This Privacy Policy explains how CRYZO (“we”, “us”) handles personal information when you visit this website or use the CRYZO restaurant POS system — including the web app, the Android POS app, restaurant online ordering pages, QR menus and the WhatsApp ordering bot (together, the “Services”). Please read it together with our Terms & Conditions.
01Who we are and our role
CRYZO provides point-of-sale, billing and restaurant management software to restaurants, cafes and other food businesses (“Restaurants”).
- When we decide why and how data is used — for example, information about Restaurant owners and their user accounts, or messages you send us — we act as the Data Fiduciary (controller) for that information.
- When a Restaurant uses CRYZO to record information about its own customers and staff — such as customer phone numbers, online orders or employee records — we process that information on the Restaurant’s behalf as its Data Processor. The Restaurant is responsible for informing those people and, where needed, obtaining their consent. If you are a customer of a Restaurant, please contact that Restaurant first about your data; we will help them respond.
02Information we collect
Restaurant accounts
- Name, email address and phone number of account users, and their role and permissions.
- Passwords — stored only in hashed form, never in plain text.
- Business details entered in settings, such as restaurant name, address, phone, email, GST number, logo, taxes, opening hours and receipt text.
Data Restaurants enter while using the Services
- Menus, tables, orders, kitchen order tickets (KOTs), invoices and reports.
- Payment records — the payment mode (for example cash, card or UPI) and amount. CRYZO does not collect or store card numbers or bank account details.
- Stock and purchase records, including supplier details the Restaurant chooses to enter.
- Employee records — such as name, phone, email, position and salary — if the Restaurant uses the Employees module.
- Customer records — such as name, phone number, email, address, visit count, amount spent, loyalty points and notes.
Customers ordering online or on WhatsApp
- Name, phone number, email (optional), saved delivery addresses and order history on a Restaurant’s online ordering page.
- One-time password (OTP) verification records, such as the phone number and the time the code was sent and verified.
- For the WhatsApp ordering bot: your WhatsApp phone number, the messages you send to the bot, your cart and order details, and technical delivery logs from the messaging provider.
Technical and security information
- Server logs that may include IP address, browser or device information, and request times.
- Audit logs of actions taken inside a Restaurant’s account (for example which user changed a menu item or cancelled an order).
- A login token and basic profile saved in your browser’s session/local storage so you stay signed in. The Services do not use advertising or tracking cookies.
Information you send us
- Details you share when you request a demo or contact support by WhatsApp, email or phone — such as your name, phone, email, restaurant name, city and number of outlets.
- When you submit the demo form on this website, your details are sent to our team by email. They are not saved in the CRYZO product database. If sending fails, the form lets you send the same details to us by WhatsApp or email instead.
03How we use information
- To provide the Services: sign-in, billing, orders, KOTs, kitchen display, invoices, reports, stock, printing and online ordering.
- To verify phone numbers with OTPs and to send order-related messages when a Restaurant enables WhatsApp.
- To manage subscriptions, respond to demo and support requests, and send important service notices.
- To keep the Services secure — for example limiting repeated login attempts, investigating misuse and keeping audit trails.
- To maintain and improve the Services using aggregated or de-identified information.
- To comply with legal obligations and enforce our Terms.
We do not use personal information for third-party advertising, and we do not sell personal information.
05How we protect information
- Passwords are hashed, and access inside each account is controlled by roles and permissions.
- Each Restaurant’s operational data is kept in its own separate database.
- Login attempts are rate-limited, security headers are applied, and important actions are recorded in audit logs.
- We use encrypted (HTTPS) connections for the hosted Services.
No system is completely secure. Please keep your password private, give staff only the permissions they need, and tell us immediately if you suspect unauthorised access.
06How long we keep information
We keep account and operational data while a Restaurant’s account is active and for as long as needed to provide the Services. When an account is closed, we delete or anonymise its data within a reasonable period, unless we must keep some records longer to meet legal, tax, accounting or dispute-resolution requirements. OTP and technical logs are kept only for as long as they are useful for security and troubleshooting.
Restaurants can download reports and menu data before closing their account.
07Your rights and choices
Subject to applicable law, including India’s Digital Personal Data Protection Act, 2023, you may:
- ask for a summary of the personal information we process about you;
- ask us to correct, complete or update it;
- ask us to erase it where it is no longer needed or you withdraw consent (withdrawal does not affect processing already done);
- nominate another person to exercise your rights in the event of death or incapacity; and
- raise a grievance with us, and if unresolved, with the Data Protection Board of India.
To make a request, contact us using the details below. We may need to verify your identity. If your data was entered by a Restaurant, we may forward your request to that Restaurant.
08Children
The Services are meant for businesses and are not directed at children. We do not knowingly collect personal information from anyone under 18 years of age. If you believe a child has provided us personal information, please contact us and we will delete it.
09Third-party links and services
The Services may link to or work with third-party websites and services, such as WhatsApp or payment apps a customer chooses to use. Their handling of your information is governed by their own policies, not this one.
10Changes to this Policy
We may update this Policy from time to time. We will change the “Last updated” date above and, for significant changes, notify account owners by email or inside the app before the changes take effect.
11Grievance Officer and contact
For questions, requests or complaints about this Policy or your personal information, contact our Grievance Officer. We will acknowledge and respond within the time required by applicable law.
- Email: info@cryzent.in
- Phone: +91 8169612293