Security

Your books. Your people.

Who can see the day, what gets written down, and what you can take with you.

Separation

One restaurant. One set of books.

Every record belongs to a restaurant, and the server checks that before it answers.

What is actually built.

Three roles decide what a person can open: admin, manager, and staff.*

Staff list showing each person and the role they hold

* Each role widens what the one below it can reach. Salary details and business settings sit above the staff role.

Cash sessions, petty-cash vouchers and electricity payments are written down with the person who entered them.*

History of changes on a cash session, each row naming the person who made it

* The record is written by the database at the moment of the change, not by the screen the person was using.

You can download your own record as a single file, whenever you want.*

* Covers your account, the cash sessions you opened, the petty-cash vouchers you issued, the banking you recorded, electricity recharges and salary advances. Payroll detail and uploaded documents are not in the file yet.

You can close an account and have the personal details on it removed.*

* Name, email and phone are cleared and the login stops working. The day’s figures stay balanced, with no person attached to them. Documents uploaded against that person are not covered by the same request.

A business signs up with its GSTIN, and the number is checked against a GST registry.*

* A live registration is confirmed against a GST lookup service at signup. It is a registration check, not a full background check.

Where it sits

Singapore. Backed up weekly.

The database runs on managed Postgres in Singapore, with the provider’s own daily backups and a separate encrypted copy written to different cloud storage each week.

Honesty

What we do not claim.

No certification. No SOC 2, no ISO 27001, no independent penetration test. If a certificate is what your buyer needs, we do not have one to send.

Questions? Answers.

Can a manager at one outlet see another outlet’s numbers?

No. Records belong to a restaurant, and a request is answered only for the restaurant the person signed in to.

Can staff see salaries?

No. Salary figures, salary configuration and the business settings sit above the staff role. Staff see the shift in front of them.

Can we see how a cash count reached its final figure?

Yes. Cash sessions, petty-cash vouchers and electricity payments keep the history of what changed and who changed it, so a figure can be explained later instead of remembered. An admin can read that history.

Can I get my data out?

Yes, at any time, as one downloadable file. It covers your account and the day-to-day entries you made. Payroll detail and uploaded documents are not in it yet.

What happens when a staff member leaves and asks to be erased?

Their name, email and phone are cleared from the account and the login is closed. The restaurant’s figures stay intact so the books still balance, with no person attached to them. Documents uploaded against that person are not covered by the same request.

Do you have SOC 2 or ISO 27001?

No. Neither, and no independent penetration test. That is the whole answer.

Where is the data stored?

On managed Postgres in Singapore. It is not stored in India — worth knowing before you assume otherwise.

Is the connection encrypted?

Yes. Everything between the phone or laptop and the server travels over HTTPS.