Skip to content

Privacy policy

Draft for review. This policy is not yet legally binding. Bracketed items and the effective date must be confirmed by counsel before publication.

1. Who we are & scope

Ensmbl Technologies Pvt. Ltd. ("EnsmblOS", "we", "us") operates a multi-app restaurant and retail platform: self-checkout kiosk, point-of-sale, kitchen display, digital menu boards, electronic shelf labels, an admin dashboard, and a customer loyalty app. This policy explains what personal data we handle, why, and the choices you have, in line with India’s Digital Personal Data Protection Act, 2023 ("DPDPA").

We act in two distinct roles. For visitors to our website, sales enquiries, and the merchant staff who hold EnsmblOS accounts, we are a Data Fiduciary (controller). For the personal data of our merchants’ own end-customers that flows through the platform (for example order, loyalty and OTP data), we act as a Data Processor on the instructions of that merchant, who remains the Data Fiduciary for their customers.

2. Personal data we collect

Depending on how you interact with us, we may handle:

  • Data you give us: name, business name, phone number, email, role, and (for paid subscriptions) billing details. Card and UPI details are collected and processed by our payment partner, never stored by us.
  • Data processed on a merchant’s behalf (as Processor): their customers’ name, phone, email and transaction/loyalty history, entered at the point of sale or kiosk.
  • Data collected automatically: device and technical data (browser, OS, IP), usage and diagnostic data, and cookies when you use our website (see below).

3. How we use personal data

  • To provide, operate, secure and support the service, and to process transactions and loyalty on behalf of merchants;
  • To manage accounts, billing and subscriptions;
  • To improve and develop the platform, using aggregated or de-identified data wherever possible;
  • To meet legal, tax and regulatory obligations;
  • To send you service and marketing communications. We send marketing only where you have consented, and you can withdraw consent at any time.

4. Cookies & tracking

Our website uses strictly-necessary cookies (for security and sign-in), and, with your consent, analytics and marketing cookies to understand traffic and improve the site. You can control non-essential cookies through your browser or our cookie settings. Our device and in-store applications do not use advertising trackers.

5. Consent & your control

Where the DPDPA requires it, we process personal data on the basis of your consent, and otherwise for legitimate uses permitted by law (such as performing a contract you have with us, or a legal obligation). You may withdraw consent at any time; withdrawal does not affect processing already carried out. For data we process as a merchant’s Processor, consent is obtained and managed by that merchant.

6. Sharing & subprocessors

We do not sell personal data. We share it only with vendors who process data on our behalf under contract, and where required by law. Our current subprocessors include our cloud host (Supabase / AWS, Mumbai), Cloudflare (hosting and CDN), PhonePe (payments), MSG91 (OTP/SMS), and, where a merchant enables them, social sign-in and third-party loyalty providers. The current list is published on our Security page.

7. Where data is stored & how long we keep it

Customer and transaction data is stored in the AWS Mumbai (ap-south-1) region in India. We keep personal data only as long as needed for the purpose it was collected: transient data such as OTPs, rate-limit records and logs is purged automatically on a short schedule, while order and transaction records are retained for up to seven years to meet Indian tax and accounting law. When data is no longer needed it is securely deleted or anonymised.

8. How we protect data

Customer contact details (phone, email and name) are encrypted at rest with AES-256 at the database layer, and only authorised services can decrypt them. Every record is isolated per merchant and location using row-level security, and all traffic is encrypted in transit (TLS 1.2+). We never store card numbers, CVV or UPI PINs. Those are handled entirely by PhonePe. No system is perfectly secure, so please avoid sending sensitive personal data to us by email.

9. Your rights as a Data Principal

Under the DPDPA you may request access to, correction of, and erasure of your personal data, nominate another person to exercise your rights, and raise a grievance. Merchant end-customers can use the self-service export and delete tools in the EnsmblOS customer app. If your data is processed by a merchant using EnsmblOS, please contact that merchant (the Data Fiduciary) directly. We will assist them as their Processor. For all other requests, contact us using the details below.

10. Children

The service is intended for businesses and adults. We do not knowingly collect personal data of children (under 18 in India) without verifiable parental or guardian consent as required by the DPDPA.

11. Grievances & contact

To exercise your rights or raise a concern about how we handle personal data, contact our Grievance Officer at privacy@ensmbl.in. [Grievance Officer name, registered office address and phone, to be confirmed by counsel.] We will respond within the timelines required by the DPDPA.

12. Changes to this policy

We may update this policy from time to time. Material changes will be notified through the service or our website, and the effective date below will be updated.

Questions? Email privacy@ensmbl.in. Effective date: [pending counsel review].

Ready when you are

Run your whole business on one platform.

Stop juggling five vendors and five logins. A 20-minute demo is enough. Bring your menu and we’ll load it live.

Or call +91-88885-02008 · Mon-Sat, 10:00-19:00 IST.