KhaoPiyo

Privacy Policy

Last updated: 24 July 2026

Ventron ("KhaoPiyo", "we", "us") builds KhaoPiyo, software that cafés and restaurants use to take orders and bill customers. This policy explains what data the product handles, why, who else processes it, and how to exercise your rights.

Who controls your data

When you order at a café using KhaoPiyo, the café decides what to collect and why — the café is the data fiduciary. KhaoPiyo processes that data on the café's instructions as its processor.

For café owner and staff accounts (login email, role), KhaoPiyo is itself the fiduciary.

If you want your order data removed, you may contact either the café or us — see “Your rights”.

What we collect

  • Customer: phone number (only if you provide it), name (optional), your order contents, amounts, and order history at that café.
  • Verification: a one-time code, stored only as a cryptographic hash, and a session token so “My Orders” stays unlocked on your device.
  • Café owner/staff: name, email, role, and actions taken in the product (audit log).
  • Payments: the payment method, amount, and — for online payments — the payment reference returned by the gateway. We never receive or store your card number, UPI PIN, or bank credentials.

What we do not collect

We do not store your location, device fingerprint, or browsing behaviour, and we do not use advertising or cross-site tracking cookies. Our infrastructure providers process technical request data (such as IP address) to deliver and secure the service.

Why we collect it

  • To send your order to the kitchen and produce a correct bill and tax invoice.
  • To let you see your own past orders and reorder.
  • To let the café run its business — sales, refunds, and statutory GST records.
  • To keep the service secure and investigate misuse.

Who else processes your data

We use these providers. They process data to run the service; they are not permitted to use it for their own purposes:

  • Supabase — database, authentication, and file storage.
  • Vercel — application hosting and delivery.
  • Razorpay — only if your café has enabled online payments; it processes the payment itself under its own policies.
  • An SMS provider (MSG91 or Twilio) — only if your café has enabled SMS receipts or phone verification.

How long we keep it

Order and invoice records are retained by the café for as long as it needs them, including any statutory tax-record period. Verification codes expire within minutes; verification sessions expire after 90 days.

We are still finalising standard retention limits. Until then, you may request erasure at any time.

How it is protected

Data is encrypted in transit. Every café's data is isolated at the database level by row-level security, so one café cannot read another's. Payment gateway secrets are encrypted at rest. Access to financial records is restricted and audited.

No system is completely secure, and we do not claim otherwise. If a breach affects your data, we will act on it and notify affected parties and authorities as required.

Your rights

You may ask us to give you a copy of your data, correct it, or delete it. Use the data request page or write to us.

  • Data requests: /legal/data-request
  • Email: privacy@ventron.in
  • Grievances: Grievance Officer, Ventron — grievance@ventron.in

Children

KhaoPiyo is intended for use by café staff and by customers placing orders. It is not directed at children.

Changes

If this policy changes materially we will update the date above and, where appropriate, notify café accounts.

Requires professional review. This notice describes our actual processing. Its sufficiency under the Digital Personal Data Protection Act, 2023 and its rules — including retention periods and any breach-notification timelines — should be confirmed with a qualified Indian data-protection adviser before commercial launch.