Nadha LabsEffective: 7 August 2026Last Updated: 7 August 2026

Privacy Policy

How Nadha Labs collects, processes, protects, and respects business and personal data under Indian privacy laws.

Notice: These documents are drafted with reference to applicable Indian legal requirements, including the Digital Personal Data Protection Act, 2023, notified Digital Personal Data Protection Rules, 2025, Consumer Protection (E-Commerce) Rules, 2020, and applicable GST Invoice Rules.

1. Who Operates OMLU

This Privacy Policy applies to the OMLU restaurant software platform operated by Nadha Labs("Nadha Labs", "we", "us", or "our"), headquartered in India.

2. Scope and Regulatory Framework

This policy governs personal data and business information processed through the OMLU platform, customer QR ordering interfaces, staff applications, and web services. It is drafted with reference to the Digital Personal Data Protection Act, 2023 (DPDP Act), the notified Digital Personal Data Protection Rules, 2025 (DPDP Rules), the Information Technology Act, 2000, and applicable rules published by the Ministry of Electronics and Information Technology (MeitY).

We distinguish between baseline statutory requirements effective upon notification and phased technical implementation timelines designated under MeitY rules.

3. Context-Dependent Data Roles (Fiduciary vs. Processor)

[LEGAL REVIEW REQUIRED] Under Indian privacy law, data roles depend strictly on the processing context:

  • Customer Dining & Order Data (Processor Context): For dining guest table orders, item instructions, service calls, and bill generation, the Restaurant acts as the primary Data Fiduciary under the DPDP Act. Nadha Labs processes such customer data solely on behalf of the Restaurant as a Data Processor pursuant to commercial terms. The Restaurant is responsible for providing appropriate notices to its dining guests.
  • Account, Staff & Security Data (Fiduciary Context): For restaurant registration, owner/staff account management, credential hashing, platform security monitoring, audit logging, rate limiting, and subscription administration, Nadha Labs acts as an independent Data Fiduciary.

4. Categories of Data Collected

We collect data in the following categories to provide and secure OMLU:

  • Restaurant Profile Data: Restaurant name, unique slug, contact email, phone number, city, GSTIN (if configured), order prefix, timezone.
  • Account & Credentials: Owner and staff full names, usernames, email addresses, bcrypt-hashed passwords, role permissions (`owner`, `admin`, `staff`, `kitchen`), staff PIN hashes.
  • Customer Dining Data: Session tokens, HMAC-SHA256 table participant tokens, 4-digit table join codes, customer item notes, order timestamps.
  • Financial & Bill Snapshots: Itemized orders, subtotal, CGST/SGST/IGST tax breakdowns, discount values, total bill amounts, bill numbers, receipt tokens, recorded payment method labels (`cash`, `upi`, `card`).
  • Technical & Security Metadata: IP addresses, User-Agent header data, audit logs (`AuditLog`: action, actor_user_id, target, timestamp, IP address, metadata JSON), WebPush subscription tokens.
  • Uploaded Assets: Menu image files uploaded by owners for AI menu extraction.

5. Data Provided Directly

We collect data directly provided when an Account Owner registers a profile, creates staff user credentials, configures menu items/prices/taxes, uploads menu images, or submits customer order instructions.

6. Data Collected Automatically

When users interact with OMLU, our servers automatically log technical metadata including IP address, browser type, request timestamps, WebSocket connection metrics, and rate-limiter state for security and operational diagnostics.

7. Customer Dining Data Processing

Customers browsing QR menus do not register account credentials. Dining sessions are managed via temporary session tokens and 4-digit join codes. Customer item notes and ordering activity are processed solely to communicate tickets to the kitchen display and generate the table bill.

8. Purpose of Processing

We process data exclusively for:

  • Authenticating users and isolating multi-tenant restaurant profiles.
  • Routing orders to kitchen display screens and staff POS interfaces.
  • Calculating bill subtotals, GST breakdowns, and issuing printable receipts.
  • Delivering real-time WebSocket updates and browser push notifications.
  • Processing menu image uploads via AI menu extraction.
  • Preventing abuse, rate-limit violations, unauthorized access, and credential theft.

9. Lawful Basis and Notice

Where Nadha Labs acts as Data Fiduciary, we process personal data based on your explicit consent granted during registration and account operation, or for legitimate uses necessary to enforce system security, prevent fraud, and fulfill statutory compliance under the DPDP Act 2023.

10. Security & Abuse Prevention

We enforce HTTPS encryption for all external API endpoints, JWT token expiry, rate-limiting on sensitive endpoints (such as `/public/restaurants/register`), and tenant-isolated database constraints (`restaurant_id` foreign keys) to safeguard database integrity.

11. Service Communications

We send transactional service communications (such as password resets, operational alerts, and subscription updates) to registered contact emails. We do not sell personal data or send unsolicited third-party marketing SMS or emails.

12. Data Sharing and Infrastructure Providers

We do not sell, rent, or trade personal data. We share data only with verified cloud infrastructure processors strictly necessary to deliver the Service:

  • Vercel Inc.: Web application hosting and CDN distribution.
  • Render / Cloud Providers: Backend API infrastructure hosting.
  • Managed PostgreSQL & Redis Providers: Encrypted data storage and realtime pub/sub caching.
  • Google Gemini API (Google LLC): Image-to-JSON menu extraction processing for menu image uploads.

13. Cross-Border Processing

Cloud infrastructure hosting servers (such as Vercel CDN nodes or cloud database instances) may process encrypted data internationally in accordance with cloud security standards and applicable DPDP Act cross-border transfer rules notified by the Central Government.

14. Data Retention

We retain restaurant sales, bill, and transaction records for the duration of the active account relationship and as required by Indian fiscal and tax laws (minimum 6 years for accounting compliance). Audit logs and security records are retained for security analysis.

15. Account Deletion and Rights

Account Owners may request profile closure and data purge by contacting our Grievance Officer. Upon verification, we will delete or anonymize personal credentials, subject to statutory tax retention exceptions.

16. Legal Exceptions

We may disclose information if required by law, court order, statutory law enforcement request, legal summons, or to protect the safety, rights, and security of Nadha Labs, OMLU users, or the public.

17. Security Safeguards

We implement technical and organizational measures including AES-GCM encryption for sensitive keys, salted password hashing, and strict CORS policies. While we adhere to industry standards, no internet transmission is 100% secure, and we cannot guarantee absolute security.

18. Breach Notification

In the event of a verified personal data breach affecting your information, Nadha Labs will notify affected Data Fiduciaries / users and the Data Protection Board of India in accordance with requirements under the DPDP Act 2023 and DPDP Rules 2025.

19. Grievance Officer Details

In accordance with the DPDP Act 2023 and Information Technology rules, you may contact our designated Grievance Officer for privacy concerns or data rights requests:

Grievance Officer: Grievance Officer, Nadha Labs

Entity: Nadha Labs

Email: privacy@omlu.app

Address: Kerala, India

Response Time: Within 15 days of receiving valid written notice.

20. Children's Privacy

OMLU is designed strictly for commercial restaurant operational management and adult restaurant guests. We do not knowingly target or collect personal data from individuals under 18 years of age.

21. Cookies and Local Storage

OMLU uses functional browser local storage and session storage (such as theme preferences, session tokens, and order draft keys) strictly necessary for navigation, authentication, and offline draft recovery. We do not use third-party tracking cookies for targeted behavioral advertising.

22. Policy Changes

We may update this Privacy Policy periodically. Modifications will be posted on this route with an updated effective date. Continued access after updates constitutes acknowledgement of the updated Privacy Policy.