Privacy Policy
Last updated: 2026-06-13 · BiteX by Shyara
SHYARA TECH SOLUTION (OPC) PRIVATE LIMITED · CIN U62011BR2025OPC080949
Jai Hanuman Colony, Bazar Samiti, Mahendru, Sampatchak, Patna-800006
support@bitexbyshyara.com
SHYARA TECH SOLUTION (OPC) PRIVATE LIMITED ("we", "us", "BiteX by Shyara") operates a B2B restaurant SaaS platform and public QR menu experiences. This Privacy Policy explains how we collect, use, store, and protect personal data in accordance with the Digital Personal Data Protection Act, 2023 and applicable rules.
Who we are
Data Fiduciary: SHYARA TECH SOLUTION (OPC) PRIVATE LIMITED
CIN: U62011BR2025OPC080949
Registered address: Jai Hanuman Colony, Bazar Samiti, Mahendru, Sampatchak, Patna-800006
Contact: support@bitexbyshyara.com
Data protection contact: Data Protection Contact - privacy@bitexbyshyara.com
Roles: restaurant owners vs diners
For restaurant owner and staff accounts, we act as the Data Fiduciary.
When a diner scans a restaurant QR code, the restaurant is primarily responsible for order and service data; BiteX processes session and cart data on the restaurant's instructions as a platform provider.
Personal data we collect (itemized)
- Account: name, email address, password (stored hashed), authentication provider ID (Google OAuth).
- Restaurant profile: restaurant name, cuisine, address, branding assets, menu content you upload.
- Billing: subscription status, invoice metadata, Razorpay payment reference IDs (we do not store full card/UPI details).
- Staff invites: invite codes, staff name, email, role permissions.
- Diner sessions: table token, session ID, optional cart items and order notes (Plus and above).
- Technical: IP address, browser type, device metadata, cookies/localStorage as described in our Cookie Policy.
- Support: messages you send via support forms or email.
Purposes of processing
- Create and manage your account and restaurants.
- Deliver QR menus, orders, staff access, and billing.
- Process subscriptions through Razorpay.
- Send service emails (billing, security, account).
- Analytics and product improvement (only with your consent for non-essential tracking).
- Marketing emails (only with separate opt-in).
- Legal compliance, fraud prevention, and grievance handling.
Legal basis
We rely on consent for marketing and non-essential analytics. Service delivery, billing, and security processing are based on contractual necessity and legitimate uses permitted under applicable law.
Retention
- Account and restaurant data: retained while your account is active. When you confirm account deletion, operational data (profile, menus, restaurants, staff access) is permanently erased.
- GST tax invoices: archived in a separate compliance store as required by Indian tax law (invoice number, amounts, billing identity snapshot, payment reference).
- Diner cart data: sessionStorage on device only (not synced across phones). Table session tokens may be stored in localStorage for rejoin.
- Analytics: per PostHog retention settings when enabled.
Account deletion
When you delete your account, we permanently erase your operational data from our systems. Tax invoices issued for subscription payments are retained in our compliance ledger for statutory record-keeping. Download invoice PDFs from Settings before deletion, or use payment receipt emails. For questions about retained invoice records, contact privacy@bitexbyshyara.com.
Cross-border transfers
Some processors (e.g. PostHog) may process data outside India. We use them only for permitted purposes and with appropriate safeguards as required by law.
Your rights (Data Principal)
Exercise rights: /legal/data-rights or privacy@bitexbyshyara.com.
- Access and review your personal data.
- Correction of inaccurate data.
- Erasure when no longer necessary (subject to legal retention).
- Withdraw consent for consent-based processing.
- Nominate another person to exercise rights on your behalf (where applicable).
- Grievance to us and complaint to the Data Protection Board of India.
Children
BiteX is intended for restaurant businesses. We do not knowingly collect personal data from children under 18 without verifiable parental consent.
Security
We implement reasonable security practices including encryption in transit, access controls, and secure password hashing. Password resets require email verification via a one-time code (OTP) before a new password can be set. No method is 100% secure; report concerns to our grievance officer.
Changes
We may update this policy. Material changes will be notified via the platform or email. Continued use after notice constitutes acknowledgment where permitted by law.