Privacy Policy
Last Updated: October 2026 • Effective Date: October 2026
At Smart Restro (developed by iQNex, operating at theiqnex.com and smartrestro.theiqnex.com), your privacy and data security are our highest priorities. This Privacy Policy outlines our transparent practices regarding data collection, handling, storage, and deletion across our mobile applications, terminal software, and web portals. This policy strictly complies with Google Play Developer Policies and global privacy regulations (GDPR, CCPA).
1. Information We Collect
We collect only the minimum information necessary to deliver seamless restaurant operations and dining services:
- Restaurant Owner & Business Account Data: When registering a restaurant, we collect the restaurant name, manager's name, official email address, phone number, physical address, city, pin code, tax/GST registration numbers (if applicable), and optional restaurant showcase images.
- Diner Guest Data: Diner guests can browse menus and order at tables without mandatory account creation. Diners may optionally provide an email address for receipt delivery or an optional name for order personalization.
- Menu Items & Showcase Content: Food dish titles, descriptions, pricing, dietary indicators (Veg/Non-Veg), and food photos uploaded by the restaurant admin.
- Operational Data: Table numbers, order timestamps, item status (Accepted, Preparing, Prepared, Completed, Cancelled), and bill totals required for kitchen coordination and order fulfillment.
2. Device Permissions & Scoped Storage Transparency
We strictly limit device permissions. Smart Restro DOES NOT request dangerous background location, contact access, microphone recording, SMS reading, or broad storage permissions (`MANAGE_EXTERNAL_STORAGE` or `READ_EXTERNAL_STORAGE`):
- Internet & Network State (`android.permission.INTERNET`, `android.permission.ACCESS_NETWORK_STATE`): Used to synchronize orders in real time with our secure Google Cloud Firestore database.
- System Photo Picker: When uploading dish photos or restaurant imagery, the app relies on Android's secure system photo picker. No wide storage or media read permissions are requested. Only the single selected image is accessed with temporary read permission.
- Storage Access Framework (SAF) for CSV Exports: Order reports are exported using Android's native document creator (`ACTION_CREATE_DOCUMENT`), saving reports directly to your chosen directory without broad file system access.
- App-Specific Sandboxed Cache: Invoices (PDF format) are generated inside the app's private sandbox cache directory (`getTemporaryDirectory()`), requiring zero storage permissions.
3. Cloud Infrastructure & Third-Party Services
All data is processed using industry-standard enterprise cloud platforms:
- Google Firebase Authentication: Provides secure, encrypted credential storage and token authentication.
- Google Cloud Firestore: Delivers encrypted-at-rest database storage and sub-second multi-terminal data sync.
- Google Firebase Cloud Storage: Stores dish images and restaurant showcase assets with TLS 1.3 encryption.
4. Data Security & Encryption
All data transmissions between user devices and our servers are encrypted in transit using industry-standard Transport Layer Security (TLS 1.3 / HTTPS). Database storage and backups are encrypted at rest using AES-256 standards. We never sell, rent, or trade your personal or business data to third-party advertisers or data brokers.
5. Account & Data Deletion (User Control)
In full compliance with Google Play's Account Deletion mandate, users have absolute control over their account lifecycle:
- In-App Immediate Deletion: Restaurant administrators can delete their entire account and all associated restaurant data directly inside the mobile app: Navigate to Admin Drawer / Admin Profile → Delete Account & Data. Once confirmed, all restaurant records, menu dishes, table history, and credentials are permanently purged from Firebase.
- Direct Email Deletion Request: Users who have uninstalled the app or prefer email-based deletion can request immediate erasure by emailing support@theiqnex.com from their registered administrator email. See our full Terms of Service & Deletion Policy.
6. Children's Privacy
Smart Restro is intended for business operators and restaurant patrons aged 18 and older. We do not knowingly collect personal data from children under the age of 13. If you become aware that a child has provided us with personal information, please contact us immediately.
7. Contact Information
If you have questions, feedback, or data privacy requests regarding this Privacy Policy, please reach out to our dedicated data privacy team: