Introduction & Corporate Identity
Welcome to DineLoom. DineLoom is an intelligent, multi-tenant SaaS restaurant management platform comprising Cloud Point-of-Sale (POS), contactless QR table ordering, real-time Kitchen Display Systems (KDS), table reservation management, multi-channel aggregator connectors, and business analytics.
DineLoom is conceived, developed, operated, and wholly owned by Rainbow Techsol, legally incorporated as RBTS Innovations Private Limited (hereinafter referred to as “Rainbow Techsol”, “Company”, “we”, “us”, or “our”).
We are committed to maintaining the confidentiality, integrity, and security of all personal, operational, and commercial data entrusted to us. This Privacy Policy informs restaurant owners, managers, staff members (collectively, “Restaurant Tenants” or “Merchants”), patrons/diners who interact with QR ordering menus (“Diners” or “Customers”), and visitors to our public websites (“Visitors”) of our policies regarding data collection, processing, protection, and retention.
DineLoom is a technological product of Rainbow Techsol (RBTS Innovations Private Limited). All legal obligations, contractual agreements, and privacy commitments for DineLoom are governed and executed by RBTS Innovations Private Limited. Official company website: https://rainbowtechsol.com.
Dual Roles: Data Controller & Data Processor
Depending on the nature of your interaction with the DineLoom platform, Rainbow Techsol operates in one of two distinct legal capacities:
For Restaurant Tenants & Visitors
Rainbow Techsol determines the purposes and means of processing personal data related to restaurant account registration, subscription billing, staff user authentication, customer support queries, and public website usage on dineloom.com and rainbowtechsol.com.
For Diners Ordering via QR Code
When a customer scans a table QR code or places an order at an affiliated restaurant, the individual restaurant business is the Data Controller. Rainbow Techsol acts strictly as a Data Processor, providing the digital infrastructure to record and route orders to the kitchen and point-of-sale.
If you are a diner and have specific questions regarding how a particular restaurant collects, stores, or utilizes your dining preferences, marketing contact information, or loyalty points, please consult that restaurant’s privacy policy directly or contact our Grievance Officer for facilitation.
Information We Collect
We collect information across three distinct categories to provide a fast, reliable, and secure restaurant management experience:
A. Restaurant Tenant & Staff Data
- Account & Business Profile: Restaurant legal name, trading name, organization slug, business physical address, contact telephone numbers, official email address, website, brand logo, and banner imagery.
- Tax & Statutory Credentials: GSTIN (Goods and Services Tax Identification Number), PAN, FSSAI registration details, or other applicable regional tax registration records for automated tax invoice generation.
- Staff User Credentials: Employee names, email addresses, assigned POS roles (e.g., Admin, Cashier, Kitchen Staff, Waiter), and cryptographically salted password hashes. We never store plain-text passwords.
- Menu & Operational Catalog: Categories, dishes, variants, add-ons, pricing, tax treatments, dietary tags (Veg, Non-Veg, Egg, Vegan, Gluten-Free), kitchen routing stations, and inventory stocks.
B. Diner & End-Customer Data (QR Ordering)
- Authentication & Verification: Customer mobile phone number or email address used for One-Time Password (OTP) login and receipt delivery.
- Order Details: Table identifier, items ordered, item customizations, preparation notes, order timestamp, order status progression, and total amounts.
- Dining Feedback: Voluntary customer star ratings, review comments, and service evaluations submitted through our post-meal feedback widget.
C. Technical, Device & Telemetry Data
- Network Identifiers: Internet Protocol (IP) address, browser user-agent, operating system, screen resolution, and language preference.
- Security Telemetry: Cloudflare Turnstile bot detection tokens, rate limiting counters, and session verification identifiers to prevent DDoS attacks and abusive automated requests.
Payment & Financial Security
DineLoom is engineered with strict financial data isolation principles. We do not store, process, or transmit unencrypted payment card details:
Rainbow Techsol and DineLoom never store raw credit card numbers, debit card numbers, CVVs, or bank account PINs on our servers. All digital transactions are processed directly by certified PCI-DSS Level 1 payment aggregators (including Razorpay, PhonePe, Cashfree, and Stripe).
For restaurants using integrated online payments, transactions are tokenized and processed via secure webhook handshakes directly with the licensed payment provider. We retain only non-sensitive transaction metadata: payment order ID, settlement status, transaction timestamp, payment gateway reference ID, and payment mode (UPI, Card, Netbanking, Cash) for accounting and audit reconciliation.
How We Use Collected Information
Rainbow Techsol processes collected data exclusively for legitimate commercial, operational, and statutory purposes, including:
- Real-Time Restaurant Operations: Routing orders instantly from table QR codes to POS billing counters and Kitchen Display Systems (KDS) via WebSockets.
- Transactional Messaging: Delivering verification OTPs, live order status notifications (Preparing, Ready, Served), and digital GST e-bills via SMS, WhatsApp, or Email.
- Business Intelligence & Analytics: Aggregating non-personally identifiable sales metrics, hourly order heatmaps, top-selling items, and category revenue for restaurant owners.
- Platform Security & Fraud Prevention: Detecting fraudulent transactions, preventing automated bot scraping, enforcing role-based permissions, and maintaining multi-tenant database isolation.
- Statutory Compliance: Generating audit-compliant GST invoices, tax calculation summaries, and maintaining regulatory financial records as required by Indian taxation statutes.
Third-Party Sharing & Sub-Processors
We uphold a strict policy against monetizing data. We do not sell, rent, lease, or trade personal information to third-party data brokers, marketers, or advertisers.
We share data only with vetted sub-processors essential to delivering the DineLoom platform:
| Service Category | Partner / Sub-Processor | Purpose | Data Transferred |
|---|---|---|---|
| Cloud Infrastructure | Google Cloud Platform (GCP) / AWS / Oracle Cloud | Encrypted application hosting, PostgreSQL database, storage | All encrypted database records & media assets |
| Payment Gateways | Razorpay / PhonePe / Stripe / Cashfree | Card, UPI, Netbanking payment settlement | Order amount, order ID, customer contact info |
| Communications & OTP | Fast2SMS / MSG91 / Twilio / Secure SMTP | Dispatching OTP logins, alerts, and digital bills | Recipient phone number / email, message text |
| Security & Bot Defense | Cloudflare | DDoS mitigation, CDN asset caching, Turnstile verification | IP address, request headers, browser telemetry |
| Legal & Law Enforcement | Competent Courts / Statutory Authorities | Compliance with valid judicial warrants or summons | Specific records required by applicable law |
Security & Multi-Tenant Isolation
Rainbow Techsol employs defense-in-depth security architecture to protect customer and merchant data:
- Cryptographic Protection: All external communication is enforced over modern TLS 1.3 / HTTPS encryption with automated SSL certificate renewal. Sensitive credentials and API tokens are encrypted at rest using AES-256 standards.
- Strict Tenant Isolation: Every database query in DineLoom is partitioned by unique restaurant identifier and organization ID, preventing cross-tenant data leakage.
- Access Controls & Authentication: Role-Based Access Control (RBAC), cryptographically signed JWT session tokens with strict expiration windows, and salted bcrypt password hashing (work factor 10+).
- System Monitoring: Real-time process supervision (PM2/Docker), container isolation, automated database backup routines, and audit logging of administrative events.
Data Retention Policies
We retain personal data only for as long as necessary to fulfill the purposes for which it was gathered, including operational service delivery, dispute resolution, and legal compliance:
- Tenant Account Records: Retained throughout the active subscription tenure. Upon account termination, tenant operational data is archived or deleted within 60 days, except records required by tax law.
- Financial & Invoicing Data: Invoices, tax computations, and payment settlement records are retained for up to 7 years in compliance with the Indian Companies Act, GST statutes, and income tax regulations.
- Diner OTP & Session Tokens: Customer authentication OTPs expire within 10 minutes. Session authentication tokens expire within 7 days unless renewed.
- Security Logs: Server access and error logs are retained for 90 days for forensic and security debugging purposes, after which they are systematically purged.
Your Privacy Rights
In accordance with India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and applicable international data protection regulations, you hold the following rights:
- Right to Access & Summary: You may request an itemized summary of personal data currently processed by Rainbow Techsol.
- Right to Correction & Erasure: You can update inaccurate data or request deletion of your personal data, subject to statutory retention obligations for financial and tax audits.
- Right to Withdraw Consent: Where processing is predicated on consent, you may withdraw your consent at any time without retroactive impact.
- Right to Grievance Redressal: You have the right to register complaints with our designated Grievance Officer regarding any perceived non-compliance or data handling concerns.
To exercise any of these rights, please submit an official written request to privacy@rainbowtechsol.com. We will acknowledge receipt within 48 hours and process verified requests within 30 calendar days.
Grievance Officer & Corporate Inquiries
If you have inquiries, feedback, or grievances concerning this Privacy Policy or Rainbow Techsol’s data handling practices, please contact our designated Grievance Officer:
Rainbow Techsol
DineLoom is an enterprise software product wholly owned and operated by Rainbow Techsol (RBTS Innovations Private Limited).
We reserve the right to revise this Privacy Policy periodically to reflect technological enhancements, statutory amendments, or operational modifications. The latest version will always be published on this URL with an updated effective date.