Legal
Privacy
Last updated 1 August 2026
Who this covers
Two different groups. Restaurants who use Resta to run their business, and diners who order through a restaurant using Resta. What we hold about each is different.
What we hold about diners
- Your order, and any cooking notes you added to it
- The table you ordered from, and the restaurant you were in
- Your phone number, only if you gave it at checkout or asked for a bill
- Any rating or feedback you left
We do not require an account to order, and we do not build a profile of you across restaurants. A restaurant sees the diners who ordered from that restaurant, and no others.
What we hold about restaurants
- Business details: name, address, GSTIN, contact information
- Staff names, phone numbers and roles
- Menus, orders, payments and invoices
Separation between restaurants
Every restaurant’s data is isolated at the database level, not merely by application code. One restaurant cannot read another’s orders, customers or menus, and we test that this holds on every change we deploy.
Who else sees your data
We use a small number of processors, each for one purpose:
- Cloudflare — hosting and content delivery
- Neon — database hosting
- Zavu — sending SMS and WhatsApp messages
- Dodo Payments — subscription billing for restaurants
- Anthropic — menu extraction from photographs you upload
We do not sell data, and we do not share it for advertising.
Where your data is stored
Currently in Singapore, with a move to an Indian region planned. We will update this page when that changes.
Your rights
Under the Digital Personal Data Protection Act, 2023 you may ask what we hold about you, ask us to correct it, or ask us to erase it. Write to privacy@resta.page. Some records — tax invoices in particular — must be retained for statutory periods and cannot be deleted on request.