Privacy Policy

Last updated: 25 July 2026 ## 1. WHO WE ARE Mint Light is an individual software commercial project operated by private individuals from Binner Baramulla, Jammu and Kashmir, 193101, India. We are NOT a registered company, corporation, or formal business entity. This is an independent commercial project. Our Services include a QR ordering platform, AI-powered restaurant tools (Aura AI), and the Echo Partner affiliate program, accessible via mintlight.online and the Mint Light mobile application. ## 2. DATA CONTROLLER As an unregistered individual project, the founders/operators act as data controllers. For privacy-related inquiries, contact: Email: mintmenu.care@gmail.com Address: Binner Baramulla, Jammu and Kashmir, 193101, India Grievance Officer: Contact via email above ## 3. DATA WE COLLECT - BY USER TYPE We collect different data depending on how you interact with our Services. ### A. Menu Customers (Diners) This applies when you scan a QR code at a restaurant and browse or order from a digital menu. What we collect: - Device & browser information (IP address, browser type, OS) - Which restaurant menu you viewed - Items added to cart and orders placed - Table/QR code identifier (for table-specific ordering) - Timestamps of interactions - Any information you voluntarily enter during ordering (e.g., special instructions) What we do NOT collect: - We do NOT require your name, email, or phone number to browse a menu - We do NOT track you across different restaurants - We do NOT sell your data to third parties How we use it: - To display the menu and process your order - To assist the restaurant in fulfilling your order - To prevent fraud (e.g., order sabotage, fake orders) ### B. Restaurant Owners & Staff This applies when you register for a Mint Light account as a restaurant owner or staff member. What we collect: - Account data: Name, email address, phone number - Business data: Restaurant name, trade name, address, GSTIN/FSSAI/other tax registration numbers, UPI ID, bank/payment details - Menu content: Menu items, descriptions, pricing, images, dietary information, category structure - Operational data: Orders received, revenue data, customer traffic patterns, QR code assignments - AI interaction data: Prompts and queries submitted to Aura AI - Billing data: Subscription plan, payment history, invoices How we use it: - To provide and maintain the restaurant management platform - To process payments and subscriptions - To generate receipts, bills, and tax-compliant invoices - To train and improve Aura AI (anonymized and aggregated) - To communicate service updates and support ### C. Affiliates (Echo Partners) This applies when you sign up for the Mintlight Echo Partner Program. What we collect: - Account data: Full name, email address, phone number - Payout data: PayPal email, UPI ID, bank account details, country of residence - Tracking data: Referral code, referral links, click data, cookies for attribution - Performance data: Number of referrals, active referrals, commission earned, commissions paid How we use it: - To track referrals and attribute commissions - To process and send payouts - To generate performance reports and analytics - To detect fraudulent referral activity Data retention for affiliates: We retain all commission records for a minimum of 2 (two) years from the date of the associated referral, or as required by applicable law. ## 4. PAYMENT PROCESSING - DODO PAYMENTS We use Dodo Payments as our merchant of record for all payment transactions. When you make a payment: - Your payment details (card numbers, billing address) are sent directly to Dodo Payments - We do NOT store full credit card numbers, CVV codes, or banking credentials on our servers - Dodo Payments processes, stores, and handles your payment data according to their own privacy policy and terms - We receive confirmation of payment status and transaction identifiers from Dodo Payments - For disputes, chargebacks, or refunds, Dodo Payments is the primary processor For wallet transactions: Dodo Payments manages customer wallets and ledger entries. We only view wallet balances and transaction history as needed for service delivery. ## 5. DATA SHARING We share your data only in these specific circumstances: With Restaurants: Menu customer order data is shared with the specific restaurant to fulfill the order. With Payment Processors: Payment data is shared with Dodo Payments for transaction processing. With Service Providers: We share necessary data with: - Supabase (database hosting - India/US regions) - ImageKit (image storage and delivery) - OneSignal (push notifications) - Vercel/Next.js (hosting) Legal Compliance: If required by law or valid legal process, we may disclose data. Business Transfer: In the event of a sale, merger, or transfer of assets, user data may be transferred as part of that transaction. ## 6. DATA RETENTION Menu customer data: Anonymized after 30 days. No personal identification is retained. Restaurant data: Retained for the duration of your active subscription plus 90 days after cancellation, unless you request earlier deletion. Affiliate data: Commission records retained for a minimum of 2 years. Account data retained for the duration of your participation plus 1 year. Payout records retained as required by tax/accounting laws. Backup data: Retained in encrypted backups for up to 30 days after deletion. ## 7. DATA SECURITY We implement reasonable security measures including: - Encryption in transit (SSL/TLS) - Encrypted database storage - Access controls and authentication - Regular security assessments However, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security. As an unregistered individual project, our security resources are limited. ## 8. YOUR RIGHTS BY COUNTRY ### India (IT Act 2000 & DPDPA 2023) - Right to access your personal data - Right to correction of inaccurate data - Right to erasure (subject to legal retention) - Right to withdraw consent at any time - Right to grievance redressal via our Grievance Officer ### United States (CCPA - California) California residents have the right to: - Know what personal information is collected, used, shared - Request deletion of personal information - Opt out of the sale of personal information (we do NOT sell data) - Non-discrimination for exercising these rights ### United Kingdom & EU (UK GDPR / GDPR) Data subjects have the right to: - Access your data (Subject Access Request) - Rectification of inaccurate data - Erasure (Right to be Forgotten) - Restriction of processing - Data portability - Object to processing - Not be subject to automated decision-making If you are in the UK/EU, note that your data is transferred to and processed in India. By using our Services, you consent to this transfer. ### Australia (Privacy Act 1988) - We comply with the Australian Privacy Principles (APPs) - You may access and correct your personal information - Complaints can be directed to us or to the Office of the Australian Information Commissioner (OAIC) ### Singapore (PDPA 2012) - You have the right to access and correct your personal data - You may withdraw consent for data collection/use - Data protection obligations apply under the PDPA ## 9. COOKIES AND TRACKING We use the following types of cookies: - Essential cookies: Required for the platform to function (session management, authentication) - Analytics cookies: To understand usage patterns (optional) - Affiliate tracking cookies: To attribute referrals to affiliates (30-day expiration) You may disable cookies in your browser settings, but this may affect platform functionality. ## 10. AURA AI - AI DATA HANDLING When you interact with Aura AI: - Prompts and queries are processed to generate responses - Anonymized data may be used to improve AI models - We advise you NOT to share sensitive personal information (government IDs, financial details) within AI prompts - AI responses may not always be accurate - verify critical information ## 11. THIRD-PARTY LINKS Our Services may contain links to third-party websites (e.g., restaurant websites, payment portals). We are not responsible for their privacy practices. Review their policies before providing data. ## 12. CHANGES TO THIS POLICY We may update this Privacy Policy at any time. Changes will be posted with an updated "Last updated" date. Material changes will be notified via email or platform notice. Continued use after changes constitutes acceptance. ## 13. ENTITY DISCLOSURE Mint Light is an individual software commercial project, NOT a registered company. The operators hold personal liability. By using our Services, you acknowledge and accept that: - We are an unregistered India-based individual project - There is no corporate veil or limited liability protection - Recourse is limited to the personal assets of the founders in India - Dodo Payments acts as merchant of record for payment transactions ## 14. PRECAUTIONARY NOTICE This platform operates as a beta service. Users and affiliates assume all risks. We strongly recommend not relying on affiliate income as a primary source of earnings. ## 15. CONTACT & GRIEVANCE OFFICER For privacy complaints, data requests, or inquiries: Email: mintmenu.care@gmail.com Address: Binner Baramulla, Jammu and Kashmir, 193101, India We will respond to all legitimate requests within 30 days. If you are unsatisfied with our response, you may lodge a complaint with your local data protection authority.