Skip to content
Security & data protection

Built to be trusted with your restaurant’s data

You’re handing a platform your menu, your customers, and your orders. Here’s exactly how we protect all three — and what we deliberately don’t claim.

Payments — we never see card numbers

Card payments are processed through your own configured payment provider’s gateway, using its hosted checkout and tokenization. Ontabee never sees or stores your customers' card numbers (PAN). Your money settles directly to your account — we don’t sit in the middle and we take no commission. Provider callbacks are signature-verified and de-duplicated before we act on them.

Your data is yours — export it any time

Your menu, customers, and order history belong to you. From your dashboard (Data & privacy → Data requests) you can request a full export of everything, in machine-readable JSON, any time — the anti-lock-in promise, built into the product, not a favor you have to ask for. If you ever leave, you take your data with you.

Privacy rights — GDPR, India DPDP, UAE

We honor access, export, and deletion requests for you and for your diners. Deletion anonymizes personal details while retaining the financial records the law requires. Production data can be hosted in the region you need at onboarding (EU, India, or GCC) so it stays in your jurisdiction. See our Privacy Policy for the full detail.

Encryption & credentials

All traffic is encrypted in transit with TLS. The payment, SMS, and email provider credentials you configure are encrypted at rest in a secrets vault, referenced indirectly, and never written to logs. We never log card data, tokens, or personal data.

Access control & auditing

Every tenant’s data is isolated — a restaurant can only ever reach its own data, and the system is built to deny rather than leak if a scope is ever missed. Access is role-based, and privileged actions — including any support impersonation — are audited. Authentication and public ordering endpoints are rate-limited against abuse.

Resilience & backups

Production runs on managed cloud infrastructure with automated daily encrypted backups to private, access-controlled storage, and a tested restore procedure. Our aim is that a bad day for the infrastructure is never a bad day for your data.

What we don’t claim

We do not currently hold SOC 2 or ISO 27001 certification, and we won’t pretend to — our engineering practices are built toward those standards, and we’ll say so plainly here the day that changes. We’d rather earn trust with accuracy than lose it with a badge we haven’t earned.

Data Processing Agreement (DPA)

Need a signed DPA for your agency, multi-location, or enterprise agreement? We have one available on request — see our DPA or email [email protected].

Reporting a security issue

Found something? Email [email protected] with the details and we’ll get back to you. We appreciate responsible disclosure and won’t pursue good-faith researchers.

Operated by Ontabee Solutions Pvt. Ltd. (a Technoduces company), Coimbatore, India. Built by Technoduces, a software company shipping products for businesses across 30+ countries since 2011.

Your data, your customers, your call.

Commission-free, no lock-in, and everything exports the day you ask.

Start free