Privacy Policy
This Privacy Policy explains how Servoraa collects, uses, stores, shares and protects your personal data when you use our QR-based dine-in ordering platform and related Services.
Last updated: 1 July 2026
1. Who We Are
Servoraa (the “Platform”, “we”, “us”, or “our”) is a QR-based dine-in ordering platform operated as a sole proprietorship from its registered office in Durgapur, West Bengal, India.
For the purposes of the Digital Personal Data Protection Act, 2023 (“DPDP Act”), Servoraa acts as the Data Fiduciary in respect of the personal data described in this Privacy Policy. We determine the purposes and means of processing your personal data and are responsible for handling it in accordance with applicable laws.
Servoraa is committed to collecting, using, storing, and protecting personal data in accordance with the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and other applicable laws of India.
Servoraa is currently developed and managed under the HashHorizon brand. If the business structure changes in the future, including the incorporation of HashHorizon as a legal entity, this Privacy Policy will be updated accordingly.
2. Scope of this Privacy Policy
This Privacy Policy explains how Servoraa collects, uses, stores, shares, protects, and otherwise processes your personal data when you access or use our website, mobile applications (if any), QR-based dine-in ordering platform, and any other products, services, or features that link to or reference this Privacy Policy (collectively, the “Services”).
This Policy applies to all individuals who interact with Servoraa, including restaurant owners and staff using our platform, customers placing dine-in orders, visitors to our website, and any other users of our Services.
By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy and consent to the processing of your personal data where such consent is required under applicable law.
This Privacy Policy does not apply to:
- Information processed by third-party websites, applications, payment gateways, or services that are not owned or controlled by Servoraa, even if they are accessible through our Services.
- Information collected by restaurants independently of Servoraa outside the scope of the Services.
Servoraa processes personal data only for lawful purposes, in accordance with the Digital Personal Data Protection Act, 2023, and other applicable laws of India. We may update this Privacy Policy from time to time to reflect changes in our Services, legal obligations, or business practices. Any material changes will be communicated through appropriate means, and the updated Policy will be made available on our platform with the revised effective date.
3. Key Definitions
For the purposes of this Privacy Policy:
- Personal Data — Any information that can identify you, either directly or when combined with other information.
- Data Principal — The individual whose personal data is being processed. This could be a customer, restaurant staff member, restaurant owner, or website visitor.
- Data Fiduciary — Servoraa, which decides why and how your personal data is collected and processed.
- Processing — Any action performed on personal data, including collecting, recording, storing, using, updating, sharing, or deleting it.
- Consent — Your clear and informed permission allowing us to process your personal data for specific purposes.
- Services — Servoraa’s website, QR-based dine-in ordering platform, and any related products or services covered by this Privacy Policy.
4. Personal Data We Collect
Depending on how you use our Services, we may collect the following categories of personal data:
4.1 Restaurant Partners
If you register or manage a restaurant on Servoraa, we may collect:
- Business information, such as your restaurant name, outlet details, business address, and branding assets.
- Owner and staff details, including names, mobile numbers, email addresses, and user roles.
- Account information, including login credentials, encrypted passwords, staff PINs (stored securely in hashed form), and authentication details.
- Business compliance information that you choose to provide, such as your GSTIN, FSSAI licence number, PAN, or other applicable registrations.
- Payment and settlement information, including your UPI ID, bank account details (where applicable), and payment gateway account identifiers used for payouts.
- Restaurant operations data, including menus, categories, items, pricing, taxes, modifiers, offers, coupons, table and QR code information, operating hours, and order settings.
- Communication records, support requests, feedback, and other information you choose to share with us.
4.2 Diners (Customers)
When a customer places an order through Servoraa, we may collect:
- The customer’s name (if voluntarily provided) and the number of guests at the table.
- Order details, including the restaurant, table number, items ordered, and any special instructions provided with the order.
- Payment information, including the payment method, transaction status, and payment reference. Servoraa does not store card numbers, CVV, UPI PINs, or other payment authentication credentials.
- Ratings, reviews, and feedback voluntarily submitted by the customer.
4.3 Information Collected Automatically
When you use our Services, we may automatically collect certain technical information, including:
- Your IP address, browser type, device type, and operating system.
- Usage information, such as the pages you visit, features you use, access dates and times, and basic interaction with our Services.
- Cookies, session identifiers, and similar technologies that help us keep the Services secure, remember your preferences, and improve your experience.
- Technical logs and diagnostic information used to monitor performance, detect errors, and prevent fraud or misuse.
5. How and Why We Use Personal Data
We process your personal data only for lawful purposes and only to the extent necessary to provide and improve our Services. Specifically, we use your personal data to:
- Provide and operate our Services, including QR-based dine-in ordering, eligible takeaway ordering, order management, billing, and payment processing.
- Route orders to restaurant staff, kitchen systems, and other authorized personnel to ensure accurate and timely order preparation and fulfillment.
- Process payments securely through our payment partners and facilitate direct settlement of payments to restaurants. Servoraa does not hold or store customer funds.
- Send essential service-related communications, including order confirmations, payment updates, OTPs, and other transactional notifications through SMS, WhatsApp, push notifications, or similar channels.
- Provide restaurant partners with operational dashboards, analytics, reports, exports, and AI-powered business insights to help manage and improve their operations.
- Enable customer engagement features such as loyalty programs, menu recommendations, personalized offers, and promotional campaigns on behalf of participating restaurants, only where permitted by applicable law and based on your consent or preferences, where required.
- Verify restaurant information (where authorized by the restaurant), maintain the security and integrity of our Services, detect and prevent fraud, misuse, unauthorized access, and other harmful activities.
- Respond to customer support requests, investigate complaints, troubleshoot technical issues, and improve the performance, reliability, and security of our Services.
- Comply with applicable laws, regulatory requirements, court orders, and lawful requests from government authorities, and protect our legal rights where necessary.
We do not sell your personal data to third parties. Where Servoraa processes personal data to send promotional communications or operate marketing campaigns on behalf of a restaurant, we do so only in accordance with applicable law and the instructions of the respective restaurant. You may withdraw your consent, opt out of promotional communications, or request the deletion of your personal data at any time through the contact methods provided in this Privacy Policy.
We retain personal data only for as long as it is necessary to fulfil the purposes described in this Privacy Policy. Unless a longer retention period is required by applicable law, necessary to resolve disputes, prevent fraud, or protect our legal rights, customer personal data is retained for up to 180 days after the last activity on the account or order. With your consent, we may retain your data for a longer period to provide services such as loyalty programs, personalized experiences, or future orders. Once the applicable retention period expires, we securely delete or anonymize your personal data.
6. Legal Basis for Processing
Servoraa processes personal data only when we have a lawful basis to do so under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and other applicable laws.
6.1 Processing Based on Your Consent
In most cases, we process your personal data based on the consent you provide when using our Services. By submitting your information, placing an order, registering a restaurant, or otherwise interacting with our platform, you consent to the collection and processing of your personal data for the purposes described in this Privacy Policy.
Where required by law, we will seek your separate consent before processing your personal data for specific purposes, such as promotional communications or loyalty programs.
You may withdraw your consent at any time by contacting us through the contact methods provided in this Privacy Policy. Withdrawal of consent will not affect the lawfulness of any processing carried out before your consent was withdrawn. Please note that withdrawing consent for certain processing activities may limit or prevent us from providing some or all of our Services.
6.2 Legitimate Uses Permitted Under the DPDP Act
In certain circumstances, the DPDP Act permits us to process personal data without obtaining separate consent. These situations may include:
- Providing or fulfilling a service that you have requested, such as processing an order or completing a payment.
- Complying with applicable laws, regulations, court orders, or lawful requests from government authorities.
- Protecting the security, integrity, and reliability of our Services, including detecting and preventing fraud, abuse, unauthorized access, or other harmful activities.
- Responding to customer support requests, resolving disputes, and enforcing our legal rights and obligations.
- Any other processing that is expressly permitted under applicable law.
Wherever possible, Servoraa processes only the minimum amount of personal data necessary for the intended purpose and retains it only for as long as required in accordance with this Privacy Policy and applicable law.
7. Diner Identity Protection
Servoraa is designed with privacy by default.
Restaurants and their staff are provided only with the information necessary to prepare and fulfil an order. A diner’s personal contact details, including their mobile number, are never shared with restaurants through the Platform.
Where possible, orders are identified and managed using unique order numbers or internal identifiers instead of personal information. This allows restaurants to serve customers efficiently while protecting their privacy.
If a restaurant wishes to send promotional messages, loyalty rewards, or personalized offers, such communications are managed by Servoraa on the restaurant’s behalf. Customer personal data is not disclosed to the restaurant for these purposes unless required by applicable law or with the customer’s explicit consent.
We implement appropriate technical and organizational safeguards, including encryption, access controls, and secure storage, to protect personal data from unauthorized access, disclosure, alteration, or misuse. Servoraa processes only the minimum personal data necessary to provide its Services and is committed to protecting customer privacy at every stage of the ordering experience.
8. Cookies and Similar Technologies
Servoraa uses cookies and similar technologies to provide, secure, and improve our Services.
These technologies help us:
- Keep you securely signed in and maintain your session.
- Remember your order and other essential preferences while you use the Platform.
- Process payments securely through our payment partners.
- Understand how our Services are used so we can improve performance, reliability, and user experience.
- Detect and prevent fraud, misuse, and other security risks.
Some cookies are essential for the Platform to function and cannot be disabled without affecting core features. Others, such as analytics cookies, help us understand how users interact with our Services and improve them over time.
You can manage or disable cookies through your browser settings. However, disabling essential cookies may prevent certain features of the Platform from working correctly.
9. Payments
Servoraa facilitates secure online payments through Razorpay, our authorized payment gateway. All payment transactions are processed securely by Razorpay in accordance with its security standards, privacy practices, and applicable laws.
Each restaurant partner uses its own Razorpay account to accept online payments. Payments made through Servoraa are processed by Razorpay and are settled directly to the respective restaurant’s designated bank account. Servoraa does not receive, hold, manage, or control customer funds at any stage of the payment process.
Servoraa does not collect, store, or have access to your complete payment credentials, including your card number, CVV, expiry date, net banking credentials, UPI PIN, or any other payment authentication information. These details are handled exclusively by Razorpay through its secure payment infrastructure.
To verify and reconcile transactions, Servoraa receives only limited payment information, such as the transaction status, payment reference, payment method, and other details necessary to confirm the payment, provide our Services, maintain transaction records, and assist with customer support where required.
For more information about how your payment information is processed, please refer to Razorpay’s Privacy Policy and Terms of Service.
10. How We Share Personal Data
Servoraa values your privacy and does not sell, rent, or trade your personal data to any third party.
We share personal data only when necessary to provide our Services or where required by law, including:
- Restaurant Partners: We share only the information necessary for restaurants to prepare, manage, and fulfil your order. Customer contact details, including mobile numbers, are not shared with restaurants through the Platform.
- Service Providers: We may share personal data with trusted third-party service providers who help us operate our Services, such as cloud hosting providers, communication service providers (including SMS and WhatsApp), analytics providers, security providers, and other technology partners. These providers process personal data only on our behalf and under appropriate contractual and security obligations.
- Payment Processing: Payment information necessary to complete a transaction is shared with Razorpay and other authorized payment partners. Servoraa does not store or process sensitive payment credentials.
- Marketing and Loyalty Services: Where a restaurant chooses to run promotional campaigns, loyalty programs, or personalized offers through Servoraa, we deliver these communications on the restaurant’s behalf without disclosing your personal contact information to the restaurant, except where required by applicable law or with your explicit consent.
- Legal and Regulatory Requirements: We may disclose personal data where required by applicable law, court order, regulatory authority, or lawful government request, or where necessary to protect our rights, users, platform security, or prevent fraud and unlawful activities.
- Business Transfers: If Servoraa undergoes a merger, acquisition, restructuring, or sale of assets, personal data may be transferred as part of that transaction, subject to applicable law and appropriate safeguards.
We require all third parties who process personal data on our behalf to implement appropriate security measures and to process personal data only for the purposes authorized by Servoraa and in accordance with applicable law.
11. Data Retention
Servoraa retains personal data only for as long as it is necessary to provide our Services, fulfil the purposes described in this Privacy Policy, comply with applicable laws, resolve disputes, prevent fraud, and protect our legal rights.
Unless a longer retention period is required by law or you have provided your consent for continued use (such as for loyalty programs, personalized experiences, or future orders), customer personal data is retained for up to 180 days after the last activity associated with your order or account.
Certain business records, including invoices, payment records, tax-related information, and other records required under applicable laws, may be retained for longer periods to meet legal, regulatory, accounting, or audit obligations.
Once the applicable retention period expires and the data is no longer required, Servoraa securely deletes or anonymizes the personal data using appropriate technical and organizational measures.
12. Security
Protecting your personal data is a fundamental part of how Servoraa is designed and operated. We implement appropriate technical, organizational, and administrative safeguards to protect personal data against unauthorized access, disclosure, alteration, loss, misuse, or destruction, in accordance with applicable laws and industry-standard security practices.
Our security measures include, where appropriate:
- Encryption of personal data during transmission using secure communication protocols.
- Secure storage of authentication credentials, including passwords and staff PINs, using one-way hashing and other appropriate security measures.
- Role-based access controls to ensure that personal data is accessible only to authorized personnel and systems with a legitimate business need.
- Privacy-by-design features that minimize the sharing of personal data, including preventing restaurants from accessing customers’ personal contact information through the Platform.
- Secure payment processing through Razorpay. Servoraa does not collect, store, or have access to sensitive payment credentials such as card numbers, CVV, expiry dates, net banking credentials, or UPI PINs.
- Continuous monitoring, security logging, and reasonable measures to detect, investigate, and prevent unauthorized access, fraud, misuse, and other security incidents.
While we strive to maintain a secure platform and continuously improve our security practices, no method of transmitting, storing, or processing data over the internet is completely secure. Accordingly, we cannot guarantee absolute security. Users are responsible for maintaining the confidentiality of their account credentials and for notifying us promptly if they believe their account has been compromised.
13. Your Rights as a Data Principal
Under the Digital Personal Data Protection Act, 2023 and other applicable laws, you have the following rights in relation to your personal data:
- Right to Access — Request a summary of the personal data we process about you and information about how it is being used.
- Right to Correction — Request that we correct, update, or complete any inaccurate or incomplete personal data.
- Right to Erasure — Request the deletion of your personal data where it is no longer required or where you withdraw your consent, subject to applicable legal and regulatory requirements.
- Right to Withdraw Consent — Withdraw your consent for the processing of your personal data at any time. This will not affect the lawfulness of any processing carried out before your consent was withdrawn. Please note that withdrawing consent may limit our ability to provide certain Services.
- Right to Nominate — Nominate another individual to exercise your rights under the DPDP Act in the event of your death or incapacity, where applicable.
- Right to Grievance Redressal — Raise any privacy-related concern or complaint with our Grievance Officer. If you are not satisfied with our response, you may approach the appropriate authority under the DPDP Act, including the Data Protection Board of India, where applicable.
To exercise any of these rights, or if you have any questions regarding the processing of your personal data, please contact us using the details provided in Section 18 (Contact Us & Grievance Officer). We will respond to your request within the timelines prescribed under applicable law.
14. Children’s Privacy
Servoraa is intended for use by individuals who are 18 years of age or older. We do not knowingly collect or process the personal data of children without the verifiable consent of a parent or lawful guardian, as required under the Digital Personal Data Protection Act, 2023 and other applicable laws.
If we become aware that we have collected or processed a child’s personal data without the required consent, we will take reasonable steps to delete such data or otherwise comply with our legal obligations as soon as reasonably practicable.
If you believe that a child has provided personal data through our Services without the required consent, or if you have any concerns regarding a child’s privacy, please contact us immediately:
- Privacy & Grievance Support: +91 92423 42799
We will investigate your request promptly and take appropriate action in accordance with applicable law.
15. Cross-Border Transfer of Personal Data
Servoraa primarily stores and processes personal data in India. However, certain trusted third-party service providers that help us operate our Services, such as cloud hosting, analytics, communication, security, or other technology providers, may process personal data in jurisdictions outside India.
Where personal data is transferred outside India, we take reasonable steps to ensure that such transfers are carried out in accordance with the Digital Personal Data Protection Act, 2023 and other applicable laws. We require our service providers to implement appropriate technical, organizational, and contractual safeguards to protect your personal data.
We do not transfer personal data to any country or territory where such transfers are prohibited or restricted under applicable law.
16. Third-Party Services
Our Services may integrate with or provide access to third-party websites, applications, payment providers, communication platforms, analytics services, cloud infrastructure providers, or other technology partners that are not owned or controlled by Servoraa.
When you interact with these third-party services, the collection, use, and protection of your personal data are governed by their respective privacy policies and terms of service. Servoraa is not responsible for the privacy practices, content, or security of third-party services.
We encourage you to review the privacy policies of any third-party service you choose to access or use through our Platform before providing your personal data.
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our Services, technology, business practices, or applicable laws.
When we make changes, we will update the “Last Updated” date at the top of this Privacy Policy. If a change is material or where required by applicable law, we will notify you through appropriate means, such as through the Platform, SMS, WhatsApp, email, or other available communication channels.
Your continued use of our Services after the updated Privacy Policy becomes effective signifies your acknowledgment of the revised Policy. Where applicable law requires your consent for a new or changed purpose of processing, we will obtain your consent before processing your personal data for that purpose.
18. Contact Us & Grievance Officer
If you have any questions, requests, or concerns regarding this Privacy Policy or the processing of your personal data, or if you wish to exercise your rights under the Digital Personal Data Protection Act, 2023, you may contact us using the details below.
- Privacy & Grievance Officer: Servoraa
- Email: product@servoraa.in
- Phone: +91 92423 42799
- Registered Office: Durgapur, West Bengal, India
We will acknowledge and respond to your request or grievance within the timelines prescribed under applicable law and will make reasonable efforts to resolve it promptly. If you are not satisfied with our response, you may seek remedies available under the Digital Personal Data Protection Act, 2023, including approaching the appropriate authority where applicable.
