Privacy Policy
What personal and business information Biller collects when you use biller.app and our apps, why we collect it, and who we share it with.
Last updated August 11, 2026 · version 2026-08-11.1
1. What we collect
Account & outlet data: the mobile phone number you register with (verified via Firebase Authentication's phone one-time-passcode flow), your name, and your outlet's details — name, address, GSTIN, menu items and prices, and staff accounts you create.
Billing data: the bills you create, their line items, taxes, payment status, and any customer name/phone number your outlet chooses to record on a bill (for example, to send that customer their bill by WhatsApp or SMS).
Menu photos: if you use menu-scan onboarding, the photo of your printed menu that you upload, sent to Google's Gemini vision model to extract item names and prices.
Payment data: if you buy a Biller-credit pack, Razorpay collects and processes your card/UPI/net-banking details directly — we receive only the payment outcome (succeeded/failed) and an order reference, never your full payment credentials.
Device & usage data: standard technical data such as IP address, browser/device type, and in-app usage events (for example, which screens you visit and which features you use), collected automatically when you use the app.
How you found us: on your first visit to our site, we capture the page you landed on and, if your browser sent one, the full address of the page that referred you — this happens on every first visit, marketing link or not. If you arrived from a marketing link (for example a Google ad or a campaign we ran), we also capture the campaign parameters on that link. We store this against your account when you sign up so we can tell which marketing efforts actually bring in real outlets — see §5 for how this is stored.
Consent record: when you check the signup box for these terms, we store the policy version you accepted and a timestamp against your account, so we can show you the same choice again if the policy changes materially. If you separately opt in to product updates and offers (see §6), we store that choice, its version and a timestamp the same way.
2. How we use it
How we use your information depends on whether you're a restaurant operating on Biller, or a customer/diner whose details a restaurant recorded while billing you.
Restaurant owners
The menu, ingredient, inventory, billing and other operational data you enter is stored and processed to run the core service for your outlet: creating bills, running the kitchen display, generating the menu catalog from a photo you upload, and calculating your own insights and reports. It's used for your own analytics — showing you what your outlet is doing — and to keep your account, staff logins and credit balance accurate.
We may use aggregated, non-identifiable data drawn across outlets — for example, typical ingredient lists or usage patterns for a dish, with no outlet identified — to prepopulate ingredient/inventory suggestions for new menu items and to improve the product generally. This aggregate use never identifies your outlet or its individual figures to anyone else.
Customers and diners
If a restaurant using Biller records your name, phone number or order preferences on a bill, providing those details at that restaurant is treated as your acceptance of this policy for how Biller, on that restaurant's behalf, uses them. We use them to show you and your preferences at restaurants you visit that use Biller, and to help that restaurant understand its customer growth and build a relationship with you over repeat visits; we also use them to send you your bill by the channel the restaurant chooses (WhatsApp, SMS, or a scannable QR code) and, if you opt in, to deliver browser push notifications for order and kitchen-status updates.
Aggregated, non-identifiable data across diners MAY also inform product insights we offer to nearby restaurants on Biller (for example, general area trends) — this is a capability we're building towards, not something active today. A restaurant MAY also use Biller to send you offers or promotions in future; we do not do this today, and any such messaging will always be sent through and disclosed by Biller, never sold or handed to a third party.
If you'd rather we and the restaurants you've visited did not hold your data, contact us (§12) and we will remove it, subject to any record-keeping a restaurant is legally required to retain (for example, for tax and accounting purposes).
3. Who we share it with
We don't sell your data. We share it only with the service providers that power the features above, and only to the extent each needs to do its job:
- Firebase Authentication (Google) — verifies your phone number and manages sign-in.
- Razorpay — processes credit-pack payments; holds your payment credentials, not us.
- Google Gemini — processes a photo of your menu when you use menu-scan onboarding, to extract item names and prices.
- Our hosting provider (see §4) — stores outlet, bill and account data on our behalf.
We may also disclose information where required by law, to a court order or government request, or to protect the rights, property or safety of Biller, our users, or the public. If Biller is ever acquired or merges with another company, your information may transfer as part of that transaction, subject to this policy.
4. Where your data is stored
Outlet, bill, menu and account data is stored in a managed MongoDB-compatible database hosted on Microsoft Azure infrastructure. If we change infrastructure or database providers, we will update this section.
5. Cookies and analytics
We do not run any in-app product-analytics tool inside the authenticated billing app today. On our public website, we use Google Analytics to see how visitors find and use Biller.app, and Google's ad tools to measure whether an ad someone clicked led to a signup — see below for the choice you get on your first visit.
On your first visit, we read the full address of the page you landed on and, if your browser sent one, the full address of the page that referred you — including its path and any query parameters, not just the site name — plus any campaign parameters already present on that URL (such as which ad or campaign you clicked, if you arrived from a marketing link). We store this in your browser (first-party local storage, not a third-party cookie) and clear it as soon as you sign up. This is how we measure which marketing channels bring in real outlets — it never leaves our own systems and is never sold or shared with an advertiser.
On your first visit, we show a short banner asking whether it's okay to collect that anonymous visit data. Choosing "No thanks" stops it for your browser; choosing "Sounds good" turns it on. You can change your mind any time by clearing your browser's saved data for Biller.app, which shows the banner again.
Separately from this analytics tracking, we may also collect non-identifiable, aggregated data about bills, restaurants and customers to improve the product generally — see §2 for what that covers. It isn't part of the choice above.
6. Push notifications and email
If you opt in, we use the standard browser Web Push API to send order and kitchen-status notifications to your device. You can withdraw consent at any time from your browser's notification settings; declining or revoking push notifications does not affect any other feature of the service.
We email you two kinds of messages: transactional (bill receipts, payment confirmations, account/security notices) that we send regardless of preference, since they're necessary to run the service, and reminder/product (onboarding tips, feature updates, re-engagement) messages that we send by default to every account. You can turn these off at any time for your own address, from your profile menu's email preference or the unsubscribe link included in every such email. If your outlet has more than one admin, each admin's email preference is managed separately, so turning yours off does not turn off a co-admin's.
Product updates and offers on your phone number: unlike the email above, we do not send you marketing messages on your phone number (WhatsApp/SMS) unless you separately opt in with a dedicated checkbox at signup or in your profile menu — this is unticked by default and never required to use Biller. If you opt in, we record that choice with a timestamp against your account so we have a clear record of when you agreed and to what. You can withdraw this at any time from the same profile-menu control, just as easily as you turned it on.
7. How long we keep it
We keep account and outlet data for as long as your account is active. What happens when you delete your account (see §10) depends on whether you're a diner or a restaurant owner/staff member.
If you're a diner: we remove your login, phone number and email right away. Bills you're already on are legally required to be kept for the outlet's accounting/tax records, so instead of deleting them we detach them from your identity and reduce them to your first name only — no phone number, email or other way to reach or identify you remains.
If you're a restaurant owner or staff member: we remove your login and your name, email/phone and photo from your profile right away. Completed bills and other financial records stay with the outlet for accounting/GST purposes, as required by law, but Bills you created or served no longer carry your name or account id — they keep only a de-identified placeholder, the same way a diner's bills keep no reachable phone/email after deletion. A note of your role, pay and departure date is kept in the outlet's team history, the same way any other staff change is recorded, but it is no longer linked to your account id either. We also remove any push-notification subscriptions tied to your device for outlets you leave, and clear your contact details from any team-invite record still on file.
Menu photos and descriptions you add are used to build your catalog; they're retained as Biller's property (non-identifiable data) and are not deleted when you delete your own account.
8. Security
We use reasonable technical and organizational measures to protect your information. No method of transmission or storage is 100% secure, so we can't guarantee absolute security, but we work to keep your data protected and to respond quickly if something goes wrong.
9. Children
Biller is a business tool for restaurant operators and is not directed at children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us (§12) and we will remove it.
10. Your rights
You can review or update your account and outlet information directly in the app. You can also self-serve delete your account at any time — a "Delete my account" control in your profile menu (diners: next to Logout on your home screen) — which removes your login and personal profile data immediately, subject to the retention described in §7. If you're the only remaining admin of an outlet, we'll ask you to hand admin access to a teammate or close the outlet first, so it isn't left with no one able to manage it. See our Account Deletion page for step-by-step instructions, including a manual-request path if you can't access the app.
You can also request a copy of your outlet's data by contacting us at the details in §12, subject to the same retention rule above. We will respond within a reasonable time, and in any case within 30 days.
11. Changes to this policy
We may update this policy from time to time. We'll update the "Last updated" date above and, for material changes, make reasonable efforts to notify active accounts.
12. Contact us
Questions about this policy, or a request about your data (including a request to remove it — see §2)? Reach us at support@biller.app or +91-8147902676, or by post to Biller, 012, Sai Vandana Brundavan Apt, Off Sarjapura Road, Bangalore - 560035, India.
See also our Terms of Service and Refund & Cancellation Policy.