Privacy Policy
Last Updated: June 6, 2026 | Effective Date: June 6, 2026 | Version: 2.0
📌 Important Notice for Restaurant Owners: Your customer data (names, phone numbers, emails, order history) belongs to YOU, not OnlineOrder.pk. We process it on your behalf and never sell or rent your customer data. You may export your customer data anytime from your admin dashboard.
1. Introduction
OnlineOrder.pk ("Company", "We", "Us", "Our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, software, and services. Please read this policy carefully. By using our services, you consent to the practices described herein.
This policy applies to:
- Restaurant Owners - using our POS and online ordering system
- End Customers - ordering food from restaurants using our platform
- Website Visitors - browsing our marketing website
2. Information We Collect
2.1 Information from Restaurant Owners
When you sign up for our services, we collect:
- Business Information: Restaurant name, business address, phone number, email
- Owner Information: Name, position, contact details
- Billing Information: Payment method, billing address, transaction history
- Restaurant Data: Menu items, pricing, business hours, delivery zones
- Technical Data: IP address, browser type, device information
2.2 Information from End Customers (Ordering from Restaurants)
When customers place orders through restaurant websites/apps powered by OnlineOrder.pk, we collect on behalf of the restaurant:
- Contact Information: Name, phone number, email, delivery address
- Order Information: Items ordered, special instructions, order total
- Payment Information: Transaction status, payment method (full payment details processed by payment gateways)
- Technical Data: IP address, device type, location (if shared)
Note: This data belongs to the restaurant. We process it on their behalf.
2.3 Information from Website Visitors
- Usage Data: Pages visited, time spent, links clicked
- Device Information: Browser type, operating system, screen resolution
- Location Data: Approximate geographic location (country/city level)
3. How We Use Your Information
We use collected information for:
- Providing, maintaining, and improving our services
- Processing payments and managing subscriptions
- Sending order confirmations, delivery updates, and support messages (for end customers)
- Sending technical notices, updates, security alerts (for restaurant owners)
- Responding to your comments, questions, and support requests
- Analyzing usage patterns to improve user experience
- Preventing fraud and ensuring security
- Complying with legal obligations
4. Legal Basis for Processing (GDPR Compliance)
For users in jurisdictions requiring a legal basis for data processing, we rely on:
- Contract Performance: To provide services you requested
- Legitimate Interests: To improve our services and prevent fraud
- Legal Obligation: To comply with tax and regulatory requirements
- Consent: For marketing communications (you may opt out anytime)
5. Data Controller vs Data Processor
| Role | Description | Responsibility |
|---|---|---|
| OnlineOrder.pk | Data Controller for restaurant owner data (account, billing, usage) | We determine how and why this data is processed |
| OnlineOrder.pk | Data Processor for end customer data (orders, customer information) | We process data on behalf of restaurants |
| Restaurant Owner | Data Controller for their customer data | Restaurant owns and controls customer data |
6. Data Sharing and Disclosure
We may share your information with:
- Payment Processors: PayFast, JazzCash, Easypaisa, bank partners (to process transactions)
- Hosting Providers: To host your website, app, and data securely
- Delivery Partners: If restaurants use integrated delivery services
- Analytics Services: To improve our platform (anonymized data only)
- Legal Authorities: When required by law, court order, or to protect our rights
- Professional Advisors: Lawyers, accountants, auditors
We do not sell your personal information to third parties. We do not rent your customer data.
7. Customer Data Ownership (Important for Restaurants)
✅ Your Customer Data is YOURS. All customer information collected through your online ordering system — names, phone numbers, email addresses, order history, preferences — belongs to YOU, the restaurant owner. We do not claim ownership, we do not sell it, we do not use it for our own purposes. You may export your complete customer database anytime from your admin dashboard.
8. Data Security
We implement industry-standard security measures:
- Encryption: SSL/TLS encryption for all data transmission
- Access Controls: Role-based access to customer data
- Secure Storage: Encrypted databases with regular backups
- Monitoring: 24/7 security monitoring and intrusion detection
- Authentication: Two-factor authentication available for admin accounts
9. Data Retention
We retain different types of data for different periods:
| Data Type | Retention Period | Reason |
|---|---|---|
| Restaurant account data | While account active + 12 months | Tax compliance, reactivation |
| End customer order data | 7 years (as required by tax laws) | Tax records, dispute resolution |
| Payment transaction data | 7 years | Legal and financial compliance |
| Website usage logs | 30 days | Security analysis |
| Marketing data (with consent) | Until consent withdrawn | User preference |
10. Your Rights (Data Subject Rights)
Depending on your location, you may have the following rights:
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure ("Right to be Forgotten"): Request deletion of your data
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Receive your data in a structured format
- Right to Object: Object to certain processing activities
- Right to Withdraw Consent: Withdraw consent for marketing
- Right to Lodge a Complaint: File complaint with supervisory authority
To exercise these rights, contact us at admin@onlineorder.pk. We will respond within 30 days.
11. Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Essential Cookies: Enable core functionality (login, cart, checkout)
- Preference Cookies: Remember your settings and preferences
- Analytics Cookies: Understand how you use our platform (Google Analytics)
- Security Cookies: Protect against fraud and unauthorized access
You can control cookies through your browser settings. Disabling essential cookies may affect website functionality.
12. Third-Party Links
Our website may contain links to third-party websites (payment gateways, social media). We are not responsible for their privacy practices. We encourage you to read their privacy policies.
13. International Data Transfers
OnlineOrder.pk operates in Pakistan, with international clients in UK and USA. Your information may be transferred to and processed in these countries. We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) where required.
14. Children's Privacy
Our services are not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us.
15. Data Breach Notification
In the event of a data breach affecting your personal information, we will notify you within 72 hours of discovery, as required by applicable laws. We will also notify relevant supervisory authorities.
16. Changes to This Privacy Policy
We may update this privacy policy from time to time. Material changes will be notified via:
- Email to registered restaurant owners
- Notice in admin dashboard
- Updated "Last Updated" date on this page
Continued use of our services after changes constitutes acceptance of the revised policy.
17. Contact Us
For privacy-related questions, data requests, or to exercise your rights:
- Email: admin@onlineorder.pk
- WhatsApp: +44 7880 748211
- Phone (Pakistan): 0300 5070285
- Address: GF-Office NO. 1, Plaza 17, Road 16, Rawalpindi, Pakistan - 46000
For data protection officer inquiries, please email dpo@onlineorder.pk.
← Back to Home