1. Introduction
RestoSuite Private Limited ("RestoSuite", "we", "us", or "our") is committed to protecting the privacy and personal data of our customers, users, and visitors. We strive to handle your information with transparency, integrity, and care.
This Privacy Policy explains how we collect, use, disclose, and safeguard personal data in connection with our restaurant management software and services. It applies to individuals and businesses in Singapore and Malaysia who access or use our platform.
By using RestoSuite's services, you acknowledge that you have read and understood this Privacy Policy. If you have any questions, we encourage you to contact us before using our services.
2. Information We Collect
We endeavour to collect only the information reasonably necessary to provide and improve our services. The categories of data we may collect include:
Personal Information
- Full name and job title
- Email address and phone number
- Business name and billing address
- Login credentials (stored in encrypted form)
Restaurant & Business Data
- Menu items, pricing, and inventory records
- Order history and transaction data
- Staff accounts and access logs
- Business intelligence and report data
Usage & Technical Data
- Browser type, device type, and operating system
- IP address and general location (country/city level)
- Pages visited, features used, and session duration
- Error logs and crash reports
Cookies & Similar Technologies
We use cookies and similar tracking technologies to maintain session state, remember preferences, and gather aggregated analytics. Please see Section 9 for details.
3. How We Use Your Information
We aim to use the information we collect for clearly defined and legitimate purposes, including:
- Providing our services: Operating, maintaining, and delivering the features of the RestoSuite platform.
- Account management: Creating and managing your account, authentication, and support.
- Product improvement: Analysing usage patterns to improve existing features and develop new ones.
- Communication: Sending service-related notices, updates, and—where you have consented—promotional messages about our products and offers.
- Billing: Processing subscription payments and managing invoicing in accordance with your contract.
- Legal compliance: Meeting our obligations under applicable laws, including Singapore's PDPA and Malaysia's PDPA 2010.
- Security: Detecting, investigating, and preventing fraudulent or unauthorised activities.
We endeavour not to use your data for purposes beyond those described above without first seeking your consent.
4. Data Sharing & Disclosure
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
We may share your information in the following limited circumstances:
Service Providers
We work with carefully selected third-party vendors (e.g., cloud hosting providers, payment processors, analytics services) who assist us in operating our platform. These providers are contractually required to protect your data and use it only as instructed by us.
Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will endeavour to notify affected users in advance where reasonably practicable.
Legal Requirements
We may disclose your data if required to do so by law, court order, or government authority, or when we believe in good faith that disclosure is necessary to protect our legal rights, prevent fraud, or ensure the safety of our users.
With Your Consent
We may share your data with third parties for other purposes when you have given us explicit consent to do so.
5. Data Security
We are committed to implementing reasonable technical and organisational measures to protect your personal data against unauthorised access, loss, misuse, or alteration. Our security practices include:
- SSL/TLS encryption: All data transmitted between your browser and our servers is encrypted.
- Access controls: Access to personal data is restricted to authorised personnel on a need-to-know basis.
- Secure storage: Data is stored on servers with industry-standard security controls.
- Regular reviews: We periodically review and update our security practices.
While we strive to protect your information, no method of transmission or storage is completely secure. We encourage you to use strong, unique passwords for your account and to notify us promptly if you suspect any unauthorised access.
6. Data Retention
We aim to retain your personal data only for as long as is necessary to fulfil the purposes described in this policy, or as required by applicable laws.
- During your subscription: Your data is retained for the duration of your active service agreement.
- After termination: Upon termination of your account or subscription, we will generally retain your data for a period of up to 12 months to allow for data retrieval requests, dispute resolution, or legal compliance, after which we will securely delete or anonymise it.
- Legal obligations: Certain records (e.g., financial transaction logs) may need to be retained for longer periods as required by law.
7. Your Rights (Singapore PDPA)
If you are located in Singapore, the Personal Data Protection Act 2012 (PDPA) provides you with the following rights in relation to your personal data:
- Right of Access: You may request access to the personal data we hold about you and information about how it has been used or disclosed in the past year.
- Right of Correction: You may request that we correct any inaccurate or incomplete personal data we hold about you.
- Right to Withdraw Consent: Where you have provided consent for us to collect, use, or disclose your personal data, you may withdraw that consent at any time. Please note that withdrawal may affect our ability to provide certain services.
- Right to Data Portability: Subject to PDPA requirements, you may request that we provide your data in a commonly used format.
To exercise any of these rights, please contact our Data Protection Officer at sales_sg@restosuite.ai. We will endeavour to respond to your request within 30 days.
8. Your Rights (Malaysia PDPA 2010)
If you are located in Malaysia, the Personal Data Protection Act 2010 (PDPA 2010) provides you with rights concerning your personal data as processed in connection with our services:
- Right of Access: You may request access to personal data we hold about you.
- Right of Correction: You may request corrections to inaccurate, incomplete, or misleading personal data.
- Right to Withdraw Consent: You may withdraw your consent for us to process your data, subject to any legal or contractual restrictions.
- Right to Prevent Processing: You may request that we cease or limit processing of your personal data in certain circumstances.
To exercise your rights under Malaysia's PDPA 2010, please contact us at sales_sg@restosuite.ai. We will endeavour to address your request in a timely manner in accordance with applicable requirements.
10. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please do not hesitate to reach out to us.
RestoSuite Private Limited
Registration No.: 202334466Z
7 Holland Vlg Wy, #05/03-05 Tower B, Singapore 275748
We strive to respond to all privacy-related enquiries within a reasonable timeframe, and typically within 30 days of receipt.