Compliance & Data Protection

Privacy Policy

How KNOMI collects, safeguards, and processes data across our restaurant guest intelligence platform, built in strict accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act 2023) and the Information Technology Act, 2000.

Effective Date: September 1, 2026 | Last Updated: September 6, 2026

1. Introduction and Governance

KNOMI ("KNOMI", "we", "us", or "our") provides a cloud-based restaurant guest intelligence, digital QR menu, and self-ordering platform engineered in Bengaluru, Karnataka, India. This Privacy Policy articulates our transparent commitments and operational protocols regarding the collection, storage, protection, and handling of digital data.

We are committed to full compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act 2023), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. This policy applies to restaurant owners and operators ("Subscribers"), restaurant staff users, website visitors, and dining guests ("Diners").

2. Diner Privacy by Design (Zero Mandatory Phone or OTP Gate)

Unlike legacy QR ordering tools and food aggregators in India, KNOMI is architected around a fundamental principle: Diner Privacy by Design.

  • Zero Forced Phone Number Capture: Diners are never compelled to input a phone number, download an application, or verify an SMS OTP merely to browse a restaurant menu, view food photographs, or place a dine-in order.
  • Anonymous Session Tokens: When a diner scans a table QR code, the browser receives an ephemeral table session identifier. This token is tied strictly to that active dining session and expires automatically upon checkout or session closure.
  • Voluntary Information: If a diner chooses to receive a digital receipt via WhatsApp or email, or opts into a merchant-specific loyalty club, they may voluntarily share contact credentials. Such information is collected strictly with express affirmative consent and used solely for that specified purpose.
Zero Ad-Tech Tracking Guarantee

KNOMI does not embed third-party surveillance advertising pixels (such as Meta Pixel or Google Ads Remarketing) on guest ordering screens. Your guests dine without being tracked across the web.

3. Restaurant Operator Data Collected

To provide restaurant intelligence and fulfill business contracts with dining establishments, we collect necessary business and operational data:

  • Business Entity Information: Legal entity name, trade name, registered address, GSTIN (Goods and Services Tax Identification Number), and FSSAI food license number.
  • Administrative Contact Information: Name, professional email address, mobile phone number, and role designation of restaurant owners, general managers, and authorized operators.
  • Catalog and Operational Data: Menu items, ingredient tags, prices, tax classifications, table layouts, and kitchen display configurations.
  • Billing Credentials: Invoicing address and transaction history. Credit card and banking details are processed directly by RBI-authorized payment aggregators and are never stored on KNOMI servers.

4. Technical Telemetry and Behavioral Analytics (KNOMI Sense)

KNOMI processes technical interaction telemetry to power our behavioral intelligence engine (KNOMI Sense) and Kitchen Display System (KDS):

  • Menu Engagement Telemetry: Aggregated dwell time per dish card, dish scroll depth, pairing suggestions explored, and basket abandonment rates.
  • Operational Insights: Average order preparation pacing, ticket dispatch timing, and table turnover metrics.
  • Anonymization Standard: All behavioral analytics are strictly aggregated and de-identified. Telemetry is utilized exclusively to provide operational intelligence to the specific restaurant where the visit occurred and to refine algorithm performance.

5. Cloud Data Residency and Information Security

In full alignment with Indian data localisation mandates and enterprise cybersecurity standards:

Data Residency
100% Hosted in India (AWS ap-south-1 Mumbai & Cloudflare Edge)
In-Transit Encryption
TLS 1.3 with Strict HTTPS / HSTS Transport Security
At-Rest Encryption
AES-256 Bit Cryptographic Database Encryption
Access Architecture
Strict Permission-Based Access Control (PBAC)

6. Payment Gateway Integration and PCI-DSS Standards

For SaaS platform subscription fees paid by restaurant operators, KNOMI integrates with Reserve Bank of India (RBI) regulated payment aggregators including Razorpay, Cashfree, and Stripe India.

All financial transactions are conducted directly through PCI-DSS Level 1 compliant secure payment gateways. KNOMI does not store, view, or process debit/credit card CVVs, net banking passwords, or UPI PINs. Dine-in guest bill settlements are settled directly into the merchant's own bank account or POS terminal.

7. Data Retention and Erasure

We retain personal and business information only for the duration necessary to satisfy commercial agreements, resolve disputes, and meet statutory tax obligations under Indian law (such as GST audit trail mandates requiring record retention for up to 6 years).

Transient diner ordering sessions are automatically flushed and purged from active cache memory within 24 hours of table closure.

8. Rights under the DPDP Act 2023

Under the Digital Personal Data Protection Act, 2023, data principals are entitled to specific rights:

  • Right to Access Information: Request a concise summary of personal data being processed by KNOMI along with identity of third parties with whom data is shared.
  • Right to Correction and Erasure: Request the correction of misleading or inaccurate personal data, or the erasure of obsolete personal records where retention is not required by law.
  • Right of Grievance Redressal: Avail of an accessible grievance redressal mechanism provided by the Data Fiduciary.
  • Right to Nominate: Nominate an authorized representative to exercise data rights in the event of death or incapacity.

9. Grievance Redressal Officer

In compliance with Rule 5(9) of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the DPDP Act 2023, the designated Grievance Officer for KNOMI is detailed below:

Officer Designation
Grievance Redressal Officer
Direct Email
grievance@knomi.in
Physical Address
KNOMI, Bengaluru, Karnataka 560001, India
Statutory Response Time
Acknowledgement: 24 Hours | Resolution: 15 Working Days

For general support inquiries or billing assistance, please contact support@knomi.in.

Chat with sales