DockShalaDockShala
HomeWhatsApp

Legal

Privacy Policy

Effective 1 August 2026 · Last updated 7 August 2026

This Privacy Policy explains how DockShala (“we”, “us”) collects, uses, stores, and shares information when you use our website, digital menus, ordering features, admin panel, and related services (the “Service”) at dockshala.com and restaurant subdomains. We respect your privacy and aim to be clear about what we do with data.

1Scope — who this covers

  • Restaurant owners / admins — people who manage a restaurant account.
  • Staff users — employees given login access (e.g. orders board / POS-style tools).
  • Diners / guests — people who open a QR menu, browse items, or place table orders.
  • Website visitors — people browsing our marketing site or demo.
  • Prospects — people who contact us on WhatsApp or other channels about DockShala.

Restaurants using DockShala are independent businesses. For much of the data diners provide while ordering at a specific restaurant, that restaurant is a controller of the guest relationship; DockShala processes data to run the Platform. Where roles differ under law, this Policy describes our practices as platform operator.

2Information we collect

2.1 Information you provide

  • Account & business data: name, email, phone/WhatsApp, restaurant name, address (if provided), slug/subdomain, branding, menu content, prices, images, table labels, staff emails, settings.
  • Authentication data: login credentials (passwords are stored hashed; we do not store plain-text passwords).
  • Operational data: orders, order items, notes, payment mode selections (e.g. cash/UPI as recorded by staff), discounts, settlement status, inventory movements, supplier/purchase records where used.
  • Support communications: messages you send us via WhatsApp, email, or forms.
  • Diner session inputs: table token/session identifiers, cart contents, order notes, and any optional details the restaurant’s flow collects for fulfilling an order.

2.2 Information collected automatically

  • Device & log data: IP address, browser type, device type, pages viewed, approximate timestamps, referrer, and error logs.
  • Cookies & similar tech: session cookies (e.g. httpOnly auth cookies for admin/staff/diner sessions), preference storage, and similar technologies needed for login, security, and core functionality.
  • Usage analytics: aggregated product usage signals (e.g. feature access patterns) to improve reliability and UX, where implemented.

2.3 Information we do not intentionally collect

  • We do not require diners to create a DockShala account to view a public menu.
  • We do not sell personal data.
  • We do not knowingly collect data from children for marketing; restaurant menus may be viewed by all ages, but admin accounts are for adults (18+).

3How we use information

PurposeExamples
Provide the ServiceHost menus, process orders, show kitchen boards, run inventory, generate QR links, authenticate users
Onboard & supportSet up restaurants, answer WhatsApp queries, troubleshoot issues, reset access (via authorised channels)
Security & abuse preventionSession management, rate limiting, detecting fraud or unauthorised access, backups
Improve the productFix bugs, performance, UX, reliability of multi-tenant platform
Legal & commercialInvoices/records of service, enforce Terms, comply with lawful requests
CommunicationsService notices, setup updates, optional product updates you may opt out of where non-essential

4Legal bases (where applicable)

Depending on applicable law, we rely on one or more of:

  • Contract — to provide the Service you requested;
  • Legitimate interests — platform security, improvement, and multi-tenant operations, balanced against your rights;
  • Consent — where required (e.g. certain cookies or marketing);
  • Legal obligation — where we must retain or disclose information by law.

5How we share information

We may share data only as needed:

  • With your restaurant users: staff/admins see operational data for their own restaurant (orders, menu, inventory) as permitted by role.
  • Service providers: hosting, database, file/image storage, analytics, or messaging infrastructure that process data on our instructions (e.g. cloud providers). They are not permitted to use your data for their own unrelated marketing.
  • Business transfers: if we merge, raise investment, or transfer assets, data may move under appropriate safeguards.
  • Legal: if required by law, court order, or to protect rights, safety, and security.
  • With your direction: integrations or exports you request.

We do not sell personal information to data brokers. We do not share one restaurant’s private operational data with another restaurant.

6Multi-tenant isolation

DockShala is multi-tenant: many restaurants run on one platform. We design data access so each restaurant’s admin/staff only see their own restaurant’s records. Operator/super-admin tools exist for onboarding and support and are restricted to authorised operators.

7Cookies and sessions

  • Essential cookies/sessions: keep you logged in (admin/staff), maintain diner order session continuity, and protect against common web threats.
  • Preferences: may remember UI choices (e.g. theme or device printer pairing keys stored locally in the browser for features like Bluetooth printing).
  • You can block cookies in browser settings; some features (especially login and ordering) may stop working correctly.

8Data retention

  • Active accounts: retained while your restaurant uses the Service.
  • Orders & operational history: retained for business continuity, reporting, dispute handling, and legal/accounting needs for a reasonable period (typically aligned with your subscription and applicable retention norms; may be longer if required by law).
  • After account closure: we disable access and may delete or anonymise data within a reasonable period, subject to backups, legal holds, and unpaid-fee or fraud investigations.
  • Support chats: retained as needed to assist you and improve support quality.

9Security

We use industry-reasonable measures such as encrypted transport (HTTPS), hashed passwords, scoped sessions, and server-side access controls. No method of transmission or storage is 100% secure. You must protect your admin/staff passwords and devices. Notify us promptly if you suspect unauthorised access.

10International processing

Infrastructure may be hosted in India and/or other countries via cloud providers. By using the Service, you understand data may be processed in locations where our providers operate, with appropriate contractual and technical safeguards where required.

11Your rights and choices

Subject to applicable law, you may have rights to:

  • Access personal data we hold about you;
  • Correct inaccurate data;
  • Request deletion (subject to legal/operational exceptions);
  • Object to or restrict certain processing;
  • Withdraw consent where processing is consent-based;
  • Lodge a complaint with a relevant data protection authority.

Restaurant admins can update much of their business and menu data directly in the admin panel. For account-level or deletion requests, contact us on WhatsApp +91 78078 73718 or email support@dockshala.com. We may need to verify identity before acting.

Diners: for issues about a specific order or in-store experience, contact the restaurant first. For platform technical privacy questions, contact DockShala.

12Restaurant responsibilities

If you are a restaurant using DockShala, you must: (a) only collect guest data you need; (b) be transparent to diners where law requires (e.g. CCTV or loyalty programs outside our Service); (c) not misuse staff or diner data; and (d) configure staff access carefully. You are responsible for content you publish on your menu.

13Third-party links and devices

Menus or our site may link to third-party sites (maps, social profiles, payment UPI apps opened by the user). Their privacy practices are their own. Optional browser features (e.g. Web Bluetooth for local printers) process data on your device/browser under those APIs’ rules.

14Children’s privacy

The Service is directed at restaurants and adult operators. We do not knowingly create admin accounts for children under 18. If you believe a child provided personal data inappropriately, contact us and we will take reasonable steps to delete it.

15Changes to this Policy

We may update this Privacy Policy from time to time. The “Last updated” date will change, and material changes may be communicated via the website, admin notice, or WhatsApp where appropriate. Continued use after changes means you acknowledge the updated Policy.

16Contact

Privacy questions or requests:

WhatsApp
+91 78078 73718
Email
support@dockshala.com
Website
dockshala.com

© 2026 DockShala. All rights reserved. This Privacy Policy is a practical template for the DockShala platform and is not legal advice. Consult counsel for formal compliance (including DPDP Act, 2023 obligations) as needed.

Terms and ConditionsRefund Policy