Legal
Privacy policy
How Cognoro Technologies handles data on QRDinesOS. Last updated 20 August 2026.
QRDinesOS is restaurant operating software developed and published by Cognoro Technologies, headquartered in Chandigarh, India. This policy sets out how we collect, process, protect, and manage personal data in strict compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act, India), the Information Technology Act, 2000, and the Consumer Protection (E-Commerce) Rules, 2020.
1. Statutory Roles: Data Fiduciary vs. Data Processor
Under the DPDP Act 2023:
- Restaurant Owner & Commercial Data: Cognoro Technologies acts as the Data Fiduciary for account identity, subscription billing, and audit information collected from restaurant owners.
- Diner & Guest Data: The individual restaurant is the Data Fiduciary determining the purpose and means of processing personal data for diners (names, contact numbers, order preferences).Cognoro Technologies acts as the Data Processor providing infrastructure, edge hosting, and database persistence on behalf of the restaurant. If a diner reaches out to us regarding their data, we assist by routing the statutory request directly to the relevant restaurant Fiduciary.
2. What Personal Data is Collected
- Restaurant Owners & Staff: Official email, phone number, restaurant physical address, GSTIN, FSSAI license number, salted bcrypt-hashed passwords and staff PINs (plaintext is never stored or logged), and system audit logs.
- Diners (Guests): Optional name and phone number (if provided during digital bill requests or loyalty rewards), vehicle registration number (only when ordering via Drive-in / Kerbside bays to locate the car), and ephemeral device tokens for active session bill tracking.
3. Consent Architecture & Marketing Governance
In accordance with Section 6 of the DPDP Act:
- Purpose Limitation: Guest data provided for dining is used strictly to fulfill order preparation, delivery, and settlement.
- Explicit Marketing Opt-In: Promotional or retention communications are sent only when a diner has provided explicit, affirmative consent (recorded with timestamp and source). Existing customers default to unconsented.
- Anti-Spam Cooldown & Revocation: Marketing contacts strictly observe automated cooldown intervals (14-day anti-spam window), and diners may withdraw consent or opt-out at any time.
4. Protection of Children's Personal Data
In strict compliance with Section 9 of the DPDP Act 2023, QRDinesOS does not track, profile, conduct behavioral monitoring, or serve targeted advertising to minors. No services are knowingly marketed to children under 18 years of age.
5. Storage, Infrastructure & Security Safeguards
In compliance with Section 8(5) of the DPDP Act:
- Hosting: Cloudflare edge runtime and Neon PostgreSQL database hosted in AWS Asia-Pacific (Singapore, ap-southeast-1). All in-transit traffic is secured with TLS 1.2 or higher.
- Encryption: Aggregator credentials and API keys are encrypted at rest using AES-256-GCM. Passwords and staff PINs are irreversibly hashed using bcrypt.
- Tenant Isolation: Data between different restaurants is separated using PostgreSQL Row-Level Security (RLS) policies and tenant isolation proxies.
6. Retention, Statutory Exceptions & CERT-In Logging Mandate
- Active Tenant Accounts: Retained for the duration of the commercial agreement, plus 90 days of rolling disaster-recovery backups.
- Statutory Tax Invoices & Fiscal Bills (CGST Act Section 36): Retained for at least 72 months (6 years) from the due date of furnishing annual returns under the Central Goods and Services Tax (CGST) Act, 2017 and Income Tax Act, 1961. Data Principal erasure requests redact customer PII from invoices while preserving statutory financial records.
- CERT-In 180-Day System Logging Mandate: In accordance with the Cyber Security Directions issued under Section 70B(6) of the Information Technology Act, 2000, system access, API telemetry, and immutable audit logs are securely retained within Indian jurisdictions for a minimum rolling period of 180 consecutive days with synchronized NTP time sources (NPL/NIC).
- Delivery PII: Delivery mobile numbers on completed orders are automatically scrubbed after 90 days.
- OTP Verification Challenges: Verification challenge records are purged after 30 days.
- Vehicle Plates: Kerbside vehicle registration numbers are purged upon bill settlement.
7. Data Principal Rights under DPDP Act 2023 & 2025 DPDP Rules
In accordance with the Digital Personal Data Protection Act, 2023 and the final DPDP Rules, 2025 (with staggered implementation milestones across consent frameworks, Data Protection Board operations, and verifiable parental consent):
- Right to Access & Information (Section 11): Right to obtain confirmation of whether data is being processed, a summary of personal data held, and identities of Data Fiduciaries/Processors with whom it has been shared.
- Right to Correction & Erasure (Section 12): Right to correct inaccurate data, complete incomplete data, or permanently erase personal data no longer necessary for the original lawful purpose (subject to statutory retention obligations under Section 36 CGST Act).
- Right of Grievance Redressal (Section 13): Right to have grievances redressed by the Data Fiduciary or Processor within published timelines.
- Right to Nominate (Section 14): Right to designate a nominee who may exercise rights in the event of death or incapacity.
8. Grievance Redressal Officer & Escalation Path
In compliance with Section 8(9) and Section 13 of the DPDP Act 2023, you may contact our designated Grievance Officer:
Designation: Grievance Redressal Officer (Data Protection)
Company: Cognoro Technologies
Address: Chandigarh, India
Email: contact@cognorotechnologies.com
Phone / WhatsApp: +91 91151 13222
Response Turnaround: Within 7 working days of receipt
If a grievance is not resolved satisfactorily through our internal grievance redressal mechanism, the Data Principal has the statutory right to escalate and lodge a complaint with the Data Protection Board of India (DPBI) in accordance with Section 18 of the DPDP Act 2023.
9. Statutory Disclaimer & Policy Changes
Notice: This privacy documentation and our technical compliance tools describe software architecture and operational safeguards. They do not constitute formal legal counsel or regulatory certification. Restaurant operators remain independent Data Fiduciaries responsible for their legal compliance under applicable Indian laws.
Any material updates to data processing practices are published here with a revised timestamp, and active restaurant account owners are notified via their registered email address.