Privacy policy
Last updated: 3 october 2026
1. Who this policy covers
ALOK KUMAR SAHU, proprietor of Grewdo ("we", "us", "BillRaw") operates:
- the Staff App: an Android application with Cashier, Chef, Manager and Owner roles, used by cafés, restaurants and other outlets ("Business Customers", "Outlets") that subscribe to our software; and
- the Customer Ordering Site (order.billraw.in): a web page a walk-in customer reaches by scanning a QR code at a table, with no account or app install required ("End Customers").
This Privacy Policy explains what personal data we collect from each group, why, how we protect it, and what rights you have. Where a provision applies to only one group, we say so.
It is written to align with India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025; the Information Technology Act, 2000 and the IT (Reasonable Security Practices and Sensitive Personal Data or Information) Rules, 2011; and Google Play's User Data Policy.
2. Information we collect
2.1 From Business Customers and Staff (Owner, Manager, Cashier, Chef)
| Category | Examples | Who provides it |
|---|---|---|
| Account identity | Full name, email address, phone number, role, password (stored only as a salted hash) | Owner, at sign-up and when adding staff |
| Outlet information | Outlet name, address, phone number, GST or business registration details (if provided), plan | Owner or Manager |
| Operational data | Orders, order items, prices, tables, voids, stock levels and stock adjustments | Created as staff use the app |
| Audit and security logs | Logins, who voided or discounted an order and why, timestamps, device/session identifiers | Created automatically |
| Device and diagnostic data | Device model, OS version, app version, crash logs, IP address | Created automatically |
We do not ask staff for Aadhaar, PAN, biometric, health or any other "sensitive personal data" under the SPDI Rules.
2.2 From End Customers (QR ordering, no login)
| Category | Examples |
|---|---|
| Order details | Items, quantities, special instructions, table and outlet identifier |
| Optional contact info | Name and/or phone number, only if the Outlet asks for it to hand over the order |
| Technical data | Browser and device type, IP address, order-status requests |
We do not collect or process card numbers, UPI IDs, bank details or wallet credentials. Payment is pay at the counter: the End Customer pays the Outlet directly, and we record only the method (cash, UPI or card) and amount for the Outlet's own sales reporting.
2.3 What we do not collect
- We do not access your contacts, photos, microphone or call logs.
- We do not use advertising SDKs, ad identifiers or third-party marketing trackers.
- We do not sell personal data to anyone.
- We do not use GPS or precise location. An outlet's address is text the Owner types in.
3. Why we use this information
We use personal data only for these purposes:
- To provide the service: accounts, sign-in, taking orders, sending them to the kitchen display in real time, low-stock alerts and bills.
- To keep the platform secure: spotting unusual patterns (such as many voids), keeping audit logs, rate-limiting abuse and enforcing role-based access.
- To give Owners business insights: daily sales, cash/UPI/card split and sales trends about the Outlet's business, not about identifying individual End Customers.
- To talk to Business Customers: service updates, billing reminders and support replies.
- To comply with law: lawful requests from courts, police or regulators, and our own tax and accounting records.
- To improve the product: aggregated, de-identified usage and crash patterns so we can fix bugs.
4. Legal basis (DPDP Act, 2023)
- Consent: the main basis. Owners and End Customers see a clear notice before data is processed, and can withdraw consent at any time (see Section 8).
- Legitimate uses recognised by the Act: such as security and fraud-prevention logs, and complying with legal obligations like keeping transaction records for tax.
5. How we share information
We do not sell or rent personal data. We share it only as below:
| Recipient | What they get | Why |
|---|---|---|
| Neon (managed PostgreSQL database, Singapore region) | The data described above, encrypted at rest | To store the data that powers the app |
| Render (backend hosting, Singapore region) | Data in transit while requests are processed | To run our servers |
| Resend (email delivery) | Your email address and the email content | To send sign-up and password-reset codes |
| Within an Outlet's own account | Staff see only what their role allows; only the Owner sees full sales and audit logs | Core functionality |
| Law enforcement / regulators | Only the data covered by a valid legal order | Legal compliance |
| A future acquirer | Data as a business asset, with the same or stronger protection and notice to users | Business continuity |
5.1 Data stored outside India
Our database and servers are in Singapore. The DPDP Act allows transfer outside India except to countries the Central Government restricts; none are restricted at the time of writing. Our providers apply security safeguards equivalent to those in Section 6.
6. How we protect your information
- Encryption in transit: HTTPS (TLS) for all traffic and secure WebSockets for live order updates.
- Encryption at rest: the database encrypts stored data.
- Passwords: hashed with bcrypt, never stored in plain text.
- Sign-in: short-lived access tokens plus a refresh token in an HttpOnly cookie.
- Role-based access: enforced on every server route, not just hidden in the app.
- Audit logging: voids, discounts and price changes are logged with who, what and when.
- Rate limiting on sign-in and ordering, and minimal staff access to production data.
No system is 100% secure. If a breach is likely to affect you, we will notify affected Outlets and users, and the Data Protection Board of India once that provision is in force, without delay.
7. How long we keep data
| Data | Kept for |
|---|---|
| Account and operational data (orders, menu, stock) | While the Outlet's subscription is active |
| Audit logs | 1 year, or longer if needed for a legal dispute |
| Data after an account closes | Deleted or anonymised within 30 days, except records we must keep by law (such as tax records) |
| End Customer order data | Only as long as needed to fulfil and show the order, then anonymised into the Outlet's sales figures |
8. Your rights
You can ask us to access, correct or erase your personal data, withdraw consent (as easily as you gave it), nominate someone to act for you, and raise a grievance (Section 11), escalating to the Data Protection Board of India if unresolved. Email support@billraw.in to use any of these rights.
9. Deleting your account
- In the app: Settings → Delete Account (Owners), or ask your Owner or Manager to remove your staff profile.
- Without the app: follow the steps on billraw.in/delete-account, or email support@billraw.in from your registered email address. We delete your account and data within 7 days and confirm by email.
Records we must keep by law (such as financial records for tax) are retained only as long as required.
10. Children
The Staff App is a workplace tool for adults (18+). The Customer Ordering Site shows a menu, like a printed menu card, and we do not knowingly collect data that identifies a child. If we learn we have, we delete it promptly.
11. Grievance Officer and contact
Under the Information Technology Act, 2000, the IT Rules, 2021, and the DPDP Act, 2023:
- Grievance Officer: ALOK KUMAR SAHU
- Email: support@billraw.in
- Address: Big Bunny , Vesu , Surat, Gujarat - 394210
- Response time: we acknowledge grievances within 48 hours and resolve them within 30 days.
12. Cookies and local storage
The Staff App keeps you signed in using secure on-device storage. The Customer Ordering Site uses minimal browser storage to remember your cart and order status. This website (billraw.in) does not use advertising or tracking cookies.
13. Changes to this policy
We may update this policy as features or laws change. We will post the new version here with a new date, and tell Outlet Owners in the app or by email before material changes.
14. Governing law
This policy is governed by the laws of India. Courts at Surat, Gujarat have exclusive jurisdiction.