Last updated 16 September 2026
This policy explains what [business name not set] collects when you use EcoGenius Restaurant, why, and what you can do about it. It covers the website, the web app, the Windows app and the Android app.
Your account. Email address and password (stored only as a cryptographic hash, never in readable form). If you sign in on a device, the authentication token that keeps you signed in.
Your business records. Everything you enter into the app: shop name, address, GSTIN, logo, invoices, the customers and suppliers you bill, items and stock, purchases, payments, expenses and accounting entries. We hold this so the same account works on the web, on Windows and on Android.
Payment records. When you subscribe, we record the amount, the plan, the time and the gateway’s payment reference. We never receive your card number, CVV, UPI PIN or netbanking credentials — those go directly to the payment gateway, which is PCI-DSS compliant.
Technical data. Standard server logs (IP address, browser, timestamps) kept briefly for security and debugging. If the Android app records field visits, the location is captured only at the moment a member of your staff taps check-in, and it is stored in your own account.
We do not collect your contacts, photos, messages or any data unrelated to running the Service.
Only the processors that make the Service work, each handling only what its job needs:
We do not sell your data, rent it, or share it for advertising. We disclose it otherwise only where the law requires it, and only to the extent required.
Records are held on infrastructure operated by the providers above, which may process data outside India. They are bound by contract to protect it and to use it only on our instructions.
Your business records stay for as long as your account exists, and for at least 12 months after a subscription lapses so that nothing is lost if you return. Ask us to delete your account and we will remove your records within 30 days, except anything we must keep for tax or legal reasons (payment records, for instance). Server logs are kept for a short period only.
Traffic is encrypted in transit (HTTPS). Passwords are hashed. Database rules isolate each account so that no shop can read another’s data, and subscription records are writable only by our server, never by an app on your device. There is more detail on the security page. No system is perfectly secure; if a breach ever affects your data we will tell you.
We use only what the Service needs: a session cookie/token to keep you signed in, and local storage for your theme and unsaved drafts. No advertising or cross-site tracking cookies are set.
The Service is for businesses and is not directed at anyone under 18.
We will post any update here with a new date. Material changes will be notified in the app or by email.
For anything in this policy, including a request to delete your data: [support email not set]. See also our contact page.