Privacy Policy for Refinerack
Effective Date: September 9, 2026
1. Introduction
Welcome to Refinerack ("we," "our," or "us"). We provide a restaurant Software as a Service (SaaS) platform that facilitates menu digitization, table management, AI-powered service, and order tracking.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web application, AI waiter services, and related platforms. This policy complies with applicable data protection laws, including the Digital Personal Data Protection (DPDP) Act, 2023 of India, and incorporates global privacy principles.
2. Information We Collect
We collect information depending on your interaction with the platform:
A. Restaurant Owners and Staff
- Identity & Contact Data: Name, phone number (via OTP authentication), email address, and Google account profile information (if linked).
- Business Data: Restaurant name, address, website, opening hours, menus (including PDF uploads), and operational configurations.
- Employment Context: Role assignment (e.g., owner, manager, waiter, cook, host) linked to a specific restaurant.
B. Dine-In Customers
- Identity & Contact Data: Name and phone number (collected when requesting to join a waitlist or a table session).
- Order & Dining Data: Order history, dietary preferences (e.g., vegetarian, allergies) inferred from orders or chat, and billing summaries.
- AI Interaction Data: Chat transcripts and interactions with our AI Waiter ("Raju") via web or WhatsApp.
Note: Customers are primarily authenticated anonymously via QR code scans to reduce friction, linking session data to a temporary profile.
C. Automatically Collected Data
- Device & Usage Data: IP address, browser type, operating system, and interaction logs collected via Firebase Analytics and Google Cloud infrastructure.
3. How We Use Your Information
We process your personal data for the following purposes:
- Service Delivery: To manage waitlists, table sessions, order processing, and billing computations.
- AI Functionality: To power the AI Waiter by processing menu blueprints and customer queries (e.g., suggesting pairings based on dietary guardrails like pure vegetarian isolation).
- Security & Auditing: To maintain an immutable audit trail of order events (e.g., tracking which staff member served or cancelled an item).
- Communication: To send OTPs for login, session join codes, or WhatsApp webhook messages.
- Analytics & Improvement: To analyze historical profiling (using anonymous customer data) to improve prep-time estimations and operational efficiency.
4. How We Share Your Information
We do not sell your personal data. We share data only with:
- Service Providers:
- Google Cloud & Firebase: For secure hosting, database (Firestore), and authentication.
- Google Gemini AI: Menu PDFs and customer chat queries are sent to Gemini APIs to extract menu data and power the conversational AI Waiter.
- WhatsApp Cloud API: For routing messages if interacting via WhatsApp.
- Restaurant Partners: Customer order and contact data are shared directly with the specific restaurant where the customer is dining.
- Legal Compliance: If required by law, court order, or government regulation.
5. Data Retention
- Audit Trails: Staff actions (e.g., order status changes) are kept as an immutable append-only log for the restaurant's operational integrity and accountability.
- Customer Profiles: Anonymous user profiles and session histories are retained for historical profiling and business intelligence for the restaurant.
- Account Deletion: Users may request data deletion by contacting us. We will delete personal data unless retention is required for legal, accounting, or auditing purposes.
6. Your Rights
Under the DPDP Act (India) and other applicable laws, you have the right to:
- Access: Request a summary of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data.
- Grievance Redressal: Lodge a complaint with our Grievance Officer.
7. Security
We implement robust security measures, including Firebase security rules, anonymous authentication for customers, role-based access control (RBAC) for staff, and transaction-locked database writes, to protect your data from unauthorized access.
8. Contact & Grievance Officer
If you have questions or wish to exercise your rights, please contact our Grievance Officer:
- Name: Ashwin Torphe
- Email: connect@refinerack.com
- Address: Megha Palms, 102, 35th main 7th cross, BTM 2nd stage, Bengaluru 560068