Privacy Policy
Effective Date: September 2026 • Last Updated: September 5, 2026
Welcome to KitchenZap("we", "us", or "our"). We provide an AI-Powered WhatsApp Restaurant Operating System and digital table-ordering platform for restaurants, cafes, cloud kitchens, and food businesses.
This Privacy Policy explains how we collect, use, store, and safeguard data when restaurant partners and end-diners interact with our platform, website (kitchenzap.in), and WhatsApp bot integration.
1. Information We Collect
A. Restaurant Partner Information
- Business Name, Owner/Manager Name, and Official Email Address.
- WhatsApp Business Phone Number & Meta WABA Credentials.
- Store Physical Address, Pincode, City, and State.
- FSSAI Food License Number & GSTIN (where applicable).
- UPI VPA / Bank details for direct customer payouts.
B. End-Diner & Customer Information
- Customer WhatsApp Phone Number & Display Name.
- Dining Table Number (for Dine-in QR orders).
- Delivery Address, Landmark & Contact (for delivery orders).
- Order Items, Cart Customizations, and Cooking Notes.
2. WhatsApp Messaging & AI Natural Language Processing
When customers order via WhatsApp, messages are received through the official Meta Graph API (WhatsApp Cloud API v19.0+).
- Zero Data Selling: We NEVER sell, lease, or distribute customer WhatsApp numbers to third-party marketing or spam networks.
- Purpose Limitation: Message text is processed exclusively by our FSM State Engine and LLM infrastructure solely to parse food items, assemble carts, calculate taxes, and send KOT tracking receipts.
- Multi-Tenant Isolation: Customer data is strictly segmented by
restaurant_idat the database level to ensure zero cross-restaurant data leakage.
3. Payment Data & RBI Compliance
KitchenZap does not collect or store sensitive credit card numbers, CVVs, netbanking passwords, or UPI PINs.
Encrypted NPCI UPI Rails & RBI Authorized Aggregators (Razorpay / Cashfree)
Online customer payments are processed directly via secure payment gateway links or merchant UPI rails. Restaurant SaaS wallet recharges are processed through encrypted 256-bit SSL gateway protocols.
4. User Rights & Contact Us
Under the Digital Personal Data Protection (DPDP) Act 2023 and IT Act 2000, restaurant partners and diners have the right to review, update, or request the permanent deletion of their account data.
Privacy Grievance Officer:
Email: privacy@kitchenzap.in / support@kitchenzap.in
Response Window: Within 48 business hours.