Privacy.
Effective 13 May 2026 · v 1.0
1. What we collect
From you (the operator) when you sign up:
- Email address and display name
- Restaurant name, slug, cuisine, currency, timezone, country
- Optional branch address, phone, and GSTIN
While you operate your restaurant:
- Menu, recipes, ingredients, stock movements
- Order data — what was sold, when, by whom, for how much
- Payment metadata (NOT card numbers — Razorpay handles those)
- Limited operational telemetry — page loads, errors, performance
From your customers, only at their initiative:
- Name and phone number when they place an order on your customer site. Customers do not need to create an account.
2. Why we collect it
To provide the service, to support you when you ask for help, to meet our legal and accounting obligations in India, and to improve the product. We do not sell your data. We do not use your data to train AI models.
3. Where it lives
Your data is stored on Supabase (Postgres) and Vercel (web hosting). Both run on AWS in the Asia-Pacific region (Mumbai primarily; Singapore as failover). Backups are encrypted at rest. We do not move your operational data outside Asia-Pacific without notice.
4. Who can see it
Inside Radius: the operator (you), every team member you invite, and our engineering team for support and incident response. We log access to operator data and review those logs regularly.
Outside Radius: nobody, unless you explicitly tell us to share (e.g. you connect a third-party integration) or unless we are compelled by law in India.
5. Your rights
You can export everything as JSON or CSV at any time from /app/settings/export. You can delete your account from the same settings area; a deletion request triggers permanent erasure after a 90-day grace window (we keep tax records as required by Indian law). Customers of your restaurant can request deletion of their phone number / order history by emailing you; you are responsible for honouring those requests in Radius.
6. Cookies
We use first-party cookies for authentication and tenant switching. We do not use third-party advertising cookies. The operator dashboard uses PostHog for product analytics; that cookie is first-party and respects the "Do not track" browser signal.
7. Security
Passwords are hashed by Supabase Auth. Tenant data is isolated at the database level using Row-Level Security policies. We rotate keys on at least an annual basis and run audit checks at /health.
8. Contact
Email privacy@radius.example for any data-protection request. We aim to respond within 7 working days.