Privacy
Privacy policy
Last updated 17 September 2026
1. Who we are
Thaalo is a product of StriveBit Technologies Private Limited (CIN U72900UP2021PTC142374), [Registered address]. We are the data fiduciary for the personal data described in this policy under the Digital Personal Data Protection Act, 2023. Restaurants using Thaalo are separately responsible for how they use their own customers’ data.
2. What we collect
From restaurant owners and staff:
- Name, phone number, email address and role, to create and secure staff accounts.
- Business details: restaurant name, address, menu, opening hours, GST details if provided, and plan.
- Usage records: when orders were accepted, edited, billed or cancelled, and by which staff account.
From diners who order through a restaurant’s Thaalo page:
- Order contents, table or fulfilment type, and the time of the order.
- Name and phone number, only where the diner enters them (for pickup, delivery, or where a restaurant has verification on).
- Device data needed to serve the page: IP address, browser type, and a cookie or local storage key that keeps the cart and order status on the diner's phone.
We do not collect payment card details. Online payments, when available, are processed by a licensed payment gateway under its own policy.
3. Why we use it
- To run the service: show menus, route orders to the kitchen, produce bills and reports.
- To keep accounts secure and to prevent abuse.
- To support restaurants on WhatsApp and email.
- To send order notifications to diners where a restaurant enables them.
- To meet legal obligations, including tax record-keeping.
Legal basis: performance of the contract with the restaurant, and consent given by the diner when they enter their details. We do not use personal data for advertising and we do not sell it.
4. Who else sees it
- Hosting and database providers that run the service.
- WhatsApp and SMS providers, for messages the restaurant or diner has asked for.
- The payment gateway, for online payments.
- Analytics on thaalo.in only, which is cookieless and does not identify individuals.
- Authorities, where the law requires it.
5. How long we keep it
- Order and billing records: eight years, as required for tax and accounting.
- Diner phone numbers: 180 days after the diner's last order, unless the restaurant asks for earlier deletion.
- Staff accounts: while the restaurant's subscription is active, then 30 days.
- A restaurant that closes its account receives an export of its menu and orders on request; the data is deleted 30 days after closure, except records we must keep by law.
6. Your rights
Owners, staff and diners can ask to see, correct or delete their personal data, or withdraw consent, by writing to [email protected]. We respond within 30 days. Diners may also ask the restaurant directly. You can complain to the Data Protection Board of India if you are not satisfied with our response.
7. Children
Thaalo is not directed at children under 18, and we do not knowingly collect their personal data.
8. Security
Data is encrypted in transit, passwords are stored hashed, and every database query is scoped to one restaurant. Staff access is by named account. No system is perfectly secure; if a breach affects you we will tell you and the Board as the law requires.
9. Grievance officer
[Grievance officer name], StriveBit Technologies Private Limited, [Registered address]. Email [email protected]. Complaints are acknowledged within 48 hours and resolved within 30 days.
10. Changes
We will post changes here and, for material changes, tell restaurants on WhatsApp or email before they take effect.