Privacy Policy

Effective date: 22 July 2026. This policy explains how RestoOS handles personal information.

1. Introduction

RestoOS ("RestoOS", "we", "us", or "our") provides cloud software for restaurants in Ghana, including point of sale, kitchen display, inventory, reports, WhatsApp ordering, Mobile Money payment verification, delivery management, and subscription billing.

This Privacy Policy describes how we collect, use, disclose, and safeguard personal information when you use our website, restaurant applications, partner portal, and related services (collectively, the "Service").

2. Information we collect

Restaurant operators and staff. When a restaurant registers or is onboarded, we collect business and account details such as restaurant name, contact information, staff names, usernames, email addresses, roles, order and payment activity, inventory records, expense entries, and configuration settings.

Platform administrators and partners. We collect names, email addresses, login credentials (stored as secure hashes), partner referral codes, commission records, Mobile Money payout details, and audit logs of administrative actions.

Customer and order data. When restaurants use WhatsApp ordering, delivery, or in-store POS, we process order contents, customer phone numbers, delivery addresses, payment references, and messages necessary to fulfil orders. Restaurants are responsible for informing their customers how order data is used.

Payment information. Subscription and setup payments are processed through Paystack. We store transaction references, amounts, and billing status — not full card or Mobile Money PIN details.

Technical data. We automatically collect device identifiers, browser type, IP address, session tokens, error logs, and usage events needed to operate and secure the Service.

3. How we use information

We use personal information to:

  • Provide, maintain, and improve the Service
  • Process orders, payments, subscriptions, and partner commissions
  • Authenticate users and enforce role-based access controls
  • Send operational notifications (for example, payout updates or subscription status)
  • Generate analytics and reports for restaurant operators
  • Detect fraud, abuse, and security incidents
  • Comply with legal obligations and respond to lawful requests
  • Provide customer and partner support

4. Legal basis and consent

We process personal information where necessary to perform our contract with restaurants and partners, to comply with law, to protect legitimate interests (such as security and fraud prevention), and where applicable based on consent — for example, when you contact us or opt in to marketing communications.

5. How we share information

We do not sell personal information. We may share data with:

  • Service providers that help us host infrastructure, process payments (Paystack), deliver WhatsApp messages (Meta/Twilio or configured providers), and monitor system reliability
  • Restaurant team members according to permissions set by each restaurant administrator
  • Referral partners only with respect to restaurants they referred and commission data linked to their account
  • Authorities when required by law, court order, or to protect rights, safety, and security
  • Business transfers in connection with a merger, acquisition, or sale of assets, subject to continued protection of your information

6. Data isolation and security

Each restaurant's operational data is logically isolated in our multi-tenant architecture. We use encryption in transit (HTTPS/TLS), hashed credentials, access controls, audit logging, and industry-standard safeguards appropriate to the nature of the data we process.

No method of transmission or storage is completely secure. We encourage strong passwords, limited role assignments, and prompt deactivation of staff who leave your business.

7. Data retention

We retain information for as long as your account is active or as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. When a restaurant account is deleted, associated operational data is removed according to our retention and backup schedules. Audit and billing records may be kept longer where required by law or legitimate business needs.

8. Your rights

Depending on applicable law, you may have the right to access, correct, delete, or restrict processing of your personal information, or to object to certain processing. Restaurant administrators can manage most staff data directly in the Service. Partners and administrators can update profile information in their respective portals.

To exercise rights or ask questions, contact us using the support details published on our website or in the Service settings.

9. Cookies and local storage

We use browser session storage and similar technologies to keep you signed in, remember preferences, and protect against unauthorized access. You can clear these through your browser settings, but some features may not function without them.

10. International processing

RestoOS is designed for use in Ghana. If data is processed outside Ghana by infrastructure or messaging providers, we take steps to ensure appropriate safeguards consistent with this policy and applicable data protection requirements.

11. Children

The Service is intended for businesses and adults. We do not knowingly collect personal information from children under 18 without appropriate parental or guardian involvement. Contact us if you believe we have collected such information.

12. Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised version on this page and update the effective date. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

13. Contact

For privacy questions or requests, contact RestoOS using the support email or WhatsApp number shown on our website or in your admin settings.

See also our Terms of Use.