Legal
Privacy Policy
Effective date: 28 June 2026
1. Introduction
TRONSoftech ("we", "us"), operating the BHOJAN brand, respects your privacy. This Privacy Policy describes how we collect, use, store, and protect information when hotels, restaurants, cafés, and food-service businesses ("Establishments") use our billing and POS software ("Service").
This policy applies to our website, cloud application, mobile apps, and support channels.
2. Data Controller
For account, billing, and platform data, TRONSoftech is the data controller. Contact details are listed at the end of this policy.
For guest and customer personal data entered into bills (names, phone numbers, addresses, loyalty details), your Establishment is the data controller and BHOJAN processes such data on your instructions to provide billing and reporting features.
3. Information We Collect
We may collect the following categories of information:
- Establishment & account data — business name, outlet address, GSTIN, owner/manager name, email, mobile number, plan details, and login credentials (stored in hashed form).
- Staff user data — names, roles (cashier, waiter, kitchen, admin), and activity related to orders and billing.
- Transaction & operational data — menu items, rates, taxes, bills, KOTs, table/room assignments, payments, discounts, inventory movements, and business reports.
- Guest/customer data (on your behalf) — information you choose to capture on invoices or CRM fields (e.g. name, mobile, delivery address).
- Payment & subscription data — records of your payments to us for BHOJAN subscriptions (not your guests' card/UPI payments unless integrated and configured by you).
- Technical data — IP address, device type, browser/app version, logs, and cookies on our marketing website.
- Support communications — emails, WhatsApp messages, and call notes when you contact us.
4. How We Use Information
- Provide, maintain, and secure the billing and POS Service.
- Process subscription payments, invoices, renewals, and support requests.
- Send service notifications (e.g. renewal reminders, payment confirmations, product updates).
- Improve performance, fix errors, and develop features for the hospitality industry.
- Comply with legal obligations and respond to lawful requests.
- Prevent fraud, abuse, and unauthorised access.
We do not sell your Establishment's business data to third parties for their marketing.
5. Legal Basis & Consent
We process data based on: performance of our contract with you (subscription Terms), legitimate interests in operating a secure SaaS platform, compliance with law, and consent where required (e.g. marketing cookies, optional communications).
Your Establishment must ensure it has a lawful basis to collect guest data in bills and comply with applicable privacy rules for hospitality businesses.
6. Data Sharing
We may share information with:
- Infrastructure providers — cloud hosting, database, and backup services located in India or other jurisdictions with appropriate safeguards.
- Communication providers — email, SMS, or WhatsApp APIs when you enable notifications or we send service messages.
- Payment processors — for subscription payments you make to us.
- Professional advisers — lawyers, accountants, or auditors when necessary and under confidentiality.
- Authorities — when required by court order, tax law, or government request.
Integrations you enable (payment gateways, delivery platforms) may receive data directly according to your configuration and their policies.
7. Data Retention
We retain account and transaction data for as long as your subscription is active and for a reasonable period afterward to allow export, dispute resolution, and legal compliance (typically up to 3 years for billing records unless a longer period is required by tax or audit law).
Website analytics and support logs are retained for shorter periods unless needed for security investigations.
You may request deletion subject to legal retention requirements.
8. Security
We implement reasonable technical and organisational measures including access controls, encrypted connections (HTTPS), role-based permissions, and regular backups. No method of transmission or storage is 100% secure; you should use strong passwords and limit staff access appropriately.
9. Your Rights
Depending on applicable Indian law (including the Digital Personal Data Protection Act, 2023, where applicable), you may have rights to:
- Access and obtain a copy of personal data we hold about you as an account holder.
- Correct inaccurate account or contact information.
- Request deletion where legally permitted.
- Withdraw consent for optional processing.
- Nominate a grievance contact as per DPDP requirements.
Guest data requests should generally be directed to your Establishment; we will assist you as a data processor where appropriate.
10. Cookies (Website)
Our marketing website may use cookies and similar technologies for basic functionality, analytics, and advertising pixels (e.g. Meta Pixel). You can control cookies through your browser settings. Essential cookies may be required for forms and security.
11. Children's Data
BHOJAN is a business product for Establishments and is not directed at children under 18. We do not knowingly collect personal data from children.
12. International Transfers
Data is primarily processed in India. If any subprocessors process data outside India, we take steps consistent with applicable law to protect that data.
13. Changes to This Policy
We may update this Privacy Policy from time to time. The effective date at the top will change when we do. Material updates may be communicated via email or in-app notice.
Contact Us
For questions about this policy, contact BHOJAN / TRONSoftech: hello@bhojan.net, phone +91 7558487199, or write to TRONSoftech, Kesnand, Wagholi, Maharashtra, India.