Privacy Policy
What we collect, why we collect it, who we share it with, and how to get it deleted.
- Effective
- September 4, 2026
- Entity
- Antigravity
- Jurisdiction
- India
- Applies to
- kafei.in
Google API Services — Limited Use disclosure
Kafei's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
1. Who we are
Antigravity ("we", "us") operates Kafei, a restaurant operations platform covering point-of-sale billing, kitchen display screens, menu management, table QR ordering, inventory, and AI-assisted forecasting (the "Services"). This policy covers https://kafei.in, the Kafei web application, and our APIs.
Data controller: Antigravity, Kolkata, West Bengal, India. Contact: privacy@kafei.in or +91 99030 85026.
For data that restaurants put into Kafei about their own guests and staff, the restaurant is the controller and we are the processor. Those terms are in our Data Processing Addendum.
2. Google Sign-In and Google user data
2.1 The scopes we request
Signing in with Google is optional — you can use an email and password instead. If you do use it, we request only these non-sensitive scopes, and nothing else:
openid— confirms that the sign-in came from Google and identifies the account..../auth/userinfo.email— your Google account email address. This is the identifier for your Kafei account and the address we send account and billing notices to..../auth/userinfo.profile— your name and profile picture, shown on your profile and next to your actions inside your restaurant workspace.
We do not request access to Gmail, Drive, Calendar, Contacts, or any other Google service, and the Services do not read, write, or store content from them.
2.2 What we do with it
- Create your account and sign you in.
- Apply your role and branch permissions (owner, manager, cashier, waiter, kitchen).
- Send transactional messages: security alerts, billing notices, and account recovery.
Google Sign-In returns a short-lived access token that we use once, server-side, to read the email and profile fields above. We do not request offline access and we do not store Google refresh tokens.
2.3 What we never do with it
- Never sold. We do not sell, rent, or license Google user data.
- Never used for advertising. We do not share it with advertisers, ad networks, or data brokers, and we do not use it for retargeting or profiling.
- Never used to train AI models. Google user data is not used to develop, train, retrain, or fine-tune generalized or foundation AI/ML models, ours or anyone else's. See the AI Usage Policy.
- Not read by humans. Google user data is processed by automated systems. A human at Antigravity reads it only with your explicit consent, when it is necessary for security purposes such as investigating abuse, or where the law requires it.
We transfer Google user data to others only when it is necessary to provide or improve a feature you are using, to comply with applicable law, or as part of a merger or acquisition in which the receiving party is bound by this policy — the exceptions permitted by the Limited Use requirements, and nothing beyond them.
2.4 Disconnecting Google
- In Kafei: Settings → Privacy → Google Account Connection, which links straight to your Google permissions page.
- At Google: revoke Kafei's access at myaccount.google.com/permissions.
- Either action stops Google sign-in immediately. Your restaurant records stay intact and you can keep signing in with an email and password. To remove the data as well, see section 7.
3. What else we collect
3.1 Information you give us
- Account: name, email, phone number, password hash, restaurant and branch names, business tax identifiers (GSTIN/VAT).
- Billing: billing address and transaction records. Card details go directly to our PCI-DSS compliant payment providers — raw card numbers never reach our servers.
- Operational content: menus, recipes, ingredients, pricing, floor and table layouts, staff profiles and roles.
- Support: tickets, contact form messages, and their attachments.
3.2 Guest data, collected for the restaurant
- Orders: table number, items, dietary notes, timestamps, and bill settlement details.
- Optional contact: a phone number or email, only if the guest gives one for a receipt or an order status update.
3.3 Collected automatically
- Logs: IP address, browser and OS, device identifiers, pages visited, and error telemetry.
- Local storage and cookies: session tokens, theme and branch preferences. Detailed in the Cookie Policy. We do not run third-party advertising or cross-site tracking pixels.
4. Why we are allowed to process it
If you are in the EEA, the UK, or another region with comparable law, our legal bases are:
- Contract: running the Services under the Terms of Service.
- Legitimate interests: keeping the platform secure, preventing fraud and abuse, and supporting customers.
- Consent: optional marketing, non-essential cookies, and optional integrations. You can withdraw it at any time.
- Legal obligation: tax, accounting, and statutory record-keeping.
5. Who we share it with
- Sub-processors: the hosting, database, payment and messaging providers listed on our Sub-processors page, each under a written data protection agreement.
- Payment processors: to take subscription payments and, where the restaurant enables it, guest payments.
- Legal: in response to a valid court order, subpoena, or lawful request, after reviewing it for validity and scope.
- Business transfer: in a merger or acquisition, with this policy continuing to apply until the successor gives notice of a change.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
6. International transfers
We are based in India and our sub-processors operate globally, so your data may be processed outside your country. Where that involves personal data leaving the EEA or the UK, the transfer is covered by the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum, plus the technical measures in our Security Policy.
7. Retention and deletion
- While your account is active: we keep your account and restaurant records so the Services work.
- Deleting your account: go to Settings → Privacy → Delete Account & Scrub Data, or email privacy@kafei.in from your account address. We confirm within 5 business days.
- What happens then: your personal data, any data obtained through Google Sign-In, and your restaurant's operational records are permanently deleted or irreversibly anonymised within 30 days. Encrypted backups are purged on their normal rotation, within 90 days.
- What we must keep: invoices and transaction records that tax and accounting law requires us to retain, for the statutory period, and nothing more.
- Inactive accounts: trial workspaces with no activity for 12 months are deleted after we give 30 days' notice by email.
8. Security
- TLS 1.3 for all traffic between your devices and our servers.
- AES-256 encryption at rest for databases and stored credentials.
- Tenant isolation: every query and cache key is scoped to a tenant ID so one restaurant cannot reach another's data.
- Role-based access control and least privilege for staff and infrastructure.
No system is perfectly secure. If we discover a personal data breach affecting you, we will notify you and the relevant supervisory authority within the time limits the law sets. Report a suspected vulnerability to security@kafei.in — see the Security Policy.
9. Your rights
Depending on where you live — the GDPR, UK GDPR, CCPA/CPRA, and India's DPDP Act all apply here — you can ask us to:
- Give you a copy of your data in a portable, machine-readable format — you can do this yourself, right now, from Settings → Privacy → Export My Data.
- Correct anything inaccurate or incomplete.
- Delete your data (see section 7).
- Restrict or object to a particular kind of processing.
- Withdraw consent where consent is the basis we rely on.
Email privacy@kafei.in and we will respond within 30 days. Exercising these rights never costs you service or a worse price. If you are unhappy with our response you can complain to your local data protection authority.
10. Children
Kafei is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children. If we learn we have, we delete it.
11. Changes
We will update this policy as the product and the law change. Material changes are announced by email and by an in-app notice before they take effect, and the effective date at the top of this page always reflects the current version.
Questions about this policy?
Write to us for data subject requests, deletion requests, security reports, or compliance reviews. We respond within 5 business days.
Antigravity, Kolkata, West Bengal, India