Privacy Policy

Privacy & Policy

Last Updated: August 14, 2026

SRV Technology operates the billnbite.com Point of Sale (POS) software, mobile applications, web dashboard, and hardware integration services (collectively, the "Services").

This Privacy Policy explains how we collect, use, process, store, and protect information when:

  • Merchants / Restaurant Operators ("Subscribers"): Register an account, manage subscriptions, and operate POS terminals, Kitchen Display Systems (KDS), or web dashboards.
  • End Customers ("Diners / Guests"): Place orders, make payments, interact with digital/QR menus, or join restaurant loyalty programs processed through our POS ecosystem.

1. Information We Collect

A. Information from Merchants & Restaurant Staff

  • Account & Business Data: Owner/manager name, restaurant legal name, physical business address, business email, phone number, tax registration identifiers (e.g., GSTIN, VAT, EIN, or business licenses).
  • Employee / Staff Profiles: Staff member names, employee IDs/passcodes, role permissions, clock-in/out timestamps, shift records, and server-specific sales tracking.
  • Subscription & Billing Data: Invoicing records, bank transfer details, and payment method details (processed via PCI-compliant payment gateways).

B. Information Processed on Behalf of Merchants (Customer & Order Data)

When guests place orders at the restaurant or via integrated ordering channels:

  • Transaction Details: Items ordered, item customizations, order totals, tips, table numbers, date and timestamps, payment status, and promotional discount codes.
  • Diner Contact Data (if provided): Customer name, phone number, delivery address (for takeout/delivery orders), and email address (for digital receipts, feedback, or loyalty programs).
  • Payment Card Data: Credit/debit card details and UPI/digital wallet IDs.
    Note: Full cardholder numbers are tokenized and processed directly by our PCI-DSS certified payment partners (Razorpay); full payment card numbers are never stored on local POS terminals.

C. Technical and Device Data (Collected Automatically)

  • Device & Terminal Info: Hardware model, operating system version, unique terminal/device IDs, IP address, and peripheral status (receipt printers, barcode scanners, cash drawers, KDS monitors).
  • Usage & Diagnostic Logs: POS session durations, crash reports, network error logs, and offline transaction synchronization logs.

2. How We Use the Information

We utilize the collected information for the following operational and commercial purposes:

  • Core POS Functionality: Operate, configure, and maintain POS terminals, handheld ordering devices, Kitchen Display Systems (KDS), and cloud-based management dashboards.
  • Order & Payment Processing: Process dining and online sales, issue physical/digital receipts, and settle card/digital transactions.
  • Offline Synchronization: Securely cache offline transactions locally and synchronize them to central cloud databases once connectivity is restored.
  • Business Analytics & Reporting: Provide restaurant owners with real-time sales reports, inventory deduction tracking, tax calculations, and end-of-day (Z-Report) summaries.
  • Customer Engagement: Facilitate merchant loyalty programs, send SMS/WhatsApp order updates, and deliver responsive customer support.
  • Security & Compliance: Monitor security events, detect fraudulent activities, verify transactions, and comply with applicable tax, financial, and accounting laws.

3. Data Sharing and Third-Party Disclosures

We do not sell customer or restaurant data to third-party data brokers. Data is shared solely under strict operational parameters:

  • Payment Processors: Integrated gateways (e.g., Stripe, Razorpay, Square, Adyen) to securely process card payments and online settlements.
  • Cloud & Hosting Infrastructure: Enterprise cloud providers (e.g., AWS, Google Cloud, Supabase) for database hosting, automatic data backups, and user authentication.
  • Integrated Third-Party Services: Food delivery aggregators (e.g., DoorDash, UberEats, Zomato, Swiggy), accounting software (e.g., QuickBooks, Tally), and SMS/messaging gateways as configured by the merchant.
  • Legal & Regulatory Authorities: When required by court order, statutory tax audit, law enforcement request, or applicable law.

4. Roles Under Data Protection Laws

  • POS Provider as Data Processor / Service Provider: For all guest/diner personal data (such as diner phone numbers, delivery addresses, and order histories), the Restaurant Merchant is the Data Controller, and we process this data strictly under their instructions.
  • POS Provider as Data Controller: For merchant account credentials, direct billing records, and merchant support communications, we act as the primary Data Controller.

MERCHANT RESPONSIBILITY

Merchants are responsible for providing appropriate privacy notices and obtaining any required consent from their diners when collecting personal information for marketing or loyalty programs.

5. Data Retention

  • Operational & Transaction Data: Retained as long as the merchant maintains an active account to provide ongoing analytics, order lookups, and reporting.
  • Financial & Tax Records: Invoices, tax summaries, and transaction logs are retained for statutory retention periods (typically 5 to 7 years) to comply with tax and accounting laws.
  • Post-Termination Deletion: Upon account closure or contract termination, merchant operational data is archived and purged within 30 to 90 days, unless retention is mandated by law.

6. Data Security & Storage Safeguards

We maintain industry-standard physical, electronic, and procedural safeguards:

  • Encryption: Data in transit is protected using TLS 1.2/1.3 encryption. Sensitive data at rest is encrypted using AES-256 standards.
  • PCI-DSS Compliance: Payment integrations strictly adhere to Payment Card Industry Data Security Standards.
  • Role-Based Access Control (RBAC): Restricts terminal operations, cashier drawers, void/refund actions, and back-office reports based on assigned employee roles.
  • Offline Security: Locally cached transactions on POS terminals are encrypted and purged or synced immediately upon internet reconnection.

7. Data Subject Rights & Choices

Depending on applicable jurisdiction (e.g., GDPR, CCPA/CPRA, India DPDP Act), merchants and individuals have specific rights:

  • Access & Portability: Request an export of business records, sales history, or customer lists in a structured, machine-readable format.
  • Correction & Update: Modify inaccurate account details via the POS settings dashboard.
  • Erasure / Deletion: Request deletion of personal records, subject to statutory tax and financial retention requirements.

Contact for Privacy Requests: To exercise these rights, or if an end customer wishes to request removal of their contact data, contact us at privacy@billnbite.com.

8. Children’s Privacy

Our POS software and related services are commercial business tools intended for business operators and adults over the age of 18. We do not knowingly collect personal data from minors.

9. Updates to This Policy

We may update this Privacy Policy periodically to reflect changes in software features, security standards, or regulations. We will notify merchants of significant modifications via the POS dashboard or registered email.

10. Contact Information

If you have questions, feedback, or data privacy requests regarding this policy:

  • Company Name: SRV TECHNOLOGY
  • Privacy Email: info@billnbite.com
  • Office Address: BT Ranadeep Colony, Matigara-734010, Siliguri, WB, India.
  • Contact Name & Number: Vikrant Singh, +91 70017 69472