At AI Restro 360, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our restaurant management platform, website (airestro360.com), applications, and related services (collectively, the “Service”). Please read this policy carefully.
1. Information We Collect
Personal information
When you register for an AI Restro 360 account, we may collect:
- Restaurant name and business details
- Contact information (name, email address, phone number)
- Business address and location
- Payment and billing information for subscription fees
- User account credentials
Restaurant data
When you use the Service, we collect and store data you enter or generate, including:
- Menu items, categories, and pricing
- Inventory and ingredient data
- Order and transaction records
- Customer information (names, phone numbers, delivery addresses)
- Staff accounts and role assignments
- Sales reports and analytics data
- WhatsApp conversation logs when you use our WhatsApp AI receptionist (Farori) or related messaging features
- Voice or AI-assisted ordering inputs where those features are enabled
Technical and usage data
- Device, browser, and approximate location information
- IP address and log data needed to operate and secure the Service
- Cookie and similar technology data as described in our Cookie Policy
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain our restaurant management services
- Process transactions and manage your subscription
- Generate your restaurant website and enable online ordering (where included)
- Power AI features you enable (for example WhatsApp receptionist replies, voice ordering assistance, or in-product AI help) using your restaurant context
- Send operational updates, technical notices, and support messages
- Respond to inquiries and provide customer support
- Improve and optimize the platform
- Monitor usage patterns and detect security issues
- Send marketing communications (with your consent, which you can withdraw at any time)
3. Data Security
We implement industry-standard measures to protect your data, including:
- Encryption in transit using SSL/TLS
- Hashed and salted password storage (passwords are never stored in plain text)
- Multi-tenant architecture designed to isolate each restaurant’s data, with role-based access controls
- Token-based authentication with expiring sessions
- Permission-gated API access and audit logging of sensitive administrative actions
- Automated backups as part of normal operations
- Restricted access to production systems for authorized personnel only
No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.
4. Data Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share data only in these circumstances:
- Service providers — trusted providers who help us operate the platform (for example hosting, payment processors, email delivery). They are obligated to protect your data.
- AI providers — where you enable AI-powered features (such as the WhatsApp AI receptionist Farori or voice ordering), relevant message or request content may be processed by our AI infrastructure provider (currently Google Gemini / Google AI) solely to generate responses on your behalf. Under our arrangements with providers, this processing is for providing the feature to you, not for selling your data.
- Messaging platforms — Meta (WhatsApp Business Platform) when you use WhatsApp features, so messages can be delivered to and from your customers.
- Legal requirements — if required by law, court order, or government regulation.
- Business transfers — in a merger, acquisition, or sale of assets, information may transfer to the new owner.
- With your consent — for any other purpose you explicitly approve.
5. Your Customers’ Data
When your customers place orders through your AI Restro 360-powered website, POS, WhatsApp, voice ordering, or related channels, we process their information — such as name, contact details, delivery address, and order history — on your behalf and under your instructions, solely to operate your restaurant’s services (taking orders, arranging delivery, receipts, and reports).
We act as a data processor for this information; you, the restaurant, are the data controller. We do not sell your customers’ data, use it to market to them independently, or share it with other restaurants on the platform. You are responsible for informing your customers about how their information is used. If a customer asks us directly to access or delete their data, we will refer the request to you and assist you in fulfilling it where reasonably possible.
6. Your Rights and Choices
- Access — review account information through your dashboard
- Correction — update information in account settings
- Deletion — request deletion of your account and associated data by contacting support
- Data portability — request an export of your restaurant’s data in a common electronic format (such as CSV) within a reasonable time, where technically practicable
- Marketing opt-out — unsubscribe using the link in our emails
For users in the European Economic Area or United Kingdom, you may have additional rights under GDPR or UK GDPR. Contact us to exercise those rights.
7. Data Breach Notification
In the unlikely event of a security breach affecting your data, we will notify affected customers without undue delay after becoming aware of it, describe the nature of the incident and the data involved, and outline the steps we are taking in response.
8. Subprocessors
We rely on trusted infrastructure and service providers to deliver the Service. Depending on which features you use, these may include cloud hosting and database providers, payment processors, transactional email providers, Google (Gemini / AI features), and Meta (WhatsApp Business Platform for WhatsApp features). Each processes data only as needed to provide their service to us or to you.
9. Data Retention
We retain your information for as long as your account is active or as needed to provide services. If you close your account, we will delete your data within 90 days, except where we must retain it for legal, regulatory, accounting, or security purposes. Transactional records may be retained longer as required by tax and accounting rules.
10. Cookies and Tracking
We use cookies and similar technologies as described in our Cookie Policy. Essential cookies are required for the Service to function. Analytics cookies are used only if you consent via our cookie banner.
11. Third-Party Links
The Service may contain links to third-party websites or services (for example payment gateways or delivery platforms). We are not responsible for their privacy practices. Review their policies before providing personal information.
12. Children’s Privacy
AI Restro 360 is intended for business use and is not designed for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, contact us immediately.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will update the “Last updated” date on this page and, for significant changes, notify you by email or a prominent notice on the platform. Continued use after changes constitutes acceptance of the updated policy.
14. Contact Us
Questions or privacy requests (include “Privacy” in the subject line):
AI Restro 360
Email: support@airestro360.com
WhatsApp: +92 301 2775034
Registered office: Islamabad, Pakistan
