered number and name on your own phone: stored only in your browser; clear your browser data to remove it.
- Login codes expire within minutes; audit records are kept for six years for security and legal purposes.
6. Your rights
Under the DPDP Act you may ask to access a summary of your data, correct or complete it, erase it (where we are not required by law to keep it), withdraw consent (future processing stops; this does not affect bills already issued), and nominate someone to exercise your rights if you cannot. You also have the right to grievance redressal. Guests: contact the restaurant or us at support@syqavo.com; we will pass requests to the restaurant where it is the Data Fiduciary. We respond within 30 days. If you are not satisfied, you may complain to the Data Protection Board of India.
7. Children
The service is not directed at children. Restaurant staff accounts are for adults only. A guest under 18 should use the service with a parent or guardian, who gives any consent needed.
8. Cookies and local storage
We use only what the service needs to work: a secure sign-in cookie for staff, and your browser's storage for your table session and (on your own phone) your remembered number and name. No advertising or tracking cookies.
On our public website we count, per day, how often each page is viewed and how often buttons such as "Book a demo" are pressed. These are totals only: no cookie, no IP address and nothing else that could identify you is stored with them, and nothing is counted at all if your browser sends a Do Not Track or Global Privacy Control signal. No third-party analytics or advertising tools are used.
9. AI features
AI features are switched off. Before any is switched on, this section will say what data is sent to which provider and where it is processed; guest phone numbers are never sent.
10. Changes and contact
We will post changes here and, for material changes, notify restaurants by email. Grievance / Data Protection Officer: Syed Qasim, support@syqavo.com, phone and WhatsApp +91 96766 42333, Hyderabad, Telangana, India.