VillsynConnect Restaurant Portal

Privacy Policy

Last updated: 24 September 2026

1. Introduction & scope

This Privacy Policy explains how VillsynConnect (“we”, “us”, Data Fiduciary) collects, uses, stores, and shares personal data when you use the VillsynConnect Restaurant Portal (the “Portal”), in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and applicable Indian law.

The Portal is for restaurant owners, outlet managers, kitchen staff, and admins to manage restaurants, menus, orders, and earnings. It is separate from the customer-facing ordering experience, though some order and delivery data is shared so you can fulfil orders.

By using the Portal or providing personal data (for example your mobile number for OTP), you acknowledge this Policy. Where consent is required, you may withdraw it as described below, subject to legal retention needs.

2. Data Fiduciary & Grievance Officer

Data Fiduciary: VillsynConnect — operating VillsynConnect Restaurant Portal.

Grievance Officer: Grievance Officer – VillsynConnect

  • Email: info@villsyn.com
  • Acknowledgement target: within 3 working days of a complete request
  • Resolution / reasoned update target: within 15 working days

Submit rights or grievance requests via Privacy rights & grievances.

3. Personal data we collect

3.1 Account and identity

  • Mobile number used for OTP login
  • Name and profile fields you provide
  • Authentication tokens / session cookies needed to keep you signed in
  • Role information (vendor, outlet manager, kitchen staff, admin)

3.2 Restaurant and business profile

  • Restaurant name, phone, cuisine, food category, description
  • Address, city, state, postal code, country, and map coordinates
  • Operational hours, photos, menus, and menu-item details
  • Verification status and admin review data
  • Outlet staff mobile numbers and roles you assign

3.3 Orders and operations

  • Order IDs, items, quantities, prices, and special instructions
  • Order status timeline
  • Customer delivery address and contact details needed for fulfilment
  • Payment method / status indicators
  • Delivery partner name and phone when assigned

3.4 Earnings and tax-related fields

  • Order value, discounts, fees, commission, and GST components where applicable
  • Gross revenue, net earnings, and payout-related analytics

3.5 Device and technical data

  • Browser / device information and approximate usage logs
  • IP address and security signals (for example session conflict detection)
  • Optional push / PWA preferences if you enable them

4. Purpose of processing

We process personal data only for lawful purposes, including to:

  • Verify your mobile number (OTP) and keep you signed in
  • Operate your restaurant account, menus, orders, and staff access
  • Calculate earnings, commission, and payout-related reporting
  • Provide support, security, fraud prevention, and legal compliance
  • Coordinate with customers and delivery partners for order fulfilment
  • Comply with legal, tax, dispute, and fraud-prevention obligations

We do not sell personal data as a standalone product. We do not use Portal personal data for unrelated third-party marketing without a lawful basis and, where required, consent.

5. Lawful basis (consent & legitimate uses)

For Portal login and account operation, processing is based on your consent (OTP / continued use) and on steps needed to provide the service you request. Restaurant onboarding requires acceptance of Terms and this Privacy Policy.

Certain processing (security, fraud prevention, tax/accounting retention, legal claims) may proceed under applicable law even if consent for voluntary features is withdrawn.

You may withdraw consent for voluntary processing via Privacy rights. Withdrawal does not affect processing already completed lawfully.

6. Sharing & data processors

We may share personal data with:

  • Customers — restaurant/menu details and order status needed for their order
  • Delivery partners — pickup details and contact information for handover
  • VillsynConnect admins — verification, support, and platform operations
  • Authorities — when required by law

Service providers (data processors) that may process data on our instructions include:

  • SMS / OTP providers (e.g. Firebase / telephony)
  • Payment gateways (e.g. Razorpay) for settlements where used
  • Cloud hosting and infrastructure providers
  • Maps / geocoding providers for restaurant location
  • Push notification providers (e.g. FCM) when enabled

7. Cookies and local storage

We use cookies and similar storage (access/refresh tokens, theme, role preference) to keep you logged in and remember display settings. Clearing cookies may require you to log in again.

8. Retention

We retain personal data only as long as needed for the purposes above, or as required by law. Indicative schedule:

  • Account & authentication (mobile, sessions): While the account is active, and up to 90 days after closure or last login
  • Restaurant profile, menus, staff assignments: While the restaurant partnership is active, then up to 3 years for disputes/audit
  • Orders, earnings, payouts, GST breakups: As required under tax and commercial law (typically 8 years), then delete or anonymise
  • Support / privacy rights requests: Up to 3 years from closure of the request
  • Security / access logs: Up to 12 months, unless needed longer for investigation

When data is no longer required, we delete or anonymise it where practical.

9. Security

We use reasonable technical and organisational measures (authenticated APIs, session controls, access roles) to protect personal data. No method of transmission or storage is 100% secure. Never share OTPs.

10. Your rights under the DPDP Act

Subject to the DPDP Act and exceptions in law, you may request to:

  • Access personal data we hold about you in connection with the Portal
  • Correct inaccurate or incomplete personal data
  • Erase personal data when it is no longer necessary (order/financial records may be retained as required by law)
  • Withdraw consent for consent-based processing
  • Grievance redressal via the Grievance Officer

Use /privacy/rights or email info@villsyn.com. We may verify your identity before fulfilling a request.

11. Children’s data

The Portal is intended for adult business users. It is not directed at children. Do not provide personal data of children through the Portal.

12. Cross-border processing

Personal data may be processed on servers or by processors that operate in or outside India, subject to applicable law and reasonable safeguards. Where transfer restrictions apply under the DPDP Act and rules notified thereunder, we will comply with those requirements.

13. Changes

We may update this Policy periodically. The “Last updated” date will change when we do. Material changes affecting consent-based processing will be highlighted in the Portal or at next login where practical.

14. Contact

Privacy and grievance contact: