Last updated: 10 August 2026
Privacy Policy
This Privacy Policy explains how Crution Pvt Ltd (“Crution”, “we”, “us”, or “our”) collects, uses, shares, and protects personal information when you use CrutionResto (the “Service”), including our marketing site, staff dashboard, APIs, and guest QR ordering experiences.
Restaurants that use CrutionResto are typically the “data controllers” of their guest and staff data. Crution processes that data on their instructions as a service provider / processor, except where we act as a controller (for example, our own billing, marketing leads, and account administration).
1. Information we collect
1.1 Account and restaurant information
- Owner and staff names, email addresses, phone numbers, and login credentials
- Restaurant and branch details (name, address, GSTIN, branding, settings)
- Roles, permissions, and activity needed to operate the workspace
1.2 Operational and guest data (processed for your restaurant)
- Menus, orders, payments recorded in the Service, invoices, and kitchen / delivery status
- Guest details you or your guests provide (for example name, phone, table notes, reviews, loyalty)
- CRM leads, campaigns, feedback, and related engagement records
- Inventory, attendance, and other back-office records you enter
1.3 Marketing and support
- Contact-form submissions and sales leads
- Support emails and correspondence
1.4 Technical data
- IP address, browser type, device information, and approximate location derived from IP
- Logs needed for security, debugging, and reliability
- Cookies and similar technologies (see below)
2. How we use information
- Provide, secure, and improve the Service
- Create and administer accounts, subscriptions, and billing
- Process orders, invoices, kitchen workflows, and reports you configure
- Send transactional messages (verification codes, password resets, billing notices)
- Respond to support and sales enquiries
- Detect abuse, prevent fraud, and comply with law
- Where permitted, send product updates or marketing (you may opt out of non-essential marketing)
3. Legal bases (where applicable)
Depending on your location and role, we rely on one or more of: performance of a contract; legitimate interests (securing and improving the Service); consent (where required); and legal obligation.
4. Sharing
We do not sell personal information. We may share information with:
- Sub-processors that help us run the Service (hosting, email, payment gateways such as Razorpay where configured, analytics limited to operating the product)
- Your authorised staff and integrations (for example aggregators or printers you connect)
- Professional advisers and authorities when required by law or to protect rights and safety
- Successors in a merger, acquisition, or asset transfer, under appropriate safeguards
Payment card data, where collected by a payment provider, is handled by that provider under their terms. We do not store full card numbers on our servers.
5. Guest QR ordering
When a guest scans a table QR code, the restaurant’s branded menu is shown. Cart and favourites for that visit may be stored in a session associated with the table token. Optional guest name, notes, and reviews are stored for the restaurant’s operations and CRM. Guests should contact the restaurant for most requests about their order data; we will assist restaurants in fulfilling lawful requests.
6. Cookies and sessions
We use essential cookies and server sessions for sign-in, security (including CSRF protection), theme preference, and guest cart state. These are required for the Service to function. We do not use third-party advertising cookies on the core product screens.
7. Retention
We retain personal information for as long as needed to provide the Service, meet legal and accounting requirements, and resolve disputes.
For restaurants, we support data-retention controls: stale customer and lead personal identifiers may be anonymised after a configurable retention window (default 24 months of inactivity / closure, unless disabled or set otherwise by configuration). Order history and aggregates may be kept in anonymised form for reporting and integrity of financial records.
When a subscription ends, we may retain workspace data for a limited period to allow export or reactivation, then delete or anonymise it subject to law.
8. Security
We use administrative, technical, and organisational measures appropriate to the risk — including access controls, encrypted transport (HTTPS), hashed passwords, and permission-scoped modules. No method of transmission or storage is completely secure; please use strong passwords and limit staff access appropriately.
9. International transfers
Your information may be processed on servers in India or other locations where we or our sub-processors operate. Where required, we use appropriate safeguards for cross-border transfers.
10. Your rights
Depending on applicable law (including Indian IT rules and, where relevant, GDPR-style rights for individuals in applicable jurisdictions), you may have rights to access, correct, delete, restrict, or port personal data, and to object to certain processing or withdraw consent.
- Restaurant staff / owners: manage much of your data in-product, or email us.
- Guests: contact the restaurant that took your order first; we will support them on verified requests.
You may also lodge a complaint with a supervisory authority where you live or work, if applicable.
11. Children
The Service is directed at businesses, not children. We do not knowingly collect personal information from children under 16 for our own purposes. If you believe a child has provided us data, contact us and we will take appropriate steps.
12. Changes
We may update this Policy from time to time. The “Last updated” date will change, and material updates may be notified by email or in-product notice.
13. Contact
Privacy questions or requests: support@crutionresto.com · Crution Pvt Ltd · CrutionResto
Related: Terms and Conditions · Subscription & Pricing Terms