Privacy Policy
Effective Date: July 24, 2026 · Compliant with the Digital Personal Data Protection (DPDP) Act, 2023 (India)
1. Introduction
Welcome to Vyte Technologies Pvt. Ltd. ("Company", "Vyte", "we", "our", or "us"). We operate the Vyte restaurant management ecosystem, including our point of sale (POS) platform, QR digital menus, kitchen display systems, and analytics services available at vytepos.com.
This Privacy Policy outlines how we collect, store, process, transfer, and protect personal data in compliance with India’s Digital Personal Data Protection (DPDP) Act, 2023, Information Technology Act, 2000, and applicable rules.
2. Data We Collect
We collect personal data necessary to provide and optimize our restaurant tech services:
- Merchant Data: Business name, owner/manager name, email address, phone number, GSTIN, billing address, and bank payout information.
- End-Customer Data: Phone number (for order updates/SMS receipts), table preferences, order history, and payment status when placing orders via QR menus.
- Technical & System Data: IP address, device identifier, browser type, operating system, app usage analytics, and cookie data.
3. Lawful Basis & Purpose of Processing
We process personal data for specific, explicit, and lawful purposes:
- To process QR food orders, generate bills, and dispatch orders to kitchen displays.
- To verify payments through secure payment gateways (e.g., Razorpay).
- To send order status SMS notifications and digital receipts.
- To provide AI analytics, inventory insights, and customer retention metrics to merchants.
- To comply with statutory legal requirements and tax obligations under Indian law.
4. Consent & User Rights under DPDP Act 2023
As a Data Principal under the DPDP Act 2023, you hold the following statutory rights:
- Right to Access: Request a summary of personal data being processed.
- Right to Correction & Erasure: Request correction of inaccurate data or deletion of data no longer required for its operational purpose.
- Right of Grievance Redressal: Submit complaints regarding data processing to our Data Protection / Grievance Officer.
- Right to Nominate: Nominate an individual to exercise data rights in the event of incapacity.
5. Data Sharing & Third-Party Vendors
We do not sell personal data. We share data only with authorized service providers under strict confidentiality agreements:
- Payment Gateways: Payment metadata processed securely via Razorpay Software Private Limited.
- Cloud & Database Hosting: Secure cloud infrastructure and PocketBase databases hosted in tier-3 data centers with AES-256 encryption.
- Communication Providers: SMS/WhatsApp gateway partners for real-time order receipts and OTP verification.
6. Security Standards & Retention
We maintain technical, organizational, and physical safeguards including TLS 1.3 encryption in transit and AES-256 encryption at rest. Personal data is retained only as long as necessary to fulfill operational purposes or statutory accounting requirements.
7. Data Protection Officer & Grievance Redressal
If you have questions, concerns, or requests to exercise your rights under the DPDP Act 2023, please contact our designated Grievance Officer:
Entity Name: Vyte Technologies Pvt. Ltd.
Grievance Officer: [GRIEVANCE_OFFICER_NAME]
Support Email: [SUPPORT_EMAIL]
Support Phone: [SUPPORT_PHONE]
Registered Address: [REGISTERED_ADDRESS]