Privacy Policy
Magic Mato ("we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-driven CRM and management platform for restaurants ("Service").
By using our Service, you consent to the practices described in this policy.
We collect the following types of information:
- Account Information: Business name, owner/contact details, billing information
- Usage Data: POS transactions, inventory records, customer orders, staff performance
- Technical Data: IP address, browser type, device info, usage analytics
- Communication Data: Support emails, chat logs, feedback
You retain full ownership of all business data (orders, inventory, customer records) uploaded to our platform.
We use your information to:
- Provide and maintain the Service (POS, billing, inventory management)
- Process payments and manage subscriptions
- Enable AI features (Mavi assistant, sales forecasting, inventory alerts)
- Improve platform functionality through analytics
- Communicate service updates, support, and billing
- Prevent fraud and ensure platform security
We implement industry-standard security measures:
- 256-bit SSL encryption for all data transmission
- AES-256 encryption for data at rest
- Role-based access controls
- Regular security audits and penetration testing
- Compliance with ISO 27001 standards
While we strive for maximum security, no online service can guarantee absolute protection against breaches.
We do not sell your data. We share information only in these limited cases:
- Service providers (payment processors, cloud hosting, analytics)
- Legal compliance (court orders, government requests)
- Business transfers (mergers, acquisitions)
You have the following rights regarding your data:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate information
- Deletion: Request data removal (subject to legal retention)
- Portability: Export your data in standard format
- Objection: Object to certain processing activities
To exercise these rights, contact info@magicmato.com. We respond within 30 days.
Business data is retained as long as your account is active. Upon cancellation:
- Account data retained for 30 days
- Permanent deletion after 30 days
- Legal/compliance records retained for 7 years
Our Service integrates with third-party providers:
- Payment gateways (Razorpay, Stripe)
- WhatsApp Business API
- Cloud storage (AWS)
These providers have their own privacy policies. Review them before connecting.
Our Service is not intended for children under 18. We do not knowingly collect data from minors.
Data is stored in India (AWS Mumbai region). We comply with India's DPDP Act 2023 for cross-border transfers.
We use essential cookies for:
- Session management
- Security
- Analytics (Google Analytics - anonymized)
You can manage cookie preferences in your browser settings.
We may update this Privacy Policy. Significant changes will be notified via email and dashboard. Continued use constitutes acceptance.
Last updated: 25 August 2025
Privacy Support
Address: Office No. 1 – Fno 768, Baliali Road, TDI City, Mohali, Punjab, 140307
Data rights requests processed within 30 days