EZBY← Home

In short

EZBY is a QR-ordering service operated by Nsquare Microtech. It lets food shops take orders from a single QR code. We collect the minimum data needed to take and fulfil your order. We never sell your data, and we don't share customer data with anyone outside the shop you ordered from (except the service providers that run our infrastructure, listed below). We don't handle your payments — those happen directly between you and the shop. Any product analytics we use is anonymous.

Who this covers

Two kinds of people use EZBY: customers(you scan a shop's QR to order) and shops (owners and staff who run their menu and orders). This policy explains what we collect for each.

What we collect — customers

  • Your order: the items you chose, the name you typed, an optional phone number if you provide one, the order short-code, and a request id used to prevent duplicate orders if your network drops. Order status changes (placed, accepted, ready, cancelled) are stored against the order.
  • Order notifications (optional): if you turn on updates for an order, your browser gives us a push subscription (a device-specific delivery address and keys). We use it only to notify you about that order.
  • Technical data: your IP address and browser user-agent reach our hosting and security layers. We use the IP for abuse prevention and rate-limiting (stored only in hashed form), not to identify you. We do not collect your precise or GPS location.

Only the staff and owner of the shop you ordered from can see your order. They cannot see orders from any other shop.

What we collect — shops (owners & staff)

  • Account details: shop name, owner and staff names, login phone number, a one-way hashed PIN (we never store the PIN itself), and an optional UPI VPA. Staff biometrics, if used, never leave the device.
  • Currency / region:at signup we read the approximate country from your IP address to pre-select your shop's currency. You can change it; we store the currency you choose, not your IP.
  • Device tokens: if the staff app sends order notifications, we store a push token for delivery.
  • Activity logs: an audit log of sensitive actions (sign-in, menu and order changes) for security and support.

Analytics & error monitoring

Where enabled, we use privacy-preserving product analytics (PostHog) to understand which features are used and where flows break. On the customer surface this is anonymous by design: automatic capture is off (we never record typed values like names or phone numbers), session recording is off, and we never link events to a person — each visitor is an anonymous id. We also use error monitoring (Sentry) to capture crash diagnostics; those reports are scrubbed of personal data (phone, PIN, tokens, request bodies) before they leave our systems. Both are enabled only when configured and may be processed outside your country (see "Where data is stored").

What we don't do

  • We don't collect or process payment instruments. Payment is offline (cash or UPI / direct to the shop), and we have no visibility into whether a payment succeeded.
  • We don't use third-party advertising trackers or marketing pixels, and we don't build advertising profiles of you.
  • We don't collect your precise or GPS location.
  • We never sell your personal data.

Cookies and local storage

We use your device's local storage to remember your cart for the current shop, your language choice, whether you dismissed the notification or app-install prompts, and your last order time for a smoother repeat visit. If analytics is enabled, an anonymous analytics identifier is also stored. We don't use cookies for advertising.

How long we keep your data

  • Customer name & phone: deleted about 30 days after the order is completed or cancelled.
  • Order items & status history:kept up to 12 months for the shop's records and accounting, with personally identifying fields removed.
  • Order status link (/o/<code>): expires about 30 days after the order, in line with deletion above.
  • Push subscriptions / device tokens: until you unsubscribe or they expire (idle staff tokens are cleared after ~90 days).
  • Security & sign-in logs: short-lived (sign-in attempt records ~7 days; vendor request logs ~30 days).
  • Device flags in local storage: stay on your device until you clear it.

A shop may request a shorter retention window for its customer data.

Service providers we share with

We share data only with the shop you ordered from and with the infrastructure providers that operate the service on our behalf, under data-processing agreements:

  • Supabase— database & storage (order and account data).
  • Vercel — application hosting and request logs (IP, user-agent; no order contents).
  • PostHog — anonymous product analytics (when enabled).
  • Sentry — error diagnostics, scrubbed of personal data.
  • Google Firebase Cloud Messaging — push notifications (delivery token and message; no name or phone).

We may also disclose data where required by law or to protect the rights and safety of users and the public.

Where data is stored & international transfers

Core order and account data is stored in our primary region (currently India — Mumbai). As EZBY supports shops in more countries and currencies, some processing — including by the providers above — may occur in other regions such as the United States or the European Union. Where data crosses borders, we rely on data-processing agreements and appropriate safeguards. If you are in a jurisdiction with its own data-protection law, that law's protections apply to you.

Your rights

Under India's Digital Personal Data Protection Act, 2023 — and, where applicable, comparable laws such as the GDPR — you can ask to access the data we hold about you, correct it, erase it (subject to lawful retention windows), and withdraw consent. To make a request, email info@nsquaremicrotech.com from the phone or contact you used; we respond within 30 days.

Security

Data is encrypted in transit. Access is scoped per shop with row-level security so one shop can never read another's data; staff PINs are stored only as one-way hashes; and sign-in attempts are rate-limited. No system is perfectly secure, but we work to protect your data and will notify affected users and the relevant authority of a qualifying breach as required by law.

Children

EZBY is not directed at children under 18. We do not knowingly collect data from minors. If you believe a minor has submitted data, contact us and we will remove it.

Changes to this policy

We'll update the "Last updated" date when this policy changes. Material changes that expand the data we collect will be highlighted on the customer surface for at least 14 days before they take effect.

Contact & grievances

Nsquare Microtech, India — operator of EZBY. For any privacy request, question, or grievance, email info@nsquaremicrotech.com. We acknowledge grievances promptly and aim to resolve them within 30 days.