Privacy Policy
How MAUZOP handles personal data, Customer Data, Pilot information, operational records and service-provider processing.
1. Who is responsible for this policy?
MAUZOP is operated by Mishika Intelligence, a proprietorship. For privacy and grievance matters, contact mauzopind@gmail.com or write to Office No. 2, Ground Floor, Patiala Highway, Opp. Gopal Sweets, Zirakpur, Punjab 140603, India.
2. Who and what this policy covers
This Policy applies when you visit MAUZOP websites, apply for or participate in the Pilot, create or use an account, contact us, receive support, upload or connect restaurant data, or use MAUZOP features.
3. Information we may process
| Category | Examples | Purpose |
|---|---|---|
| Pilot / enquiry data | Name, business/restaurant name, city, role, outlet count, phone/WhatsApp, work email, current POS/billing system, stated goal | Evaluate fit, contact you, onboard and support the Pilot. |
| Account data | Email, name, mobile, locale, timezone, authentication/account identifiers | Create, administer and secure accounts. |
| Restaurant operational data | Sales, food-cost inputs, inventory, stock movement, wastage, purchases, vendor rates, invoices, aggregator data, recipe/menu information and other agreed records | Provide restaurant-profit intelligence, evidence, reports, confidence, explanations and action support. |
| Business / compliance records | Business identity, legal name, GST/FSSAI or other business information where supplied | Account administration, verification and agreed service workflows. |
| Technical and security data | IP address, user-agent/device information, timestamps, session/security events, rate-limit and system logs | Security, abuse prevention, troubleshooting, reliability and legal compliance. |
| Consent / audit records | Consent version/text snapshot, timestamp, language and related request/session metadata | Document permissions, preferences and accountability. |
| Email / support records | Recipient email, invitations, support messages and related communication metadata | Transactional communication, support and invitations. |
4. Data you should not upload unless specifically required
- Passwords, OTPs, private keys or payment-card secrets.
- Government identity documents, bank credentials or special/sensitive personal information unless an agreed workflow specifically requires it.
- Children's personal data. MAUZOP is intended for business users aged 18 or older.
- Any information you are not authorised to provide.
5. How we use information
- Evaluate Pilot/access requests and communicate with you.
- Create, administer and secure accounts.
- Ingest, analyse and explain agreed restaurant operational data.
- Provide reports, evidence, confidence labels and recommended next-verification steps.
- Provide onboarding, customer support and service communications.
- Detect abuse, fraud, attacks, unauthorised access and reliability issues.
- Maintain consent, audit, security and contractual records.
- Comply with law and establish, exercise or defend legal claims.
6. Customer Data ownership and permitted processing
As between MAUZOP and a restaurant/business customer, the customer retains its rights in the data it uploads, connects or otherwise supplies (“Customer Data”). Supplying Customer Data does not transfer ownership to MAUZOP. The customer grants MAUZOP only the rights reasonably required to host, transmit, scan, analyse, secure, support and otherwise process Customer Data for the agreed service and lawful obligations.
7. Advertising, sale of data and product improvement
- No sale: MAUZOP does not sell personal data or Customer Data.
- No targeted advertising from identifiable Customer Data: MAUZOP does not currently use identifiable restaurant/customer operational data for targeted advertising.
- No cross-customer model training by default: MAUZOP will not use identifiable Customer Data to train a general-purpose or cross-customer model unless a separate written agreement and legally sufficient notice/permission expressly authorise that use.
- De-identified improvement: MAUZOP may use information that has been properly de-identified or aggregated for product reliability, analytics and improvement, provided MAUZOP does not reasonably attempt to re-identify it.
8. AI processing
MAUZOP can operate in deterministic and AI-enabled modes. The production architecture contains an approved external OpenAI provider path for AI reporting, but external AI processing may be disabled or enabled by controlled configuration. When an AI-enabled feature is active, relevant business context, derived metrics, text and/or other content needed for that requested feature may be sent to the disclosed AI provider. Because payload scope is feature-dependent, do not assume that every AI feature is local-only. MAUZOP should show or otherwise document the applicable processing where required.
AI output is advisory. It can be incomplete or wrong and depends on source data. The operator remains responsible for material business decisions.
9. Infrastructure and service providers
| Provider | Current role | Data relevance |
|---|---|---|
| Supabase | Production PostgreSQL database, authentication and storage/evidence workflows; production project recorded in Mumbai | Account, consent, Pilot, business, report, AI-run/audit and other application records; storage workflows where used. |
| UpCloud | Production Next.js/Docker runtime, Caddy, malware scanning and ClamAV | Application/runtime data and logs; uploaded evidence may pass through scanning. Exact UpCloud deployment zone is not represented here as verified. |
| Resend | Transactional and notification email | Recipient email and message/invitation information required for email delivery. |
| OpenAI | Conditional external AI-report provider when approved/enabled | Feature-dependent business context/content required for an enabled AI request. |
Vercel is not treated as current production hosting based on the current production architecture. GitHub is used for source-code/repository workflows and is not represented here as a Customer Data store.
10. Cross-border processing
The production Supabase project is recorded in Mumbai. Other infrastructure or service providers may process limited data outside India depending on their service architecture and the configured deployment. MAUZOP will use cross-border processing only as permitted by applicable law and appropriate contractual/security safeguards.
11. Retention
Account/contact data may be retained while the account is active and for up to 12 months after closure. Uploaded restaurant operational data is deleted from active systems within 30 days after closure or a valid deletion request, subject to applicable legal obligations. Generated reports may be retained for up to 30 days after closure. Rolling backups may persist for up to 35 days. Security and audit logs are generally retained for 12 months and may be kept longer for an active legal or security issue. Billing, tax and legal records are retained as required by applicable law.
Security and ICT logs may be retained for at least the minimum period required by applicable cyber-security law where that requirement applies. Customer Data after termination is handled under the applicable service/Pilot terms, valid deletion requests, legal holds and the verified backup lifecycle. We do not claim a backup deletion period that the production system has not been technically verified to meet.
12. Security
MAUZOP uses risk-based technical and organisational safeguards such as authentication, access control, least privilege, logging/monitoring, malware scanning, secure transport, backups and incident-response processes. No internet service is absolutely secure, and MAUZOP does not claim otherwise.
13. Privacy and data rights
Depending on applicable law and MAUZOP's role for the data, you may request access/information, correction, updating, completion, erasure, withdrawal of consent and grievance redressal. For Customer Data controlled by a restaurant customer, MAUZOP may need to coordinate the request with that customer.
14. Grievance Officer
Legal Head — MAUZOP
mauzopind@gmail.com
Office No. 2, Ground Floor, Patiala Highway, Opp. Gopal Sweets, Zirakpur, Punjab 140603, India
We aim to acknowledge privacy or grievance requests within 2 business days and target resolution within 15 business days, or sooner where applicable law requires.
15. Changes to this policy
We may update this Policy when our product, infrastructure or law changes. Material changes will be communicated reasonably, and fresh consent will be sought where law requires it.
Privacy contact: Avishek Kamboj, Legal Head, mauzopind@gmail.com. MAUZOP has not appointed a formal Data Protection Officer (DPO).