Introduction
Welcome to SwiftDine.
SwiftDine is a restaurant technology platform that provides digital tools for restaurants, their staff, and their customers, including digital menus, QR-based table experiences, ordering, kitchen coordination, reservations, waitlists, table management, customer relationship management, loyalty and rewards, analytics, restaurant operations, reviews, recommendations, campaigns, and related services.
This Privacy Policy explains how SwiftDine collects, uses, stores, shares, protects, and otherwise processes personal information when you:
- visit or use the SwiftDine website;
- use a SwiftDine-powered restaurant experience;
- scan a SwiftDine QR code;
- browse a restaurant menu;
- create or use a customer account;
- place an order;
- participate in a restaurant waitlist or reservation;
- use loyalty or rewards functionality, including SwiftPoints;
- submit reviews;
- communicate with a restaurant through SwiftDine;
- use SwiftDine's restaurant management portals;
- interact with SwiftDine's marketing, analytics, AI, or recommendation features; or
- communicate with SwiftDine directly.
For purposes of this Privacy Policy, "SwiftDine", "we", "us", and "our" refer to [LEGAL ENTITY NAME], operating the SwiftDine platform.
- Registered / Principal Address
- [LEGAL ADDRESS]
- Privacy Contact
- swiftdineos@gmail.com
- Grievance Officer / Data Protection Contact
- [NAME / DESIGNATION]
- [EMAIL]
- [ADDRESS, IF REQUIRED]
This Privacy Policy should be read together with our Terms of Service.
Scope of This Policy
This Privacy Policy applies to personal information processed through SwiftDine's websites, applications, restaurant interfaces, customer interfaces, QR experiences, dashboards, APIs, and other services that link to this Policy.
It applies to information relating to:
Restaurant customers
People who interact with a restaurant using a SwiftDine-powered experience.
Restaurant personnel
Owners, managers, waiters, kitchen staff, administrators, and other authorized restaurant personnel using SwiftDine.
Restaurant businesses
Information relating to restaurants and their representatives, including business contact details, account information, operational information, menus, tables, staff information, and configuration data.
Website visitors
People who visit SwiftDine's public website or otherwise communicate with SwiftDine.
Applicable legal framework
SwiftDine operates from India. Where Indian law applies, this Policy is intended to operate consistently with the Digital Personal Data Protection Act, 2023 and rules made under it, the Information Technology Act, 2000 and rules made under it, and the Consumer Protection Act, 2019, each as amended from time to time.
Where you are located in a jurisdiction whose data-protection law applies to this processing, additional or different rights may be available to you under that law.
Confirm the full list of data-protection regimes SwiftDine is treating as applicable, and whether any jurisdiction-specific annexure is required: [TO BE CONFIRMED BY SWIFTDINE + LAWYER]
Important Relationship Between SwiftDine and Restaurants
SwiftDine provides technology infrastructure to restaurants.
Depending on the particular activity, SwiftDine and the restaurant may have different responsibilities concerning personal information.
For example, when a customer provides information to a restaurant through a SwiftDine-powered ordering experience, the restaurant may determine why that information is required for fulfilling the customer's order or providing restaurant services, while SwiftDine may process the information to provide the underlying technology.
Accordingly, the restaurant may be responsible for certain processing activities that it independently controls.
In broad terms, and subject to the facts of each activity: where SwiftDine processes information on a restaurant's instructions in order to deliver restaurant services, SwiftDine acts as a data processor and the restaurant acts as the data fiduciary or controller. Where SwiftDine determines the purposes and means of processing for its own platform purposes - including platform accounts, SwiftPoints, platform-level security, abuse prevention, and improving the Services - SwiftDine acts as a data fiduciary or controller in its own right.
Where appropriate, restaurant-specific privacy notices or policies may apply in addition to this Privacy Policy.
Nothing in this Privacy Policy should be interpreted as transferring responsibility for a restaurant's independent legal obligations to SwiftDine.
Confirm the final allocation of data fiduciary / data processor roles across each processing activity, and the form of the data-processing terms entered into with restaurants: [TO BE CONFIRMED BY SWIFTDINE + LAWYER]
Information We Collect
We collect information depending on how you use SwiftDine.
We do not necessarily collect every category described below from every person.
The categories of information we may process are described in this Section 4 and continue through Sections 5 to 12 of this Policy.
Identity and contact information
This may include:
- name;
- mobile phone number;
- email address;
- account identifiers;
- restaurant-specific customer identifiers;
- authentication information;
- communication preferences.
Where OTP authentication is used, SwiftDine may process the phone number necessary to verify the user's identity.
A SwiftDine customer profile is identified by mobile phone number. That profile is platform-wide and is held by SwiftDine rather than by any single restaurant.
Restaurant personnel information
Where you use SwiftDine as an owner, manager, waiter, kitchen user, or other restaurant staff member, we may process:
- name and role;
- staff account identifiers and authentication information;
- contact details provided by the restaurant;
- assigned permissions and portal access;
- shift, availability, and assignment information;
- actions performed in the platform, including order, table, billing, and configuration actions;
- operational performance information derived from timestamps on work you perform, such as response and service times;
- audit records of security-relevant and financially significant actions.
Restaurant staff information is generally provided and controlled by the employing restaurant. Operational performance information is derived from records the platform already creates in the course of service, and is made available to the restaurant for workforce management and service-quality purposes.
Restaurants are responsible for informing their personnel about this processing and for using it in accordance with applicable employment, privacy, and workplace law.
Information you provide about other people
Some features allow you to provide information about another person - for example, referring a friend, or making a reservation on behalf of someone else.
You should only provide another person's information where you are permitted to do so, and where you have told them that their information will be shared with SwiftDine and the relevant restaurant for that purpose.
Information we do not ask you to provide
SwiftDine does not require you to provide information revealing categories such as health, biometric identifiers, religious or political beliefs, or similar sensitive matters, and asks that you do not submit such information through free-text fields, reviews, or support messages.
Where you voluntarily provide a dietary preference or allergy note in order to be served safely, we process it only for that purpose and for the associated food-safety and service records.
Restaurant and Table Information
When you interact with SwiftDine at a restaurant, we may process information relating to:
- restaurant identifier;
- table number;
- QR code identifier;
- table session;
- dining session;
- check-in information;
- session timestamps;
- number of diners;
- waitlist position;
- reservation information;
- table allocation;
- seating status;
- ordering status;
- payment status;
- session duration.
QR codes may be associated with particular restaurant tables.
Scanning a QR code may therefore establish a relationship between your device/session and the relevant restaurant or table.
Customers do not select a restaurant table manually. A table is resolved only through a valid restaurant-issued QR or table proof, which limits the table information associated with you to the table you were actually seated at.
Where a restaurant operates in counter-service mode, there are no physical dining tables, and table-related information described in this Section is not created for that restaurant. Counter-service visits generate order, preparation, payment, and completion information instead.
Order and Transaction Information
When you place an order through SwiftDine, we may process:
- items ordered;
- quantities;
- prices;
- discounts;
- taxes;
- order status;
- restaurant;
- table/session information;
- order timestamps;
- customer session information;
- payment status;
- payment method;
- applicable loyalty redemption information;
- applicable promotional rewards.
Payment card, banking, UPI, or other payment credentials may be processed directly by third-party payment providers rather than stored by SwiftDine. SwiftDine generally retains only payment references, amounts, status, and settlement records necessary to evidence the transaction.
Where a third-party payment provider processes payment information, its own privacy policy and terms may also apply.
Order, billing, and settlement records form part of the restaurant's financial records and are retained accordingly. They are not deleted merely because a customer profile is closed, to the extent retention is required for tax, accounting, audit, or dispute-resolution purposes.
Reservations and Waitlists
If you use SwiftDine's reservation or waitlist functionality, we may process:
- name;
- phone number;
- party size;
- reservation date and time;
- waitlist entry;
- queue position;
- estimated waiting time;
- table allocation;
- seating status;
- reservation status;
- cancellation information;
- no-show information;
- timestamps associated with the reservation or waitlist.
Where a restaurant operates its own reservation or waitlist policies, those policies may also apply.
Loyalty and Rewards
SwiftDine may offer loyalty programs and rewards. These operate at two distinct levels, and it is important to understand the difference.
We may process:
- loyalty points earned;
- loyalty points redeemed;
- reward history;
- eligible rewards;
- reward type;
- redemption status;
- order/session associated with redemption;
- loyalty activity;
- customer-specific reward eligibility.
Rewards may have additional terms, expiry periods, eligibility conditions, or restrictions established by the relevant restaurant or SwiftDine program.
Platform loyalty (SwiftPoints)
SwiftPoints are a platform-wide loyalty currency operated by SwiftDine. A SwiftPoints balance is associated with your platform customer profile, which is identified by your mobile phone number, and may reflect activity across participating restaurants.
Because SwiftPoints are platform-level, redeeming them adjusts your platform balance rather than a balance held by any individual restaurant.
Restaurant loyalty
A restaurant may separately operate its own loyalty program, rewards, and point balances applicable only at that restaurant. Those balances and rules are configured and controlled by that restaurant.
Referrals
Where referral functionality is offered, we may process:
- the referral code or link issued to you;
- the fact that a referred person used it;
- the qualifying activity that made a referral eligible for a reward;
- referral status and any reward issued.
If you refer another person, you should only provide their details where you are permitted to do so. See Section 4.3.
Reviews and User Content
If you submit a review, rating, feedback, comment, or other content, we may process:
- review text;
- rating;
- categories selected;
- associated restaurant;
- associated order/session;
- timestamps;
- customer identifier;
- loyalty reward associated with submitting the review, where applicable.
You should not include sensitive personal information, payment credentials, passwords, or information about another person in public reviews or feedback.
Restaurant CRM Information
Restaurants using SwiftDine may have access to customer information generated through their interactions with the restaurant.
Depending on the restaurant's configuration and applicable law, this may include:
- customer name;
- contact details;
- visit history;
- order history;
- spending information;
- average spending;
- visit frequency;
- loyalty activity;
- preferences inferred from ordering behaviour;
- review history;
- reservation history;
- waitlist history;
- approximate time spent at the restaurant;
- customer classification or segmentation.
Restaurant CRM features are intended to help restaurants understand and serve their customers.
SwiftDine applies tenant isolation controls so that a restaurant can access customer information arising from activity at its own venue, and not the activity of the same customer at a different restaurant. Your platform-level profile settings remain under your control and are not controlled by any restaurant.
Restaurants remain responsible for their own use of customer information and should not use SwiftDine data for purposes prohibited by applicable law.
Analytics Information
SwiftDine may collect technical and usage information such as:
- IP address;
- browser type;
- device type;
- operating system;
- approximate location derived from technical information, where applicable;
- pages viewed;
- features used;
- timestamps;
- referring pages;
- session information;
- performance information;
- error information;
- QR scan events;
- interaction events.
Analytics information may be aggregated or otherwise de-identified where appropriate.
SwiftDine does not use precise satellite positioning to track customers. Any location information referred to above is approximate and derived from technical information such as an IP address.
QR Scan Information
SwiftDine may record QR interactions to measure restaurant engagement and improve the reliability of its QR experience.
A QR scan may generate information such as:
- QR identifier;
- restaurant identifier;
- table identifier;
- scan timestamp;
- visit/session identifier;
- whether the scan subsequently resulted in a customer interaction.
SwiftDine uses safeguards designed to prevent ordinary page refreshes, authentication steps, or repeated rendering from being incorrectly treated as separate QR scans.
How We Use Personal Information
We may use personal information to:
- provide SwiftDine services;
- authenticate users;
- establish and maintain dining sessions;
- process restaurant orders;
- facilitate reservations;
- manage waitlists;
- facilitate table allocation;
- coordinate kitchen and restaurant operations, including preparation and readiness estimates;
- process or facilitate payments;
- calculate and administer loyalty rewards, including SwiftPoints and referrals;
- process reviews and feedback;
- provide customer support;
- maintain restaurant CRM functionality;
- generate analytics;
- provide recommendations;
- generate restaurant insights;
- facilitate marketing campaigns where authorized;
- provide restaurants with operational and workforce performance information;
- maintain audit records of security-relevant and financially significant actions;
- administer restaurant subscriptions, plan entitlements, usage limits, and billing;
- prevent fraud, abuse, and unauthorized access;
- maintain application security;
- troubleshoot errors;
- improve SwiftDine;
- conduct product research;
- comply with applicable law;
- enforce our agreements;
- protect SwiftDine, restaurants, users, and other parties; and
- perform other purposes disclosed at the time information is collected.
Where applicable law requires a specified lawful basis or consent for a particular purpose, we process that information only on that basis, and we give notice of the purpose at or before the point of collection.
AI and Automated Recommendations
SwiftDine may use algorithmic or AI-assisted systems to provide features such as:
- menu recommendations;
- customer recommendations;
- restaurant insights;
- customer segmentation;
- campaign suggestions;
- operational recommendations;
- predictive estimates, including preparation and readiness estimates;
- loyalty recommendations;
- business intelligence.
These systems may use information such as order history, restaurant configuration, operational information, aggregated usage data, or other permitted information.
AI-generated recommendations are intended to assist users and restaurant operators.
Unless expressly stated otherwise, recommendations do not constitute guarantees, professional advice, financial advice, or decisions that SwiftDine represents as infallible.
SwiftDine does not represent that AI-generated recommendations will always be accurate, complete, or suitable for a particular situation.
SwiftDine does not use AI features to make decisions that produce legal effects concerning you or similarly significantly affect you without human involvement. Recommendations are presented to restaurant personnel, who decide whether to act on them.
Where SwiftDine uses third-party AI providers, it seeks contractual terms restricting the use of restaurant and customer personal information for training those providers' general-purpose models.
Confirm the current AI subprocessor list and the training-restriction terms actually in force with each provider: [TO BE CONFIRMED BY SWIFTDINE + LAWYER]
Where applicable law provides rights concerning automated decision-making, SwiftDine will address those rights in accordance with applicable requirements.
Communications
SwiftDine or a participating restaurant may contact users regarding:
- authentication;
- OTP verification;
- orders;
- reservations;
- waitlist status;
- table allocation;
- payments;
- loyalty activity;
- service notifications;
- security matters;
- customer support.
Communications may be delivered by SMS, WhatsApp, email, push, or in-application notification, depending on the channels configured and the contact details you have provided.
Marketing communications will be provided subject to applicable law and required consent or opt-out mechanisms. Marketing consent is the single control that governs promotional messaging and campaigns; where it has not been given, or has been withdrawn, you will not be included in marketing campaigns.
A user may not be able to opt out of essential service communications, such as authentication, order, payment, and security messages, for as long as the related service is being used.
Third-Party Services
SwiftDine may integrate with third-party services.
Examples may include:
- payment processors;
- messaging providers;
- email providers;
- hosting providers;
- analytics providers;
- authentication providers;
- cloud infrastructure;
- point-of-sale and restaurant systems;
- social media services;
- AI or machine-learning providers.
Third-party services may process information under their own terms and privacy policies.
SwiftDine does not control the privacy practices of independent third parties.
Where a restaurant chooses to connect a third-party integration to its SwiftDine account, that connection is made on the restaurant's instruction, and the restaurant is responsible for ensuring it is permitted to share the relevant information with that provider.
Confirm whether a named, publicly maintained subprocessor list should be published and linked from this Section: [TO BE CONFIRMED BY SWIFTDINE + LAWYER]
Data Security
SwiftDine takes reasonable technical and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, loss, destruction, or misuse.
Security measures may include:
- access controls;
- authentication, including one-time-password verification where applicable;
- role-based authorization;
- tenant isolation;
- encryption where appropriate;
- secure credential handling;
- audit mechanisms, including tamper-resistant audit records;
- monitoring;
- logging;
- database security;
- application security controls;
- least-privilege principles.
No electronic system can be guaranteed to be completely secure.
Accordingly, SwiftDine cannot guarantee absolute security of information transmitted through or stored on the platform.
You are responsible for keeping your authentication methods, devices, and one-time passwords secure, and for notifying us promptly if you believe your account has been accessed without authorization.
Data Retention
We retain personal information only for as long as reasonably necessary for:
- providing services;
- fulfilling contractual obligations;
- maintaining business records;
- complying with legal obligations;
- resolving disputes;
- enforcing agreements;
- preventing fraud;
- maintaining security;
- legitimate operational purposes.
Different categories of information may have different retention periods. In particular, financial, tax, settlement, and audit records are retained for the periods required by applicable law, even where other information relating to the same person has been deleted.
When information is no longer required, we may delete, anonymize, aggregate, or otherwise securely dispose of it, subject to applicable legal or operational requirements.
Specific retention schedules: [TO BE CONFIRMED BY SWIFTDINE + LAWYER]
Your Rights
Subject to applicable law and relevant conditions, individuals may have rights relating to their personal information, which may include rights to:
- obtain information about processing;
- access relevant personal information;
- request correction, completion, or updating of inaccurate or incomplete information;
- request deletion;
- withdraw consent where processing is based on consent;
- nominate another individual to exercise your rights in the event of your death or incapacity, where applicable law provides for nomination;
- obtain information regarding processing;
- raise grievances;
- exercise other rights available under applicable data-protection law.
Requests should be submitted to swiftdineos@gmail.com.
We may need to verify your identity before processing certain requests.
We respond to requests within the period required by applicable law. Where a request is complex, or where a large number of requests are received, we may extend that period to the extent permitted, and we will tell you if we do.
Statutory response timelines and any prescribed request format: [TO BE CONFIRMED BY SWIFTDINE + LAWYER]
Where your information is controlled independently by a restaurant, the restaurant may need to process the request or may need to participate in responding to it. We will direct your request appropriately and tell you where we have done so.
Exercising these rights is free of charge, and we will not treat you detrimentally for doing so.
Consent Withdrawal
Where processing is based on consent, you may withdraw consent subject to applicable law. Withdrawing consent should be as easy as giving it.
Withdrawal of consent does not necessarily affect the lawfulness of processing carried out before withdrawal.
Some services may no longer be available if information necessary for providing them cannot be processed.
Where you decline optional personalization, we process only what is needed to take, serve, and settle your order, and you will not receive personalized recommendations or marketing based on your history. You can change this later from your customer profile.
Children's Information
SwiftDine is not intended to knowingly collect personal information from children except where permitted and appropriately authorized under applicable law.
Where applicable law requires parental or guardian consent for processing a child's personal information, SwiftDine will follow the applicable requirements. Under Indian law, an individual below the age of eighteen years is a child, and verifiable consent of a parent or lawful guardian is required.
SwiftDine does not knowingly undertake tracking, behavioural monitoring, or targeted advertising directed at children.
If you believe a child has provided personal information to SwiftDine improperly, contact us at swiftdineos@gmail.com and we will take appropriate steps.
Confirm the age-verification and verifiable-parental-consent mechanism to be operated, and any exemption relied on: [TO BE CONFIRMED BY SWIFTDINE + LAWYER]
International Data Processing
SwiftDine and its service providers may process information in jurisdictions other than the jurisdiction where the user resides.
Where information is transferred internationally, SwiftDine will implement safeguards required by applicable law, and will not transfer personal information to any territory to which such transfer is restricted under applicable law.
Confirm hosting and processing locations, and the transfer mechanism relied on for each: [TO BE CONFIRMED BY SWIFTDINE + LAWYER]
Data Breaches and Security Incidents
SwiftDine maintains processes intended to identify, investigate, contain, and respond to security incidents.
Where applicable law requires notification of a personal-data breach to users, authorities, or other parties, SwiftDine will make such notifications within the applicable timeframe and through appropriate channels. In India, this may include notification to the Data Protection Board of India and to affected individuals.
Where a breach affects information processed on behalf of a restaurant, SwiftDine will notify that restaurant without undue delay so that it can meet its own obligations.
Restaurant Responsibilities
Restaurants using SwiftDine are responsible for:
- providing legally appropriate notices to their customers where required;
- obtaining required permissions or consents;
- using customer information only for permitted purposes;
- maintaining appropriate staff access controls, including promptly removing access for personnel who leave;
- informing their own personnel about the processing described in Section 4.2;
- complying with applicable privacy and consumer-protection laws;
- responding appropriately to customer requests concerning restaurant-controlled information.
SwiftDine may suspend access where a restaurant materially violates applicable law or SwiftDine's agreements.
Restaurants process personal information through SwiftDine subject to the data-protection terms forming part of their agreement with SwiftDine.
Changes to This Privacy Policy
We may update this Privacy Policy periodically.
When we make material changes, we may provide notice through:
- the SwiftDine website;
- application interfaces;
- email;
- account notifications; or
- other reasonable methods.
The "Last Updated" date will indicate when the Policy was most recently revised.
Where a change requires your consent under applicable law, we will obtain that consent before the change applies to you.
Grievance Redressal
Privacy-related complaints or requests may be directed to the contacts below. We acknowledge grievances on receipt and respond within the period required by applicable law.
- swiftdineos@gmail.com
- Grievance Officer
- [NAME]
- Designation
- [DESIGNATION]
- Address
- [ADDRESS]
- Response procedure
- [LAWYER TO FINALIZE BASED ON APPLICABLE LAW]
If you are not satisfied with our response, you may be entitled to escalate the matter to the relevant data-protection or consumer authority in your jurisdiction.
Contact Us
For privacy questions:
- SwiftDine
- Email: swiftdineos@gmail.com
- SwiftDine
- @swiftdineos
- Legal Entity
- [LEGAL ENTITY NAME]
- Registered Address
- [LEGAL ADDRESS]
Demonstration and Synthetic Data
SwiftDine's public interactive demo is a simulation intended for evaluation. It runs in your browser, uses fictional data, does not represent any real restaurant or customer, and does not collect personal information about you.
SwiftDine may also generate synthetic activity within its own systems for testing, demonstration, and quality-assurance purposes. Synthetic records are artificially generated, are identified as such internally, and do not describe real individuals.