Privacy Policy
How Soven Labs collects, uses, stores, processes, discloses, and protects information for the KhaanPaan platform.
1. Introduction
Soven Labs Private Limited ("Soven Labs", "Company", "we", "our", or "us") respects your privacy and is committed to protecting the information entrusted to us.
This Privacy Policy explains how we collect, use, store, process, disclose, and protect information when businesses, employees, operators, and customers interact with the KhaanPaan Restaurant Management Platform ("Platform").
This Policy applies to KhaanPaan POS, web applications, mobile applications, reporting portals, APIs, loyalty modules, customer-facing ordering experiences, and integrated services.
By accessing or using the Platform, you acknowledge and agree to the practices described in this Privacy Policy.
2. Scope of This Policy
This Policy applies to information collected directly from Customers using the Platform, through integrations with third-party systems, through websites operated by Soven Labs, through customer support interactions, and through software usage and system logs.
This Policy does not apply to third-party services not controlled by Soven Labs.
3. Information We Collect
Account Information. When registering or subscribing to the Platform, we may collect business name, restaurant name, contact person name, email address, mobile number, business address, GST information, and subscription information.
Business Operations Data. The Platform may store menu information, product catalogues, pricing information, orders, KOTs, bills, invoices, inventory records, supplier records, employee records, loyalty transactions, and business reports.
Customer Information. Restaurants using the Platform may collect customer information including name, mobile number, email address, delivery address, loyalty profile information, order history, and preferences. Such information is collected on behalf of the Restaurant using the Platform.
Device and Technical Information. We may automatically collect device identifiers, browser type, operating system, IP address, application version, network information, crash reports, and diagnostic information.
Usage Information. We may collect information relating to Platform usage, including login history, feature usage, transaction activity, user actions, configuration changes, and system interactions.
4. How We Use Information
We use information to provide services, operate the Platform, process transactions, generate reports, enable integrations, improve services, monitor performance, enhance functionality, fix bugs, develop new features, provide customer support, resolve issues, respond to requests, troubleshoot problems, detect fraud, prevent abuse, monitor suspicious activity, protect Platform integrity, meet legal obligations, maintain records, and respond to lawful requests.
5. Customer Data Ownership
Restaurants retain ownership of their business and customer data. Soven Labs does not claim ownership over menu data, customer records, orders, invoices, inventory records, or loyalty information.
Soven Labs acts as a technology provider and processes such information solely for the purpose of delivering Platform functionality.
6. Data Processing Role
Restaurant as Data Controller. For customer information collected by the restaurant through the Platform, the restaurant determines what data is collected, why data is collected, and how data is used. In such cases, the restaurant acts as the Data Controller.
Soven Labs as Data Processor. Soven Labs processes such information on behalf of the restaurant and in accordance with instructions necessary to provide Platform services.
7. Information Sharing
We do not sell personal information. Information may be shared only in the following situations:
- Service Providers: We may engage trusted service providers for cloud hosting, data storage, analytics, monitoring, customer support, and communication services. Such providers may process information only as necessary to perform services on our behalf.
- Third-Party Integrations: When enabled by the Customer, information may be shared with payment gateways, delivery aggregators, accounting systems, SMS providers, WhatsApp providers, and CRM systems. Such sharing occurs only to support requested functionality.
- Legal Requirements: We may disclose information where required to comply with law, respond to lawful requests, protect rights, investigate fraud, or enforce agreements.
- Corporate Transactions: In the event of a merger, acquisition, investment, or asset sale, relevant information may be transferred as part of the transaction.
8. Data Retention
We retain information for as long as reasonably necessary to provide services, maintain records, resolve disputes, meet legal obligations, and ensure security.
Certain transaction records and audit logs may be retained after account closure where required for compliance, fraud prevention, system integrity, or legal defense.
9. Audit Logs
To maintain accountability and operational security, we may record login events, user actions, configuration changes, discounts, voids, refunds, invoice changes, and permission changes.
These logs help investigate incidents, resolve disputes, detect misuse, and improve security. Audit records may be retained beyond operational data retention periods.
10. Data Security
Soven Labs implements commercially reasonable security measures including access controls, authentication mechanisms, encryption where appropriate, secure cloud infrastructure, monitoring, and logging.
However, no method of transmission or storage is completely secure. Accordingly, we cannot guarantee absolute security.
11. International Data Transfers
Where services involve infrastructure located outside India, information may be transferred and processed in other jurisdictions. Soven Labs takes reasonable steps to ensure such transfers are protected through appropriate safeguards.
12. Cookies and Similar Technologies
Our websites and applications may use cookies, session identifiers, local storage, and analytics technologies. These technologies help maintain sessions, improve performance, understand usage patterns, and enhance user experience.
Users may manage cookie settings through browser controls.
13. Artificial Intelligence Features
The Platform may use artificial intelligence and machine learning technologies to provide recommendations, insights, forecasts, operational assistance, and reporting enhancements.
AI systems may process Business Data to generate outputs. Such outputs are generated algorithmically and may not always be accurate. Customers remain responsible for all business decisions.
14. Customer Responsibilities
Customers are responsible for obtaining necessary consents from their customers, maintaining lawful privacy notices, complying with applicable data protection laws, and ensuring information entered into the Platform is lawful.
15. Children's Privacy
The Platform is intended for business use. We do not knowingly collect personal information from children under 18 years of age. If such information is identified, reasonable steps will be taken to remove it.
16. Your Rights under the DPDP Act, 2023
If you are an individual residing in India, you have the following statutory rights under the Digital Personal Data Protection Act, 2023 ("DPDP Act"):
- Right to Access (Section 11): You have the right to obtain a summary of the personal data we process about you, the processing activities, and the identities of other Data Fiduciaries/Processors with whom it has been shared.
- Right to Correction, Completion, and Erasure (Section 12): You have the right to request correction of inaccurate data, completion of incomplete data, or deletion/erasure of your personal data when the purpose of collection is fulfilled or consent is withdrawn, subject to compliance retention requirements (e.g. tax laws).
- Right to Grievance Redressal (Section 13): You have the right to file a grievance with our designated Grievance Officer regarding any processing of your personal data.
- Right to Nominate (Section 14): You have the right to nominate another individual to exercise your rights under the DPDP Act in the event of death or incapacity.
To exercise any of these rights, please complete our DPDP Rights Request Form or email our Grievance Officer.
17. Third-Party Websites
The Platform may contain links to third-party websites or services. Soven Labs is not responsible for the privacy practices, content, or security measures of such third-party services. Users should review applicable privacy policies independently.
18. Changes to this Privacy Policy
We may modify this Privacy Policy from time to time. Updated versions shall become effective upon publication. Continued use of the Platform after changes are published constitutes acceptance of the revised Policy.
19. Grievance Officer & Contact Us
Under the DPDP Act, 2023, the designated Grievance Officer for Soven Labs is:
Name: Mr. Anil Kumar
Designation: Head of Compliance & Data Protection Officer
Company: Soven Labs Private Limited
Grievance Email: grievance-officer@khaanpaan.app
General Support/Privacy Queries: privacy@khaanpaan.app
Address: Suite 402, Technology Park, Okhla Phase III, New Delhi, 110020, India
20. Governing Law
This Privacy Policy shall be governed by the laws of India. Any disputes relating to privacy matters shall be subject to the jurisdiction of courts located in New Delhi, India.