1.Who we are
Restaurant OS is a software service for restaurants, operated by The Research Desk (theresearchdesks.com). In this policy, “we”, “us” and “our” mean The Research Desk.
You can reach us about anything in this policy at info@theresearchdesks.com.
2.Who this policy covers
This policy covers:
- Restaurants that sign up for Restaurant OS, and the owners, managers and staff (including kitchen staff and riders) who use it.
- Visitors to the Restaurant OS website.
Guests who order from a restaurant’s ordering site are covered differently. See Guest data and the restaurant’s role below.
3.Information we collect
- Account details: name, email address, phone number and password. Passwords are handled by our authentication provider and stored only in hashed form; we never see them in plain text.
- Restaurant details: business name, branches, opening hours, menu, prices, taxes, branding, logos and photos you upload.
- Operational data you create in the app: orders, tables, kitchen tickets, inventory, suppliers and purchase orders, staff roles and shifts, promotions, loyalty settings and reports.
- Billing records: your plan, invoices, payment method (for example bank transfer, Easypaisa or JazzCash), payment references and the payment proof files you upload. We do not collect or store card numbers.
- Rider location: if a restaurant uses delivery, a rider’s approximate position is shared with that restaurant while the rider is on shift, so orders can be dispatched and tracked.
- Technical data: information our servers need to run and protect the service, such as IP address, browser type, and request and error logs, including rate-limiting records used to block abuse.
4.How we use information
- To provide Restaurant OS: sign-in, ordering, kitchen, delivery, inventory, loyalty, reporting and the rest of the features you use.
- To send service messages, such as order updates to guests on the restaurant’s behalf, invitations, billing notices and security emails.
- To issue invoices, review payment proofs and manage your subscription.
- To keep the service secure, prevent fraud and abuse, and fix problems.
- To answer your questions and provide support.
5.Guest data and the restaurant’s role
When a guest orders from a restaurant’s ordering site, creates a guest account there or joins its loyalty programme, the details they give (such as name, phone, email, delivery address, order history and points) belong to that restaurant.
The restaurant decides how that guest data is used and is responsible for it (it is the “controller”). Restaurant OS processes it on the restaurant’s behalf and only to run the service for that restaurant. Each restaurant’s data is kept separate from every other restaurant’s.
If you are a guest and want to access, correct or delete your information, please contact the restaurant you ordered from. If you cannot reach them, email us and we will pass your request on.
8.How we protect information
We take reasonable technical and organisational measures to protect data, including:
- Tenant isolation: database row-level security keeps each restaurant’s data separate, so one restaurant cannot read another’s.
- Role-based permissions: staff only see and change what their role allows.
- Encrypted connections: the service is served over HTTPS.
- Hashed passwords managed by our authentication provider.
- Private file storage: payment proofs are stored privately and opened through short-lived links.
No online service can be guaranteed to be completely secure. If we become aware of a security incident that affects your data, we will let you know as required by law.
9.How long we keep data, and deletion
We keep your data while your account is active, so the service works and your history is available to you.
If you cancel your subscription or ask us to delete your data, we will delete your restaurant’s data within one month (30 days) of the request, or of the end of your paid period if you asked for your access to continue until then.
We may keep a limited amount of information for longer where we must, for example:
- invoices and payment records we need for accounting and tax purposes;
- information needed to meet a legal obligation, resolve a dispute or enforce our terms;
- security logs needed to protect the service.
Anything we keep for these reasons is limited to what is needed and deleted once it is no longer required. Cancellation on its own does not delete data immediately; see our Terms for how cancellation works.
10.Your choices and rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, or to object to or restrict how it is used. Restaurant owners and staff can update most account and restaurant details directly in the app.
For anything else, email info@theresearchdesks.com from the email address on your account. We may need to confirm your identity before acting on a request. Guests should contact the restaurant first (see above).
11.Where data is processed
Our service providers may store and process data in countries other than your own. Where this happens, we rely on providers that apply appropriate safeguards to protect it.
12.Children
Restaurant OS is a business tool and is not directed at children. Restaurant accounts must be created by adults who are authorised to act for the business.
13.Changes to this policy
We may update this policy as the service changes. We will change the “Last updated” date above and, for significant changes, let account owners know by email or in the app before they take effect.
14.Contact
Questions or requests about privacy: info@theresearchdesks.com.