We take your privacy seriously. Here's how we handle your data.
Last updated: 15 July 2026Ordrji respects your privacy and is committed to protecting personal data processed through our website, applications, software, devices and related services.
This Privacy Policy explains how SYNCKRAFT TECHNOLOGIES PVT LTD, operating under the brand name “Ordrji”, collects, uses, stores, discloses and protects personal data when you interact with:
Collectively, these are called the “Services.”
In this Privacy Policy:
Ordrji may have different privacy roles depending on the circumstances.
Ordrji generally determines why and how personal data is processed when we collect information directly for our own purposes, including:
For such processing, Ordrji acts as the Data Fiduciary, controller or equivalent responsible entity under applicable law.
A Restaurant Customer generally determines why and how personal data relating to its End Customers, staff, suppliers and business operations is processed.
Examples include:
For this data, the Restaurant Customer normally acts as the Data Fiduciary or controller, and Ordrji processes the data on the Restaurant Customer’s documented instructions as a Data Processor or service provider.
End Customers or restaurant employees seeking to exercise rights relating to this data should ordinarily contact the relevant restaurant first. Ordrji will provide reasonable assistance to the Restaurant Customer as required by law and the applicable Data Processing Agreement.
The personal data collected depends on how you use the Services and which Ordrji modules are enabled.
When you visit ordrji.com, request a demo, submit a contact form, communicate through WhatsApp, call us or contact our sales team, we may collect:
When a Restaurant Customer creates or operates an Ordrji account, we may collect:
We do not require government identification documents unless they are necessary for account verification, payments, legal compliance, fraud prevention or a separately disclosed feature.
Restaurant Customers may create accounts for owners, managers, cashiers, waiters, kitchen employees and other staff. Depending on the modules enabled, we may process:
Ordrji does not collect biometric information unless a separately enabled attendance or authentication module requires it and a separate notice and lawful basis are provided.
When an End Customer places an order, uses a QR menu, requests delivery, joins a loyalty programme or provides feedback, the Restaurant Customer may collect and process through Ordrji:
Restaurants should not use Ordrji to collect unnecessary medical, financial, identity or other highly sensitive information.
Ordrji may process restaurant operational records such as:
Some of this information may constitute personal data when it is linked to a customer, staff member, supplier or other identifiable individual.
When payments are enabled, Ordrji may process:
Ordrji is not designed to collect or store your full card number, CVV, UPI PIN, online-banking password or similar payment credentials. Such credentials should be entered only into the secure interface of the relevant bank or payment service provider. Payment service providers may process personal data under their own privacy policies.
We may automatically collect technical data when a person uses the Services, including:
Precise location, Bluetooth, camera, local-network or notification permissions are accessed only where required by an enabled feature and subject to device settings.
Ordrji may operate as an offline-first or local-first POS system. This means that certain information may be temporarily or persistently stored on an authorised restaurant device before being synchronised with Ordrji’s cloud systems. Local information may include:
Restaurant Customers are responsible for maintaining appropriate physical security, user access controls, operating-system updates, antivirus protection and secure disposal or transfer of devices on which Ordrji is installed.
When providing onboarding, installation, troubleshooting or data migration, we may receive:
We will use migrated data only to provide the requested migration and related support, subject to the Restaurant Customer’s instructions.
We may receive data from:
The data received depends on the integration, permissions granted and the third party’s terms.
We may generate information such as:
Where reasonably possible, we aggregate or de-identify information before using it for benchmarking, research, product development or service improvement.
We collect personal data:
We may use personal data to:
This includes:
We use information to:
We may process information to:
We may analyse usage and feedback to:
Where enabled, Ordrji may analyse operational data to provide:
Such insights are intended as operational assistance and should be reviewed by the Restaurant Customer before business decisions are made. Unless separately disclosed and contractually authorised, Ordrji will not use Restaurant Customer or End Customer personal data to train third-party general-purpose artificial-intelligence models.
We may send:
Marketing messages will be sent subject to applicable consent and communication rules. Recipients can opt out of promotional communications, although essential service messages may continue.
We may process information to:
Depending on the context and applicable law, we process personal data where:
Where processing is based on consent, consent may be withdrawn through the available account settings or by contacting us. Withdrawal does not affect processing lawfully carried out before withdrawal.
Ordrji may use cookies, local storage, software development kits, pixels and similar technologies.
These are required for:
These remember settings such as:
These help us understand:
Where used, these may help measure marketing campaigns or show relevant Ordrji advertisements. Non-essential technologies will be used subject to applicable consent requirements.
You can control cookies through our cookie banner, browser settings or device settings. Disabling essential cookies may prevent certain Services from working.
We may disclose personal data to the following categories of recipients.
Information relating to restaurant operations may be accessible to the relevant Restaurant Customer and users authorised by that Restaurant Customer, based on configured roles and permissions.
We may use vendors for:
These providers are permitted to process data only for agreed services and are expected to maintain appropriate confidentiality and security protections.
When a Restaurant Customer enables an integration, we may exchange information with the selected provider. These providers may include payment services, delivery platforms, accounting systems, communication platforms and other restaurant technology services. The third party’s use of information is governed by its own privacy policy and the Restaurant Customer’s agreement with that provider.
We may share information with lawyers, auditors, accountants, insurers, consultants and other advisers where reasonably necessary.
We may disclose information where required by law, court order, regulation or valid legal process, or where reasonably necessary to prevent fraud, investigate wrongdoing or protect legal rights.
Personal data may be disclosed in connection with an investment, financing, merger, acquisition, restructuring, sale of assets or similar transaction. Any recipient will be required to handle personal data consistently with applicable law.
We may share personal data for another purpose where you or the relevant Restaurant Customer has instructed or authorised us to do so.
Ordrji does not sell or rent personal data to data brokers or unrelated third parties.
Ordrji and its service providers may process information in India and in other countries where approved infrastructure or service providers operate.
When personal data is transferred outside India, we will take reasonable steps to:
Restaurant Customers requiring specific data-location arrangements should ensure those requirements are included in their contract or Data Processing Agreement.
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, to provide the Services, resolve disputes, enforce agreements and comply with legal requirements.
Our general retention approach is:
| Data category | General retention approach |
|---|---|
| Website enquiries and demo requests | Normally up to 24 months after the last meaningful interaction |
| Restaurant Customer account information | During the relationship and normally up to 3 years after account closure |
| Hosted restaurant operational data | During the subscription and for the export or recovery period stated in the contract, normally up to 90 days after termination |
| Orders, invoices and financial records | For the period required by tax, GST, accounting and other applicable laws |
| Support tickets and communications | Normally up to 3 years after closure |
| Marketing records | Until consent is withdrawn, an objection is received or the data is no longer required |
| Opt-out or suppression records | As long as necessary to honour the opt-out |
| Application and security logs | Normally at least 1 year, or longer where required for security or legal compliance |
| Local device data | Until synchronised, deleted through authorised controls or removed during secure device decommissioning |
| Backups | Until overwritten through the applicable backup cycle, normally within 90 days |
| Aggregated or de-identified data | May be retained for a longer period where it no longer identifies an individual |
Retention periods may differ where:
A Restaurant Customer may request account closure in accordance with its subscription agreement.
Before deletion, the Restaurant Customer should export data it is legally required to retain. Following termination:
Ordrji may request written authorisation and identity verification before processing an export or deletion request.
Ordrji uses reasonable technical and organisational safeguards designed to protect personal data. Depending on the Service and risk, these may include:
No internet, cloud or device-based system can be guaranteed to be completely secure. Restaurant Customers must protect passwords, PINs, devices, printers, local networks and authorised-user accounts and must notify Ordrji promptly of suspected misuse.
If Ordrji becomes aware of a personal-data breach, we will investigate and take reasonable steps to:
Where Ordrji processes affected data on behalf of a Restaurant Customer, we will notify and reasonably assist that Restaurant Customer in meeting its legal obligations.
Subject to applicable law, you may have the right to:
Rights are not absolute. We may retain or continue processing information where required for legal compliance, security, fraud prevention, contractual claims or another lawful purpose.
Send a request to:
Privacy email: privacy@ordrji.com
Subject: Privacy Rights Request
Include:
We will not ask for passwords, UPI PINs or CVVs.
When Ordrji processes data on behalf of a Restaurant Customer, we may:
Questions, complaints or grievances concerning this Privacy Policy may be sent to the Privacy and Grievance Officer.
Privacy and Grievance Officer: ASIYA IMRAN SHAIKH
Designation: Software Developer
Legal entity: SYNCKRAFT TECHNOLOGIES PVT. LTD
Registered office: 414, 4th Floor, Daga Plazzo Biyani Sqaure, opp. Dmart Camp, Amravati, Maharashtra 444602
Email: privacy@ordrji.com
General email: hello@ordrji.com
Phone: +91 90044 02006
Working hours: 11 AM-6PM, Monday to Saturday
We aim to acknowledge grievances promptly and respond within 30 days, unless a shorter or longer period is required or permitted by applicable law.
You may stop promotional communications by:
Opting out of marketing will not stop essential communications relating to orders, security, payments, subscriptions, support or legal matters.
Restaurant Customers using Ordrji’s WhatsApp, SMS, email or campaign features are responsible for:
Ordrji’s business accounts and administrative Services are intended for adults authorised by a Restaurant Customer. Ordrji does not knowingly permit children to independently create Restaurant Customer or staff-administrator accounts.
Where an End Customer under 18 uses a restaurant ordering service:
Do not enter the following information into free-text fields, order notes, support chats or other Ordrji areas unless it is strictly necessary and expressly authorised:
Where allergy or dietary information is provided for an order, it should be limited to what is reasonably necessary to fulfil that order safely.
Restaurant Customers using Ordrji are responsible for:
Restaurant Customers must not use Ordrji to unlawfully monitor employees, create discriminatory profiles or send unsolicited communications.
The Services may contain links to or integrations with third-party websites, payment providers, delivery platforms, messaging services, accounting software or other systems.
Ordrji does not control the privacy practices of independent third parties. You should review their privacy policies before providing information or enabling an integration. Disabling an integration may not automatically delete information already processed by that third party.
Ordrji may use aggregated or de-identified information to:
We will take reasonable steps to prevent such information from being used to identify an individual or disclose the confidential business data of a Restaurant Customer.
We may update this Privacy Policy to reflect:
The updated policy will display a revised “Last updated” date. Where a change materially affects how personal data is used, we will provide additional notice through the website, application, registered email, dashboard or another appropriate channel. Where required, we will obtain fresh consent.
For privacy questions, rights requests or complaints, contact:
SYNCKRAFT TECHNOLOGIES PVT. LTD., operating as Ordrji
414, 4th Floor, Daga Plazzo Biyani Sqaure, opp. Dmart Camp, Amravati, Maharashtra 444602
Email: privacy@ordrji.com
General enquiries: hello@ordrji.com
Phone: +91 90044 02006