RestoSync Privacy Policy
How ByteRiver collects, uses, stores, and protects information across the RestoSync platform — the offline-first desktop POS, the Android staff and driver apps, and the RestoSync Food consumer marketplace.
1. Introduction and Scope
This Privacy Policy explains how ByteRiver ("ByteRiver", "we", "us", or "our") handles information when you use RestoSync, our all-in-one restaurant platform. It applies to:
- The RestoSync desktop point-of-sale (POS) application for Windows and macOS, which is offline-first;
- The RestoSync staff and RestoSync Driver Android apps;
- The RestoSync Food consumer marketplace app; and
- Any related cloud sync, websites, and services we provide (together, the "Services").
Different people interact with RestoSync in different roles — restaurant owners and staff who operate the POS, and guests or diners who place orders through QR ordering or the RestoSync Food app. This policy describes our practices for each. Where a restaurant uses RestoSync to serve its own customers, that restaurant is responsible for its own privacy practices toward those customers; see "Data Ownership" below.
By using the Services, you acknowledge the practices described here. If you do not agree, please do not use the Services.
2. Who We Are
RestoSync is a product of ByteRiver. You can reach us about this policy or any privacy question at:
- Email: aby.jacob@byteriver.tech
- Website: byteriver.tech
If you contact us on behalf of a restaurant that uses RestoSync, please tell us the restaurant name so we can respond accurately.
3. Information We Collect
We collect the following categories of information, depending on how you use the Services.
Account information. When a restaurant signs up or a user is created, we may collect names, email addresses, phone numbers, login credentials, role and permission assignments, and billing and statement details.
Restaurant and business information. Information about the restaurant itself, such as business name, address, contact details, outlet and table/floor configuration, menu items (including photos and allergen tags), pricing, tax registration details used for GST/GSTR and Tally accounting, inventory, bill-of-materials and supplier records, and region/locale settings (India, GCC, APAC).
Order and transaction data. Details of orders and bills processed through the POS, kitchen display (KDS), and counter — including line items, modifiers, amounts, taxes, tips, discounts, payment method and status, KOT/order numbers, and timestamps. We generally receive payment confirmation status rather than full card or bank credentials, which are handled by our payment processors (see "Third-Party Services").
Staff data. For staff management, ratings, and dispatch, we may process staff names, roles, contact details, shift/assignment data, performance ratings, and — for the RestoSync Driver app — driver identity and delivery assignments.
Device and technical data. Information about the devices and software you use, such as device and operating-system identifiers, app version, IP address, log and diagnostic data, error reports, and sync metadata. This helps us operate, secure, and improve the Services.
Location data. The RestoSync Driver app collects GPS location during active deliveries to enable dispatch, live tracking, and navigation. Location is used for delivery operations and is not collected for unrelated purposes.
Guest and marketplace order data. When a guest orders via QR ordering, live order tracking, or the RestoSync Food consumer marketplace, we may process the guest's order contents, delivery or table details, contact information (such as name and phone number), delivery address, tips, and — where enabled — loyalty/CRM identifiers. For cash-on-delivery (COD) and online orders, we process the associated order and payment-status information.
Communications and notifications. If WhatsApp notifications or other messaging features are enabled, we process the phone numbers and message content needed to send order updates and related notifications.
AI copilot inputs. When you use AI features (daily brief, forecasting, menu engineering, and "ask"), the relevant business data (such as sales, menu, and inventory data) is processed to generate insights and responses.
4. How We Use Information
We use information to:
- Provide and operate the Services — process orders and bills, run the KDS and counter, manage tables and reservations, dispatch and track deliveries, and sync data across devices;
- Enable the RestoSync Food marketplace, QR ordering, live order tracking, tips, and loyalty/CRM features;
- Support accounting and tax workflows (GST/GSTR, Tally) and generate analytics and reports for the restaurant;
- Power AI copilot features such as daily briefs, forecasting, and menu engineering;
- Manage staff, roles, permissions, and ratings;
- Send transactional and operational notifications (including via WhatsApp where enabled);
- Maintain security, prevent fraud and abuse, and troubleshoot and improve the Services;
- Manage billing, revenue-share statements, and account settlement; and
- Comply with applicable legal and tax obligations.
We do not sell personal information. We use information for the purposes described here and do not use it for unrelated purposes without an appropriate basis.
5. Cloud Sync and Storage
RestoSync is offline-first. The desktop POS is designed to keep working without an internet connection, storing data locally on the device so that billing, KOT, and order-taking continue during outages.
When cloud sync is enabled (for features that require it, such as the marketplace, multi-device sync, live tracking, and AI), data is transmitted to and stored on our cloud infrastructure and synchronized across the restaurant's devices and apps. Local queued changes are uploaded when connectivity is restored. Some data may remain cached locally on devices to support offline operation.
Cloud data is hosted on third-party infrastructure providers on our behalf (see "Third-Party Services").
6. Data Ownership
The restaurant owns its customer data. When a restaurant uses RestoSync to serve its own guests — including orders placed through RestoSync Food at 0% commission on the restaurant's own orders — the restaurant retains ownership of, and access to, the customer and order data generated. Unlike third-party aggregators that withhold customer data, RestoSync is designed to keep that data with the restaurant.
In this arrangement, the restaurant is the party that decides how its guests' data is used, and ByteRiver processes that data to provide the Services to the restaurant. Restaurants are responsible for having an appropriate basis to collect and use their guests' information and for their own privacy commitments to those guests. ByteRiver does not impose price-parity clauses, contract lock-in, or hardware lock-in as a condition of these Services.
7. Third-Party Services
We rely on trusted third parties to provide parts of the Services. These providers process information only as needed to perform their functions.
Payment processors. Card, UPI, and other online payments are handled by payment processors such as Razorpay and Stripe. When you pay through these processors, your payment details are provided to and processed by them under their own terms and privacy policies. We generally receive transaction and payment-status information rather than full payment credentials.
Hosting and infrastructure. Our cloud data and services run on third-party hosting and infrastructure providers that store and process data on our behalf.
Messaging. Where enabled, notifications may be delivered through messaging providers (for example, WhatsApp) using the phone numbers and message content needed to send them.
Delivery-aggregator sync. On plans that support it, RestoSync can sync with third-party delivery aggregators such as Zomato and Swiggy. When you connect these integrations, order and menu information is exchanged with those platforms, which handle data under their own policies.
AI processing. AI copilot features may use server-side AI processing to generate insights and responses from the relevant business data.
Each third party operates under its own privacy policy. We encourage you to review the policies of any payment processor, aggregator, or messaging service you use with RestoSync.
8. Data Security
We take reasonable technical and organizational measures designed to protect information against unauthorized access, loss, misuse, or alteration. These include measures such as encryption of data in transit, access controls and role-based permissions, and authentication for accounts and devices.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping account credentials confidential, managing staff roles and permissions appropriately, and securing the devices on which the POS and apps run. Please notify us promptly at aby.jacob@byteriver.tech if you believe your account or data has been compromised.
9. Data Retention
We retain information for as long as it is needed to provide the Services, operate your account, and meet legitimate business, accounting, tax, and legal obligations.
Because RestoSync is offline-first, some data is also retained locally on your devices to support offline operation until it is synced, cleared, or the device is reset.
When information is no longer required for these purposes, we take steps to delete or de-identify it. Retention periods can vary depending on the type of data and applicable legal requirements. If you would like more detail about retention for a specific type of data, contact us at aby.jacob@byteriver.tech.
[Note for review: specific retention periods should be confirmed and inserted by ByteRiver in consultation with legal counsel.]
10. Your Rights
Depending on your location and applicable law, you may have rights over your personal information, such as the right to access, correct, update, or delete it, to object to or restrict certain processing, or to obtain a copy of it.
How to exercise these rights depends on your role:
- If you are a restaurant owner or staff member with a RestoSync account, you can review and update much of your information directly within the Services (for example, in staff management and profile settings), or contact us for assistance.
- If you are a guest or diner whose data was collected by a restaurant using RestoSync, that restaurant controls your data. Please direct requests to the relevant restaurant; we will support the restaurant in responding where we act as its processor.
To make a request to ByteRiver directly, email aby.jacob@byteriver.tech. We may need to verify your identity before acting on a request. We will respond in accordance with applicable law.
[Note for review: the exact rights available depend on the governing jurisdiction(s), which should be confirmed by legal counsel.]
11. Cookies and Similar Technologies
Our websites and web-based features (such as QR guest ordering, live order tracking, and any custom restaurant website) may use cookies and similar technologies. These are used for purposes such as keeping you signed in, remembering preferences, maintaining sessions, ensuring security, and understanding how the Services are used so we can improve them.
Where required, we will ask for your consent to non-essential cookies. You can usually control cookies through your browser or device settings; disabling some cookies may affect how parts of the Services function.
The desktop POS and mobile apps use local storage and similar mechanisms to support offline-first operation and app functionality.
12. Children's Privacy
The Services are intended for use by restaurants, their staff, and adult diners. They are not directed to children, and we do not knowingly collect personal information from children. If you believe a child has provided personal information to us, please contact us at aby.jacob@byteriver.tech so we can take appropriate action.
13. Multi-Region and International Data
RestoSync supports operation across multiple regions, including India, the GCC, and APAC. Depending on your region and configuration, your information may be processed and stored on infrastructure located in, or accessible from, more than one country.
Where information is transferred across borders, we take steps intended to ensure it remains protected consistent with this policy and applicable law.
[Note for review: applicable data-localization and cross-border transfer requirements, and the governing jurisdiction(s), should be confirmed by legal counsel.]
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the Services, our practices, or legal requirements. When we make material changes, we will take reasonable steps to notify you, such as posting the updated policy with a new effective date or providing notice within the Services. Your continued use of the Services after an update takes effect means you acknowledge the revised policy.
15. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your information, contact us at:
- ByteRiver
- Email: aby.jacob@byteriver.tech
- Website: byteriver.tech
We will do our best to address your inquiry promptly.
Ready to keep more of every order?