Legal
Privacy Policy
Cloudora Restro
Last updated: 5 September 2026
Data controller: Cloudora Solutions ("Cloudora", "we", "us", "our")
Registered address: Kirtipur, Kathmandu, Nepal
Contact for privacy matters: support@cloudorarestro.com
1. Introduction
1.1. This Privacy Policy explains how Cloudora Solutions collects, uses, stores, shares, and protects personal information in connection with the Cloudora Restro service ("the Service"), available at app.cloudorarestro.com and cloudorarestro.com.
1.2. It applies to two categories of individuals: (a) Subscribers — the restaurant owners and staff who hold accounts and use the Service; and (b) End Customers — the restaurant's own customers whose information a Subscriber enters into the Service (for example, for credit/khata or customer records).
1.3. By using the Service, you acknowledge this Policy. If you do not agree, do not use the Service.
2. Information We Collect
2.1. Information you provide as a Subscriber:
- (a) Account information — name, email address, phone number, password (stored in hashed form by our authentication provider);
- (b) Restaurant/business information — restaurant name, address, contact details, tax/PAN identifiers you choose to enter, logo, currency, country, and timezone;
- (c) Subscription and billing information — plan selected and related records (payment card details, where applicable, are handled by payment providers and are not stored by us in full).
2.2. Operational data you enter into the Service ("Subscriber Data"):
- (a) Menu, dishes, pricing, and inventory;
- (b) Orders, bills, invoices, sales records, and payment records;
- (c) Customer records you create, which may include your End Customers' names, phone numbers, and credit/khata balances;
- (d) Staff and role records;
- (e) Financial records, expenses, and reports.
2.3. Information collected automatically:
- (a) Log and usage data — actions taken in the Service, timestamps, and error logs;
- (b) Device and connection data — IP address, browser type, and similar technical information;
- (c) Cookies and similar technologies — used for authentication, session management, and preferences (see Section 8).
2.4. Communications: records of your correspondence with our support team.
3. How We Use Information
3.1. We use information to:
- (a) provide, operate, maintain, and secure the Service;
- (b) authenticate you and send login verification codes (one-time passwords) by email;
- (c) process subscriptions and manage your account;
- (d) provide customer support and respond to enquiries;
- (e) improve and develop the Service, including diagnosing problems and analysing usage in aggregate;
- (f) send service-related communications (for example, security, billing, or important updates);
- (g) comply with legal obligations and enforce our Terms;
- (h) prevent fraud, abuse, and security incidents.
3.2. We do not sell your personal information or your Subscriber Data.
4. Legal Basis and Your Responsibilities
4.1. We process Subscriber personal information to perform our contract with you (the Terms), to comply with legal obligations, and for our legitimate interests in operating and securing the Service.
4.2. Regarding End Customer data: where you (the Subscriber) enter your own customers' personal information into the Service, you are the controller of that data and are responsible for having a lawful basis to collect and process it and for informing your customers as required by applicable law. We process that data on your behalf, as a processor, solely to provide the Service to you.
5. How and Where Data Is Stored (Including Cross-Border Transfer)
5.1. The Service is hosted on secure cloud infrastructure provided by Supabase (built on Amazon Web Services). This means your data, including Subscriber Data, may be stored and processed on servers located outside Nepal.
5.2. By using the Service, you acknowledge and consent to this cross-border storage and processing. We take reasonable steps to ensure our infrastructure providers maintain appropriate security standards.
6. Sharing and Disclosure
6.1. We share information only as follows. Service providers (sub-processors) who help us operate the Service, under confidentiality obligations, including:
- (a) Supabase (built on Amazon Web Services) — cloud hosting and database;
- (b) Brevo (Sendinblue) — sending transactional emails, including login verification codes;
- (c) Twilio — sending SMS messages, where SMS features are used;
- (d) other providers we may engage for payments, analytics, or infrastructure, under similar obligations.
6.2. Legal and safety: where required by law, court order, or a lawful request by a competent authority, or to protect the rights, safety, or property of Cloudora, our users, or the public.
6.3. Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this Policy continuing to apply to your information.
6.4. We do not otherwise share your personal information with third parties for their own marketing.
7. Data Retention
7.1. We retain Subscriber Data for as long as your account is active and as needed to provide the Service.
7.2. After account termination, we retain data for a reasonable period to allow export and to meet legal, tax, and accounting obligations, after which it is deleted or anonymised, unless a longer retention period is required by law.
7.3. Backup copies may persist for a limited period after deletion from live systems, consistent with our backup cycle.
8. Cookies and Similar Technologies
8.1. We use cookies and similar technologies strictly to authenticate users, maintain sessions, remember preferences, and keep the Service secure. We do not use them for third-party advertising.
8.2. You can control cookies through your browser settings, but disabling essential cookies may prevent the Service from functioning.
9. Security
9.1. We implement reasonable technical and organisational measures to protect personal information, including encryption in transit, access controls, and row-level security in our database.
9.2. No method of transmission or storage is completely secure. While we strive to protect your information, we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential.
10. Your Rights
10.1. Subject to applicable Nepali law, you may request to access, correct, update, or delete your personal information, or to export your data, by contacting support@cloudorarestro.com. Much of this can also be done directly within the Service.
10.2. For End Customer data, requests from your customers should generally be directed to you (the Subscriber) as the controller of that data; we will assist you as reasonably required.
10.3. We will respond to legitimate requests within a reasonable time, subject to identity verification and legal limits.
11. Children
11.1. The Service is intended for businesses and is not directed to individuals under 18. We do not knowingly collect personal information from children.
12. Changes to This Policy
12.1. We may update this Policy from time to time. We will post the updated Policy with a revised "Last updated" date and, for material changes, take reasonable steps to notify you. Continued use of the Service after changes take effect constitutes acceptance.
13. Contact
13.1. For any questions, requests, or concerns about this Privacy Policy or your personal information, contact Cloudora Solutions, Kirtipur, Kathmandu, Nepal, by email at support@cloudorarestro.com.