Privacy policy

Your data stays yours

Last updated 11 October 2026

Your data stays yours
never sold, never shared
Encrypted
in transit and at rest
Plain language
no legal maze

EasAlpha is a point-of-sale and management service for restaurants. This page explains, in plain language, what data the service holds, who can see it and what you can ask us to do with it. It applies to the public website, the admin panel, the till, tablet, kitchen, rider and storefront apps and the WhatsApp gateway.

What we store

  • Your account: the owner's name, email, phone number and a hashed password. We never store the password itself.
  • Your restaurant's records: menu, orders, payments, stock, suppliers, expenses, accounts, staff records (including attendance, fingerprint identifiers from your kiosk and payroll), riders, customers (names, phone numbers, khata balances, loyalty points) and settings. You enter this data or your staff and customers generate it while using the service.
  • Device and usage records: which devices are paired, login sessions, and an audit log of changes made in your account, so you can see who did what.
  • Messages: if you link a WhatsApp number or use the included messaging, we keep a log of what was sent, to whom and whether it was delivered.
  • Website visits: this public website uses no advertising trackers. Server logs record IP address and pages requested for security and capacity planning and are kept for a short period.

Who can see it

  • Your data belongs to your account. It is separated from other customers' data at the database level, and only users you add, with the permissions you grant, can see it.
  • EasAlpha staff access customer data only to fix a problem you have reported or to keep the service running, and that access is logged.
  • We do not sell data or share it with advertisers. We share it with third parties only where you have set up an integration (for example WhatsApp through Meta's Cloud API, Foodpanda, or tax filing to FBR or PRA) and only the data that integration needs.
  • We use hosting and infrastructure providers to run the service. They process data on our instructions and do not use it for their own purposes.

Customers of your restaurant

When you add a customer's phone number or send them a receipt, you are responsible for having a basis to do so. Marketing messages require the customer's opt-in and honour STOP replies, and the service enforces this. Customers who want their data removed from your account should contact you; if they contact us we will pass the request on and help you fulfil it.

Exports and deletion

  • Every report exports to CSV and PDF, and customers, products and other records download as spreadsheets from the admin panel at any time, including during a read-only period after a trial or subscription ends.
  • You can ask us to delete your account and all its data by writing to hello@easalpha.com from the owner's email. We confirm the request, then delete within 30 days, except where tax or accounting law requires us to keep invoice records longer.
  • Backups that contain your data roll off on their normal schedule after deletion.

Security

Connections to the service are encrypted. Passwords are hashed. Till devices hold only the data they need to sell offline and can be unpaired from the admin panel at any time. We keep the software and its dependencies updated and review security findings as they appear. No service can promise perfect security; if we learn of a breach affecting your data we will tell you without undue delay and explain what happened.

Changes and contact

If this policy changes in a way that matters to you, we will tell account owners by email before it takes effect. Questions go to hello@easalpha.com or through the contact page.

Need help?