1. Who We Are
Resto is a cloud-based point-of-sale (POS), business-management, and hospitality software platform for restaurants, cafés, hospitality businesses, and other supported businesses.
Resto functionality may include:
• Point-of-sale (POS).
• Order and sales management.
• Table and reservation management.
• Kitchen and order-status management.
• Menu and item management.
• Inventory management.
• Branch management.
• Employee roles and permissions.
• Customer and loyalty management.
• Electronic invoicing.
• Expense and operational records.
• Reports and analytics.
• Digital menus and self-ordering.
• Merchant websites.
• Customer displays.
• Technical integrations with third-party systems and devices.
Resto is a software and technology provider and point-of-sale platform. Resto is not a bank, financial institution, payment company, digital-wallet provider, money-transfer service, card issuer, acquiring institution, or payment-processing service provider.
2. Data Protection Roles
For personal information collected directly by Resto to administer its accounts, subscriptions, and services, Resto may act as the data controller depending on the relevant processing activity.
Where a merchant uses Resto to process information relating to its own customers, employees, or operations, the merchant generally determines the purposes of the processing, while Resto processes the information on the merchant's behalf in order to provide the requested services.
3. Personal Information We May Process
Depending on the services used, Resto may process:
Account and contact information:
• Name.
• Email address.
• Telephone number.
• Account information.
• User identifier.
• Roles and permissions.
• Authentication information required to secure the account.
Business information:
• Business name.
• Business details.
• Branch information.
• Business addresses.
• Billing information.
• Tax information where required.
Operational information:
• Orders.
• Sales.
• Invoices.
• Menu items.
• Inventory.
• Tables.
• Reservations.
• Employee roles and permissions.
• Expenses.
• Branches.
• Operational reports.
4. Sales and Collection Records
For POS reporting, invoicing, and business records, Resto may store operational information associated with a sale, including:
• Sale amount.
• Collection method recorded by the merchant, such as cash or card.
• Transaction status.
• Transaction or reference number where available.
• Transaction date and time.
• Relevant branch or POS location.
This information is used for order management, invoicing, reports, and merchant operational reconciliation.
Recording a collection method such as "card" in a POS invoice or report does not mean that Resto stores or processes the card credentials themselves.
Resto does not collect or store:
• Full payment-card numbers.
• CVV/CVC security codes.
• Card PINs.
• Online-banking passwords.
• Complete confidential bank-account credentials.
• Complete payment-card credentials.
5. Merchant Customer Information
A merchant using Resto may enter information relating to its own customers, including:
• Name.
• Telephone number.
• Email address.
• Order history.
• Loyalty activity or balances.
Resto processes this information only to the extent necessary to provide the requested software services to the merchant.
6. Technical Information
Technical information may include:
• IP address.
• Device type.
• Operating system.
• Application version.
• Browser information for web services.
• Crash logs.
• Performance logs.
• Security and operational information necessary to protect and troubleshoot the Services.
7. Resto as a Point-of-Sale Platform
Resto is primarily point-of-sale (POS) and business operations software.
A merchant may record a collection method for an order in Resto, including:
• Cash.
• Card.
• Bank transfer.
• Another collection method configured by the merchant.
The collection method is recorded for invoicing, sales records, reporting, and operational reconciliation.
Recording the collection method does not mean that Resto provides the underlying payment service.
8. Tap Payments — Web Use Only
Tap Payments is not used to accept or process payments within the Resto POS iOS application.
Tap is used only in specific web-based scenarios, including:
• Processing Resto subscription fees paid through the Resto website.
• Processing online payments on a merchant's customer-facing ordering website where the merchant chooses to enable online payment.
In these scenarios, Tap Payments provides the underlying payment service and processes payment instrument information under its own terms, privacy policy, and regulatory obligations.
Resto does not receive or store:
• Full payment-card numbers.
• CVV/CVC security codes.
• Card PINs.
• Complete online-banking credentials.
Resto may receive limited operational information following a transaction, including:
• Transaction reference.
• Transaction amount.
• Transaction status.
• Information required to associate the transaction with the relevant order or subscription.
9. Nearpay Integration in the Resto POS iOS App
The Resto POS iOS application may support a technical integration with Nearpay Connect for remote communication with a separate external payment terminal used by the merchant.
This integration does not turn the iPhone or iPad running Resto into a card-reading terminal.
When the merchant selects card payment:
1. The merchant's staff selects the collection method in Resto.
2. Resto may send the sale amount and limited operational information to the external Nearpay terminal.
3. The customer completes the actual payment on the separate external payment terminal.
4. The card or other supported payment method is presented to the external terminal and is not entered into the Resto application.
5. The external terminal and payment provider perform the payment transaction.
6. Resto may receive limited operational information, such as the transaction result or reference, solely to update the POS order, invoice, and reports.
Resto does not read, collect, or store full card numbers, CVV/CVC codes, or card PINs through this integration.
Resto also does not:
• Hold merchant or customer funds.
• Transfer funds.
• Perform financial settlement.
• Issue payment cards.
• Operate digital wallets.
• Provide bank accounts.
• Provide lending or financing.
• Act as a card issuer or acquiring institution.
Resto's role is limited to operational communication between the POS software and the external payment terminal.
10. Resto POS Device Permissions
Camera:
The camera may be used to scan QR codes, product barcodes, device-pairing codes, and loyalty codes.
Resto does not retain camera images merely for the purpose of scanning a code.
The decoded value may be used or transmitted where necessary to perform the requested function.
Bluetooth and Local Network:
These permissions may be used to discover and communicate with devices selected by the merchant, including receipt printers and supported operational hardware.
Face ID and Touch ID:
Biometric authentication may be used as an optional local authentication mechanism. The biometric check is performed by the device operating system. Resto does not receive or store copies of facial or fingerprint biometric templates.
Notifications:
Notifications may be used to deliver order updates, operational alerts, account notifications, and service-related information.
11. How We Use Information
Resto may use information to:
• Create and manage accounts.
• Operate point-of-sale functionality.
• Manage orders and sales.
• Generate and manage invoices.
• Manage inventory.
• Manage branches.
• Manage employees and permissions.
• Operate loyalty functionality.
• Manage customers.
• Manage tables and reservations.
• Generate reports and analytics.
• Administer Resto subscriptions and billing.
• Provide customer and technical support.
• Diagnose errors and improve performance.
• Protect accounts and systems.
• Prevent misuse and technical fraud.
• Comply with legal, accounting, and tax obligations.
• Deliver operational notifications.
• Send marketing communications where legally permitted or where appropriate consent has been obtained.
12. Legal Bases for Processing
Depending on the context, Resto may process personal information where necessary:
• To perform or administer a contractual relationship.
• To provide a service requested by the user or customer.
• To comply with a legal or regulatory obligation.
• To protect the security and integrity of the Services.
• For legitimate interests where permitted by applicable law.
• Based on consent where consent is required.
• Under the lawful instructions of a merchant where Resto acts as a data processor.
13. Sharing Information
Resto does not sell or rent personal information.
The minimum information necessary may be shared with parties that support the Services or provide a feature selected by the merchant.
Service providers may include:
• Hosting providers.
• Cloud infrastructure.
• Database, storage, and backup providers.
• Firebase Cloud Messaging.
• Sentry.
Independent third parties may include, depending on the services enabled:
• Tap Payments.
• Nearpay.
• The merchant's bank or payment provider.
• Other integrations selected by the merchant.
Independent providers operate under their own terms, privacy policies, and regulatory responsibilities.
Information may also be disclosed to government, regulatory, judicial, or law-enforcement authorities where required by applicable law.
14. Cookies and Similar Technologies
Resto websites may use cookies and similar technologies to:
• Maintain authenticated sessions.
• Enable login functionality.
• Protect accounts.
• Save user preferences.
• Operate website functionality.
• Measure performance.
• Improve user experience.
Users may manage cookies through their browser settings.
15. Data Retention
Resto retains personal information only for as long as necessary for the purpose for which it was collected or as required to meet contractual or legal obligations.
Certain records may need to be retained after an account or subscription ends, including:
• Invoices.
• Accounting records.
• Tax records.
• Records required to establish or defend legal rights.
• Records required to be retained by applicable law.
16. Data Destruction
When there is no longer a lawful or operational reason to retain personal information, and no legal obligation requires continued retention, the information will be deleted, destroyed, or anonymized as appropriate.
17. Account Deletion
Users may request deletion of their account and associated personal information that Resto is not legally required to retain.
Privacy and account-deletion requests may be submitted to:
support@resto.sa
Where individual account creation is available directly through the iOS application, Resto provides a method to initiate account deletion within the application in accordance with applicable platform requirements.
Certain legally required records may continue to be retained after account deletion.
18. Data Security
Resto implements reasonable technical and organizational safeguards designed to protect information against:
• Unauthorized access.
• Unlawful use.
• Unauthorized disclosure.
• Unauthorized alteration.
• Loss or destruction.
Measures may include:
• Encryption in transit.
• Access controls.
• Role and permission management.
• System monitoring.
• Security and event logging.
• Backups.
No electronic system can guarantee absolute security.
19. International Data Transfers
Some service providers may operate systems or infrastructure outside the Kingdom of Saudi Arabia.
Where providing the Services requires the international transfer of personal information, Resto handles such transfers in accordance with applicable Saudi data-protection requirements and applies appropriate safeguards where required.
20. Advertising and Tracking
Resto does not sell personal information.
Resto does not use information collected through the Resto POS application to track users across third-party apps or websites for third-party advertising purposes.
21. Children
Resto is a business platform primarily intended for businesses and their authorized personnel and is not directed toward children.
Where a merchant enters information relating to its customers into Resto, the merchant remains responsible for having an appropriate lawful basis for collecting and processing that information.
22. Your Rights
Subject to applicable law, data subjects may have the right to:
• Be informed about the legal basis and purposes of processing.
• Access their personal information.
• Request a readable and clear copy of their personal information where applicable.
• Request correction, completion, or updating of inaccurate or incomplete information.
• Request destruction of personal information where legally permitted.
• Withdraw consent where consent is the applicable legal basis.
• Submit an inquiry or complaint regarding the processing of personal information.
Requests may be submitted to:
support@resto.sa
Resto handles qualifying requests within the periods required by applicable law.
23. Changes to This Privacy Policy
Resto may update this Privacy Policy to reflect changes in:
• Services or functionality.
• Processing practices.
• Security requirements.
• Legal or regulatory requirements.
The latest revision date will be displayed at the top of the page.
24. Contact Us
Mustari Establishment For IT Systems
National Number: 7043488738
Kingdom of Saudi Arabia
Email: support@resto.sa
Need help?
If you have any questions about this Privacy Policy or your personal information, contact us at support@resto.sa. We can assist with access, correction, deletion, or other privacy-related requests. support@resto.sa