Privacy Policy
This Privacy Policy describes our practices concerning the collection, storage, processing, and protection of information across the Oylaa platform.
1.Introduction
Oylaa ("we," "our," or "us") provides a cloud-native restaurant management operating system. We respect the privacy of our subscribers, their staff members, and their dining patrons.
This policy details how data is handled across our public site (oylaa.com), the application portal (restro.oylaa.com), and restaurant tenant instances.
2.Information We Collect
We collect information strictly necessary to provision, maintain, and secure restaurant management services:
- Subscriber Account Details: Restaurant business name, authorized contact person, business email, and verified phone number.
- Operational Records: Menu catalog items, inventory stock levels, pricing recipes, floor layouts, and seating assignments.
- Transaction Logs: Order identification, timestamp, items ordered, order amounts, and payment settlement tokens.
- Staff Credentials: Names, employee roles, PINs, and audit logs for cashier till opening and day-close reports.
3.How We Use Information
The information collected is used solely to:
- Operate real-time POS billing, table dispatch, and kitchen order ticket (KOT) printing.
- Synchronize digital QR menus and guest table orders.
- Generate sales trajectory analytics, item margin calculations, and inventory replenishment alerts.
- Deliver transactional notifications (e.g., e-bills, order receipts) to patrons when requested by the restaurant.
4.Multi-Tenant Data Isolation
Oylaa is architected with strict multi-tenant database partitions. Your restaurant data is logically isolated and secured so that no other subscriber or external entity can view, query, or access your venue's proprietary business metrics.
5.Digital Payment Processing
Oylaa interfaces with compliant digital payment infrastructure (including UPI, BharatQR, and RBI-authorized payment aggregators). Oylaa does not store raw credit card numbers or banking passwords on our servers. All financial transactions are tokenized and processed over encrypted protocols.
6.Data Retention & Deletion
We retain your restaurant operational records for the duration of your active subscription and as required by standard accounting and tax compliance laws.
Restaurant owners and staff members may permanently delete their accounts and associated records at any time from within our mobile applications or via our dedicated Account Deletion Portal (/delete-account).
When an account is deleted, Oylaa enforces a strict minimal data retention standard: we store only your email ID in our suppression registry to track deletion status and protect future re-registrations (which require contacting platform management for unblocking). All menus, floor plans, orders, credentials, and staff records are permanently purged.
7.Security Safeguards
We employ modern security safeguards, including TLS 1.3 encryption in transit, AES-256 encryption at rest, regular security patching, role-based access control, and automated daily cloud snapshots.
8.Your Rights & Access
Restaurant operators maintain the right to inspect, correct, export, or restrict the processing of their operational data at any time via the Oylaa administrative console.
9.Policy Updates
We may update this Privacy Policy from time to time to reflect operational, regulatory, or technical improvements. Updated versions will be published on this page with an updated revision date.
10.Contact Us
If you have questions regarding our privacy practices or security infrastructure, please contact us via our Contact Form or directly via email at [email protected].