Privacy Policy Resto Genius Queensland AU

Privacy Policy for Tech Sprints Pty Ltd trading as RestoGenius

Effective Date: 1st July, 2024.

At RestoGenius, we are committed to protecting your privacy under the Privacy Act 1988 (Cth) and Australian Privacy Principles. This policy covers merchants, diners ordering online or via QR, and website visitors.

1. Information We Collect

  • Name, email, phone, business details, and ABN
  • Order history and billing reference — full card numbers are never stored
  • Device type, IP address, and app usage data
  • Location — for service delivery only; advertising requires explicit opt-in

We process merchant and diner data to fulfil our contract with you. We rely on your explicit consent for marketing communications and location-based advertising.

2. How We Use Your Information

  • Operate the POS system, online ordering, and QR ordering
  • Process and fulfil orders on behalf of merchants
  • Provide account support and send service updates
  • Improve the platform — using anonymised analytics only
  • Meet Australian tax and legal obligations (ATO, Privacy Act)

We will not use your data for any other purpose without your consent.

3. Who We Share With

  • Tyro, Till Payments & Linkly — payments (PCI DSS certified, Australia)
  • Uber Eats — delivery integration (USA / Australia)
  • Cloud hosting — platform storage (USA / Singapore — Data Processing Agreements in place)

We never sell, rent, or trade your personal information. Ever.

4. Payment Security

Your card is tokenised at the point of payment. CVV codes are never stored. All payments use TLS 1.2+ encryption and are processed by PCI DSS-certified partners.

5. Cookies & Location

  • Essential — login & security; cannot be disabled
  • Analytics — usage improvement; disable via browser settings
  • Marketing — explicit opt-in required; withdraw anytime
  • Location ads — separate opt-in required; declining won't affect app access

6. Online & QR Ordering

When you order at a venue using RestoGenius, the venue is your data controller — we process the order on their behalf only.

  • Your order data is visible only to the venue you ordered from
  • No other merchant can ever access your data
  • Contact details are used for fulfilment only — never marketing
  • Access or delete your data: contact the venue or legal@techsprints.com.au

7. Your Rights

  • Access — copy of your data, free, within 30 days
  • Correction — fix incorrect information, within 30 days
  • Deletion — erase your data within 30 days of acknowledgement, except where we are legally required to retain it.
  • Opt-out — unsubscribe from marketing anytime in one click
  • Complain — raise a concern with us, or with the OAIC

Email: legal@techsprints.com.au | Call: 1300 198 789

OAIC: www.oaic.gov.au | enquiries@oaic.gov.au | 1300 363 992

8. Security & Data Breaches

  • TLS 1.2+ encryption in transit and at rest
  • Role-based access controls — authorised staff only
  • Tested data breach response plan in place

Under the NDB Scheme, if a breach is likely to harm you, we notify you and the OAIC promptly with details and steps to protect yourself.

9. Data Retention

  • Financial records — 7 years (ATO requirement)
  • Account data — account term + 2 years
  • App analytics — 12 months (A list of AI service providers is available on request.)
  • On account closure — data deleted within 90 days

10. Policy Changes & Governing Law

  • Material changes emailed to you 14 days in advance
  • Governed by the Privacy Act 1988 (Cth) — Queensland, Australia
  • Privacy regulator: www.oaic.gov.au

11. Contact Us

If you have any questions about this Privacy Policy, please contact us at:

Email: legal@techsprints.com.au
Address: Suite 3645, 29/97 Creek Street, Brisbane, QLD 4000, Australia
Phone: +61 1300 198 789

For more information about your privacy rights in Australia, visit the Office of the Australian Information Commissioner (OAIC).