…
Smart Restaurant Cloud
ProductWho it's forPricingScenariosFAQContact
Sign inRequest a demo
Legal documents

Privacy policy

What personal data the Platform collects, why it is used, who it is shared with and how long it is kept. This document is written to the requirements of the Law of the Republic of Uzbekistan "On personal data" (ZRU-547 of 02.07.2019).

This is a draft

It must be reviewed by a lawyer before it takes effect. Version 0.1, 2026-08-22.

Last revised: 2026-08-22 · Version 0.1

Contents
  1. 1. Who is the operator, who is the processor
  2. 2. What is collected
  3. 3. What it is used for
  4. 4. Legal basis
  5. 5. How long it is kept
  6. 6. Who it is shared with
  7. 7. Security
  8. 8. Your rights
  9. 9. Cookies
  10. 10. Children
  11. 11. Changes to this document
  12. 12. Contact

1. Who is the operator, who is the processor

There are two layers in this document, and keeping them apart matters — both responsibility and the address to write to depend on it.

Guest and employee data. The Restaurant is the operator: it decides what data is collected and what it is used for. The Platform is the processor: it handles that data only on the Restaurant’s instruction and within the limits described here, and never for its own purposes.

The Restaurant’s own account. For the console accounts of the owner and the staff — email address, phone number, role, sign-in log — the operator is the Platform itself: that data records who the Platform contracted with and who signed in.

A Guest asks the Restaurant first about their own data. Where the Restaurant cannot answer, or the question is technical — which system holds the data, for instance — the Platform answers directly.

Data is collected and stored on servers located in the territory of the Republic of Uzbekistan. This is the requirement of article 27¹ of the Law: the personal data of citizens of the Republic of Uzbekistan is processed using technical means located in Uzbekistan.

2. What is collected

The list is split into four categories, because they have different owners and different legal bases.

WhoseWhat is collected
GuestPhone number, name, delivery address, order history and contents, loyalty balance, reviews and ratings left
EmployeeName, phone number, position and role, an irreversible hash of the PIN, shift and attendance records, payroll figures
Restaurant ownerEmail address, phone number, company registration details, payment history and invoices
Technical dataIP address, device and browser type, push notification token, cookie identifiers, sign-in and change log

The Platform does not store bank card numbers. Payment happens on the payment provider’s own page, and only the result of the transaction and the last four digits come back to the Platform.

Biometric data — face images, fingerprints — is not collected at present. If such a method of recording attendance is switched on, this document is updated in advance and separate written consent is obtained from the employee.

3. What it is used for

Each field is collected for a specific purpose. Using it beyond that purpose requires separate consent.

DataPurpose
Phone number and nameTaking the order, reporting its status, putting the courier in touch
Delivery addressDelivering the order and calculating the delivery charge
Order historySettlement, refunds and dispute resolution, the loyalty programme, tax reporting
PIN hashConfirming an employee’s identity at the till and in the staff app
Attendance and payrollRecording the employment relationship and calculating pay
Technical dataSecurity, fraud detection, fixing errors, measuring load
Email addressService messages, invoices, notice that a document has changed

4. Legal basis

Performance of the contract — the data needed for an order, a payment, delivery and Plan billing. The service cannot be provided without it, so refusing that processing also cancels the order.

Consent — the loyalty programme, marketing messages and push notifications. Entering the one-time code sent by SMS counts as confirmation of consent, and the fact is recorded with its date. Consent may be withdrawn at any time; the ability to place orders is unaffected.

Legal requirement — fiscal receipts, tax and accounting records, employment documents. These records cannot be deleted even when consent is withdrawn: the obligation to keep them comes from the law, and the periods are in section 5.

Legitimate interest — security logs, fraud checks and keeping the Platform stable. Only technical data is processed on this basis.

5. How long it is kept

When the period ends the data is deleted or de-identified. A de-identified record stays in the statistics, but no person can be identified from it.

DataPeriod
Order and payment records5 years — required by tax and accounting law
Fiscal receipt data5 years
Employee attendance and shifts3 years
Employment and payroll documentsThe period set by employment law
One-time SMS code (OTP)5 minutes
Push notification tokenUntil the app is removed or notifications are turned off
Sign-in and change log12 months
Backups30 days
Loyalty account and bonus balanceUntil the Guest asks for deletion
Restaurant account30 days after the contract ends — the export window in section 6

6. Who it is shared with

The list below is exhaustive. Data is not passed to any third party not named here, is not sold and is not sent to advertising networks.

WhoWhat is sentWhere
Payment providers — Payme, Click, UzumThe amount and the order number. Card details never reach the Platform at allUzbekistan
SMS provider — EskizPhone number and message textUzbekistan
Push notifications — Expo, Apple, GoogleThe device token and the text shown on screen. Name, phone number, address and order contents are not sentUnited States
Fiscal data operator (OFD)Receipt contents — to the extent the law requiresUzbekistan
TelegramWhen the mini app or a bot is used — the Telegram account identifier and the message sentTelegram servers
State authoritiesOnly on a written request properly made on a lawful basis, and only to the extent requestedUzbekistan

A note on push. The notification servers of Expo and of the device manufacturer are located in the United States. All that goes there is the device token and the message text shown on screen — no person can be identified from that. Order contents, phone numbers and addresses are never sent. Turning notifications off deletes the token as well.

Each provider is bound in writing to use the data only within our instruction and to protect it.

7. Security

Traffic between the browser and the server is encrypted with TLS; the database is encrypted at rest.

Each restaurant sees only its own data. This is not a check in the application: the separation is in the database itself, through row-level security policies — even a badly written query cannot return a single row belonging to another restaurant.

Passwords and PINs are never stored in the clear — only an irreversible hash. A lost PIN is not recovered; a new one is issued. The number of PIN attempts is limited and lockout applies.

Permissions are granted by role and follow the principle of least privilege. Every significant action is written to the audit log: who changed what, and when.

Backups are taken at least once a day and kept for 30 days. The restore procedure is tested regularly — an untested backup is not a backup.

If a data breach is identified, the Restaurant is notified within 72 hours; where the law requires it, the competent state authority is notified as well.

8. Your rights

Access — ask what data about you is held and who it has been shared with.

Correction — require inaccurate or outdated data to be changed.

Deletion — ask for data to be deleted. Records the law requires us to keep — fiscal receipts, accounting and employment documents — are the exception; the reply says which record stayed and why.

Withdrawal of consent — opt out of marketing messages, push notifications and the loyalty programme. The ability to place orders remains.

Export — receive your data in machine-readable form.

Restriction and objection — ask for processing to stop or be limited for particular purposes.

Requests are sent through the Contact page or to the address in section 12. Replies are given within 30 calendar days. We may ask you to confirm your identity: otherwise we would be handing someone else’s data to a stranger.

If the reply does not satisfy you, you keep the right to complain to the competent state authority.

Send a request

9. Cookies

The Platform uses no advertising or tracking cookies and loads no third-party analytics scripts. The cookies below are the ones it needs to work; without them signing in and the cash shift do not function.

NameWhat forLifetime
restaurant-campus-sessionThe session of the person signed in to the console8 hours
restaurant-campus-terminalWhich till this is — the device token1 year
restaurant-campus-shiftWho is standing at the till — the open shift12 hours
restaurant-campus-crew-deviceWhich phone this is — the staff app’s device token1 year
restaurant-campus-crew-tenantWhich restaurant that phone belongs to1 year
restaurant-campus-crew-sessionWho is holding the phone right now12 hours
srcp.site.langThe language chosen on the public site1 year

The till cookies and the staff app cookies are deliberately separate: one person can be at the till and on their own phone at the same time, and signing out of the phone must not close the shift at the till.

Session cookies are httpOnly — a script on the page cannot read them. Cookies can be turned off in the browser, but then signing in becomes impossible.

10. Children

The Platform is not intended for anyone under 16 and does not knowingly collect personal data from them.

If it turns out that a child’s data was entered without the consent of their legal guardian, it is deleted. If you notice such a case, write to the address in section 12 — we will look into it and tell you the outcome.

11. Changes to this document

The date and version of each revision are shown at the top of this page.

Material changes — a new purpose, a new recipient, a longer retention period, or a transfer of data to another country — are announced at least 30 days in advance by email and by a notice in the console.

Earlier revisions are archived and provided on request: it must be possible to check which terms applied in which period.

12. Contact

Formal requests about personal data are sent to the address below. In this draft revision these fields are not filled in.

FieldValue
Operator — registered name of the legal entity[to be filled in]
Postal address[to be filled in]
Number in the state register of personal data bases[to be filled in]
Email address for privacy requests[to be filled in]
Person responsible for data security[to be filled in]
Data centre where the data is held (Uzbekistan)[to be filled in]

For day-to-day questions the phone, Telegram and email on the Contact page are live — an answer comes the same day.

Contact

Move your restaurant across in a week

We migrate your data and train your staff. You just keep serving.

Request a demoSee pricing
Call us
+998 90 475 09 09
Telegram@Yoqubjon_099
Emailnurmamatovyoqub@gmail.com
HoursDaily, 9:00–21:00
SRSmart Restaurant

A POS and management system built for restaurants in Uzbekistan.

Product
ProductWho it’s forPricingDownload the appSign in
Company
ScenariosContactTermsPrivacy
Help
FAQMessage us on TelegramCall us
© 2026 Smart Restaurant Cloud · All rights reservedv2.4.0·Made in Termez