Privacy policy
What personal data the Platform collects, why it is used, who it is shared with and how long it is kept. This document is written to the requirements of the Law of the Republic of Uzbekistan "On personal data" (ZRU-547 of 02.07.2019).
Last revised: 2026-08-22 · Version 0.1
1. Who is the operator, who is the processor
There are two layers in this document, and keeping them apart matters — both responsibility and the address to write to depend on it.
Guest and employee data. The Restaurant is the operator: it decides what data is collected and what it is used for. The Platform is the processor: it handles that data only on the Restaurant’s instruction and within the limits described here, and never for its own purposes.
The Restaurant’s own account. For the console accounts of the owner and the staff — email address, phone number, role, sign-in log — the operator is the Platform itself: that data records who the Platform contracted with and who signed in.
A Guest asks the Restaurant first about their own data. Where the Restaurant cannot answer, or the question is technical — which system holds the data, for instance — the Platform answers directly.
Data is collected and stored on servers located in the territory of the Republic of Uzbekistan. This is the requirement of article 27¹ of the Law: the personal data of citizens of the Republic of Uzbekistan is processed using technical means located in Uzbekistan.
2. What is collected
The list is split into four categories, because they have different owners and different legal bases.
| Whose | What is collected |
|---|---|
| Guest | Phone number, name, delivery address, order history and contents, loyalty balance, reviews and ratings left |
| Employee | Name, phone number, position and role, an irreversible hash of the PIN, shift and attendance records, payroll figures |
| Restaurant owner | Email address, phone number, company registration details, payment history and invoices |
| Technical data | IP address, device and browser type, push notification token, cookie identifiers, sign-in and change log |
The Platform does not store bank card numbers. Payment happens on the payment provider’s own page, and only the result of the transaction and the last four digits come back to the Platform.
Biometric data — face images, fingerprints — is not collected at present. If such a method of recording attendance is switched on, this document is updated in advance and separate written consent is obtained from the employee.
3. What it is used for
Each field is collected for a specific purpose. Using it beyond that purpose requires separate consent.
| Data | Purpose |
|---|---|
| Phone number and name | Taking the order, reporting its status, putting the courier in touch |
| Delivery address | Delivering the order and calculating the delivery charge |
| Order history | Settlement, refunds and dispute resolution, the loyalty programme, tax reporting |
| PIN hash | Confirming an employee’s identity at the till and in the staff app |
| Attendance and payroll | Recording the employment relationship and calculating pay |
| Technical data | Security, fraud detection, fixing errors, measuring load |
| Email address | Service messages, invoices, notice that a document has changed |
4. Legal basis
Performance of the contract — the data needed for an order, a payment, delivery and Plan billing. The service cannot be provided without it, so refusing that processing also cancels the order.
Consent — the loyalty programme, marketing messages and push notifications. Entering the one-time code sent by SMS counts as confirmation of consent, and the fact is recorded with its date. Consent may be withdrawn at any time; the ability to place orders is unaffected.
Legal requirement — fiscal receipts, tax and accounting records, employment documents. These records cannot be deleted even when consent is withdrawn: the obligation to keep them comes from the law, and the periods are in section 5.
Legitimate interest — security logs, fraud checks and keeping the Platform stable. Only technical data is processed on this basis.
5. How long it is kept
When the period ends the data is deleted or de-identified. A de-identified record stays in the statistics, but no person can be identified from it.
| Data | Period |
|---|---|
| Order and payment records | 5 years — required by tax and accounting law |
| Fiscal receipt data | 5 years |
| Employee attendance and shifts | 3 years |
| Employment and payroll documents | The period set by employment law |
| One-time SMS code (OTP) | 5 minutes |
| Push notification token | Until the app is removed or notifications are turned off |
| Sign-in and change log | 12 months |
| Backups | 30 days |
| Loyalty account and bonus balance | Until the Guest asks for deletion |
| Restaurant account | 30 days after the contract ends — the export window in section 6 |
7. Security
Traffic between the browser and the server is encrypted with TLS; the database is encrypted at rest.
Each restaurant sees only its own data. This is not a check in the application: the separation is in the database itself, through row-level security policies — even a badly written query cannot return a single row belonging to another restaurant.
Passwords and PINs are never stored in the clear — only an irreversible hash. A lost PIN is not recovered; a new one is issued. The number of PIN attempts is limited and lockout applies.
Permissions are granted by role and follow the principle of least privilege. Every significant action is written to the audit log: who changed what, and when.
Backups are taken at least once a day and kept for 30 days. The restore procedure is tested regularly — an untested backup is not a backup.
If a data breach is identified, the Restaurant is notified within 72 hours; where the law requires it, the competent state authority is notified as well.
8. Your rights
Access — ask what data about you is held and who it has been shared with.
Correction — require inaccurate or outdated data to be changed.
Deletion — ask for data to be deleted. Records the law requires us to keep — fiscal receipts, accounting and employment documents — are the exception; the reply says which record stayed and why.
Withdrawal of consent — opt out of marketing messages, push notifications and the loyalty programme. The ability to place orders remains.
Export — receive your data in machine-readable form.
Restriction and objection — ask for processing to stop or be limited for particular purposes.
Requests are sent through the Contact page or to the address in section 12. Replies are given within 30 calendar days. We may ask you to confirm your identity: otherwise we would be handing someone else’s data to a stranger.
If the reply does not satisfy you, you keep the right to complain to the competent state authority.
10. Children
The Platform is not intended for anyone under 16 and does not knowingly collect personal data from them.
If it turns out that a child’s data was entered without the consent of their legal guardian, it is deleted. If you notice such a case, write to the address in section 12 — we will look into it and tell you the outcome.
11. Changes to this document
The date and version of each revision are shown at the top of this page.
Material changes — a new purpose, a new recipient, a longer retention period, or a transfer of data to another country — are announced at least 30 days in advance by email and by a notice in the console.
Earlier revisions are archived and provided on request: it must be possible to check which terms applied in which period.
12. Contact
Formal requests about personal data are sent to the address below. In this draft revision these fields are not filled in.
| Field | Value |
|---|---|
| Operator — registered name of the legal entity | [to be filled in] |
| Postal address | [to be filled in] |
| Number in the state register of personal data bases | [to be filled in] |
| Email address for privacy requests | [to be filled in] |
| Person responsible for data security | [to be filled in] |
| Data centre where the data is held (Uzbekistan) | [to be filled in] |
For day-to-day questions the phone, Telegram and email on the Contact page are live — an answer comes the same day.