Privacy Policy
What Servkro collects, why, who can see it, and how to have it removed. This covers both the restaurants that use Servkro and the diners who order through it.
Last updated 17 September 2026
Who this is from
- Operator of Servkro
- Servkro
- Registered address
- JAIPUR
- [email protected]
- Phone
- +91 797601 6321
Two different relationships
Servkro is used by two kinds of people, and the law treats them differently.
- Restaurants are our customers. We decide what we collect about them and why, so for that information we are the data fiduciary.
- Diners are the restaurant’s guests, not ours. When you scan a table code, the details you give belong to that restaurant. We hold them on its behalf and act on its instructions — we do not sell them, share them with other restaurants, or use them to market anything of our own.
That split matters when you want something deleted: ask the restaurant you gave it to. If you cannot reach them, write to us and we will pass it on and help.
What we collect from diners
Only what an order needs. There is no diner account and no password.
- Your phone number, if you give one. It is what links this visit to your loyalty points and your past orders at that restaurant.
- Your name and email, only if you type them. Both are optional.
- What you ordered, what it cost, and how it was paid for.
- Feedback and ratings you submit, and the loyalty points, coupons and game results attached to your number.
- A session record for the table you scanned: which table, when it was opened, your browser’s user agent, and a device fingerprint. This is what stops one table reading another table’s bill.
- If you allow notifications, the push subscription your browser issues. It carries no name or number.
We do not ask for your address, your date of birth, or any payment card details. Card and UPI details are never seen by Servkro — see “Payments” below.
What we collect from restaurants
- The account: owner name, email, phone, the restaurant’s name, address and GST details.
- Staff logins, roles and PINs — stored hashed, never in a readable form.
- Business records created by using the product: menu, orders, bills, invoices, expenses, shift cash-ups and reports.
- Wallet top-ups, commission charged, and the invoices we issue for them.
- Documents uploaded during verification, held outside the public web root and served only against a signed, expiring link.
How one restaurant is kept out of another’s data
Separation is enforced by the database, not by our code remembering to ask nicely. Every table carrying restaurant data has a row-level security policy on it, and the application connects as a database role that is not permitted to bypass those policies. A query that fails to name a restaurant returns nothing at all rather than everything.
Payments
Wallet top-ups are processed by Razorpay. Your card number, UPI PIN and bank credentials are entered on Razorpay’s systems and are never sent to, or stored by, Servkro. We receive only the outcome of the payment and the identifiers we need to reconcile it.
Notifications
Push notifications are opt-in and your browser controls them. Allowing them lets the restaurant you scanned tell you when your order is ready and send you its own offers. You can withdraw that at any time in your browser’s site settings, and we stop sending as soon as your browser tells us the subscription is dead.
How long it is kept
- Table sessions expire on their own and are cleaned up nightly.
- One-time codes and rate-limit records are short-lived and deleted automatically.
- Loyalty points expire on the schedule the restaurant sets.
- Orders, bills and tax invoices are kept for as long as Indian tax law requires them to be kept. We cannot delete an issued tax invoice on request; a gap in an invoice series is itself a compliance failure.
- A restaurant that leaves can export everything first. Records are then archived, and destroyed only where no tax invoice, platform invoice or payment stands against them.
Your rights
You can ask what we hold about you, ask for it to be corrected, ask for it to be deleted, and withdraw a consent you have given. Diners should ask the restaurant first, since the information is theirs. Write to us using the details on the Contact page and we will answer.
Changes
When this policy changes, the date at the top changes with it. A change that materially affects restaurants is told to them directly rather than left here to be discovered.