Data Processing Terms
Last Updated: [date you publish this]
This document explains, in clear terms, who is legally responsible for what data, across RestroPod. It works alongside our Privacy Policy — the Privacy Policy tells people what data is collected; this document says who is accountable for it.
1. The Two Layers of Data in RestroPod
There are two separate relationships in RestroPod, and they work differently:
Layer 1 — Between you (the restaurant owner) and RestroPod
This covers your account, your billing details, your device information, your license. Here, RestroPod is the Data Fiduciary — the party responsible for how this data is collected, used, and protected. You are the Data Principal.
Layer 2 — Between you (the restaurant owner) and your own customers
This covers anything you choose to store about the people who eat at your restaurant — their name, phone number, loyalty points, and so on. Here, you are the Data Fiduciary for your customers' data. RestroPod is only the tool you use to store it — the same way a notebook or a spreadsheet would be a tool. We do not receive, see, or process this data at all; it stays on your device, inside your own encrypted local database.
This distinction matters because it decides who is answerable if something goes wrong. If a diner asks what data you hold about them, that's your responsibility to answer, not RestroPod's — because we genuinely don't have access to it.
2. What This Means in Practice
For your account and device data (Layer 1):
- We only use it for the purposes listed in the Privacy Policy — running your account, activating your license, processing payments, fraud detection, support.
- We don't use it for anything else, and we don't sell it.
- We use a small number of outside services to help run RestroPod — Razorpay for payments, ipapi.co for rough location lookups, and our email provider for account emails. Each only receives the specific data it needs to do its job, listed in the Privacy Policy.
For your customers' data (Layer 2):
- It never leaves your device unless you personally choose to back it up somewhere.
- We cannot read it, search it, or hand it over to anyone, because we don't have it.
- If you back up your local database and restore it, that backup and its contents remain entirely under your control.
- You are responsible for deciding why you collect this data, how long you keep it, and how you respond if a customer asks about it — the same responsibility you'd have with any other business record you keep.
3. The Recovery Phrase — A Special Case
Your local database is protected by a recovery phrase. A copy of it is stored on our servers, but in encrypted form, and only you can unlock it — using your account password.
We are not able to decrypt or view your recovery phrase ourselves. This means: even though a copy technically exists on our servers, we do not have practical access to your local data through it. It exists only so that you don't lose access to your own database if you forget your phrase.
4. If You Stop Using RestroPod
If you close your account, Layer 1 data (your account, billing, device records) is handled as described in the Privacy Policy's retention section.
Layer 2 data (your customers' data) was never on our servers, so closing your account has no effect on it — it remains on your device, under your control, exactly as it was.
5. Governing Law
This document is governed by the laws of India, in line with the Digital Personal Data Protection Act, 2023. Any disputes will be handled in the courts of Indore, Madhya Pradesh.
6. Contact Us
If you have any questions about this document, please contact us via our Contact Page.