Skip to content

Legal

Privacy Policy

Last updated 30 September 2026

This policy explains what information Restaurant OS collects, why, how it is protected, and how you can have it deleted. We have tried to keep it short and in plain language.

1.Who we are

Restaurant OS is a software service for restaurants, operated by The Research Desk (theresearchdesks.com). In this policy, “we”, “us” and “our” mean The Research Desk.

You can reach us about anything in this policy at info@theresearchdesks.com.

2.Who this policy covers

This policy covers:

  • Restaurants that sign up for Restaurant OS, and the owners, managers and staff (including kitchen staff and riders) who use it.
  • Visitors to the Restaurant OS website.

Guests who order from a restaurant’s ordering site are covered differently. See Guest data and the restaurant’s role below.

3.Information we collect

  • Account details: name, email address, phone number and password. Passwords are handled by our authentication provider and stored only in hashed form; we never see them in plain text.
  • Restaurant details: business name, branches, opening hours, menu, prices, taxes, branding, logos and photos you upload.
  • Operational data you create in the app: orders, tables, kitchen tickets, inventory, suppliers and purchase orders, staff roles and shifts, promotions, loyalty settings and reports.
  • Billing records: your plan, invoices, payment method (for example bank transfer, Easypaisa or JazzCash), payment references and the payment proof files you upload. We do not collect or store card numbers.
  • Rider location: if a restaurant uses delivery, a rider’s approximate position is shared with that restaurant while the rider is on shift, so orders can be dispatched and tracked.
  • Technical data: information our servers need to run and protect the service, such as IP address, browser type, and request and error logs, including rate-limiting records used to block abuse.

4.How we use information

  • To provide Restaurant OS: sign-in, ordering, kitchen, delivery, inventory, loyalty, reporting and the rest of the features you use.
  • To send service messages, such as order updates to guests on the restaurant’s behalf, invitations, billing notices and security emails.
  • To issue invoices, review payment proofs and manage your subscription.
  • To keep the service secure, prevent fraud and abuse, and fix problems.
  • To answer your questions and provide support.

5.Guest data and the restaurant’s role

When a guest orders from a restaurant’s ordering site, creates a guest account there or joins its loyalty programme, the details they give (such as name, phone, email, delivery address, order history and points) belong to that restaurant.

The restaurant decides how that guest data is used and is responsible for it (it is the “controller”). Restaurant OS processes it on the restaurant’s behalf and only to run the service for that restaurant. Each restaurant’s data is kept separate from every other restaurant’s.

If you are a guest and want to access, correct or delete your information, please contact the restaurant you ordered from. If you cannot reach them, email us and we will pass your request on.

6.How information is shared

We do not sell personal data, and we do not use it for advertising.

We share information only:

  • With the service providers that host and run Restaurant OS for us, such as Supabase (database, authentication and file storage) and our web hosting and email delivery providers. They may only use it to provide their service to us.
  • Within a restaurant, according to the roles and permissions the restaurant sets for its staff.
  • When required by law, or to protect the rights, safety and security of our users and the service.

7.Cookies and local storage

We use only what the service needs to work. We do not use advertising or tracking cookies.

  • Sign-in cookies keep you logged in securely. Without them you cannot use your account.
  • Branch cookie (ros-branch) remembers which branch a guest chose on a restaurant’s ordering site.
  • Local storage in your browser remembers preferences such as light or dark theme, the contents of a guest’s cart, and a few display settings on kitchen and rider screens.

You can clear cookies and local storage in your browser settings at any time. You will then need to sign in again, and a saved cart will be emptied.

8.How we protect information

We take reasonable technical and organisational measures to protect data, including:

  • Tenant isolation: database row-level security keeps each restaurant’s data separate, so one restaurant cannot read another’s.
  • Role-based permissions: staff only see and change what their role allows.
  • Encrypted connections: the service is served over HTTPS.
  • Hashed passwords managed by our authentication provider.
  • Private file storage: payment proofs are stored privately and opened through short-lived links.

No online service can be guaranteed to be completely secure. If we become aware of a security incident that affects your data, we will let you know as required by law.

9.How long we keep data, and deletion

We keep your data while your account is active, so the service works and your history is available to you.

If you cancel your subscription or ask us to delete your data, we will delete your restaurant’s data within one month (30 days) of the request, or of the end of your paid period if you asked for your access to continue until then.

We may keep a limited amount of information for longer where we must, for example:

  • invoices and payment records we need for accounting and tax purposes;
  • information needed to meet a legal obligation, resolve a dispute or enforce our terms;
  • security logs needed to protect the service.

Anything we keep for these reasons is limited to what is needed and deleted once it is no longer required. Cancellation on its own does not delete data immediately; see our Terms for how cancellation works.

10.Your choices and rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, or to object to or restrict how it is used. Restaurant owners and staff can update most account and restaurant details directly in the app.

For anything else, email info@theresearchdesks.com from the email address on your account. We may need to confirm your identity before acting on a request. Guests should contact the restaurant first (see above).

11.Where data is processed

Our service providers may store and process data in countries other than your own. Where this happens, we rely on providers that apply appropriate safeguards to protect it.

12.Children

Restaurant OS is a business tool and is not directed at children. Restaurant accounts must be created by adults who are authorised to act for the business.

13.Changes to this policy

We may update this policy as the service changes. We will change the “Last updated” date above and, for significant changes, let account owners know by email or in the app before they take effect.

14.Contact

Questions or requests about privacy: info@theresearchdesks.com.

Questions about this policy?

Email us and we will get back to you.

Email us

info@theresearchdesks.com