RushQR
Draft — not yet in force. This document is a working draft prepared for internal review. Do not rely on it. Placeholders marked [[like this]] must be completed and the full text reviewed by qualified legal counsel before publication.

Legal

Privacy Policy

Last updated: [[YYYY-MM-DD]] · Effective from: [[YYYY-MM-DD]] · Version [[v1]]. This document was last reviewed by [[counsel name / firm]] on the date this draft was accepted.

This policy explains what personal data RushQR collects when someone uses the platform — as a Merchant running an outlet, as a Guest placing an order, or simply as a visitor to our website — why we collect it, who we share it with, and what rights the person the data is about has. It applies alongside the Terms of Service.

1.Who this policy is from

This policy is issued by [[Registered entity name, e.g. RushQR Technologies Private Limited]] (referred to below as “RushQR”, “we”, “us”, or “our”). Our registered office is at [[full postal address]]. CIN: [[CIN]]. We are an Indian company and our processing of personal data is subject to the Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and other applicable Indian law.

2.The roles: controller and processor

Under the DPDP Act, the entity that decides why and how personal data is processed is called a “Data Fiduciary” (roughly equivalent to a controller elsewhere). The entity that processes data on the Fiduciary's instructions is a “Data Processor”.

  • For personal data about Merchants and their staff (KYC, bank details, employee logins, and so on): RushQR is the Data Fiduciary.
  • For personal data about Guests that a Merchant obtains through the platform (name, phone, order history, allergen notes): the Merchant is the Data Fiduciary. RushQRacts as the Data Processor for the Merchant and only processes Guest data on the Merchant's instructions and to run the platform.
  • For RushQR's own website analytics and product improvement: RushQR is the Data Fiduciary.

3.What personal data we collect

From Merchants (during onboarding and while an outlet is active):

  • Business name, legal name, and constitution
  • Registered and outlet addresses
  • PAN, GSTIN, CIN or LLPIN as applicable
  • Bank account holder, account number, and IFSC for settlement
  • Authorized signatory's name, contact number, and email
  • KYC document(s) uploaded to support the application
  • Any staff logins created inside the outlet workspace

From Guests (when placing an order):

  • Name and phone number (when requested by the Merchant, for example for parking or curbside orders)
  • Order contents, order total, and time of order
  • Vehicle number plate for in-car pickup (optional)
  • UPI transaction reference (returned by the payment aggregator)
  • Any dietary or allergen notes the Guest chooses to add

Technical data (from any visitor to the platform):

  • IP address, coarse geolocation derived from it, and user-agent string
  • Session cookie (identifies the logged-in device to our servers)
  • A language preference cookie (English or Hindi)
  • Diagnostic logs written by the platform when a request fails

We do not collect government-issued IDs from Guests, we do not ask Guests to create an account to order, and we do not store payment card numbers — UPI carries no card data.

4.Why we collect it (purposes and lawful basis)

We rely on the following lawful bases under the DPDP Act, matched to the specific purpose:

  • Performance of contract. Merchant KYC, settlement, and invoicing are needed to run the account under the Terms of Service. Guest order details and the UPI reference are needed to fulfil the Order that the Guest placed.
  • Legal obligation. Retaining KYC documents, GST invoices, and financial records for the periods required by Indian tax and company law.
  • Legitimate use. Fraud prevention, abuse detection, security monitoring, and internal analytics used to keep the platform running well.
  • Consent.Any use of a Guest's contact information for direct marketing by the Merchant, if the Merchant chooses to run such a campaign, requires the Guest's explicit consent captured at the time. RushQR itself does not send Guests marketing.

5.Cookies, sessions, and local storage

We set a small number of strictly-necessary cookies and use browser-local storage for a handful of preferences:

  • Session cookie ([[cookie name, e.g. better-auth.session_token]]) — identifies a signed-in Merchant or staff device. HTTP-only, Secure, and SameSite=Lax. Not used for tracking.
  • Language preference (localStorage key lang) — remembers whether you chose English or Hindi.
  • UI state (localStorage) — remembers which sidebar sections are collapsed inside the app shell.

We do not set third-party advertising cookies, we do not use fingerprinting, and we do not embed advertising trackers on the Guest ordering surfaces.

6.Who we share personal data with

We share personal data only with the entities below, and only to the extent needed for the stated purpose:

  • The Merchantreceives the personal data of a Guest who places an Order at that Merchant's outlet — as needed to fulfil the Order and to handle refund or dispute follow-up.
  • Payment infrastructure. [[Payment aggregator / UPI PSP name]]receives the payment amount, the Merchant's VPA, and any bank references needed to settle the funds.
  • Cloud hosting. [[Cloud provider(s), e.g. Amazon Web Services (Mumbai region)]] hosts our servers, databases, and object storage under a data processing agreement.
  • Communication providers. [[SMS / WhatsApp / email vendor name]] deliver transactional messages such as OTPs and order-status notifications.
  • Auditors, tax authorities, and law enforcement where we are required by law to disclose. We will notify the affected person before disclosing wherever we are legally permitted to do so.

We do not sell personal data. We do not rent it or trade it. We do not share Guest lists with other Merchants.

7.Where data is stored

Personal data is stored on servers located in [[region, e.g. Mumbai, India]]. Backups are kept in the same country and encrypted at rest. We do not routinely transfer personal data outside India; if that changes in the future, we will update this policy and give notice as required by law.

8.How long we keep data

  • Merchant KYC and settlement records: retained for as long as the account is active, and thereafter for the minimum period required by Indian tax and anti-money-laundering law (typically eight years for financial records).
  • Order records: retained for [[duration, e.g. 3 years]] after the Order date to support dispute resolution and statutory audits.
  • Guest contact data linked to an Order: retained for the same period as the Order itself, unless the Guest asks earlier for it to be erased (see rights below).
  • Diagnostic logs: retained for [[duration, e.g. 30 days]], then automatically deleted.
  • Audit trail of admin actions (KYC approvals, suspensions, grants): retained for [[duration, e.g. 3 years]].

9.Your rights under the DPDP Act

If we hold personal data about you, you have the right to:

  • Confirm whether we hold it, and receive a summary of it
  • Ask us to correct or update inaccurate data
  • Ask us to erase data we no longer need to keep by law
  • Withdraw a consent you previously gave (going forward)
  • Nominate another person to exercise these rights on your behalf if you cannot
  • File a grievance with our Grievance Officer, and, if unresolved, escalate to the Data Protection Board of India

To exercise any of these rights, write to the Data Protection Officer at the address in section 14. We will acknowledge within seventy-two hours and respond substantively within the timeline required by law.

Where the personal data was collected by a Merchant through the platform (for example, an order-history record on a Merchant's dashboard), the Merchant is the Data Fiduciary — we will forward the request to the Merchant and support them in fulfilling it.

10.How we protect the data

  • All traffic between the browser and the platform is encrypted in transit (TLS 1.2+).
  • Passwords are stored hashed and salted; we never store the plaintext.
  • Access to production data is role-based and gated by named admin accounts; every admin action is written to an immutable audit log.
  • Backups are encrypted at rest. Restore procedures are exercised on a documented schedule.
  • Access to KYC documents is limited to RushQR staff who need it to review or refresh KYC.

No online service can guarantee absolute security. If we become aware of a personal-data breach that is likely to result in significant harm, we will notify the Data Protection Board and the affected persons within the timelines required by law.

11.Children

The platform is intended for adults (18 and over). We do not knowingly collect personal data of children. If a child's personal data comes to us through a Merchant surface (for example a child ordering from a parent's phone), the Merchant is responsible for ensuring the order is placed by, or with the consent of, a parent or lawful guardian.

12.Change of control (acquisition or restructuring)

If RushQR undergoes a merger, acquisition, or corporate reorganisation, personal data may be transferred to the successor entity as part of the assets of the business. The successor will take on the same privacy commitments described in this policy at least until an updated policy is notified to the affected persons.

13.Changes to this policy

We may update this policy from time to time. When we do, we will post the new version at this URL and update the “Last updated” date at the top. For material changes affecting how we use personal data, we will give notice by email to Merchants on file at least [[N days]] before the change takes effect.

14.Grievance officer and Data Protection Officer

To exercise any right, raise a concern, or file a grievance under the DPDP Act, contact the officers below. We aim to acknowledge within seventy-two hours and to resolve grievances within the statutory deadline. If the response does not satisfy you, you may escalate to the Data Protection Board of India.

Contact

[[Registered entity name]]
[[Registered office address, line 1]]
[[City, State, PIN, India]]
CIN: [[CIN]] · GSTIN: [[GSTIN]]
General: [[hello@your-domain]]
Grievance officer: [[Name, email, phone]]
Data protection officer: [[dpo@your-domain]]