Skip to content
Legal

Privacy policy

What personal data Golak handles, why we handle it, who we share it with, and the rights you have over it. Written to be read, not skimmed past.

Effective
3 August 2026
Last updated
3 August 2026

01Who we are

Golak is a restaurant operating system — point of sale, billing, kitchen display, inventory, ordering and analytics — operated by Golak Technologies Pvt. Ltd. (“Golak”, “we”, “us”). We are registered in India with our office at Saravanampatti, Coimbatore, Tamil Nadu 641035.

This policy explains what personal data we handle, why, who we share it with and what rights you have. It covers https://golak.store, the Golak web and mobile applications, and the support channels we run alongside them.

02The two roles we play

The distinction below decides who you should approach about a given piece of data, so it is worth reading before the rest of this policy.

As a data fiduciary

When you visit our website, book a demo, subscribe to our newsletter, contact support or administer a Golak account, we decide why and how that data is processed. We are the data fiduciary (equivalent to a controller) and this policy governs it.

As a data processor

When a restaurant uses Golak to run its business, it uploads and generates data about its own guests, staff and suppliers — names, phone numbers, order histories, addresses, attendance. That restaurant decides what to collect and why; we only process it on their instructions under our agreement with them. If you are a guest of a restaurant that uses Golak and want your data corrected or erased, contact the restaurant directly. We will support them in responding, but we cannot act on their data without their instruction.

03Personal data we collect

You give us

  • Identity and contact details — name, business name, work email, phone number, outlet address, role — when you request a demo, start a subscription or contact us.
  • Account credentials for the Golak dashboard, including authentication factors. Passwords are stored only as salted hashes; we never see them in plain text.
  • Billing details — GSTIN, PAN where required for tax invoicing, billing address and subscription plan. Card and bank details are entered directly with our payment gateway; we receive only a token, the last four digits and the outcome.
  • Anything you choose to send us in a support ticket, WhatsApp message, call recording or onboarding questionnaire.

We collect automatically

  • Device and connection data — IP address, browser and OS version, device identifiers, referring page and timestamps.
  • Product usage — pages and features opened, actions taken, performance timings and error traces, used to diagnose faults and decide what to build next.
  • Cookies and similar technologies, as described in the cookies section below.

We receive from others

  • Our payment gateway and billing partners, for subscription and settlement status.
  • Integration partners you connect — aggregators, delivery platforms, accounting tools, payment terminals — limited to what that integration requires.
  • Publicly available business sources and referral partners, where we are assessing a sales enquiry.

04Why we use it, and on what basis

Under the Digital Personal Data Protection Act, 2023, we process personal data either with your consent or for a legitimate use permitted by the Act — most commonly to perform the contract you or your employer has with us, and to meet legal obligations.

  • To provide the platform — create and secure accounts, sync outlets, process bills, deliver the features your plan includes. Basis: performance of contract.
  • To support you — answer tickets, run onboarding and training, investigate incidents. Basis: performance of contract.
  • To bill you and keep tax records, including GST invoices and statutory retention. Basis: legal obligation and performance of contract.
  • To keep the service safe — detect fraud, abuse and unauthorised access, maintain audit logs, run backups. Basis: legitimate use.
  • To improve the product — aggregate usage analysis, performance monitoring, research on features. Basis: legitimate use; we work with aggregated or de-identified data wherever it will do the job.
  • To market to businesses — send product updates, invitations and offers to work contacts. Basis: consent, which you can withdraw at any time using the unsubscribe link or by writing to us.

We do not sell personal data. We do not use restaurant guest data belonging to one customer to market to another, and we do not train models on identifiable customer content without a separate written agreement.

05Who we share it with

We share personal data only where it is needed to run the service, and only under contracts that bind the recipient to protect it.

  • Cloud hosting and infrastructure providers who store and serve the platform.
  • Payment gateways, banks and billing processors, to take payment and reconcile settlements.
  • Communication providers for transactional email, SMS, WhatsApp and push notifications.
  • Support, analytics, logging and error-tracking tools we use to operate the product.
  • Integration partners you explicitly connect to your Golak account.
  • Professional advisers — auditors, lawyers, accountants — under duties of confidentiality.
  • Law enforcement, regulators or courts where we are legally required to disclose, and an acquirer if we are ever involved in a merger, acquisition or restructuring.

A current list of the sub-processors we use for a given subscription is available to account administrators on request at privacy@golak.store.

06Where data is stored and transferred

We host Golak on infrastructure located in India for customers billed in India. Some of the service providers listed above operate outside India; where personal data is transferred abroad, we do so only to countries not restricted by the Central Government under the DPDP Act, and under contractual safeguards requiring an equivalent standard of protection.

Golak is built to work offline at the counter. That means bills and orders can be held on your own device until connectivity returns. Data at rest on your hardware is your responsibility to secure — device passcodes, disk encryption and physical access controls all sit with you.

07How long we keep it

  • Account and transaction records: for the life of the subscription, then up to 90 days after termination so you can export, after which we delete or de-identify unless the law requires otherwise.
  • Invoices, tax and accounting records: eight years, as required under Indian tax law.
  • Support correspondence: three years from the last message on a ticket.
  • Security and audit logs: twelve months, longer where an investigation is open.
  • Marketing contact details: until you withdraw consent or after two years of no engagement, whichever comes first.

Backups are retained on a rolling cycle and overwritten in the ordinary course; data deleted from the live system will persist in backups for a short period after deletion.

08How we protect it

  • Encryption in transit over TLS, and encryption at rest for databases and backups.
  • Role-based access control, with staff access granted on least privilege and reviewed periodically.
  • Multi-factor authentication available on Golak accounts, and required for our own administrative access.
  • Segregated environments for development, staging and production; customer data is not used in development.
  • Logging, monitoring and alerting on access to production systems, with regular backups and restore testing.

No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board of India and affected users as required under the DPDP Act and its rules, and tell you what happened and what to do about it.

09Cookies and similar technologies

  • Strictly necessary — sign-in, session integrity, security and load balancing. These cannot be switched off without breaking the service.
  • Preference — your theme, language and layout choices.
  • Analytics — how the site and product are used in aggregate, so we can fix what is slow or confusing.

You can clear or block cookies in your browser settings. Blocking strictly necessary cookies will stop you from signing in. Where we use non-essential cookies, we ask for consent first and you can change your mind at any time.

10Your rights

As a Data Principal under the DPDP Act you may ask us to do the following in respect of data for which we are the data fiduciary:

  • Access a summary of the personal data we hold about you and how we process it.
  • Correct data that is inaccurate, and complete or update data that is incomplete.
  • Erase personal data where it is no longer needed for the purpose it was collected for and no law requires us to keep it.
  • Withdraw consent you previously gave, as easily as you gave it. Withdrawal does not affect processing already carried out.
  • Nominate another person to exercise these rights on your behalf in the event of your death or incapacity.
  • Raise a grievance with us, and escalate to the Data Protection Board of India if we do not resolve it.

Write to privacy@golak.store and we will respond within 30 days. We may ask you to verify your identity first. If your request concerns data held by a restaurant that uses Golak, we will point you to that restaurant, as explained above.

11Children

Golak is a business tool and is not directed at children. We do not knowingly collect personal data of anyone under 18 without verifiable consent from a parent or guardian, as required by the DPDP Act. If you believe a child’s data has reached us, write to privacy@golak.store and we will delete it.

12Changes to this policy

We update this policy as the product and the law change. The effective date at the top always reflects the current version. Where a change materially affects how we handle your personal data, we will notify account administrators by email or in-product notice before it takes effect.

13Contact and grievances

For any question about this policy, or to exercise a right, contact our privacy team at privacy@golak.store.

If you are not satisfied with our response, you may escalate to our Grievance Officer, appointed under the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000, at grievance@golak.store or by post to Golak Technologies Pvt. Ltd., Saravanampatti, Coimbatore, Tamil Nadu 641035, India. We acknowledge grievances within 48 hours and aim to resolve them within 30 days.

If your grievance remains unresolved, you may complain to the Data Protection Board of India. See also our terms and conditions.