Skip to main content
Octap
  • Platform
  • Features
  • Solutions
  • Pricing
  • Resources
Start Free Trial

Privacy Policy

This Privacy Policy explains how Octap collects, uses, stores, and discloses information when hospitality businesses use Octap software and related services. Octap is built for restaurants, cafes, cloud kitchens, hotels, and other food-and-beverage operators. The focus of this policy is business and operational data generated by merchant users of the platform.

This document is intended to help operators in India and the United Arab Emirates understand how data is handled in the normal course of service delivery. It is not legal advice. Contract-specific commitments may be described in your order form, master services agreement, or other written terms.

If you have questions about this policy, contact us at hello@theoctap.com or through our contact page.

1. Scope

This policy applies to information processed by Octap in connection with:

  • Point-of-sale and ordering workflows.
  • Billing and payment-adjacent workflows inside the Octap application.
  • Staff, outlet, and operational configuration records.
  • Service communications with authorized merchant representatives.

This policy does not automatically cover third-party products and services that may be connected to Octap, such as payment gateways, banks, messaging providers, accounting software, or hardware vendors. Those providers maintain their own privacy notices and terms.

2. Categories of information we process

Depending on account setup and usage, we may process the following categories of information:

  1. Business account information: organization name, outlet details, business identifiers, and authorized contact details.
  2. User and staff information: names, role assignments, login identifiers, and activity needed for access control and audit visibility.
  3. Operational records: orders, bills, taxes, discounts, refunds, modifiers, table activity, and service workflow states.
  4. Configuration and settings data: menu structure, pricing setup, outlet preferences, permission mapping, and workflow configuration.
  5. Support and communication data: service requests, issue descriptions, and operational troubleshooting information shared with our team.
  6. Technical and diagnostic data: logs, device/application metadata, and performance events required to maintain service quality and platform reliability.

Octap is primarily designed around merchant operational data. The platform is not positioned as a consumer social network and does not rely on broad consumer profiling as a business model.

3. How we use information

We use information for legitimate business purposes related to providing and improving Octap, including:

  • Delivering core POS, order, and operations functionality.
  • Enabling account security, authentication, authorization, and role-based access.
  • Supporting onboarding, migration, implementation, and issue resolution.
  • Monitoring reliability, preventing abuse, and maintaining service integrity.
  • Communicating product, support, and account updates to authorized users.
  • Complying with applicable legal obligations.
  • Enforcing contractual rights and resolving disputes.

We do not state that every use case is exhaustive in this policy. We may process information in related ways reasonably compatible with the purposes above and applicable law.

4. Legal basis and contractual context

Where required by applicable law, processing may be based on one or more of the following:

  • Performance of a contract with the merchant customer.
  • Legitimate interests in operating, securing, and improving the service.
  • Compliance with legal and regulatory obligations.
  • Consent where specifically requested for a particular use case.

The merchant customer remains responsible for ensuring that its own use of the platform, including staff management and local workflows, complies with applicable law in its operating jurisdictions.

5. Data sharing and disclosure

Octap may disclose information to the following categories of recipients:

  1. Service providers that help us operate the platform, such as infrastructure, monitoring, communications, and support tooling providers.
  2. Integration partners where the merchant enables optional integrations.
  3. Professional advisors such as legal, audit, or compliance advisors where reasonably necessary.
  4. Authorities and regulators where required by law, legal process, or enforceable government request.
  5. Corporate transaction parties in connection with a merger, acquisition, financing, reorganization, or similar event, subject to applicable confidentiality safeguards.

We do not sell merchant operational data as a standalone data product.

6. Cross-border processing

Octap may process data in one or more jurisdictions depending on deployment architecture, vendor infrastructure, and support operations. By using the service, customers acknowledge that data may be transferred across borders as reasonably necessary for service delivery and reliability.

Where required, we implement contractual and organizational measures appropriate to the transfer context. Merchants with specific residency requirements should discuss those needs during procurement and onboarding.

7. Security safeguards

Octap applies administrative, technical, and organizational measures designed to protect information against unauthorized access, alteration, disclosure, or loss. Security is addressed in more operational detail on our security page.

No online service can guarantee absolute security. Merchants should maintain strong internal controls, including role-based permission governance, device hygiene, and account lifecycle management for staff.

8. Data retention

We retain information for as long as reasonably necessary to:

  • Provide contracted services.
  • Maintain business and security records.
  • Comply with legal, accounting, and tax obligations.
  • Resolve disputes and enforce agreements.

Retention periods vary by data type, account status, legal requirements, and documented business needs. When information is no longer required, we may delete, anonymize, or de-identify it in accordance with applicable obligations and system constraints.

9. Customer controls and rights

Authorized merchant users may request access, correction, or operational updates to account information through standard support channels. Depending on applicable law and context, data subjects may also have rights such as:

  • Access to relevant personal information.
  • Correction of inaccurate records.
  • Deletion in appropriate circumstances.
  • Restriction or objection to certain processing.
  • Portability where legally applicable.

Rights requests are evaluated based on legal requirements, system architecture, account role, and contractual limitations. Some requests may be denied or limited when exemptions apply, including legal retention requirements, security concerns, or rights of other parties.

10. Merchant responsibilities

Merchant customers are responsible for:

  • Obtaining any notices, consents, or internal authorizations required for their use of Octap.
  • Managing staff access and role assignments appropriately.
  • Using platform features in compliance with local labor, tax, and privacy laws.
  • Ensuring information entered into the platform is lawful and accurate.

Octap provides platform controls, but operational compliance decisions remain with the merchant.

11. Children and sensitive categories

Octap services are intended for business use by authorized personnel. The service is not directed to children. Merchants should avoid entering unnecessary sensitive personal data into free-text fields unless operationally required and legally appropriate.

12. Third-party links and services

Our website and platform materials may link to third-party websites or tools. We are not responsible for privacy practices of external services not controlled by Octap. You should review third-party privacy policies separately.

13. Policy updates

We may update this Privacy Policy periodically to reflect product changes, legal developments, and operational practices. Material changes will be reflected by updating the date above and, where appropriate, through service communications.

Continued use of the service after an updated policy becomes effective constitutes acceptance to the extent permitted by law and contract.

14. Contact and escalation

For privacy questions, requests, or concerns:

  • Email: hello@theoctap.com
  • Web: Contact page
  • Security context: Security page

Include your business name, outlet details, account email, and the nature of your request so we can route it correctly.


Important: This policy is provided for operational transparency and is marked for legal review before long-term publication. Contract documents govern in case of conflict.

Features

  • QR Menu
  • Payments
  • Analytics
  • Multi-Location

Solutions

  • Restaurants
  • Hotels
  • Cafes
  • Cloud Kitchen

Resources

  • Guides
  • Blog
  • Compare
  • FAQ

Company

  • About
  • Contact
  • Security
  • Sitemap
  • Privacy

© 2026 Octap. All rights reserved. v5.0.6

  • LinkedIn
  • Twitter