Said-itt · Legal

Privacy Policy

Said-itt is committed to protecting the privacy of restaurant owners and their guests. This policy explains what data we collect, why we collect it, and your rights.

Last updated: July 2026

1. Who We Are

[LEGAL ENTITY NAME](“Said-itt”, “we”, “us”, or “our”), registered at [REGISTERED ADDRESS], is the Data Fiduciary within the meaning of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) in respect of data processed through the Said-itt platform.

This policy applies to personal data processed in connection with:

  • Restaurant owner accounts and subscription management
  • Guest interactions with QR code feedback forms
  • Communication features within the platform
  • Our website at said-itt.com

[NOTE FOR LAWYER: Confirm whether Said-itt is a Data Fiduciary or also a Significant Data Fiduciary under DPDP rules once thresholds are notified]

2. Information We Collect

2a. Restaurant Owner / Subscriber Data

When you create an account or use the platform, we collect:

  • Name and email address (used for login and communications)
  • Business name, address, cuisine type, and contact phone number (used to configure your restaurant profile)
  • Password (stored as a one-way cryptographic hash — we cannot read your password)
  • Billing email address and subscription payment history (we receive confirmation of payment from Razorpay; we do not receive or store card numbers, CVV codes, or bank account details)
  • Log-in timestamps and IP addresses
  • Any content you upload, including restaurant descriptions, reward definitions, and profile images

2b. Guest Data

When a guest scans a Said-itt QR code and submits feedback, we collect:

  • Mobile phone number (used to associate subsequent visits with the same guest and to send reward notifications — guests provide this voluntarily)
  • Star rating (1–5) and feedback text (if provided)
  • Date and time of the feedback submission
  • Reward issuances and redemption records (what reward was earned, when it was redeemed)
  • Whether the guest has opted in to receive direct messages from the restaurant

We do not collect guest names, email addresses, or payment information directly. We do not build advertising profiles on guests.

2c. Payment Data

Subscription payments are processed by Razorpay Software Private Limited, a licensed payment aggregator. Said-itt receives confirmation of successful payment (amount, date, transaction reference) but does notstore card numbers, CVV codes, UPI handles, or net banking credentials. Razorpay’s data practices are governed by Razorpay’s Privacy Policy.

2d. Technical and Usage Data

We automatically collect limited technical data when you use the platform:

  • Browser type and operating system
  • IP address and approximate location (country/city level)
  • Pages visited within the dashboard and time spent
  • Error logs for debugging

We use this data only to operate, maintain, and improve the service.

3. How We Use Your Information

We process personal data for the following purposes:

Account and Service Delivery

  • Creating and managing your restaurant account
  • Authenticating logins and maintaining session security
  • Delivering the feedback, rewards, and analytics features you have subscribed to
  • Sending transactional emails (account setup, password resets, subscription receipts)

Guest Experience

  • Linking a guest's phone number to their visit history so rewards accumulate correctly
  • Sending reward notifications to guests via SMS or other channels when they earn or can redeem a reward
  • Enabling direct messages from the restaurant to guests who have opted in

Billing and Compliance

  • Processing subscription payments and issuing GST invoices
  • Maintaining payment records for accounting and tax compliance
  • Responding to payment disputes or chargebacks

Platform Improvement

  • Understanding how features are used in aggregate (non-personalised analytics)
  • Diagnosing and fixing bugs
  • Developing new features

[LEGAL REVIEW: Map each purpose to a lawful basis under DPDP Act (consent / legitimate use) — currently drafted on the assumption that processing is necessary for contract performance or constitutes a legitimate use under DPDP]

4. How We Share Information

Restaurants see their own guests’ data

This is core to the service. Restaurant owners and their authorised staff can view, through the Said-itt dashboard, the following data for guests who gave feedback at their establishment:

  • Guest phone number
  • Feedback text and star rating
  • Visit count and reward history
  • Opt-in status for direct messaging

By submitting feedback through a Said-itt QR code, guests acknowledge that this information is shared with the restaurant. This is disclosed on the feedback form. [CONFIRM DISCLOSURE IS CLEARLY SHOWN ON FEEDBACK FORM]

Service providers

We share data with third-party providers only as necessary to operate the service:

  • Razorpay (payment processing)
  • Resend (transactional email delivery)
  • Cloud hosting and database infrastructure provider(s) — servers located in India
  • [LIST OTHER SUB-PROCESSORS: SMS gateway, CDN, error monitoring, etc.]

We require all processors to maintain appropriate security standards and to use data only for the purposes we direct.

Legal obligations

We may disclose data if required to do so by law, court order, or a lawful request from a government authority.

Business transfers

In the event of a merger, acquisition, or sale of substantially all our assets, personal data may be transferred to the successor entity, subject to the same commitments in this policy.

We do not sell your data

We do not sell, rent, or trade personal data — of restaurant owners or of guests — to any third party for marketing, advertising, or any other purpose.

5. Data Retention

  • Active account data: retained for the duration of your subscription and deleted within [90 DAYS — CONFIRM] of account closure upon request, except where longer retention is required by law.
  • Guest data: retained while the restaurant’s account is active. When a restaurant account is closed, guest data associated with that account is scheduled for deletion within [90 DAYS — CONFIRM].
  • Payment records: retained for [7 YEARS — CONFIRM WITH ACCOUNTANT] to comply with GST and accounting obligations, even after account closure.
  • Technical logs: retained for up to [90 DAYS] and then deleted automatically.

6. Security

We implement industry-standard technical and organisational security measures, including:

  • Passwords stored using bcrypt/argon2 one-way hashing — we cannot retrieve your password
  • Data in transit encrypted via TLS/HTTPS
  • Database access restricted to application infrastructure only
  • Authentication tokens stored server-side and invalidated on logout and password change

No method of internet transmission is completely secure. We cannot guarantee absolute security, and encourage you to use a strong, unique password and to notify us immediately of any suspected breach.

7. Your Rights Under the DPDP Act

Under the Digital Personal Data Protection Act, 2023, you have the following rights in respect of your personal data:

Right to Access

You may request a summary of the personal data we hold about you and the purposes for which it is processed.

Right to Correction and Erasure

You may request correction of inaccurate or incomplete personal data. You may also request erasure of your personal data where we no longer have a legal basis to retain it. Note that erasure requests may be limited where retention is required by law (e.g. payment records for GST compliance).

Right to Grievance Redressal

You have the right to a timely response to any grievance relating to your personal data. See the Grievance Officer details in Section 9 below.

Right to Nominate

You may nominate another individual to exercise your rights in the event of your death or incapacity, as provided under the DPDP Act. [ADD NOMINATION MECHANISM / FORM IF REQUIRED]

Rights of Guests

If you are a guest (end consumer) who submitted feedback at a restaurant, you may request access to or deletion of your data by contacting us with the phone number you used when submitting feedback. We will action your request within [30 DAYS — CONFIRM].

[LEGAL REVIEW: DPDP Act rules on response timelines and exemptions not fully notified as of drafting — review once Rules are published]

8. How to Request Deletion or Exercise Rights

To exercise any of the rights described above, please contact us at:

Email: [SUPPORT / PRIVACY EMAIL — e.g. privacy@saidit.in]
Subject line: Data Request — [your name or phone number]

We will acknowledge your request within [72 HOURS] and complete it within [30 DAYS] (or such period as required by applicable law). We may request identity verification before acting on a request.

9. Children

Said-itt is not directed at individuals under 18 years of age. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected such data, please contact us immediately and we will delete it.

[LEGAL REVIEW: DPDP Act has specific provisions for children's data and parental consent — confirm applicability given guest use case (guests may be under 18)]

10. Grievance Officer

In accordance with applicable law, we have designated a Grievance Officer to address data protection concerns:

Name: [GRIEVANCE OFFICER NAME]
Designation: [TITLE]
Email: [GRIEVANCE EMAIL]
Address: [REGISTERED ADDRESS]

Grievances will be acknowledged within [48 HOURS] and resolved within [30 DAYS].

[LEGAL REVIEW: Confirm Grievance Officer requirement under IT (Intermediary Guidelines) Rules 2021 or DPDP Act Rules when notified]

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify registered subscribers by email at least 7 days before the changes take effect. The “Last updated” date at the top of this page reflects the most recent revision.