Privacy Notice
Effective 6 October 2026
In short: we collect only what we need to run your digital menu, we ask your permission for the things that need it, we never sell personal data, and you can see, correct, download or delete your data at any time.
1. Who we are
Vikalp is a digital-menu service operated by the Vikalp operator, an individual (“we”, “us”). For the personal data described below we are the “Data Fiduciary” under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”).
This notice covers three groups of people: restaurant owners who use Vikalp; guests who open a restaurant’s menu; and anyone who writes to us.
2. What we collect, why, and for how long
| Data | Why we use it | How long we keep it |
|---|---|---|
| Data: Account: your name, email address and password | Why we use it: To create and secure your account and to contact you about it. Your password is stored only as a one-way hash by our sign-in provider; we cannot read it. | How long we keep it: While your account is open. Deleted when you ask us to erase your account (see section 8). |
| Data: Restaurant details: name, description, address, city, phone and WhatsApp number, Google review link, logo and cover photo | Why we use it: To build and publish your menu page. Once you publish, these details are public by design: anyone with your menu link can see them. | How long we keep it: While your account is open. |
| Data: Menus: sections, dishes, prices, dietary labels, dish photos, branches | Why we use it: To run your menu and QR codes. | How long we keep it: While your account is open. |
| Data: Plan and payment records (plan, amount, date, reference). We never receive or store card, UPI PIN or bank login details | Why we use it: To provide your plan and to keep the accounting records the law requires. | How long we keep it: As long as Indian tax and accounting law requires, even after account deletion. |
| Data: Referral code, if you enter one | Why we use it: To credit the partner who introduced you. | How long we keep it: While your account is open. |
| Data: Your activity in the dashboard (for example “menu published”, “dish edited”) | Why we use it: To keep your account secure and to help you if something goes wrong. | How long we keep it: 1 year (the DPDP Rules require processing logs to be kept for at least a year). |
| Data: AI usage records (which feature, how many tokens, success or failure; not the content) | Why we use it: To apply your daily AI allowance and detect abuse. | How long we keep it: 1 year. |
| Data: Menu photos you upload for AI import | Why we use it: Only to read your menu, and only if you allow AI processing (section 4). They are deleted as soon as they have been read, and any left behind are swept within 2 days. | How long we keep it: Up to 2 days. |
| Data: Your consent choices and the version of this notice you accepted | Why we use it: To prove what you agreed to and to honour changes you make. | How long we keep it: While your account is open and for at least a year after it is closed. |
| Data: Requests and complaints you send us, and our replies | Why we use it: To answer you and to show we did so. | How long we keep it: Three years after the request is closed. |
| Data: Backups of the above | Why we use it: To restore the service after a fault. | How long we keep it: Rolling 14 days. |
| Data: Technical logs: the page or API route used, result, time and a request number. We do not put your email, password or the content you type in these logs | Why we use it: To keep the service running and secure. | How long we keep it: Short, platform-managed retention. |
We ask only for what these purposes need. Your name, email and a password are needed for an account; everything else is information you choose to add to your menu page.
3. Guests who open a menu
If you scan a QR code and view a restaurant’s menu, you do not need an account and we do not ask for your name, phone or email. We count, per restaurant and per day, how many times a menu, section or dish was viewed and which words were searched, so the restaurant can see what interests guests. These counts are added together; they are not linked to you, your device or your address. Search words are kept for 90 days and view counts for about 13 months. Please do not type personal information into a menu’s search box.
Our hosting provider briefly sees your network address to deliver the page and to block abuse such as floods of requests; we do not store it in our own records.
6. How we protect it
- Encryption in transit (HTTPS) everywhere, and access limited to the owner of each restaurant: one restaurant can never read another’s data.
- Administrator access requires multi-factor authentication and every administrative change is recorded in an append-only audit trail that cannot be edited afterwards.
- Rate limiting, input validation and regular backups.
If a personal-data breach affects you, we will tell you promptly, describing what happened, the likely consequences, what we have done and what you can do, and we will report it to the Data Protection Board of India as the law requires.
7. Children
Vikalp is a business service for people aged 18 or over. We do not knowingly collect personal data of children. If you believe a child has given us data, tell us (section 9) and we will delete it.
8. Your rights and how to use them
Under the DPDP Act you may:
- Know and access the personal data we hold about you and who we share it with. Owners can download everything in Settings → Privacy & data.
- Correct inaccurate or incomplete data. Most details can be edited directly in the dashboard; for the rest, send a correction request.
- Erase your data and close your account. We will delete it unless a law requires us to keep it (for example billing records), and we will tell you what we kept and why.
- Withdraw consent at any time, as easily as you gave it, in Settings → Privacy & data. Withdrawing consent to this notice means closing your account.
- Nominate another person to exercise these rights if you die or become unable to.
- Complain to us, and to the Data Protection Board of India if we do not resolve it.
Signed-in owners can raise requests in Settings → Privacy & data. Anyone else can use the grievance form. We aim to reply within 30 days and will in any case respond within the time the law allows.
9. Grievance Officer and contact
Grievance contact, Vikalp · Online form
Please use our grievance process first. If you are not satisfied with our answer, you may complain to the Data Protection Board of India.
10. Changes, and language
If we change this notice in a way that matters, we will update the version number and ask signed-in owners to review and accept it again before they continue. This notice is in English; if you would like it in Hindi or another language listed in the Eighth Schedule to the Constitution, ask us through the grievance form.
See also our Terms of Service.