Privacy Policy
生效日期: 2026-08-20 · v1.0.0
本文件以英语和阿拉伯语发布。其他语言显示英语版本。
1. Scope and roles
This policy explains how Ramlyon, trading as Ramlyon, handles personal data in the Ramlyon service.
For account, security, billing, and platform-administration data, Ramlyon acts as the controller. For diner and order data processed for a merchant, the merchant determines the purpose and Ramlyon processes the data on the merchant's behalf.
2. Personal data collected — Ramlyon as controller
| Category | Fields |
|---|---|
| Account | full name, email, phone, password (encrypted), preferred locale, acquisition source |
| Session | session id + encrypted secret, IP, user agent, last used |
| Security | login attempts incl. attempted email, IP, user agent, success |
| Verification | email-OTP and password-reset token hashes, optional IP/UA |
| Billing | payer name, transfer reference, wallet/InstaPay identifier, amounts, invoice history |
| Audit | actor id, action, entity, changed-field diffs, IP as a metadata |
3. Personal data processed — Ramlyon as processor for the merchant
| Category | Fields |
|---|---|
| Diner directory | name, phone, email (optional) |
| Orders | customer name/phone snapshots, notes, table label, items, amounts |
| Menu telemetry | localStorage anchor id, item/category views, add-to-cart, device type, browser, OS |
| Diner identity link | phone number, set on the guest session when an order is placed |
| Merchant analytics | per-customer spend, order count, first/last order |
4. Payment information
Ramlyon collects, stores, and transmits no payment-card data at any point. Billing is a manual bank or wallet transfer followed by human review of the payment claim submitted by the merchant.
5. Purposes and lawful bases
The product uses account data to create and administer accounts; session and security data to authenticate users, revoke access, and detect abuse; billing data to review payment claims and maintain invoices and subscriptions; audit data to show who changed operational records; and merchant-processor data to provide menus, ordering, customer management, and analytics selected by the merchant.
6. Explicit limits
Ramlyon uses no advertising pixel. Ramlyon uses no third-party analytics SDK. Ramlyon makes no AI or model-training use of personal data. Ramlyon performs no cross-tenant benchmarking of diner personal data. Ramlyon does not sell personal data.
Ramlyon may use a merchant’s business name, logo, and non-confidential information about its use of Ramlyon — such as how long the merchant has used Ramlyon and the number of menu items it maintains — to identify the merchant as a Ramlyon customer and to promote Ramlyon, including on Ramlyon websites, marketing materials, and advertisements. Any merchant name, logo, or trademark remains the property of its respective owner, and Ramlyon will not claim ownership of it or falsely imply endorsement.
Menu measurement uses a random identifier in the diner's localStorage, not a cookie. It is tenant-specific and is not shared with other restaurants or used for advertising. A diner can reset the identifier or turn measurement off from the menu privacy control.
7. Sharing and sub-processors
Data is shared only as needed to operate the service, fulfil a merchant's instructions, comply with a valid legal requirement, or protect the service. Current infrastructure and service providers are listed on the Sub-processors page. Ramlyon does not disclose diner data to another merchant.
8. Security measures verified in the product
Passwords, one-time-password values, and session secrets are protected with a robust hashing. Sessions are database-backed and can be revoked immediately. The data layer applies per-tenant query isolation. Role-based access control uses four independent gates. The application records a full change-audit trail. Traffic uses TLS in transit. Incoming payment-status webhooks use HMAC verification.
Security concerns can be reported to [email protected].
9. Retention and deletion
The Data Retention Policy lists the periods applied. Tenant closure has a 30-day recovery window before operational data is purged. Old diner names and phone numbers are erased while financial order rows and amounts remain. Billing records are retained for the stated legal-record period.
10. Requests and rights
Merchants can use the tenant export and customer-erasure functions. Because the merchant controls most diner data, a diner request will usually be routed to that merchant and Ramlyon will assist the merchant. Requests can be sent to [email protected].
11. Changes and contact
Material policy changes should be communicated through an appropriate product or written notice. Privacy questions and requests can be sent to [email protected].