Merchant App Privacy Policy
Effective and last updated: 29 September 2026
This policy explains how Khana Hazir (also displayed as “KhanaHazir”), referred to as “we”, “us” or “our”, handles information in the KhanaHazir Merchant app for approved restaurant partners.
The Merchant app is used to manage restaurant orders, menus, availability, offers, receipts, performance and settlements. It does not request approximate, precise or background location from the merchant device.
Privacy questions: [email protected]. Restaurant account deletion can be requested from our Account & Data Deletion page.
1. Information we handle
- Merchant account information: owner or authorised user name, phone number, restaurant name, restaurant identifier, sign-in credentials and account status.
- Restaurant and menu information: profile details, operating hours, availability, food categories, item names, descriptions, prices, options, preparation times, offers and images selected for upload.
- Order fulfilment information: order identifiers, items, quantities, prices, payment method and status, preparation and delivery states. After an order is accepted, the app can display the customer or recipient name, phone number, confirmed delivery address, delivery pin and instructions needed to fulfil that order.
- Settlement and performance information: sales, commissions, delivery amounts, deductions, settlement periods, payout records, transaction references, restaurant health metrics and operational history.
- Notifications and device information: notification device token, notification status and basic technical information such as IP address, app version, device or request details received when the app connects to our systems.
- Support information: messages, issue details and information voluntarily provided when requesting support.
2. How we use information
We use relevant information to authenticate authorised restaurant users; receive and fulfil orders; show customer details only when operationally required; manage menu content, offers, availability and operating hours; send necessary order and account notifications; create receipts; calculate performance and settlements; provide support; secure accounts; prevent misuse; resolve disputes; and meet applicable legal, tax and accounting obligations.
3. Android permissions and device features
- Camera and photos: the app can open the camera or system image picker when an authorised merchant chooses to add a menu image. Only the image selected or captured for that action is uploaded.
- Notifications: notification permission and a Firebase Cloud Messaging token are used for order, account and operational alerts. Notification permission can be changed in Android settings.
- Bluetooth: Bluetooth access is used only when the merchant chooses to find a previously paired compatible receipt printer and print an order receipt. The app reads the paired device name and address needed to connect to that printer.
- Location: the Merchant app does not request the merchant device’s approximate, precise or background location. A customer’s confirmed delivery pin or address is order fulfilment data received from our server, not merchant-device GPS data.
5. Device storage and security
The app stores an authentication token and limited preferences on the merchant device so the authorised user can remain signed in. Signing out removes the local merchant session and revokes notification registration where available. Clearing app data or uninstalling removes device-local data but does not by itself delete server records.
We use reasonable safeguards appropriate to the information, including HTTPS and access controls. Merchants should protect their device and credentials, restrict account access to authorised staff and report suspected unauthorised access promptly. No transmission or storage system can be guaranteed completely secure.
6. Retention
We keep merchant profile and restaurant information while the account is active and needed to provide the service. Order, settlement, payout, support, audit and security records may be retained for fulfilment, refunds, accounting, tax, dispute resolution, fraud prevention and legal obligations. Records are deleted or anonymised when they are no longer required for those purposes.
7. Account and data deletion
An authorised restaurant representative can request deletion of the merchant account and associated personal data without reinstalling the app by visiting Account & Data Deletion or emailing [email protected] with the subject Khana Hazir account deletion request.
Include the registered phone number or email, restaurant name and state that the request concerns a restaurant account. We verify authority before acting. Never send a password, OTP, full payment credential or identity document in the initial email. Verified requests are completed within 30 days, except for limited records that must be retained for an existing dispute, security, accounting, tax or legal requirement.
8. Your choices
Authorised merchants can update available restaurant and menu fields, change app permissions in Android settings, sign out, and contact us to request access, correction or deletion. Declining a permission affects only the feature that needs it: for example, camera access is not required to receive an order, and Bluetooth access is needed only for compatible printer functions.
9. Changes to this policy
We may update this policy when Merchant app features, providers or legal requirements change. The current version and effective date will remain available at this URL, with additional notice or consent where required.
10. Contact Khana Hazir
For privacy questions, complaints or requests, email [email protected]. Include enough information to identify the restaurant account or issue, but do not send passwords, OTPs or payment security codes.