Last updated: 30 August 2026
Privacy Policy
Who we are
Mangaale Partner is a business application for restaurant owners and their staff. It is used to run a restaurant: taking and fulfilling orders, managing menus and inventory, printing receipts, viewing sales reports, and handling staff, riders and outlets.
This policy is issued by MANGAALE QUICK COMMERCE (OPC) PRIVATE LIMITED (CIN U47912UP2026OPC251523), registered office: Village Kadrabad, P.O. Kadrabad, Kadrabad, Nagina, Bijnor – 246722, Uttar Pradesh, India ("Mangaale", "we", "us").
The app is intended for business use by restaurant operators. It is not directed to children.
1. Information we collect
1.1 Account and sign-in information
When you create a Partner account we collect and send to our servers:
- Full name (split into first and last name), and business name
- Email address
- Phone number, defaulted to the
+91country code - Password
- Your role (for example
restaurant_owner)
Password-reset flows use your email address and a one-time password (OTP) to verify the request.
Your authentication token and certain saved account details are stored in encrypted storage on your device backed by the Android Keystore rather than in plain preferences.
1.2 Restaurant and business information
- Restaurant name, owner name, restaurant type
- Street address, city, state, postal code
- Map coordinates (latitude and longitude)
- GST number and GST settings, FSSAI licence number
- UPI ID, where you choose to add one
- Restaurant logo and background/branding images
- Wallet balance and subscription status
1.3 Identity and compliance documents
During restaurant registration the app asks you to upload images of:
- Aadhaar card — required
- PAN card — required
- FSSAI licence — required
- GST certificate — optional
These are uploaded to Mangaale and are used solely to verify that your restaurant is a genuine, registered business before it is allowed to accept orders.
Because Aadhaar and PAN are government identifiers, we treat these uploads as sensitive. We do not use them for any purpose other than onboarding verification and any statutory record-keeping we are required to perform.
1.4 Operational data you enter or generate
Menu items, categories, combos and item photos; offers and coupons; orders and order items; invoices and receipts; inventory and recipe records; vendor records; staff, rider and counter setup; printer preferences; sales reports; referral records; and activity tickets.
1.5 Customer information you enter
To take a counter or phone order, the app lets you enter or look up a customer's name and phone number, and it can show that customer's recent orders from your restaurant.
The WhatsApp marketing feature lets you build customer segments and campaign messages. The campaign title, message template and target segment are stored on our servers; the message itself is sent from your own device through your own WhatsApp or other sharing app — we do not send messages on your behalf.
You are responsible for having a lawful basis to enter your customers' details into the app.
1.6 Location information
The app requests ACCESS_FINE_LOCATION and ACCESS_COARSE_LOCATION. Location is used in exactly two places, and never in the background:
- Setting your restaurant's map pin. When you tap the "use my location" control on Profile → Set Location, the app takes a single high-accuracy GPS reading and fills in the latitude, longitude and address fields on that screen. The reading stays on your device until you review the address and tap Save location; only then are the coordinates sent to our servers.
- Bluetooth printer discovery on Android 11 and below, where the operating system requires the location permission before an app may scan for nearby Bluetooth devices. In this case no position is read, stored or transmitted — the permission is a platform prerequisite only. On Android 12 and above the app declares
BLUETOOTH_SCANwithandroid:usesPermissionFlags="neverForLocation", so scanning cannot be used to derive your location at all.
A prominent disclosure explaining which of these two purposes applies is shown before the Android permission prompt appears.
We never collect location in the background, and the app declares no background-location permission.
Address look-up: when you pick a point on the map, the app converts those coordinates into a street address using the Android platform geocoder. On most Android devices this look-up is performed by Google Play services, which means the coordinates are sent to Google for that purpose.
1.7 Camera
The app requests CAMERA for two purposes:
- Scanning ticket QR codes in the activity/ticket module, using an on-device barcode scanner.
- Taking photos of menu items, your logo, and compliance documents, when you choose the camera as the source instead of your gallery.
The camera preview is not recorded. Barcode decoding runs entirely on your device — no camera frames are uploaded. Only a photo you deliberately capture and submit is uploaded.
1.8 Microphone
The app requests RECORD_AUDIO for the optional voice ordering feature. When you start voice ordering, your speech is passed to your device's own speech-recognition service to be converted to text.
On most Android devices that service is provided by Google, and depending on your device settings the audio may be processed on your device or sent to Google's servers for recognition — this is controlled by your device, not by us. We receive only the resulting text transcript, which is used to build the order. We do not store audio recordings.
The microphone is active only while you are using the voice-order screen.
1.9 Photos and media
The app declares no gallery or media-read permission. Picking an image for a menu item, your logo and background, an offer or a compliance document goes through the Android system photo picker, which hands the app only the specific item you choose. The app cannot scan or index your gallery, and no runtime permission prompt is shown for it.
Selected images are resized and compressed on your device before upload.
The app can also save images to your gallery — your restaurant's QR code and standee artwork. On Android 10 and below this write needs WRITE_EXTERNAL_STORAGE, which the app declares with android:maxSdkVersion="29" so it is not requested on newer Android versions.
1.10 Bluetooth and nearby devices
The app requests BLUETOOTH_SCAN (flagged neverForLocation), BLUETOOTH_CONNECT, and on Android 11 and below the legacy BLUETOOTH and BLUETOOTH_ADMIN permissions. It also optionally supports USB-host connections for OTG-connected thermal printers.
These are used only to discover and connect to your thermal receipt printer so orders and bills can be printed. Discovered device names and addresses are used locally to show you a printer list and to remember your chosen printer; they are not used for advertising or analytics.
1.11 Notifications
The app requests POST_NOTIFICATIONS to alert you to new orders and other operational events. When you grant it, the app registers your Firebase Cloud Messaging device token and platform (android/ios) with our servers so we can route order alerts to the right device. The token is de-registered when you log out.
1.12 Device and technical information
- A random app-instance identifier: a 128-bit random hex string generated on first launch and stored on the device. It is not derived from any hardware identifier and cannot be used to track you across other apps.
- The Firebase Cloud Messaging token described above.
- Android OS version, read locally to decide which permission model to apply for features such as image selection and printer setup.
- Crash and diagnostic data — see § 2 below.
- Standard server-side request metadata such as IP address and timestamps, which our API receives as an inherent part of any internet request.
2. Crash reporting
The app uses Firebase Crashlytics to report crashes and unhandled errors so we can fix them. Crash collection is enabled when the app starts, and release builds provide the technical information needed to make crash reports readable.
A crash report contains the exception and stack trace, the app version, and the device and OS information collected by the Crashlytics SDK, together with a Crashlytics-generated installation identifier. We do not attach your name, email or restaurant details to crash reports.
We may collect diagnostic information including crash reports, crash logs, device information, operating-system information, the application version, application diagnostics, performance information, technical error information, and technical identifiers provided by diagnostic services where applicable. We use it for debugging, detecting technical problems, security, application stability, performance monitoring, and improving our products and services.
Crash reporting is always on: the current build enables it at startup and there is no in-app toggle to switch it off. This is why diagnostics are declared as required rather than optional in our Play Data Safety entry.
3. How we use information
- To create, authenticate and secure your account
- To register and verify your restaurant, including document verification
- To receive, display, update and fulfil orders
- To generate invoices, receipts, GST records and sales reports
- To manage menus, inventory, recipes, vendors, staff, riders and outlets
- To discover and connect to your receipt printer
- To send order and operational push notifications
- To place your restaurant on the map so customers can find it
- To provide optional voice ordering and business-insight features
- To diagnose crashes, fix defects and improve reliability
- To bill you for your subscription and track wallet balances
- To comply with tax, accounting and other legal obligations
We do not use your data for advertising, and we do not sell personal information.
4. Who we share information with
We do not sell personal information. Information is disclosed only as follows.
4.1 Processors acting on our instructions
| Processor | What it receives | Why |
|---|---|---|
| Firebase Cloud Messaging (Google) | Device push token, platform, and the content of order notifications | Delivering push notifications |
| Firebase Crashlytics (Google) | Crash traces, app version, device/OS info, Crashlytics installation ID | Crash and stability reporting |
| Amazon Web Services (AWS) | All data you submit through the app | Server, backend, database and related cloud infrastructure hosting the Mangaale API |
| MSG91 | Phone number and message content | OTP delivery, SMS and authentication-related communications |
Our service-provider list may change as our technical infrastructure evolves. Providers used for any additional purpose will be added here once their production configuration is confirmed.
4.2 Services provided by your own device
| Service | What it receives | Why |
|---|---|---|
Google ML Kit barcode scanning (bundled via mobile_scanner) |
Camera frames | QR/barcode decoding — runs on-device; frames are not uploaded |
| Your device's speech-recognition service (usually Google) | Microphone audio, while voice ordering is active | Speech-to-text; may be processed on-device or by Google depending on your device settings |
| Android platform geocoder (usually Google Play services) | Map coordinates you select | Converting coordinates into a street address |
4.3 Within your own account
Staff, riders and other users you invite see the restaurant data their assigned role permits.
4.4 Legal and corporate
We may disclose information where required by law, regulation, court order or a lawful government request, or to protect our rights, our users and the security of the service; and in connection with a merger, acquisition, restructuring or sale of assets, subject to this policy.
5. Where your data is processed
Our production infrastructure runs on Amazon Web Services, Asia Pacific (Mumbai), region ap-south-1, in India.
We seek to process and host production information using infrastructure selected according to our operational, security and business requirements. Certain technology or service providers may process limited information from other jurisdictions depending on their own infrastructure and service configuration — Google's Firebase services in particular operate globally. Where cross-border processing occurs, we take the measures required under applicable data-protection law together with appropriate contractual or security safeguards.
6. Security
- All communication between the app and our servers uses HTTPS/TLS.
- Your authentication token and personal session details are stored on your device in encrypted storage backed by the Android Keystore.
- Android backup of app data is disabled, so your session is not copied into device backups.
- Logging out clears your session token, personal details, cached restaurant data and the registered push token.
- Release builds are minified and obfuscated.
No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
We implement reasonable technical and organisational safeguards appropriate to the nature of the information processed and the services provided. More specific claims about encryption of data at rest will be added once our production infrastructure configuration has been verified.
7. How long we keep data
We keep information for as long as your account is active and for as long as we need it to provide the service, meet legal and tax obligations, resolve disputes and enforce our agreements.
When you delete your account:
When personal information becomes eligible for deletion, we will delete, anonymise or restrict that information in accordance with our operational deletion processes, subject to applicable legal, accounting, fraud-prevention, security, dispute-resolution, regulatory and backup-retention requirements.
Residual copies of information may temporarily remain in backups until those backups are overwritten or expire according to our applicable backup-retention procedures.
What we must retain after deletion
- Invoices, GST records and other tax documents
- Payment and settlement records for completed orders
- Anonymised order totals used for accounting, which carry no personal details
Where required under applicable law we may retain invoices, accounting records, books of account, transaction records, tax documentation, relevant vouchers and payment-related records for their applicable legal retention periods. For books of account and relevant vouchers this means eight financial years where applicable under Section 128(5) of the Companies Act, 2013.
This does not mean every user's personal information is automatically retained for eight years. Extended retention applies only where it is required for accounting, tax, legal or regulatory compliance, fraud prevention or dispute resolution. Other personal data is retained only for as long as reasonably necessary for its purpose or for a legal requirement.
8. Your choices and rights
- Update your information — profile, restaurant, menu and operational data can be edited in the app.
- Withdraw a permission — location, camera, microphone, nearby devices, photos and notifications can each be revoked in Android Settings. The features that depend on them will stop working; the rest of the app continues to work.
- Access, correction, or a copy of your data — contact us using the details below.
- Delete your account — see the next section.
Subject to applicable law, you may request:
- information about our processing of your personal information;
- correction of inaccurate personal information;
- updating of incomplete or outdated personal information;
- erasure, where legally applicable;
- withdrawal of consent, where processing relies on consent;
- grievance redressal; and
- any other right available to you under applicable data-protection law.
Send privacy requests to supportmangaale@gmail.com. We aim to respond to a valid request within 30 days where reasonably possible, subject to identity verification, the complexity of the request, applicable statutory requirements and legal limitations. Where applicable law requires a different response period, the legally required period takes precedence.
Rights under the EU/UK GDPR apply only where our processing actually falls within that legislation's territorial scope; they are not claimed for every user.
9. Deleting your account
You can request deletion of your Mangaale Partner account from inside the app:
Profile → Delete account, then type DELETE to confirm. The same screen is available in the desktop app under Settings. It also provides an email-request option if automated processing is unavailable.
The app sends an authenticated deletion request to Mangaale. If the request cannot proceed because your account has an active subscription or an unpaid balance, follow the instructions shown under Billing & Subscription or contact support. Only the account owner can delete the account.
What is deleted: your login (name, email, phone, password); your restaurant profile (branding, logo, address, contact and GST details); your menu, categories, item photos, offers and coupons; staff, rider, counter and printer setup; saved customer contacts and WhatsApp marketing lists; and app settings and cached data held on the device.
What is retained is listed in § 7 above.
You can also request deletion at https://mangaale.com/account-deletion without installing the app.
You can also email a deletion request to the address in § 12.
10. Children
Mangaale Partner is a business tool for restaurant operators and is not directed to children under 13. We do not knowingly collect personal information from children through the app.
11. Changes to this policy
We may update this policy. When we do, we will change the "Last updated" date at the top. Where a change is significant we will give notice in the app or by email. Continuing to use the app after an update means the updated policy applies.
12. Contact us
| Company | MANGAALE QUICK COMMERCE (OPC) PRIVATE LIMITED |
| CIN | U47912UP2026OPC251523 |
| Registered office | Village Kadrabad, P.O. Kadrabad, Kadrabad, Nagina, Bijnor – 246722, Uttar Pradesh, India |
| Privacy / grievance email | supportmangaale@gmail.com |
| Official email | officialmangaale@gmail.com |
| Website | https://mangaale.com |
Grievance Officer
In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021:
| Name | Harsh Sharma |
| Designation | Grievance Officer |
| Company | MANGAALE QUICK COMMERCE (OPC) PRIVATE LIMITED |
| supportmangaale@gmail.com | |
| Address | Village Kadrabad, P.O. Kadrabad, Kadrabad, Nagina, Bijnor – 246722, Uttar Pradesh, India |
The Grievance Officer aims to acknowledge and address grievances within 30 days of receipt, subject to identity verification and the complexity of the request. Where applicable law requires a shorter period, that period applies.
Governing law
This policy is governed by and construed in accordance with the laws of India. Subject to applicable law, the courts of competent jurisdiction in Bijnor, Uttar Pradesh, India have exclusive jurisdiction over disputes arising out of or relating to this policy or the Mangaale platform.