RestroPulse ("we", "us", "our") provides a multi-property hospitality operations platform — Customer Pulse Index, financial intelligence, operational dashboards, and connected third-party integrations including Google Business Profile. This Privacy Policy explains what data we collect, how we use it, the third parties we integrate with, and the rights you have over your information.
1. Information we collect
Account & tenant data
- Name, work email, role, tenant (organisation) you belong to.
- Hashed authentication credentials. We never store passwords in plain text.
- Outlet / property metadata you configure inside RestroPulse.
Operational data you submit
- Financial entries, checklists, recipes, inventory counts, marketing entries, customer feedback submissions and any other content you record in the app.
- Customer Pulse Index (CPI) guest submissions — these are submitted by your guests via QR-driven public forms. Your tenant alone controls and owns this data.
Telemetry & security logs
- Login attempts, IP address, browser user-agent, and timestamps for audit + abuse prevention.
- Application error reports (no sensitive payload data) so we can fix bugs.
Public demo & prospective-customer data
When you request access to the RestroPulse live demo at /demo, we collect the following to grant secure access and (only where you explicitly opt in) to follow up with you:
- Work email address.
- Mobile number and phone country code.
- The demo persona you selected — Owner / Admin or Manager.
- Whether you ticked the follow-up consent checkbox, and the timestamp of that consent.
- Access timestamps (first access, last access, number of accesses).
- Salted hashes of IP address and browser user-agent, used solely for abuse detection.
- One-time access code (OTP) and demo-session metadata — never the OTP itself in plaintext; only an HMAC hash we cannot reverse.
- Campaign attribution:
utm_source,utm_medium,utm_campaign,utm_content,utm_term, and the HTTP referrer that brought you to the demo.
We use this information only for the following purposes:
- Provide secure, rate-limited access to the read-only demo environment.
- Deliver the one-time access code by email so you can enter the demo.
- Detect and prevent abuse, fraud, and automated attacks on the demo.
- Understand demo usage in aggregate so we can improve the product story.
- Attribute marketing campaigns that brought a visitor to the demo.
- Contact you by phone about RestroPulse only where you have explicitly ticked the follow-up consent checkbox — never by default.
Requesting demo access does not constitute email-marketing consent. Providing your mobile number does not by itself permit sales follow-up. Sales follow-up happens only when you explicitly opt in via the follow-up consent checkbox, and the flag marketing_email_consent is always initialised to false for every demo record. You can withdraw follow-up consent at any time (see Section 8 below).
2. Google Business Profile integration
Where a tenant connects their Google Business Profile to RestroPulse, we request the OAuth scope https://www.googleapis.com/auth/business.manage. This authorisation is granted by the individual admin who completes Google's consent screen, and can be revoked by them at any time from their Google Account permissions page.
We use Google Business Profile data only for the following purposes:
- Discovering the list of business locations the connecting admin manages, so they can map each Google location to a RestroPulse outlet.
- Fetching customer reviews, ratings, reviewer names, review timestamps and existing replies for the locations the admin has explicitly mapped.
- Posting review replies on behalf of the tenant only when the admin composes and submits the reply inside RestroPulse.
We do not use Google Business Profile data to train AI models, sell to third parties, advertise, build user-level behavioural profiles, or share with any party outside the tenant who authorised the connection. Refresh tokens are encrypted at rest in our database and are never exposed to the browser or to any third party. If a tenant disconnects their Google account from RestroPulse, all tokens and synchronised review data for that tenant are deleted within 30 days.
RestroPulse's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3. How we use your data
- To deliver the features you sign up for — dashboards, P&L, CPI, inventory, etc.
- To enforce role-based access inside your tenant.
- To send essential service emails (password resets, security alerts, billing).
- To investigate and prevent abuse, fraud, and security incidents.
- To comply with legal obligations.
4. Data sharing & service providers
We do not sell tenant data, customer data, demo-visitor data, or any data obtained from Google APIs to anyone. We share data only with:
- Cloud hosting, database, and infrastructure providers that run the RestroPulse platform under confidentiality and data-processing agreements, solely to operate the service.
- Transactional email delivery provider — used to send the public-demo one-time access code, password-reset emails, security alerts and service notifications. The provider only receives the recipient address, subject and message body needed to deliver the email.
- Cloudflare Turnstile — the bot / abuse-protection challenge on the public demo page. Cloudflare receives only the minimum browser signal needed to score the challenge; RestroPulse never sends your email or mobile number to Cloudflare.
- Analytics / security processors — where applicable, aggregate, non-identifying telemetry and error-report processors that help us keep the platform reliable and safe. These processors do not receive tenant financial data or CPI guest submissions.
- Authorised users within your tenant — admins, area managers, and outlet managers see the slice of data their role permits.
- Legal authorities if compelled by valid legal process, and only the minimum required.
5. Data retention
- Operational and financial data: retained for the active life of your tenant + 7 years for statutory record-keeping (financial regulation).
- CPI guest submissions: retained for the active life of your tenant + 24 months unless you delete earlier.
- Google Business Profile tokens + synchronised reviews: deleted within 30 days of disconnection or tenant termination.
- Telemetry logs: 90 days.
- Public-demo OTP challenges, active demo sessions, and rate-limit counters: automatically deleted at the end of their technical window (OTP: 10 minutes; demo session: 45 minutes; rate-limit windows: 1 hour) via database TTL indexes.
- Public-demo / prospective-customer contact records (
demo_access_leads): demo and prospective-customer information is generally retained for up to 12 months after the last interaction, subject to active commercial discussions, ongoing customer relationships, legal or compliance requirements, and any earlier deletion request where applicable law grants that right. Deletion is currently executed on request — the underlying database does not automatically delete these records. To have your demo record deleted, contact us using the details in Section 10.
6. Security
- All traffic is encrypted in transit via TLS 1.2+.
- Tokens and secrets are encrypted at rest.
- Every API endpoint enforces per-tenant isolation server-side. A user from Tenant A can never query Tenant B's data, even via direct API calls.
- Role-based access control + feature governance is enforced both in the UI and at the API layer.
7. Your rights
Subject to applicable law, you have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or outdated details.
- Delete your personal data where deletion is available under applicable law and no legal / compliance obligation requires us to keep it (see Section 5).
- Withdraw follow-up consent given on the public-demo form — reply to any RestroPulse email or contact us at the address in Section 10 with the request "withdraw demo follow-up consent". We will stop follow-up communications and record the withdrawal.
- File a privacy grievance or complaint about how we handle your data.
To exercise any of these rights, contact us at the address in Section 10. We will respond to privacy requests within the timeframe required by applicable law.
Public-demo follow-up consent
On the public-demo page you may tick a checkbox that reads:
"I agree that RestroPulse may contact me by phone regarding this demo and its products or services."
This checkbox is optional and unchecked by default. It authorises phone follow-up only. It is distinct from — and does not imply — marketing-email consent. You may withdraw it at any time using the process above.
8. International transfers
Our infrastructure may process data in jurisdictions different from yours. Where required by law (e.g. GDPR), transfers are governed by Standard Contractual Clauses or equivalent safeguards.
9. Changes
We will post material changes to this policy with at least 30 days' notice via the "Last updated" date and an in-app notification.
10. Contact
RestroPulse is currently operated by Lokesha V, Founder & CEO, pending formal business registration. All privacy, grievance, and legal correspondence should be addressed to:
- Email: restropulsesystems@gmail.com
- Phone: +91 73494 42077
Formal legal-entity details (registered company name, address, and registration numbers) will be added here once RestroPulse's business registration is completed.