DineLoomDineLoom
Terms & Conditions← Back to Home
Legal Documentation

Privacy Policy

This Privacy Policy details how Rainbow Techsol (registered corporate entity: RBTS Innovations Private Limited) collects, processes, protects, and handles personal and business information across the DineLoom restaurant management platform, point-of-sale (POS) software, QR table ordering system, and associated online services.

Effective Date:October 2026
Governing Entity:Rainbow Techsol (RBTS Innovations Private Limited)
Compliance:DPDP Act 2023 (India) & Global Standards
📑 Table of Contents
  • 1. Introduction & Corporate Identity
  • 2. Dual Roles: Controller & Processor
  • 3. Information We Collect
  • 4. Payment & Financial Security
  • 5. How We Use Collected Information
  • 6. Third-Party Sharing & Sub-Processors
  • 7. Security & Tenant Isolation
  • 8. Data Retention Policies
  • 9. Your Privacy Rights
  • 10. Cookies & Local Storage
  • 11. Grievance Officer & Inquiries
Related DocumentView Terms & Conditions →
01

Introduction & Corporate Identity

Welcome to DineLoom. DineLoom is an intelligent, multi-tenant SaaS restaurant management platform comprising Cloud Point-of-Sale (POS), contactless QR table ordering, real-time Kitchen Display Systems (KDS), table reservation management, multi-channel aggregator connectors, and business analytics.

DineLoom is conceived, developed, operated, and wholly owned by Rainbow Techsol, legally incorporated as RBTS Innovations Private Limited (hereinafter referred to as “Rainbow Techsol”, “Company”, “we”, “us”, or “our”).

We are committed to maintaining the confidentiality, integrity, and security of all personal, operational, and commercial data entrusted to us. This Privacy Policy informs restaurant owners, managers, staff members (collectively, “Restaurant Tenants” or “Merchants”), patrons/diners who interact with QR ordering menus (“Diners” or “Customers”), and visitors to our public websites (“Visitors”) of our policies regarding data collection, processing, protection, and retention.

💡 Key Relationship

DineLoom is a technological product of Rainbow Techsol (RBTS Innovations Private Limited). All legal obligations, contractual agreements, and privacy commitments for DineLoom are governed and executed by RBTS Innovations Private Limited. Official company website: https://rainbowtechsol.com.

02

Dual Roles: Data Controller & Data Processor

Depending on the nature of your interaction with the DineLoom platform, Rainbow Techsol operates in one of two distinct legal capacities:

Data Controller

For Restaurant Tenants & Visitors

Rainbow Techsol determines the purposes and means of processing personal data related to restaurant account registration, subscription billing, staff user authentication, customer support queries, and public website usage on dineloom.com and rainbowtechsol.com.

Data Processor

For Diners Ordering via QR Code

When a customer scans a table QR code or places an order at an affiliated restaurant, the individual restaurant business is the Data Controller. Rainbow Techsol acts strictly as a Data Processor, providing the digital infrastructure to record and route orders to the kitchen and point-of-sale.

If you are a diner and have specific questions regarding how a particular restaurant collects, stores, or utilizes your dining preferences, marketing contact information, or loyalty points, please consult that restaurant’s privacy policy directly or contact our Grievance Officer for facilitation.

03

Information We Collect

We collect information across three distinct categories to provide a fast, reliable, and secure restaurant management experience:

A. Restaurant Tenant & Staff Data

  • Account & Business Profile: Restaurant legal name, trading name, organization slug, business physical address, contact telephone numbers, official email address, website, brand logo, and banner imagery.
  • Tax & Statutory Credentials: GSTIN (Goods and Services Tax Identification Number), PAN, FSSAI registration details, or other applicable regional tax registration records for automated tax invoice generation.
  • Staff User Credentials: Employee names, email addresses, assigned POS roles (e.g., Admin, Cashier, Kitchen Staff, Waiter), and cryptographically salted password hashes. We never store plain-text passwords.
  • Menu & Operational Catalog: Categories, dishes, variants, add-ons, pricing, tax treatments, dietary tags (Veg, Non-Veg, Egg, Vegan, Gluten-Free), kitchen routing stations, and inventory stocks.

B. Diner & End-Customer Data (QR Ordering)

  • Authentication & Verification: Customer mobile phone number or email address used for One-Time Password (OTP) login and receipt delivery.
  • Order Details: Table identifier, items ordered, item customizations, preparation notes, order timestamp, order status progression, and total amounts.
  • Dining Feedback: Voluntary customer star ratings, review comments, and service evaluations submitted through our post-meal feedback widget.

C. Technical, Device & Telemetry Data

  • Network Identifiers: Internet Protocol (IP) address, browser user-agent, operating system, screen resolution, and language preference.
  • Security Telemetry: Cloudflare Turnstile bot detection tokens, rate limiting counters, and session verification identifiers to prevent DDoS attacks and abusive automated requests.
04

Payment & Financial Security

DineLoom is engineered with strict financial data isolation principles. We do not store, process, or transmit unencrypted payment card details:

🔒 Zero Cardholder Data Retention

Rainbow Techsol and DineLoom never store raw credit card numbers, debit card numbers, CVVs, or bank account PINs on our servers. All digital transactions are processed directly by certified PCI-DSS Level 1 payment aggregators (including Razorpay, PhonePe, Cashfree, and Stripe).

For restaurants using integrated online payments, transactions are tokenized and processed via secure webhook handshakes directly with the licensed payment provider. We retain only non-sensitive transaction metadata: payment order ID, settlement status, transaction timestamp, payment gateway reference ID, and payment mode (UPI, Card, Netbanking, Cash) for accounting and audit reconciliation.

05

How We Use Collected Information

Rainbow Techsol processes collected data exclusively for legitimate commercial, operational, and statutory purposes, including:

  • Real-Time Restaurant Operations: Routing orders instantly from table QR codes to POS billing counters and Kitchen Display Systems (KDS) via WebSockets.
  • Transactional Messaging: Delivering verification OTPs, live order status notifications (Preparing, Ready, Served), and digital GST e-bills via SMS, WhatsApp, or Email.
  • Business Intelligence & Analytics: Aggregating non-personally identifiable sales metrics, hourly order heatmaps, top-selling items, and category revenue for restaurant owners.
  • Platform Security & Fraud Prevention: Detecting fraudulent transactions, preventing automated bot scraping, enforcing role-based permissions, and maintaining multi-tenant database isolation.
  • Statutory Compliance: Generating audit-compliant GST invoices, tax calculation summaries, and maintaining regulatory financial records as required by Indian taxation statutes.
06

Third-Party Sharing & Sub-Processors

We uphold a strict policy against monetizing data. We do not sell, rent, lease, or trade personal information to third-party data brokers, marketers, or advertisers.

We share data only with vetted sub-processors essential to delivering the DineLoom platform:

Service CategoryPartner / Sub-ProcessorPurposeData Transferred
Cloud InfrastructureGoogle Cloud Platform (GCP) / AWS / Oracle CloudEncrypted application hosting, PostgreSQL database, storageAll encrypted database records & media assets
Payment GatewaysRazorpay / PhonePe / Stripe / CashfreeCard, UPI, Netbanking payment settlementOrder amount, order ID, customer contact info
Communications & OTPFast2SMS / MSG91 / Twilio / Secure SMTPDispatching OTP logins, alerts, and digital billsRecipient phone number / email, message text
Security & Bot DefenseCloudflareDDoS mitigation, CDN asset caching, Turnstile verificationIP address, request headers, browser telemetry
Legal & Law EnforcementCompetent Courts / Statutory AuthoritiesCompliance with valid judicial warrants or summonsSpecific records required by applicable law
07

Security & Multi-Tenant Isolation

Rainbow Techsol employs defense-in-depth security architecture to protect customer and merchant data:

  • Cryptographic Protection: All external communication is enforced over modern TLS 1.3 / HTTPS encryption with automated SSL certificate renewal. Sensitive credentials and API tokens are encrypted at rest using AES-256 standards.
  • Strict Tenant Isolation: Every database query in DineLoom is partitioned by unique restaurant identifier and organization ID, preventing cross-tenant data leakage.
  • Access Controls & Authentication: Role-Based Access Control (RBAC), cryptographically signed JWT session tokens with strict expiration windows, and salted bcrypt password hashing (work factor 10+).
  • System Monitoring: Real-time process supervision (PM2/Docker), container isolation, automated database backup routines, and audit logging of administrative events.
08

Data Retention Policies

We retain personal data only for as long as necessary to fulfill the purposes for which it was gathered, including operational service delivery, dispute resolution, and legal compliance:

  • Tenant Account Records: Retained throughout the active subscription tenure. Upon account termination, tenant operational data is archived or deleted within 60 days, except records required by tax law.
  • Financial & Invoicing Data: Invoices, tax computations, and payment settlement records are retained for up to 7 years in compliance with the Indian Companies Act, GST statutes, and income tax regulations.
  • Diner OTP & Session Tokens: Customer authentication OTPs expire within 10 minutes. Session authentication tokens expire within 7 days unless renewed.
  • Security Logs: Server access and error logs are retained for 90 days for forensic and security debugging purposes, after which they are systematically purged.
09

Your Privacy Rights

In accordance with India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and applicable international data protection regulations, you hold the following rights:

  • Right to Access & Summary: You may request an itemized summary of personal data currently processed by Rainbow Techsol.
  • Right to Correction & Erasure: You can update inaccurate data or request deletion of your personal data, subject to statutory retention obligations for financial and tax audits.
  • Right to Withdraw Consent: Where processing is predicated on consent, you may withdraw your consent at any time without retroactive impact.
  • Right to Grievance Redressal: You have the right to register complaints with our designated Grievance Officer regarding any perceived non-compliance or data handling concerns.

To exercise any of these rights, please submit an official written request to privacy@rainbowtechsol.com. We will acknowledge receipt within 48 hours and process verified requests within 30 calendar days.

10

Cookies & Local Storage

DineLoom utilizes lightweight cookies and browser LocalStorage mechanisms strictly for essential operational and functional requirements:

  • Essential Authentication: Storing JWT session tokens (e.g., authToken, customerAuthToken) to keep restaurant operators and diners authenticated.
  • Cart & Table State: Storing active dining cart items, chosen table identifiers, and order drafts locally to prevent data loss during network interruptions.
  • Security: Anti-CSRF verification cookies and bot mitigation tokens from Cloudflare.

We do not deploy invasive third-party cross-site behavioral tracking cookies on DineLoom. You can configure your browser to decline cookies, but doing so may impact table ordering and POS dashboard functionality.

11

Grievance Officer & Corporate Inquiries

If you have inquiries, feedback, or grievances concerning this Privacy Policy or Rainbow Techsol’s data handling practices, please contact our designated Grievance Officer:

🏢

Rainbow Techsol

RBTS Innovations Private Limited

DineLoom is an enterprise software product wholly owned and operated by Rainbow Techsol (RBTS Innovations Private Limited).

Corporate Entity
RBTS Innovations Private Limited
Brand / Trade Name
Rainbow Techsol
Product
DineLoom — Restaurant Management Platform
Parent Website
rainbowtechsol.com
Platform Portal
dineloom.com
Privacy & Grievance Email
privacy@rainbowtechsol.com
Support Email
support@dineloom.com
Jurisdiction
Bhabua, Kaimur, Bihar, India

We reserve the right to revise this Privacy Policy periodically to reflect technological enhancements, statutory amendments, or operational modifications. The latest version will always be published on this URL with an updated effective date.

DineLoomDineLoom

Powered by Rainbow Techsol (RBTS Innovations Private Limited)

HomeRestaurantsTerms & ConditionsPrivacy Policy

© 2026 DineLoom. All rights reserved.

A product of Rainbow Techsol (RBTS Innovations Private Limited).