Privacy policy
Last updated: 15 September 2026
KhaataPeeta, including KhaataPeeta Backups, is operated by Kaura Enterprises. This policy explains how we handle information in our restaurant POS and optional backup features. Contact support@khaatapeeta.com with questions or data requests.
Restaurant and account information
We process account and restaurant information needed to provide the POS, control access, synchronise records and support the service. Depending on what your restaurant enters, records can include menus, orders, bills, payment records, customer contact details, staff records, inventory and settings. Some records are stored in your browser and saved restaurant data is stored in our hosted backend.
Restaurants decide what customer and staff information they enter and which authorised staff can access it. If you are a restaurant’s customer or employee, contact that restaurant about its use of your information. You may also contact us for assistance routing a request.
Optional Google Drive connection
Connecting Google Drive is optional and initiated by the restaurant owner. We request:
- Your primary Google email address, to identify and display the account connected for backups.
- Access to specific Drive files used with this app (the
drive.filepermission), to create a backup folder, upload backup files and verify upload metadata. This is not permission to access all files in your Drive.
Google’s permission wording includes reading, editing and deleting app-accessible files. The current backup feature creates new files and checks their size and checksum; it does not overwrite or automatically delete your existing backups. We do not request Gmail access or your Google password.
How backups and connection data are used
We use the Google connection solely to provide and maintain the backup feature you request. We store the connected email, encrypted refresh token, restaurant and owner identifiers, backup folder and latest file identifiers, schedule, timezone, and backup status or error information. Short-lived connection state helps securely complete authorisation.
When a backup runs, our server reads the saved restaurant snapshot and sends it to your chosen Google Drive as a JSON file. This may include customer and staff information in the restaurant records. Daily Drive backups can run without an open POS browser because the server uses the authorised connection. Backup files do not contain POS login accounts or the complete database schema.
Local-folder backups write a JSON copy to the folder you authorise on your computer while the POS is open. Local backup scheduling and folder access are stored in that browser.
Service providers and disclosure
We use Supabase for hosted application data, authentication and backend processing, Cloudflare for web hosting and delivery, and Google for the Drive destination you connect. These providers process information needed to deliver their part of the service. Hosting providers may process technical request information such as IP addresses and error logs for operation and security.
We do not sell Google user data or use it for advertising, credit decisions or training general-purpose AI models. Human access to Google user data is limited to your explicit agreement, necessary security investigation or legal requirements. KhaataPeeta’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
Security and backup-file access
We use HTTPS for transfers, encrypt stored Google refresh tokens, and restrict connection-management actions to authorised owners. The backup JSON itself is not encrypted by KhaataPeeta. Access to a local file depends on your computer permissions; access to a Drive file depends on your Google account and sharing settings. We do not automatically make backup files public. Protect your account and avoid sharing backup folders with people who should not see restaurant records.
Retention, disconnection and deletion
Connection and schedule information is kept while your Drive connection is active. Disconnect Drive in Settings to remove the active stored connection and stop future scheduled backups. We also attempt to revoke the Google authorisation when no other restaurant connection uses that Google account. You can revoke access directly from your Google Account’s connections page.
Disconnecting does not delete files already uploaded to Drive or written to your computer, or delete the restaurant’s POS data. You manage and delete those backup files yourself. Contact support to request deletion of restaurant or account information held by us. We may need to verify your authority; records required for legal, security or dispute purposes may need to be retained. Infrastructure backup and log copies may persist according to the providers’ retention processes.
Changes and contact
We will update this page when our practices change. If the Google integration needs new permissions or a new use of Google data, we will explain the change and request consent before that use. For access, correction, deletion or privacy enquiries, contact Kaura Enterprises at support@khaatapeeta.com.