Overview
Plateform.cloud ("Plateform," "we," "our") provides QR-based guest ordering,
kitchen operations, and reporting tools for restaurants, cloud kitchens, and hotels.
This policy covers three kinds of people: the businesses that sign up
for Plateform, the staff those businesses invite onto the platform, and
the guests who scan a table or room code to place an order. We've tried
to write this in plain language rather than pure legal boilerplate — if anything is
unclear, the contact section at the bottom is a real inbox.
In short: we collect what's needed to run ordering, kitchen, and
reporting for your outlet — menu data, order data, table and room session data, and
account details for your staff. We don't sell personal data, and guest ordering
sessions are scoped tightly so one guest's session can't be seen by another.
Who this policy covers
- Business accounts — the restaurant, cloud kitchen, or hotel that
signs up for Plateform (Owner-level account).
- Staff accounts — Managers, Staff, Waiters, and Kitchen users
invited by a business account.
- Guests — anyone who scans a table QR code or a per-stay room code
to view a menu or place an order. Guests do not create a Plateform account; their
data is tied to the ordering session, not to a persistent identity, unless they
choose to provide their name for a hotel stay record.
What we collect
From businesses and staff
- Account details: name, email, phone number, role, outlet(s) assigned.
- Business details: outlet name, address, tax settings, currency, branding assets
(logos, cover images) uploaded to the menu builder.
- Menu content: sections, items, prices, modifiers, allergen tags, and any images
sourced through the built-in Unsplash search or uploaded directly.
- Usage data: pages visited in the dashboard, actions taken (e.g. approving an
order, moving a kitchen ticket), and device/browser information for security and
debugging.
- Billing information, handled by our payment processor — we do not store full card
numbers on our own servers.
From devices and browsers
Standard technical data collected by any web application: IP address, browser type,
device type, and timestamps — used for security, fraud prevention, and diagnosing
issues, not for advertising.
Guest ordering data
Because guest ordering is central to the product, it gets its own section.
- Table sessions: we record the items ordered, quantities,
modifiers, timestamps, and which participant in a shared session added which item
(shown to the table as "added by R" style labels). We do not require a guest name,
phone number, or login to place a dine-in order.
- Per-stay room codes: each hotel stay's code is scoped to that stay
only. If the property chooses to record a primary guest name against the stay, that
name is visible to hotel staff for that stay's order history and nowhere else. Once
a code is regenerated for the next guest, the previous stay's data becomes read-only
order history and the code itself stops working immediately.
- Payment: where a payment QR (UPI, PayNow, bank code) is shown at
checkout, the guest pays through their own banking or payment app directly — we
facilitate the display of that code but do not process or store the payment
credentials ourselves.
- Historical accuracy: every order snapshots its prices, item names,
and tax rates at the moment it was placed, so past receipts remain accurate even if
a business later edits its menu.
How we use data
- To operate the core product: guest ordering, kitchen ticket routing, table and
room session management, waiter-call and bill-request notifications.
- To generate the analytics and reporting features shown to Owners and Managers —
revenue, order volume, average order value, and top-selling items.
- To secure accounts and detect abuse, such as unusual login activity or attempts to
access a session that isn't yours.
- To provide support when a business or staff member contacts us with an issue.
- To improve the product — we may use aggregated, de-identified usage patterns to
decide what to build next. This aggregated analysis is never used to single out a
specific guest.
We do not use guest ordering data to build advertising profiles, and we do not sell
personal data to third parties.
Sharing & processors
We share data only in the following circumstances:
- Within a business's own account: data is scoped to the business
that collected it. Our multi-tenant architecture isolates each business on its own
subdomain, and one business cannot see another's orders, menus, or staff.
- Service providers: infrastructure hosting, payment processing,
email delivery, and similar functions are handled by vetted third-party processors
bound by contract to use data only to provide that service.
- Custom domains: if a business connects its own domain (e.g.
order.yourrestaurant.com), the domain registrar and certificate authority involved in
that automated DNS/SSL setup only receive the technical information needed to issue
and verify the domain — not guest ordering data.
- Legal requirements: if required by law, regulation, or a valid
legal process.
- Business transfers: if Plateform is involved in a merger,
acquisition, or asset sale, data may transfer as part of that transaction, subject to
the same protections described here.
Retention
Order history is retained for as long as a business's account is active, so that
analytics, reporting, and historical receipts remain available and accurate. Retired
hotel-stay codes are kept as read-only history rather than deleted outright, since
that history is itself a feature of the product. If a business closes its account, we
retain data only as long as needed for legal, tax, or dispute-resolution purposes, then
delete or anonymize it.
Security
We use encryption in transit (HTTPS/SSL, including for connected custom domains) and
access controls scoped to each business's isolated subdomain. Staff accounts are
role-based, so a Kitchen login only ever sees the ticket queue, not billing or
business-level settings. No system is perfectly secure, and we encourage businesses to
use strong, unique passwords for Owner and Manager accounts and to remove staff access
promptly when someone leaves.
Your rights
Depending on where you're located, you may have some or all of the following rights
over your personal data:
| Right | What it means |
| Access | Ask what personal data we hold about you. |
| Correction | Ask us to fix inaccurate data. |
| Deletion | Ask us to delete personal data, subject to legal retention needs. |
| Portability | Ask for a copy of your data in a portable format. |
| Objection | Object to certain uses of your data. |
For business and staff accounts, most of these can be handled directly from the
dashboard. For guest ordering data tied to a specific table or stay, contact the
business you ordered from, or reach us directly using the details below and we'll
coordinate with the relevant business.
Cookies & similar technologies
The dashboard and guest ordering pages use essential cookies and local storage to keep
you logged in, remember a table session, and keep a guest's cart in sync across
devices at the same table. We don't use third-party advertising trackers. Guests
arriving via an in-app browser (e.g. from an Instagram or Facebook link) may be
prompted to continue in their device's regular browser so their session isn't lost —
this is a UX safeguard, not a tracking mechanism.
Children's privacy
Plateform is a business tool intended for use by adults operating or ordering from
restaurants and hotels. We do not knowingly collect personal data from children beyond
what a guest voluntarily includes in an order (which typically involves none). If you
believe a child has provided us with personal data, contact us and we'll address it.
Changes to this policy
We'll update this page as the product evolves, and update the "last updated" date at
the top when we do. For material changes, we'll make a reasonable effort to notify
business account owners directly.