SECURITY AND TRUST

Built to be trusted with your guests.

Your guests’ numbers, visits and preferences are the most valuable thing you own. Here is how EatLabs keeps them safe — and yours.

Data stored in India

Data stored in India (AWS Mumbai), designed for the DPDP Act.

We never see card or UPI details

Payments run on Razorpay, and each restaurant settles directly to its own account.

Role-based access, checked on every release

Role-based access across roughly 290 API routes, checked automatically on every release.

Encryption

All connected-account keys and tokens are encrypted.

Full audit trail

Every refund, point change and review reply is logged with who did it and when.

Consent respected at every send

Marketing consent is respected at every send, and guests can opt out at any time.

Guest data is never shared between restaurants

Including in cross-brand promotions — partners reach each other’s guests without either side seeing the other’s data.

HOW IT FITS TOGETHER

Your money and your data never pass through us.

Guests pay on your own Razorpay account. EatLabs only sees that a payment happened. Guest records live in your account in AWS Mumbai; you can export them at any time, and delete them on request.

Guest pays

UPI / card on Razorpay

→ settles to your bank account

EatLabs records

booking, visit, bill total

no card or UPI details stored

Stored in

AWS Mumbai · encrypted keys

DPDP-ready · audit trail

Who can see it

roles per outlet

owner · manager · host · marketing · read-only

Questions about compliance?

Ask for our data-processing summary and DPIA on the demo call.