1. Introduction
Restro provides digital menus, QR-code guest ordering, kitchen order boards, and related restaurant operations tools. Restaurant owners and staff create accounts to manage a restaurant. Diners typically use Restro as guests: they scan a menu QR code, place an order, and (where offered) pay or receive order notifications. Guests do not need a Restro account.
2. Information we collect
We collect only the information needed to run the features you use. Depending on how you use Restro, that may include:
Restaurant owners
- Name, email address, and password (or Google sign-in)
- Account identifiers such as a user ID, role, and subscription plan
- Restaurant profile information (name, cuisine, slug, logo, theme, currency, and order settings)
- Menu content you create or import, including item names, prices, photos, availability, and stock
- Billing and plan information, including Razorpay customer or subscription identifiers when you subscribe to a paid plan
- Payment onboarding details you submit so guests can pay online (business, contact, and bank information is sent to Razorpay; see Payments)
Kitchen staff (chefs)
- Name, email address, and password, created by the restaurant owner
- Role and the restaurant they are assigned to; accounts can be disabled by the owner
Guests placing an order
- Name
- Phone number (collected as a WhatsApp-capable number, including country code)
- Table number, when the restaurant requires it
- Order details: items, quantities, prices, totals, currency, kitchen token, order status, and payment status
- Payment method choice (pay at the restaurant or pay online, when the restaurant offers online checkout)
Technical and operational data
- Authentication tokens stored in the browser on restaurant-owner and staff devices (local storage), so you can stay signed in
- A short-lived browser record of an open guest order (so the same phone can add items to the current visit)
- A short-lived browser record of the guest’s name, WhatsApp number, and table number on that device, so a later order during the same visit does not ask for those details again
- Server request logs, which may include IP address, date and time, requested URL, and browser user-agent, used to operate and secure the service
We do not run a third-party advertising or product-analytics SDK in the Restro application. Restaurant owners on eligible plans can view sales insights derived from their own order records.
3. How we use information
We use the information above to:
- Create and manage restaurant-owner and staff accounts
- Verify email addresses and handle password resets
- Publish digital menus and process guest orders
- Show orders to the restaurant’s owner and authorized kitchen staff, including live kitchen boards
- Show public display boards that use kitchen token numbers and order status only (not guest names or phone numbers)
- Send transactional WhatsApp messages when that feature is enabled for the restaurant
- Process online payments and plan subscriptions through Razorpay when those features are used
- Extract menu items from photos or PDFs that an owner uploads (processed with Google Gemini)
- Provide customer support and fix problems
- Maintain, secure, and improve the service
4. WhatsApp communications
Some Restro plans include transactional WhatsApp notifications through the WhatsApp Business Platform (Meta). Messages are sent only when all of the following apply:
- The restaurant’s plan includes WhatsApp notifications
- The owner has not turned WhatsApp off for that restaurant
- The guest has provided a phone number with the order (or a restaurant user sends a test notification they initiate)
When sent, messages are limited to operational updates such as:
- Order confirmations
- Notifications that items were added to an existing order
- Payment or invoice confirmations after an order is paid
To deliver those messages, Restro transmits the guest’s phone number and limited order information (such as guest name, restaurant name, a short order reference, item summary where applicable, and total) to Meta. Restro does not use this integration to send marketing or promotional campaigns.
Meta may send delivery-related webhook events to Restro so the integration can operate. Restro does not keep a general log of those webhook payloads. For paid-order invoice notifications, Restro may store a send result on the order (for example, whether the notification was claimed or sent, a provider message identifier, and error details). That record is for restaurant operations and is not shown on the guest order tracker.
5. Third-party service providers
Restro uses the following providers to operate the product. Each processes information only as needed for the role described.
- Google Firebase (Authentication, Firestore, and Storage) — restaurant-owner and staff accounts, application data, and uploaded images (such as logos and dish photos). Optional Google sign-in is handled through Google.
- Meta / WhatsApp Business Platform — delivery of the transactional WhatsApp messages described above.
- Razorpay — guest online checkout (when the restaurant has enabled payments), restaurant plan billing, and payout onboarding (Linked Accounts / Route) when the owner completes that flow.
- Google Gemini — optional AI menu import. Images or PDFs an owner uploads for import are sent to Gemini so menu items can be extracted. Extracted items are saved only if the owner confirms the import.
- Hosting providers — the Restro website and API run on cloud infrastructure. Those providers may process connection data (such as IP addresses) as part of hosting.
Those providers have their own privacy policies. We do not sell personal information.
6. Payments
Restro does not store payment card numbers, UPI PINs, or full bank account numbers used to pay an order. When a guest pays online, card, UPI, and similar instruments are collected by Razorpay Checkout and processed under Razorpay’s terms and policies.
Restro stores order payment metadata needed to run the restaurant, such as payment status, payment method, amounts, and Razorpay payment or order identifiers. Refunds, when initiated by the restaurant, are also processed through Razorpay and recorded as status and identifiers on the order.
Online guest checkout is available only when the restaurant has completed payment onboarding. Owners can skip onboarding; in that case online payments stay disabled and guests may still order with pay-at-restaurant where the restaurant allows it.
If an owner completes payout onboarding, business, tax, and bank details they enter are submitted to Razorpay. Restro stores onboarding status and limited identifiers (for example a linked account id and masked account last four digits), not the full instrument used at checkout.
8. Data security
We use reasonable administrative and technical measures appropriate to this service, including HTTPS for the public website and API, hashed passwords stored by Firebase Authentication (Restro does not store account passwords in Firestore), server-side session verification for restaurant accounts, and access controls so guest-facing views do not expose payment-provider fields. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Data retention
Restro does not currently run an automated deletion schedule for accounts or orders. We keep restaurant accounts, menus, and order records while they are needed to operate the service for that restaurant, including kitchen history, billing, and dispute handling, and as required by law.
A guest’s browser may forget an “open order” reference after a few hours, and remembered checkout details after about a day, so later visits start a new order session. That local expiry does not delete the order from restaurant records.
Uploaded images are stored in order to display menus and restaurant branding until the owner replaces or removes them.
10. Your rights and data deletion
You may request access to, correction of, or deletion of personal information we hold about you. Restro does not currently provide an in-product account-deletion button or an automated deletion API. Requests are handled manually.
Restaurant owners can update much of their own profile and restaurant information in the dashboard. Guests who want an order or phone number deleted should contact us (and may also ask the restaurant they ordered from). We may need enough detail to locate the records (for example restaurant name, approximate time, and the phone number used).
We may decline or limit a request where we cannot verify the requester, where we must keep information for legal, security, or billing reasons, or where deletion would interfere with another user’s account (for example a restaurant’s remaining order history). We will explain when that applies.
A dedicated privacy contact email is not yet published in this application (TODO). Until one is listed, contact The Refactor Factory through the Restro website at https://restro.therefactorfactory.com.
11. Children’s privacy
Restro is built for restaurants and diners. It is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us and we will take reasonable steps to remove it.
12. Changes to this Privacy Policy
We may update this policy as Restro changes. The “Last updated” date at the top will change when we do. Continued use of Restro after an update means you are using the service under the revised policy. Material changes will be reflected on this page.
13. Contact us
Restro is operated by The Refactor Factory.
Website: https://restro.therefactorfactory.com
A dedicated privacy contact email is not yet published in this application (TODO). Until one is listed, contact The Refactor Factory through the Restro website at https://restro.therefactorfactory.com.