Last updated: 30 August 2026

Privacy Policy

App: Mangaale Partner (Android package com.mangaale.restaurant)
Effective date: 30 August 2026

Who we are

Mangaale Partner is a business application for restaurant owners and their staff. It is used to run a restaurant: taking and fulfilling orders, managing menus and inventory, printing receipts, viewing sales reports, and handling staff, riders and outlets.

This policy is issued by MANGAALE QUICK COMMERCE (OPC) PRIVATE LIMITED (CIN U47912UP2026OPC251523), registered office: Village Kadrabad, P.O. Kadrabad, Kadrabad, Nagina, Bijnor – 246722, Uttar Pradesh, India ("Mangaale", "we", "us").

The app is intended for business use by restaurant operators. It is not directed to children.


1. Information we collect

1.1 Account and sign-in information

When you create a Partner account we collect and send to our servers:

Password-reset flows use your email address and a one-time password (OTP) to verify the request.

Your authentication token and certain saved account details are stored in encrypted storage on your device backed by the Android Keystore rather than in plain preferences.

1.2 Restaurant and business information

1.3 Identity and compliance documents

During restaurant registration the app asks you to upload images of:

These are uploaded to Mangaale and are used solely to verify that your restaurant is a genuine, registered business before it is allowed to accept orders.

Because Aadhaar and PAN are government identifiers, we treat these uploads as sensitive. We do not use them for any purpose other than onboarding verification and any statutory record-keeping we are required to perform.

1.4 Operational data you enter or generate

Menu items, categories, combos and item photos; offers and coupons; orders and order items; invoices and receipts; inventory and recipe records; vendor records; staff, rider and counter setup; printer preferences; sales reports; referral records; and activity tickets.

1.5 Customer information you enter

To take a counter or phone order, the app lets you enter or look up a customer's name and phone number, and it can show that customer's recent orders from your restaurant.

The WhatsApp marketing feature lets you build customer segments and campaign messages. The campaign title, message template and target segment are stored on our servers; the message itself is sent from your own device through your own WhatsApp or other sharing app — we do not send messages on your behalf.

You are responsible for having a lawful basis to enter your customers' details into the app.

1.6 Location information

The app requests ACCESS_FINE_LOCATION and ACCESS_COARSE_LOCATION. Location is used in exactly two places, and never in the background:

  1. Setting your restaurant's map pin. When you tap the "use my location" control on Profile → Set Location, the app takes a single high-accuracy GPS reading and fills in the latitude, longitude and address fields on that screen. The reading stays on your device until you review the address and tap Save location; only then are the coordinates sent to our servers.
  2. Bluetooth printer discovery on Android 11 and below, where the operating system requires the location permission before an app may scan for nearby Bluetooth devices. In this case no position is read, stored or transmitted — the permission is a platform prerequisite only. On Android 12 and above the app declares BLUETOOTH_SCAN with android:usesPermissionFlags="neverForLocation", so scanning cannot be used to derive your location at all.

A prominent disclosure explaining which of these two purposes applies is shown before the Android permission prompt appears.

We never collect location in the background, and the app declares no background-location permission.

Address look-up: when you pick a point on the map, the app converts those coordinates into a street address using the Android platform geocoder. On most Android devices this look-up is performed by Google Play services, which means the coordinates are sent to Google for that purpose.

1.7 Camera

The app requests CAMERA for two purposes:

The camera preview is not recorded. Barcode decoding runs entirely on your device — no camera frames are uploaded. Only a photo you deliberately capture and submit is uploaded.

1.8 Microphone

The app requests RECORD_AUDIO for the optional voice ordering feature. When you start voice ordering, your speech is passed to your device's own speech-recognition service to be converted to text.

On most Android devices that service is provided by Google, and depending on your device settings the audio may be processed on your device or sent to Google's servers for recognition — this is controlled by your device, not by us. We receive only the resulting text transcript, which is used to build the order. We do not store audio recordings.

The microphone is active only while you are using the voice-order screen.

1.9 Photos and media

The app declares no gallery or media-read permission. Picking an image for a menu item, your logo and background, an offer or a compliance document goes through the Android system photo picker, which hands the app only the specific item you choose. The app cannot scan or index your gallery, and no runtime permission prompt is shown for it.

Selected images are resized and compressed on your device before upload.

The app can also save images to your gallery — your restaurant's QR code and standee artwork. On Android 10 and below this write needs WRITE_EXTERNAL_STORAGE, which the app declares with android:maxSdkVersion="29" so it is not requested on newer Android versions.

1.10 Bluetooth and nearby devices

The app requests BLUETOOTH_SCAN (flagged neverForLocation), BLUETOOTH_CONNECT, and on Android 11 and below the legacy BLUETOOTH and BLUETOOTH_ADMIN permissions. It also optionally supports USB-host connections for OTG-connected thermal printers.

These are used only to discover and connect to your thermal receipt printer so orders and bills can be printed. Discovered device names and addresses are used locally to show you a printer list and to remember your chosen printer; they are not used for advertising or analytics.

1.11 Notifications

The app requests POST_NOTIFICATIONS to alert you to new orders and other operational events. When you grant it, the app registers your Firebase Cloud Messaging device token and platform (android/ios) with our servers so we can route order alerts to the right device. The token is de-registered when you log out.

1.12 Device and technical information


2. Crash reporting

The app uses Firebase Crashlytics to report crashes and unhandled errors so we can fix them. Crash collection is enabled when the app starts, and release builds provide the technical information needed to make crash reports readable.

A crash report contains the exception and stack trace, the app version, and the device and OS information collected by the Crashlytics SDK, together with a Crashlytics-generated installation identifier. We do not attach your name, email or restaurant details to crash reports.

We may collect diagnostic information including crash reports, crash logs, device information, operating-system information, the application version, application diagnostics, performance information, technical error information, and technical identifiers provided by diagnostic services where applicable. We use it for debugging, detecting technical problems, security, application stability, performance monitoring, and improving our products and services.

Crash reporting is always on: the current build enables it at startup and there is no in-app toggle to switch it off. This is why diagnostics are declared as required rather than optional in our Play Data Safety entry.


3. How we use information

We do not use your data for advertising, and we do not sell personal information.


4. Who we share information with

We do not sell personal information. Information is disclosed only as follows.

4.1 Processors acting on our instructions

Processor What it receives Why
Firebase Cloud Messaging (Google) Device push token, platform, and the content of order notifications Delivering push notifications
Firebase Crashlytics (Google) Crash traces, app version, device/OS info, Crashlytics installation ID Crash and stability reporting
Amazon Web Services (AWS) All data you submit through the app Server, backend, database and related cloud infrastructure hosting the Mangaale API
MSG91 Phone number and message content OTP delivery, SMS and authentication-related communications

Our service-provider list may change as our technical infrastructure evolves. Providers used for any additional purpose will be added here once their production configuration is confirmed.

4.2 Services provided by your own device

Service What it receives Why
Google ML Kit barcode scanning (bundled via mobile_scanner) Camera frames QR/barcode decoding — runs on-device; frames are not uploaded
Your device's speech-recognition service (usually Google) Microphone audio, while voice ordering is active Speech-to-text; may be processed on-device or by Google depending on your device settings
Android platform geocoder (usually Google Play services) Map coordinates you select Converting coordinates into a street address

4.3 Within your own account

Staff, riders and other users you invite see the restaurant data their assigned role permits.

4.4 Legal and corporate

We may disclose information where required by law, regulation, court order or a lawful government request, or to protect our rights, our users and the security of the service; and in connection with a merger, acquisition, restructuring or sale of assets, subject to this policy.


5. Where your data is processed

Our production infrastructure runs on Amazon Web Services, Asia Pacific (Mumbai), region ap-south-1, in India.

We seek to process and host production information using infrastructure selected according to our operational, security and business requirements. Certain technology or service providers may process limited information from other jurisdictions depending on their own infrastructure and service configuration — Google's Firebase services in particular operate globally. Where cross-border processing occurs, we take the measures required under applicable data-protection law together with appropriate contractual or security safeguards.

6. Security

No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

We implement reasonable technical and organisational safeguards appropriate to the nature of the information processed and the services provided. More specific claims about encryption of data at rest will be added once our production infrastructure configuration has been verified.


7. How long we keep data

We keep information for as long as your account is active and for as long as we need it to provide the service, meet legal and tax obligations, resolve disputes and enforce our agreements.

When you delete your account:

When personal information becomes eligible for deletion, we will delete, anonymise or restrict that information in accordance with our operational deletion processes, subject to applicable legal, accounting, fraud-prevention, security, dispute-resolution, regulatory and backup-retention requirements.

Residual copies of information may temporarily remain in backups until those backups are overwritten or expire according to our applicable backup-retention procedures.

What we must retain after deletion

Where required under applicable law we may retain invoices, accounting records, books of account, transaction records, tax documentation, relevant vouchers and payment-related records for their applicable legal retention periods. For books of account and relevant vouchers this means eight financial years where applicable under Section 128(5) of the Companies Act, 2013.

This does not mean every user's personal information is automatically retained for eight years. Extended retention applies only where it is required for accounting, tax, legal or regulatory compliance, fraud prevention or dispute resolution. Other personal data is retained only for as long as reasonably necessary for its purpose or for a legal requirement.

8. Your choices and rights

Subject to applicable law, you may request:

Send privacy requests to supportmangaale@gmail.com. We aim to respond to a valid request within 30 days where reasonably possible, subject to identity verification, the complexity of the request, applicable statutory requirements and legal limitations. Where applicable law requires a different response period, the legally required period takes precedence.

Rights under the EU/UK GDPR apply only where our processing actually falls within that legislation's territorial scope; they are not claimed for every user.


9. Deleting your account

You can request deletion of your Mangaale Partner account from inside the app:

Profile → Delete account, then type DELETE to confirm. The same screen is available in the desktop app under Settings. It also provides an email-request option if automated processing is unavailable.

The app sends an authenticated deletion request to Mangaale. If the request cannot proceed because your account has an active subscription or an unpaid balance, follow the instructions shown under Billing & Subscription or contact support. Only the account owner can delete the account.

What is deleted: your login (name, email, phone, password); your restaurant profile (branding, logo, address, contact and GST details); your menu, categories, item photos, offers and coupons; staff, rider, counter and printer setup; saved customer contacts and WhatsApp marketing lists; and app settings and cached data held on the device.

What is retained is listed in § 7 above.

You can also request deletion at https://mangaale.com/account-deletion without installing the app.

You can also email a deletion request to the address in § 12.


10. Children

Mangaale Partner is a business tool for restaurant operators and is not directed to children under 13. We do not knowingly collect personal information from children through the app.


11. Changes to this policy

We may update this policy. When we do, we will change the "Last updated" date at the top. Where a change is significant we will give notice in the app or by email. Continuing to use the app after an update means the updated policy applies.


12. Contact us

Company MANGAALE QUICK COMMERCE (OPC) PRIVATE LIMITED
CIN U47912UP2026OPC251523
Registered office Village Kadrabad, P.O. Kadrabad, Kadrabad, Nagina, Bijnor – 246722, Uttar Pradesh, India
Privacy / grievance email supportmangaale@gmail.com
Official email officialmangaale@gmail.com
Website https://mangaale.com

Grievance Officer

In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021:

Name Harsh Sharma
Designation Grievance Officer
Company MANGAALE QUICK COMMERCE (OPC) PRIVATE LIMITED
Email supportmangaale@gmail.com
Address Village Kadrabad, P.O. Kadrabad, Kadrabad, Nagina, Bijnor – 246722, Uttar Pradesh, India

The Grievance Officer aims to acknowledge and address grievances within 30 days of receipt, subject to identity verification and the complexity of the request. Where applicable law requires a shorter period, that period applies.

Governing law

This policy is governed by and construed in accordance with the laws of India. Subject to applicable law, the courts of competent jurisdiction in Bijnor, Uttar Pradesh, India have exclusive jurisdiction over disputes arising out of or relating to this policy or the Mangaale platform.