1. Who We Are
[LEGAL ENTITY NAME](“Said-itt”, “we”, “us”, or “our”), registered at [REGISTERED ADDRESS], is the Data Fiduciary within the meaning of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) in respect of data processed through the Said-itt platform.
This policy applies to personal data processed in connection with:
- Restaurant owner accounts and subscription management
- Guest interactions with QR code feedback forms
- Communication features within the platform
- Our website at said-itt.com
[NOTE FOR LAWYER: Confirm whether Said-itt is a Data Fiduciary or also a Significant Data Fiduciary under DPDP rules once thresholds are notified]
2. Information We Collect
2a. Restaurant Owner / Subscriber Data
When you create an account or use the platform, we collect:
- Name and email address (used for login and communications)
- Business name, address, cuisine type, and contact phone number (used to configure your restaurant profile)
- Password (stored as a one-way cryptographic hash — we cannot read your password)
- Billing email address and subscription payment history (we receive confirmation of payment from Razorpay; we do not receive or store card numbers, CVV codes, or bank account details)
- Log-in timestamps and IP addresses
- Any content you upload, including restaurant descriptions, reward definitions, and profile images
2b. Guest Data
When a guest scans a Said-itt QR code and submits feedback, we collect:
- Mobile phone number (used to associate subsequent visits with the same guest and to send reward notifications — guests provide this voluntarily)
- Star rating (1–5) and feedback text (if provided)
- Date and time of the feedback submission
- Reward issuances and redemption records (what reward was earned, when it was redeemed)
- Whether the guest has opted in to receive direct messages from the restaurant
We do not collect guest names, email addresses, or payment information directly. We do not build advertising profiles on guests.
2c. Payment Data
Subscription payments are processed by Razorpay Software Private Limited, a licensed payment aggregator. Said-itt receives confirmation of successful payment (amount, date, transaction reference) but does notstore card numbers, CVV codes, UPI handles, or net banking credentials. Razorpay’s data practices are governed by Razorpay’s Privacy Policy.
2d. Technical and Usage Data
We automatically collect limited technical data when you use the platform:
- Browser type and operating system
- IP address and approximate location (country/city level)
- Pages visited within the dashboard and time spent
- Error logs for debugging
We use this data only to operate, maintain, and improve the service.
3. How We Use Your Information
We process personal data for the following purposes:
Account and Service Delivery
- Creating and managing your restaurant account
- Authenticating logins and maintaining session security
- Delivering the feedback, rewards, and analytics features you have subscribed to
- Sending transactional emails (account setup, password resets, subscription receipts)
Guest Experience
- Linking a guest's phone number to their visit history so rewards accumulate correctly
- Sending reward notifications to guests via SMS or other channels when they earn or can redeem a reward
- Enabling direct messages from the restaurant to guests who have opted in
Billing and Compliance
- Processing subscription payments and issuing GST invoices
- Maintaining payment records for accounting and tax compliance
- Responding to payment disputes or chargebacks
Platform Improvement
- Understanding how features are used in aggregate (non-personalised analytics)
- Diagnosing and fixing bugs
- Developing new features
[LEGAL REVIEW: Map each purpose to a lawful basis under DPDP Act (consent / legitimate use) — currently drafted on the assumption that processing is necessary for contract performance or constitutes a legitimate use under DPDP]
5. Data Retention
- Active account data: retained for the duration of your subscription and deleted within [90 DAYS — CONFIRM] of account closure upon request, except where longer retention is required by law.
- Guest data: retained while the restaurant’s account is active. When a restaurant account is closed, guest data associated with that account is scheduled for deletion within [90 DAYS — CONFIRM].
- Payment records: retained for [7 YEARS — CONFIRM WITH ACCOUNTANT] to comply with GST and accounting obligations, even after account closure.
- Technical logs: retained for up to [90 DAYS] and then deleted automatically.
6. Security
We implement industry-standard technical and organisational security measures, including:
- Passwords stored using bcrypt/argon2 one-way hashing — we cannot retrieve your password
- Data in transit encrypted via TLS/HTTPS
- Database access restricted to application infrastructure only
- Authentication tokens stored server-side and invalidated on logout and password change
No method of internet transmission is completely secure. We cannot guarantee absolute security, and encourage you to use a strong, unique password and to notify us immediately of any suspected breach.
7. Your Rights Under the DPDP Act
Under the Digital Personal Data Protection Act, 2023, you have the following rights in respect of your personal data:
Right to Access
You may request a summary of the personal data we hold about you and the purposes for which it is processed.
Right to Correction and Erasure
You may request correction of inaccurate or incomplete personal data. You may also request erasure of your personal data where we no longer have a legal basis to retain it. Note that erasure requests may be limited where retention is required by law (e.g. payment records for GST compliance).
Right to Grievance Redressal
You have the right to a timely response to any grievance relating to your personal data. See the Grievance Officer details in Section 9 below.
Right to Nominate
You may nominate another individual to exercise your rights in the event of your death or incapacity, as provided under the DPDP Act. [ADD NOMINATION MECHANISM / FORM IF REQUIRED]
Rights of Guests
If you are a guest (end consumer) who submitted feedback at a restaurant, you may request access to or deletion of your data by contacting us with the phone number you used when submitting feedback. We will action your request within [30 DAYS — CONFIRM].
[LEGAL REVIEW: DPDP Act rules on response timelines and exemptions not fully notified as of drafting — review once Rules are published]
8. How to Request Deletion or Exercise Rights
To exercise any of the rights described above, please contact us at:
Email: [SUPPORT / PRIVACY EMAIL — e.g. privacy@saidit.in]
Subject line: Data Request — [your name or phone number]
We will acknowledge your request within [72 HOURS] and complete it within [30 DAYS] (or such period as required by applicable law). We may request identity verification before acting on a request.
9. Children
Said-itt is not directed at individuals under 18 years of age. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected such data, please contact us immediately and we will delete it.
[LEGAL REVIEW: DPDP Act has specific provisions for children's data and parental consent — confirm applicability given guest use case (guests may be under 18)]
10. Grievance Officer
In accordance with applicable law, we have designated a Grievance Officer to address data protection concerns:
Name: [GRIEVANCE OFFICER NAME]
Designation: [TITLE]
Email: [GRIEVANCE EMAIL]
Address: [REGISTERED ADDRESS]
Grievances will be acknowledged within [48 HOURS] and resolved within [30 DAYS].
[LEGAL REVIEW: Confirm Grievance Officer requirement under IT (Intermediary Guidelines) Rules 2021 or DPDP Act Rules when notified]
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify registered subscribers by email at least 7 days before the changes take effect. The “Last updated” date at the top of this page reflects the most recent revision.