Shyara

Privacy Policy

Last updated: 2026-06-13 · BiteX by Shyara

SHYARA TECH SOLUTION (OPC) PRIVATE LIMITED · CIN U62011BR2025OPC080949
Jai Hanuman Colony, Bazar Samiti, Mahendru, Sampatchak, Patna-800006
support@bitexbyshyara.com

SHYARA TECH SOLUTION (OPC) PRIVATE LIMITED ("we", "us", "BiteX by Shyara") operates a B2B restaurant SaaS platform and public QR menu experiences. This Privacy Policy explains how we collect, use, store, and protect personal data in accordance with the Digital Personal Data Protection Act, 2023 and applicable rules.

Who we are

Data Fiduciary: SHYARA TECH SOLUTION (OPC) PRIVATE LIMITED

CIN: U62011BR2025OPC080949

Registered address: Jai Hanuman Colony, Bazar Samiti, Mahendru, Sampatchak, Patna-800006

Contact: support@bitexbyshyara.com

Data protection contact: Data Protection Contact - privacy@bitexbyshyara.com

Roles: restaurant owners vs diners

For restaurant owner and staff accounts, we act as the Data Fiduciary.

When a diner scans a restaurant QR code, the restaurant is primarily responsible for order and service data; BiteX processes session and cart data on the restaurant's instructions as a platform provider.

Personal data we collect (itemized)

  • Account: name, email address, password (stored hashed), authentication provider ID (Google OAuth).
  • Restaurant profile: restaurant name, cuisine, address, branding assets, menu content you upload.
  • Billing: subscription status, invoice metadata, Razorpay payment reference IDs (we do not store full card/UPI details).
  • Staff invites: invite codes, staff name, email, role permissions.
  • Diner sessions: table token, session ID, optional cart items and order notes (Plus and above).
  • Technical: IP address, browser type, device metadata, cookies/localStorage as described in our Cookie Policy.
  • Support: messages you send via support forms or email.

Purposes of processing

  • Create and manage your account and restaurants.
  • Deliver QR menus, orders, staff access, and billing.
  • Process subscriptions through Razorpay.
  • Send service emails (billing, security, account).
  • Analytics and product improvement (only with your consent for non-essential tracking).
  • Marketing emails (only with separate opt-in).
  • Legal compliance, fraud prevention, and grievance handling.

Legal basis

We rely on consent for marketing and non-essential analytics. Service delivery, billing, and security processing are based on contractual necessity and legitimate uses permitted under applicable law.

Retention

  • Account and restaurant data: retained while your account is active. When you confirm account deletion, operational data (profile, menus, restaurants, staff access) is permanently erased.
  • GST tax invoices: archived in a separate compliance store as required by Indian tax law (invoice number, amounts, billing identity snapshot, payment reference).
  • Diner cart data: sessionStorage on device only (not synced across phones). Table session tokens may be stored in localStorage for rejoin.
  • Analytics: per PostHog retention settings when enabled.

Account deletion

When you delete your account, we permanently erase your operational data from our systems. Tax invoices issued for subscription payments are retained in our compliance ledger for statutory record-keeping. Download invoice PDFs from Settings before deletion, or use payment receipt emails. For questions about retained invoice records, contact privacy@bitexbyshyara.com.

Sharing and processors

  • Razorpay - payment processing (India).
  • PostHog - product analytics and optional session replay (United States) when you consent.
  • Google - OAuth sign-in and Google Fonts (see Cookie Policy).
  • Cloud hosting and email providers as configured by our backend (see BACKEND_INTEGRATION.md).

Cross-border transfers

Some processors (e.g. PostHog) may process data outside India. We use them only for permitted purposes and with appropriate safeguards as required by law.

Your rights (Data Principal)

Exercise rights: /legal/data-rights or privacy@bitexbyshyara.com.

  • Access and review your personal data.
  • Correction of inaccurate data.
  • Erasure when no longer necessary (subject to legal retention).
  • Withdraw consent for consent-based processing.
  • Nominate another person to exercise rights on your behalf (where applicable).
  • Grievance to us and complaint to the Data Protection Board of India.

Children

BiteX is intended for restaurant businesses. We do not knowingly collect personal data from children under 18 without verifiable parental consent.

Security

We implement reasonable security practices including encryption in transit, access controls, and secure password hashing. Password resets require email verification via a one-time code (OTP) before a new password can be set. No method is 100% secure; report concerns to our grievance officer.

Changes

We may update this policy. Material changes will be notified via the platform or email. Continued use after notice constitutes acknowledgment where permitted by law.

Privacy PolicyTerms of ServiceCookie PolicyRefund PolicySubscription TermsGrievance RedressalYour Data Rights

This document is provided for transparency and does not constitute legal advice. Have your counsel review before production use.