Privacy Policy
Last updated: 16 July 2026
This Privacy Policy explains what data Taplo ("we", "us") collects, why, how we use and share it, and your choices. It forms part of our Terms of Service. By using the Service you consent to the practices described here.
Official domain & no affiliation
Taplo operates exclusively at taplo.in (website taplo.in, app app.taplo.in, API api.taplo.in). We are not affiliated with, endorsed by, or connected to"taplo.com" or any other similarly-named website or entity. We never collect your data through, and are not responsible for, any domain other than taplo.in. Verify the domain is taplo.in before entering any personal or payment information.
1. Who is responsible
For data you enter about your own customers, staff, vendors, and operations, you (the Restaurant) are the data controller and Taplo acts as your processor, hosting and processing that data to provide the Service. For your account, billing, and platform-security data, Taplo is the controller.
2. Data we collect
Account & identity: restaurant name, email, phone, business type, address, GST/PAN numbers, subscription details; owner and staff login accounts (name, email, phone, hashed password, role, last login, email-verification status); staff HR records that you enter (name, role, phone, email, and salary if you record it); platform super-admin accounts.
Customer data you collect: customer name, phone, email, address, GSTIN, order history, spend, loyalty points, tags, and free-text notes — including details captured through QR/self-ordering.
Orders & financial: orders, items, taxes/GST, discounts, invoices, cancellations, payment methods and status, vendor purchase records.
Subscription payment data: the amount, UPI/bank transaction reference (UTR), and any payment screenshot you upload to verify a subscription payment. Screenshots may contain bank/UPI details and are stored privately.
Operational: menu/products, inventory, vendors, tables, kitchen (KOT/KDS) records, tax/unit masters, analytics derived from the above.
Uploaded files: product images and payment QR/screenshots (stored as bytes in our database; screenshots are marked private and are not served publicly).
Technical & security: a login session token stored in an httpOnly cookie, email-verification and password-reset tokens (stored hashed), IP addresses in audit logs, and records of administrative actions.
3. How we use data
- To provide, operate, secure, and improve the Service.
- To authenticate users, process orders and payments, and generate invoices/reports.
- To send transactional emails (verification, password reset, payment and subscription notices).
- To provide support, prevent fraud/abuse, and comply with legal obligations.
4. Administrative & super-admin access
Taplo super admins can access, view, audit, export, modify, or delete data across accounts, and may temporarily access ("impersonate") an account for support, security, billing, or compliance. These actions are recorded in an internal audit log with the administrator's identity and IP. By using the Service you acknowledge and consent to this access.
5. Sharing & sub-processors
We do not sell your data. We share it only with service providers that help us run the Service, and where required by law:
- Neon — cloud PostgreSQL database hosting (stores all application data).
- Hostinger — application/server hosting and outbound email (SMTP) delivery.
- api.qrserver.com — generates table QR-code images from a table's public-menu URL.
- Vercel Analytics — aggregate, privacy-friendly web usage analytics on our web app.
Subscription payments use a manual UPI/bank + screenshot flow verified by us; we do not integrate an automated third-party payment gateway, and we do not store card numbers.
6. Data retention
We retain data for as long as your account is active and as needed to provide the Service and meet legal, tax, and accounting obligations. Much data is "soft-deleted" (hidden) rather than immediately erased. There is currently no automated self-service account-deletion; to request deletion or export, contact us (see below) and we will act within a reasonable period, subject to records we must retain by law.
7. Security
We use measures including hashed passwords (bcrypt), tokens stored in httpOnly cookies, transport encryption (HTTPS), scoped access controls, and audit logging. However, no system is completely secure; we cannot guarantee absolute security, and you use the Service at your own risk.
8. Your responsibilities & rights
- You are responsible for collecting your customers' and staff's personal data lawfully and for any consents/notices required in your jurisdiction.
- Subject to applicable law, you may request access, correction, export, or deletion of personal data we hold as controller by contacting us.
9. Children
The Service is for businesses and is not directed to children under 18.
10. Changes & contact
We may update this Policy; the "Last updated" date reflects the current version. Questions or requests: support@taplo.in.
This document is provided for general use and does not constitute legal advice. Have licensed counsel review it for your jurisdiction (e.g. India's DPDP Act, or GDPR/CCPA if you serve those regions) before relying on it.