Privacy Policy

OotaOS privacy policy. Compliant with DPDPA 2023 (India), Australian Privacy Act 1988, GDPR (EU), and CCPA (California).

What data the platform holds, and under which laws

The privacy policy explains what personal data OotaOS collects from restaurants and from the diners who order through them, why it is held, how long it is kept, and who it is shared with — the payment processors, delivery platforms and messaging providers that need it to complete a transaction.

Because the platform runs in ten countries, the policy is written against several regimes at once: India's Digital Personal Data Protection Act 2023, the Australian Privacy Act 1988, the GDPR in the European Union and the CCPA in California. It sets out the rights a person has over their data under each of them, and how to exercise those rights.

Two roles are worth separating when reading it. A restaurant on OotaOS decides what it collects from its own diners and why; OotaOS processes that data on the restaurant's behalf to run the service. The policy says which of the two holds what, how long each is kept, and who to write to about a request — for diners, usually the restaurant they ordered from, and for anything else, info@ootaos.com.