1. Introduction
RasoiOS – Restaurant Operating System ("RasoiOS", "we", "us", or "our") provides cloud-based restaurant management software for restaurants, cafés, cloud kitchens, and food businesses in India and internationally.
RASOIOS POS is a restaurant management application intended solely for restaurant owners, managers, cashiers, counter staff, and other authorized personnel. It is not a consumer food ordering or food delivery application.
This Privacy Policy explains how we collect, use, disclose, store, and protect personal information when you use our websites (including https://rasoios.com), the RASOIOS POS Android and iOS mobile applications, owner portals, and related services (collectively, the "Services").
Data controller: RasoiOS Technologies, operating from Raipur, Chhattisgarh, India. For privacy requests, contact rasoios.team@gmail.com.
2. Scope and Roles
RasoiOS serves business users only — restaurant owners, managers, cashiers, counter staff, and other authorized personnel. When you register a business account, we act as a data controller for your account and profile information.
Your restaurant may record operational data about dine-in or QR orders placed at your premises (for example, table number, order items, or a customer name or phone number your staff enters). In those cases you are the data controller for that customer information and RasoiOS acts as a data processor on your instructions. You are responsible for providing appropriate notices and obtaining consents from your customers under applicable law.
3. Information We Collect
Depending on how you use RasoiOS, we may collect:
- Identity and contact data — name, email address, mobile number, business role, and restaurant affiliation.
- Authentication data — credentials, one-time passwords (OTP) used for account recovery or optional verification, session tokens, and sign-in method identifiers.
- Restaurant and business data — business name, address, GST or tax identifiers you provide, menu items, categories, pricing, table layout, operating hours, branding, and configuration settings.
- User-generated content — menu photos, restaurant logos, item descriptions, staff notes, and other content you upload.
- Operational and transaction data — in-restaurant orders, bills, KOTs, inventory movements, staff actions, payment status indicators, and timestamps needed to run POS and reporting.
- Guest order data entered by your staff — table identifiers, order contents, customer names or phone numbers, and special instructions your team records while operating the POS.
- Device and technical data — device model, operating system, app version, language, time zone, IP address, and connectivity state.
- Analytics and diagnostics — app usage statistics, feature usage, crash reports, performance metrics, and error logs (for example via Firebase Analytics and Sentry). Diagnostic tools may be configured to mask or exclude sensitive fields where possible.
- Payment and subscription information — plan name, billing cycle, invoice references, transaction status, and amounts. Payments are processed through trusted third-party payment gateways such as Razorpay and, where applicable, Google Play or Apple App Store billing. RasoiOS does not store complete debit or credit card numbers, CVV, UPI PINs, or other sensitive payment credentials.
- Communications — support emails, chat messages, feedback, and call records where you contact us.
- Marketing preferences — whether you opt in or out of promotional communications where offered.
4. Sign-In Methods and Authentication
RasoiOS supports the following sign-in methods (availability may vary by platform and configuration):
- Email and password — we collect your email address and a hashed password for authentication and account recovery.
- Mobile number and password — we collect your mobile number for account creation, communication, support, and login. OTP verification is not required at registration; you may verify your number later to enable SMS-related features.
- One-time passwords (OTP) — where enabled, OTPs delivered via SMS through Firebase Authentication or similar providers are used for forgot-password flows, changing your registered mobile number, optional phone verification, and account security — not as the default registration step.
- Google Sign-In — if you choose Google Sign-In, Google shares basic profile information with us such as your name, email address, and profile picture (if available). We use this information solely to create and authenticate your RasoiOS account. Google's use of your data is governed by Google's Privacy Policy.
- Apple Sign-In — on supported Apple devices, you may sign in with Apple. Apple may provide your name and email address (including Apple's private relay email option). We use this information solely for authentication and account management. Apple's use of your data is governed by Apple's Privacy Policy.
By using a third-party sign-in method, you authorize us to receive the profile data that provider shares with us for authentication purposes. You can disconnect third-party sign-in by contacting support or deleting your account.
5. Device Permissions
The RASOIOS POS Android app requests the following permissions. You may deny optional permissions, but related features may not work.
- Internet — required to sync data, authenticate, process orders, and receive updates.
- Notifications — to deliver new order alerts, kitchen updates, billing reminders, account security notices, and optional product announcements. You can disable notifications in device settings.
- Camera — to scan QR codes at tables or counters and capture menu item photos where you choose to use the camera.
- Photos / storage (READ_MEDIA_IMAGES) — to upload menu item images, restaurant logos, and save exported reports or receipts where you choose to save them locally.
- Bluetooth, Bluetooth Connect, and Bluetooth Scan — used solely to discover and connect compatible receipt and kitchen (KOT) thermal printers. We do not use Bluetooth for location tracking.
- Nearby devices (Android 12+) — required by Android to pair and connect Bluetooth printers; used only for printer connectivity, not for tracking users.
- Location (when in use) — to set or display your restaurant pin on a map during setup when you enable location-based features. Location is not collected continuously in the background for core POS use.
- Biometrics (Face ID / fingerprint) — to optionally unlock the app or authorize sensitive actions on your device. Biometric data stays on your device and is not transmitted to our servers.
6. How We Use Information
We use personal information to:
- Provide, operate, maintain, secure, and improve the Services;
- Authenticate users, manage roles, and enforce access controls;
- Process orders, billing, inventory, staff workflows, analytics, and reports;
- Enable cloud sync, offline queuing, printing, and device notifications;
- Process subscriptions and payments through authorized payment partners;
- Send transactional communications (order alerts, security notices, billing receipts);
- Send marketing communications only where permitted and, where required, with your consent;
- Provide AI-powered insights and recommendations (see Section 12);
- Detect fraud, abuse, and security incidents;
- Comply with law and enforce our Terms & Conditions.
7. Legal Bases for Processing
Where the GDPR or similar laws apply, we rely on the following legal bases:
- Contract — processing necessary to provide the Services you request.
- Legitimate interests — security, fraud prevention, product improvement, and analytics, balanced against your rights.
- Consent — marketing communications, optional cookies, and certain permissions where consent is required.
- Legal obligation — tax, accounting, and regulatory compliance.
Under India's Digital Personal Data Protection Act, 2023 (DPDP Act), we process personal data based on your consent, contractual necessity, legitimate uses permitted by law, or other grounds recognized under applicable Indian law.
8. Data Storage and Security
We implement industry-standard safeguards, including:
- Encryption in transit — HTTPS/TLS for data transmitted between your devices and our servers.
- Encryption at rest — encrypted storage on cloud infrastructure and encrypted backups where supported by our hosting providers.
- Secure cloud infrastructure — production systems hosted on reputable providers with physical and network controls.
- Access control — role-based permissions, authentication, and least-privilege internal access.
- Monitoring — logging and alerting for security events and operational anomalies.
No method of transmission or storage is 100% secure. You are responsible for safeguarding credentials and limiting staff access within your restaurant account.
9. Cloud Storage and Third-Party Services
We use trusted subprocessors to operate RasoiOS, including:
- Razorpay — subscription billing and payment processing;
- Google Sign-In / Google Play services — optional authentication and Android distribution;
- Apple Sign-In — optional authentication on iOS;
- Firebase Authentication (Google) — optional phone OTP for account recovery and verification;
- Firebase Cloud Messaging — push notifications for order and account alerts;
- Firebase Analytics — aggregated app usage statistics to improve performance and features;
- Firebase Crashlytics / error monitoring — crash and performance diagnostics (e.g. Sentry where enabled);
- Google Analytics — website usage analytics on marketing properties where enabled;
- Cloud hosting and databases — infrastructure, storage, and backups (e.g. AWS, GCP, Railway, or similar);
Subprocessors process data on our instructions under contractual safeguards. Each provider is governed by its own privacy policy. For a current subprocessor list or Data Processing Agreement (DPA) requests, email rasoios.team@gmail.com.
11. Push Notifications
With your permission, RasoiOS may send push notifications to your device:
- Order and operations — new orders, kitchen (KOT) updates, billing events, and other alerts needed to run your restaurant.
- Account and security — sign-in alerts, subscription notices, and important account changes.
- OTP and verification — when you initiate forgot-password or phone-verification flows that use SMS; related in-app status messages may also appear.
- Product updates (optional) — feature announcements, tips, or promotional offers only where permitted and, where required by law or platform policy, with your opt-in consent. You can disable notifications in device settings or in-app notification preferences where available.
Push delivery uses Firebase Cloud Messaging (Android) and Apple Push Notification service (iOS). Device notification tokens are stored to route messages to your device.
12. AI Features and Data Processing
RasoiOS offers AI-powered capabilities, including Rasoi Brain, that analyze operational data such as sales trends, menu performance, inventory patterns, and aggregated business metrics to generate insights, recommendations, forecasts, or suggested actions.
- AI outputs are informational and operational aids only — not financial, legal, tax, or food-safety advice;
- AI recommendations may be inaccurate or incomplete; you must verify outputs before acting on them;
- You remain responsible for menu pricing, inventory decisions, staffing, and compliance with applicable law;
- Where possible, we use aggregated or de-identified data to improve AI features;
- We do not use your confidential business data to train public third-party AI models without your consent, except as required to deliver features you enable.
14. Your Rights
Depending on your location, you may have the right to:
- Access and obtain a copy of personal data we hold about you;
- Correct inaccurate or incomplete information;
- Request deletion of personal data, subject to legal exceptions;
- Export data you provided through the Services;
- Restrict or object to certain processing;
- Withdraw consent where processing is consent-based;
- Lodge a complaint with a supervisory authority.
India (DPDP Act): You may contact our Grievance Officer at rasoios.team@gmail.com to exercise rights of access, correction, erasure, and grievance redressal. We aim to respond within timelines prescribed under applicable law.
California (CCPA/CPRA — best effort): California residents may request access to, deletion of, or correction of personal information we collect. We do not sell personal information. To submit a request, email rasoios.team@gmail.com. We may verify your identity before processing requests.
End-customers of restaurants should contact the restaurant first for order-related requests. Business users may exercise rights via rasoios.team@gmail.com or in-app account tools.
15. Data Retention Policy
We retain information only as long as necessary for the purposes described in this policy:
- Active accounts: For the duration of your active account and subscription.
- Deleted accounts: Personal account data is deleted or anonymized within 30 days of a verified deletion request, except where law requires longer retention.
- Backups: Encrypted backup copies may persist up to 90 days before automatic purging.
- Billing and tax records: Billing, invoice, and tax records may be retained for up to 8 years as required under Indian tax and accounting law.
- Security logs: Security and fraud-prevention logs may be retained for up to 12 months.
- Aggregated analytics: Aggregated or de-identified analytics may be retained indefinitely.
16. Account Deletion
Users may request deletion of their account and associated business data by using the Delete Account option in the RASOIOS POS mobile app (Settings → Delete Account) or by contacting rasoios.team@gmail.com.
What is deleted: your account credentials, profile information, and linked business operational data (including menus, orders, and staff access tied to the deleted account), subject to verification and legal exceptions.
What may be retained: billing, invoice, and tax records as required under Indian law; encrypted backup copies for up to 90 days; and aggregated or de-identified analytics that cannot reasonably identify you.
In-app deletion requests are typically processed within 7 days. Email requests are processed within 30 days after identity verification. See our Account Deletion page at https://rasoios.com/account-deletion.
17. Children's Privacy
RasoiOS is a business-to-business service not directed at children under 13 (or 16 in certain jurisdictions). We do not knowingly collect personal information from children. If you believe a child has provided us personal data, contact rasoios.team@gmail.com and we will take appropriate steps to delete it.
18. International Users and Transfers
RasoiOS is operated from India. If you access the Services from outside India, your information may be transferred to, stored in, and processed in India and other countries where we or our subprocessors operate.
Where cross-border transfers are subject to GDPR or similar laws, we implement appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms with subprocessors.
19. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and revise the "Last updated" date. Material changes may be communicated through the Services or by email where appropriate. Continued use after changes constitutes acceptance of the updated policy.
20. Contact and Grievance Officer
For privacy questions, rights requests, or grievances:
- Email: rasoios.team@gmail.com
- Data controller: RasoiOS Technologies, Raipur, Chhattisgarh, India
- Website: https://rasoios.com
- Contact Us