Privacy Policy
Shopifire ( shopifire.in) · Last updated: September 2026
This Privacy Policy explains how Shopifire ("we", "us") collects, uses, shares, and protects personal information when you use shopifire.in, the restaurant dashboard, public QR menus, and related services. It should be read with our Terms of Service and Cookie Policy.
1. Roles & scope
Restaurant owners & staff are our direct customers. We act as a data controller for account, billing, and support data relating to your organisation.
Diner / end-customer data submitted through your QR menu (orders, delivery address, optional sign-in) is processed on your behalf to fulfil ordering. For that data you are typically the data controller and Shopifire acts as a data processor, as described in Section 8 below.
2. Information we collect
Restaurant accounts: name, email, password (hashed) or Google account identifier, country, restaurant profile (name, address, phone, branding), staff invitations, support tickets, and billing records.
Menu & operations: menu items, categories, images, prices, modifiers, delivery zones, operating hours, QR scan analytics (counts, language selected), order history, payment status (not full card numbers), WhatsApp alert configuration, and dashboard activity needed to operate the Service.
Diner orders (via your menu): items ordered, table/room identifiers where applicable, optional name, phone, delivery address, notes, payment method selection, and payment references from Razorpay. Delivery QR customers who sign in with Google: name, email, and profile identifier.
Marketing site inquiries: if you contact us via the website widget: name, phone, topic, message, and page URL.
Technical data: IP address, browser type, device information, and server logs for security and troubleshooting (typically retained for a limited period).
3. How we use information
- Provide, maintain, and improve the Service
- Authenticate users and prevent fraud or abuse
- Process orders and route payments through configured providers
- Send transactional email (account, support, billing) and optional WhatsApp messages you enable
- Provide AI features you request (menu import, translation, image generation)
- Respond to support requests and legal obligations
- Produce aggregated, non-identifying analytics for product improvement
We do not sell personal information to advertisers.
4. Legal bases (where applicable)
Depending on your location, we rely on: performance of a contract (providing the Service), legitimate interests (security, product improvement), consent (where required for marketing or non-essential cookies), and legal obligation.
5. Sharing & subprocessors
We share data only as needed to operate the Service:
- Razorpay — diner online payments and PRO subscription billing (India)
- Google — optional OAuth sign-in for owners and delivery customers
- Resend (or similar) — transactional email delivery
- Meta / WhatsApp Business API — order alerts and inquiry messages you configure
- AI providers (e.g. OpenAI, Google Gemini, Groq) — menu OCR, translation, and image generation when you use those features; content is sent only for the requested task
- Hosting infrastructure — servers and PostgreSQL database used to run shopifire.in
Subprocessors are bound by contractual confidentiality and security obligations appropriate to their role. A current list is available on request at privacy@shopifire.in.
6. Retention
Account and menu data are retained while your account is active. You may delete a restaurant and associated data from the dashboard where available. Order records may be retained for accounting, tax, and dispute resolution (typically up to seven years where required by law). Server logs and support tickets are retained for operational needs then deleted or anonymised.
7. Security
We use industry-standard measures including HTTPS, hashed passwords, access controls, signed webhooks, and isolated authentication for diner vs owner sessions. No method of transmission or storage is 100% secure; please use strong passwords and protect staff access.
8. Data processing for restaurants (processor terms)
When you use Shopifire to collect diner orders and related information, you instruct us to process that personal data on your behalf for the purposes described in this policy and your use of the Service. You agree to:
- Provide appropriate privacy notices to your customers (e.g. on your menu or premises)
- Collect only data necessary for orders and comply with applicable privacy laws (including India's Digital Personal Data Protection Act, 2023 where applicable)
- Not use the Service to process special-category data except where lawful and disclosed
We will:
- Process diner data only on your documented instructions via the Service
- Implement appropriate technical and organisational measures to protect personal data
- Assist with reasonable data subject requests where technically feasible (contact us with your customer's request details)
- Notify you without undue delay if we become aware of a personal data breach affecting your diner data, where required by law
- Delete or return diner data when you delete the restaurant or upon termination, subject to legal retention requirements
For a written Data Processing Agreement (DPA) for enterprise or high-volume use, email privacy@shopifire.in.
9. Your rights
Depending on applicable law, you may have rights to access, correct, delete, restrict, or export personal data, or to object to certain processing. Restaurant owners can manage much of their data in the dashboard. Contact privacy@shopifire.in for other requests. We may verify identity before responding.
Diners should contact the restaurant they ordered from first; we will assist restaurants in responding where appropriate.
10. International transfers
Data is primarily processed in India. Some subprocessors (e.g. AI or email providers) may process data in other countries. Where required, we use appropriate safeguards for cross-border transfers.
11. Children
The Service is not directed at children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect data from children.
12. Contact
Privacy questions: privacy@shopifire.in
General support: roshan@shopifire.in · Contact page