Privacy Policy
Last Updated: July 26, 2026
ZaykaBill ("we", "our", "us") respects your privacy and is committed to protecting the personal and business information of our users. This Privacy Policy explains how we collect, use, store, and protect information when you use our Restaurant POS Software ("Service", "Platform", "App").
By using ZaykaBill, you agree to the terms of this Privacy Policy.
1Information We Collect
Business & Account Information
- Restaurant name
- Owner or authorized person name
- Mobile number and email address
- GST number (if provided)
- Business address
Operational Data
- Bills and invoices
- Order details (KOT, Token, Direct Bill)
- Sales, reports, and analytics
- Staff and role data
Customer Information Entered by the Restaurant
- Customer name (optional)
- Mobile number (optional)
- Order history linked to customer
ZaykaBill does not independently collect customer data. Any customer data is entered solely by the restaurant.
2How We Use Information
We use the collected information to:
- Provide and operate POS features
- Generate bills, reports, and analytics
- Maintain user accounts
- Provide customer support
- Improve product performance and security
- Comply with legal and regulatory requirements
3Data Storage & Security
- All data is stored on secure servers with industry-standard protections.
- We use reasonable administrative, technical, and physical safeguards to prevent unauthorized access.
- Despite safeguards, no method of transmission over the internet is 100% secure.
4Data Sharing & Disclosure
We do not sell or rent your data.
Data may be shared only:
- When required by law or government authorities
- With trusted service providers (hosting, analytics, payment gateways) strictly for service operation
- To protect our legal rights, users, or platform integrity
5Data Fiduciary and Restaurant Responsibilities
For account, billing, support, and platform security information, Infinion Solutions determines the purposes and means of processing and acts as the Data Fiduciary for that information.
For customer, staff, order, and attendance information entered by a restaurant, the restaurant determines the business purpose and remains responsible for providing notices, obtaining permissions, and responding to data requests. ZaykaBill processes that information to provide the restaurant service on the restaurant's instructions.
- Restaurants must collect and use customer and staff information lawfully and only for legitimate operational purposes.
- Restaurants must not enter sensitive information into fields that do not require it.
- Restaurants remain responsible for their customer-facing notices and retention decisions where they control the purpose of processing.
6Biometric and Fingerprint Attendance
- Fingerprint attendance is an optional restaurant feature and is enabled only by the restaurant account administrator.
- The biometric attendance workflow uses encrypted fingerprint templates and template hashes for matching; it is designed not to retain raw fingerprint images.
- The local SecuGen agent keeps the device-side template cache and offline queue on the registered restaurant machine, while the platform stores the encrypted enrollment and attendance records needed for synchronization.
- The restaurant is responsible for informing employees, obtaining any required consent or authorization, limiting access to authorized administrators, and removing an enrollment when it is no longer needed.
7Third-Party Services
ZaykaBill may integrate with:
- Payment gateways
- Printers and hardware services
- Analytics or error-monitoring tools
These third parties have their own privacy policies. ZaykaBill is not responsible for third-party practices.
8Public Subprocessor List
The following service providers may process limited information when the related product feature is enabled:
- Razorpay: payment checkout, payment processing, and payment verification.
- Google Analytics: consent-based analytics on public pages only.
- Deployment-configured SMTP provider: signup verification, password, and account notification email delivery.
- Sentry: error monitoring only when a Sentry DSN is configured by the deployment.
The enabled provider and processing scope can vary by deployment configuration. We do not publish credentials or secret configuration values in this list.
9Cookies, Local Storage & Consent
Essential Technologies
- We use essential cookies or local storage for secure sign-in, session continuity, CSRF protection, restaurant context, and core site preferences.
- These technologies are required for core account access and product operation.
Analytics on Public Pages
- We use Google Analytics on public-facing pages only after you accept analytics consent.
- Analytics may collect high-level usage information such as pages viewed, approximate location, device or browser details, and referral sources.
Declining analytics consent does not block access to public pages or core product functionality.
Payment and Checkout Technologies
- If you choose to make a payment, Razorpay or other enabled payment providers may use cookies or similar technologies required to complete checkout, fraud checks, and payment verification.
10Data Retention
- Account, configuration, and operational data is retained while the account remains active and while it is needed to provide support, security, reconciliation, or requested exports.
- After account closure or a verified deletion request, deletion or de-identification is scheduled within 90 days unless a longer period is required for tax, accounting, fraud prevention, dispute handling, legal claims, or other legal obligations.
- Biometric enrollments are retained only while the restaurant has enabled the attendance feature and the enrollment is needed; disabled or removed enrollments are scheduled for deletion with the associated account data.
- Backups and legally required records may remain for the period needed to complete the applicable backup rotation or statutory obligation, after which they are deleted or anonymized.
11DPDP Act 2023 and Grievance Officer
We handle personal data in accordance with applicable Indian data-protection requirements, including the Digital Personal Data Protection Act, 2023, as applicable to the Service. We provide reasonable means for users to request access, correction, deletion, or information about processing, subject to verification and legal exceptions.
For privacy requests or grievances, contact the Grievance Officer through support@zaykabill.com. Please include the account or restaurant details needed to verify the request. We aim to acknowledge requests promptly and respond within the period required by applicable law.
12Company and Legal Information
- Legal entity: Infinion Solutions
- GSTIN: 09BEWPJ9978R1ZP
- Registered office: Dudhi, Sonbhadra, Uttar Pradesh, India
- Privacy and grievance contact: support@zaykabill.com
13User Responsibilities
- You are responsible for the accuracy of business and customer data entered.
- You must obtain necessary consent from customers before storing their personal information.
- ZaykaBill is not liable for misuse of customer data by the restaurant.
14Children's Privacy
- ZaykaBill is not intended for individuals under 18 years of age.
- We do not knowingly collect data from minors.
15Your Rights
You may:
- Request access to your data
- Request correction of incorrect information
- Request account deletion (subject to legal requirements)
- Ask questions about analytics consent or payment-related privacy handling
Requests can be sent to support@zaykabill.com.
16Changes to This Privacy Policy
- We may update this Privacy Policy from time to time.
- Updates will be posted on our website.
- Continued use of the Service constitutes acceptance of the updated policy.
17Governing Law
This Privacy Policy is governed by the laws of India, with jurisdiction in Sonbhadra, Uttar Pradesh.
18Contact Us
For any privacy-related questions or concerns:
- Email: support@zaykabill.com
- Website: https://zaykabill.com