Privacy Policy
Last updated: June 2026 | Effective date: June 1, 2026
Tantrija Enterprises (“we”, “us”, or “our”) is the company behind AhaarScan, a commission-free QR ordering platform for restaurants. This Privacy Policy explains how we collect, use, share, and protect personal data when you use our website at www.ahaarscan.com or any of our services. We are committed to complying with India's Digital Personal Data Protection Act, 2023 (DPDP Act).
Contents
1. Information We Collect
For Restaurant Owners (account holders):
- Name, email address, and phone number (provided at sign-up)
- Restaurant details: name, address, GST number, UPI ID, logo, and business description
- Profile photo (optional)
- Payment information processed through Razorpay (we do not store full card numbers)
- Usage data: pages visited, features used, login times
For Customers (diners scanning QR codes):
- Mobile phone number (used for OTP-based authentication)
- Name and email address (provided optionally at checkout)
- Delivery address and location coordinates (only for delivery orders)
- Order history: items ordered, amounts paid, timestamps
- Marketing consent preference
Automatically collected data:
- IP address and browser/device type
- Session and page-view data (via cookies)
- Approximate geographic location (country/region level)
2. How We Use Your Information
We use the information we collect for the following purposes:
- To create and manage your restaurant or customer account
- To process and fulfil orders placed through the platform
- To send OTP verification messages via WhatsApp
- To process subscription payments and issue invoices
- To send transactional emails (order confirmations, password resets, billing receipts)
- To provide analytics reports to restaurant owners on their own order and customer data
- To improve platform performance, reliability, and features
- To respond to support requests and resolve disputes
- To comply with applicable laws and regulations
We do not use customer data collected on behalf of a restaurant to market our own services to those customers, nor do we sell personal data to third parties.
5. Data Retention
- Restaurant account data — Retained for the duration of the active subscription, plus up to 12 months after account closure (for legal and billing record-keeping purposes).
- Customer order data — Retained for up to 24 months from the date of the last order, unless the restaurant requests earlier deletion.
- Payment records — Retained for 7 years as required by Indian tax and accounting regulations.
- OTP logs — Deleted within 24 hours of generation.
6. Your Rights Under the DPDP Act 2023
Under India's Digital Personal Data Protection Act, 2023, you have the following rights as a data principal:
- Right to Access — You may request a summary of the personal data we hold about you.
- Right to Correction — You may request correction of inaccurate or incomplete personal data.
- Right to Erasure — You may request deletion of your personal data, subject to our legal retention obligations.
- Right to Grievance Redressal — You may lodge a complaint with our Grievance Officer (see Section 10).
- Right to Nominate — You may nominate another individual to exercise your rights on your behalf in the event of your death or incapacity.
To exercise any of these rights, email admin@ahaarscan.com with the subject line “Data Rights Request”. We will respond within 30 days.
7. Children's Privacy
AhaarScan is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us personal data, please contact us immediately and we will delete it.
8. Data Security
We implement industry-standard technical and organisational measures to protect personal data, including:
- HTTPS/TLS encryption for all data in transit
- Encrypted storage for sensitive fields (passwords are hashed using bcrypt)
- Access controls limiting data access to authorised personnel only
- Regular security reviews of our platform and infrastructure
No system is completely secure. In the event of a data breach that is likely to result in harm, we will notify affected users and the relevant authorities as required by law.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last Updated” date at the top of this page. If the changes are material, we will notify registered users by email. Continued use of the platform after changes are published constitutes acceptance of the updated policy.
10. Grievance Officer
In accordance with the Information Technology Act, 2000, and the DPDP Act, 2023, the name and contact details of the Grievance Officer are provided below:
Grievance Officer: Tantrija Enterprises — Grievance Team
Email: admin@ahaarscan.com
Response time: Within 30 days of receipt
11. Contact Us
For any general questions about this Privacy Policy or our data practices, please contact us at: