Privacy Policy
How Peppar collects, uses, shares, and retains personal information.
Last updated: 28 August 2026 · Version: 2026-08-28
1. Who we are
This policy is issued by Peppar Enterprises, operating the Peppar restaurant platform ("Peppar", "we", "us"). Udyam registration: UDYAM-KR-03-0746307. We do not currently publish a registered office; privacy requests should use the email and phone in Section 15.
This policy covers peppar.in, the partner portal, staff console, guest ordering experiences, Print Agent / Merchant App connections to our servers, and related services. It is intended to meet transparency expectations under the Information Technology Act, 2000 and to align with the Digital Personal Data Protection Act, 2023 and related rules (phased implementation).
Peppar is software for restaurants. We do not operate restaurants or sell food. How a restaurant uses guest information in its outlet (for example printing a name on a KOT or calling a diner) is that restaurant's responsibility.
2. Roles: restaurant vs Peppar
- Restaurant partners — Peppar is typically the data fiduciary for your Peppar account, subscription billing, and platform support records.
- Guests and diner data — When we process names, phones, orders, or reservations so a restaurant can serve customers, that Restaurant is typically the data fiduciary (controller) and Peppar is a processor acting on the Restaurant's instructions. The Restaurant must tell guests how it uses their data and obtain consent where required (especially marketing, loyalty, and non-essential cookies). Peppar is not responsible for the Restaurant's privacy notices, marketing, or misuse of guest data.
- Website visitors and demo leads — Peppar is the fiduciary for forms you submit on peppar.in.
For restaurant-uploaded content and guest reviews, Peppar may act as an intermediary under the Information Technology Act, 2000.
3. Information we collect
Restaurant partners and staff
- Name, email, mobile number, restaurant name, city, country, URL slug
- Role assignments, credentials, and device/session logs
- GSTIN and billing details if you enter them; Razorpay subscription and invoice records
- Support communications and audit logs (including legal-acceptance records)
- Optional: logos, photos, menu files, and AI menu-digitisation uploads
Guests and end customers
- Name, email, or phone when ordering, reserving, joining a queue, or creating an account
- Name, email, and profile identifier if you sign in with Google or Facebook
- Order, payment status (not full card numbers — gateways tokenise cards), table, and feedback
- Loyalty / rewards activity if the restaurant enables it
- Technical data: IP address, browser type, device identifiers, and session cookies
Automatically collected
- Server logs, security events, and basic analytics (including Google Tag Manager if enabled)
- Approximate location derived from IP for fraud prevention and localisation
We do not ask for Aadhaar as a condition of using Peppar.
Order contents (what you ate) are processed so the Restaurant can fulfil the order. Peppar does not use that information to sell you food in its own name.
4. How we use information
- Provide, operate, secure, and improve the Platform
- Process orders, reservations, queue tokens, notifications, and support on behalf of the Restaurant
- Authenticate users (password, OTP, social login) and prevent fraud or abuse
- Bill subscriptions (Razorpay) and enable guest online pay (PayU or other gateways)
- Send transactional email/SMS/WhatsApp (order updates, OTPs, password resets)
- Send Peppar's own marketing only where we have a lawful basis (separate from placing a food order)
- Comply with law, tax, GST invoicing retention, and dispute resolution
- Record partner acceptance of Terms and this Privacy Policy (user, restaurant, version, time, IP)
Restaurant-initiated campaigns (SMS, WhatsApp, email) are sent for that Restaurant. The Restaurant is responsible for consent, TRAI/DLT compliance, and content of those messages.
5. Lawful basis and consent (DPDP)
We process personal data with consent and/or for uses permitted by law (for example fulfilling a contract to provide the Platform, or complying with tax obligations). Consent for restaurant onboarding is captured as a distinct tick-box and stored with the document version. Marketing and loyalty must not be bundled as a condition of placing a food order. You may withdraw consent where processing is consent-based; we will stop that processing within a reasonable period, subject to legal retention.
6. Sharing of information
We do not sell personal information. We may share data with:
- The restaurant a guest is ordering from or dining at (order, table, and contact details needed to fulfil). Once shared, that restaurant controls how it uses the data in its operations, subject to law.
- Infrastructure and messaging providers under contract: Amazon Web Services (hosting, S3, email/SMS where used), Razorpay (SaaS billing), PayU or similar (guest payments), MSG91 or similar (SMS/WhatsApp), Google and Meta (if you use social login), analytics/tag managers
- Professional advisers and authorities when required by law or to protect rights and safety
Payment card data is handled by the payment gateway PCI environment; Peppar does not store full card numbers. Settlement of guest food payments is between the Restaurant and the gateway.
7. Cookies and analytics
We use cookies and similar technologies for login sessions, security, preferences, and analytics (including Google Tag Manager / related tags when configured). You can control cookies in your browser; some features will not work without session cookies. Restaurant guest pages may set additional cookies needed to keep a cart or table session.
8. Retention
- Partner accounts and restaurant configuration — while the account is active, then a reasonable wind-down
- GST invoices, subscription tax records, and similar — as required by Indian tax law (often 6+ years)
- Guest orders — as needed for the restaurant to operate, handle disputes, and meet tax rules
- Legal consent records — for the life of the account and as needed to evidence the contract
- Server logs — typically a shorter operational period unless needed for security investigations
When a purpose is complete and law does not require keeping the data, we delete or anonymise it. The Restaurant may have its own retention duties for GST and food-business records; Peppar's deletion of platform data does not complete those duties for the Restaurant.
9. Security
We use encryption in transit (HTTPS), access controls, and cloud hosting safeguards. No method of transmission is 100% secure. Restaurants must use strong passwords, limit staff permissions, and protect devices that run POS or Print Agent software. Peppar is not responsible for unauthorised access caused by the Restaurant's staff, shared logins, or unsecured outlet devices. Notify us promptly of suspected unauthorised access to Peppar systems.
10. Your rights
Depending on applicable law, you may request access, correction, erasure, or a copy of personal data we hold, and you may withdraw consent for consent-based processing. Guest requests that concern a restaurant's own use of diner data should be made to that restaurant as well; we will assist where we process that data for them.
Complaints about food quality, refunds, or service are not privacy requests — contact the restaurant.
11. How to request deletion
Email contact@peppar.in from the email on your account (or include the mobile number you use to sign in). Use the subject Data deletion request and say whether you are a guest or a restaurant partner. We will verify the request and delete or anonymise account data within 30 days, except records we must keep for tax, GST, dispute resolution, or other legal duties.
Deleting a Peppar guest account does not automatically delete copies the Restaurant already printed, exported, or stored outside the Platform.
If you signed in with Facebook, you can also remove Peppar from Facebook Settings → Apps and Websites. That stops future Facebook login; it does not delete data already on Peppar — email us for that.
12. Children
The Platform is not directed at children. We do not knowingly collect personal data from persons under 18. If you believe we have, contact us and we will delete it except where law requires otherwise. Age-restricted items (for example alcohol) are the Restaurant's responsibility.
13. International processing
We currently operate for restaurants in India. Infrastructure may process data in regions where our cloud and subprocessors host servers. We take contractual and technical steps appropriate to those transfers.
14. Third-party sites
Linked sites, payment gateways, social networks, and restaurant-owned channels have their own privacy practices. Peppar is not responsible for them.
15. Grievance and contact
Until a registered office is published, the contact for privacy and IT Act grievances is:
Peppar Enterprises
Email: contact@peppar.in
Phone: +91 733-7876270
We will acknowledge privacy complaints and respond within a reasonable period required by law. Food and service complaints should be sent to the restaurant concerned.
16. Changes
We may update this policy by posting a new version with a revised date. Material changes will be highlighted on this page. Continued use after the effective date means you acknowledge the updated policy, except where a fresh consent is required.
See also our Terms & Conditions.