Privacy Policy
Last updated: July 25, 2026
1. Introduction
This Privacy Policy explains how Code Peak Nepal Pvt. Ltd., operating the MeroBites platform ("MeroBites," "we," "us," "our"), collects, uses, discloses, stores, and protects personal data in connection with the MeroBites Restaurant Operating System (the "Service"), covering Customers, Restaurant Staff (Waiters, Cooks/Kitchen, Receptionists), Managers, Merchants, and Platform Administrators.
This Policy is designed to comply with Nepal's Individual Privacy Act, 2075 (2018) ("Privacy Act"), the Individual Privacy Regulation, 2077 (2020), the Electronic Transactions Act, 2063 (2008), and, where applicable, the Electronic Commerce (E-Commerce) Act, 2081 (2025). Article 28 of the Constitution of Nepal, 2072 guarantees privacy as a fundamental right covering body, residence, property, documents and data, correspondence, and reputation; this Policy is designed with that constitutional foundation in mind.
2. Who Controls Your Data
Code Peak Nepal Pvt. Ltd. operates the Service and is the primary party responsible for personal data collected through the platform infrastructure — Accounts, app usage, payment facilitation records, and centrally stored operational data.
For restaurant-specific HR or staff data, the relevant restaurant may also be responsible for certain staff data fields; see Section 9. Where a Merchant accesses, processes, or exports personal data through MeroBites — including customer transaction data, staff records, or operational logs — for its own purposes beyond those needed to fulfil orders or operate on the platform, the Merchant is independently responsible for that processing and for compliance with the Individual Privacy Act, 2075 (2018) and all other applicable privacy, employment, and consumer protection laws. MeroBites is not responsible for a Merchant's independent use or misuse of personal data accessed through the Service.
3. Information We Collect
3.1 Information You Provide
- Account information: name, phone number, email address, and password, or social/OTP login credentials.
- Profile information you choose to add.
- Order and transaction information: items ordered, special instructions, table number, payment method selected.
- Reservation and waitlist details: party size, requested time, contact information.
- Reviews, ratings, and other content you submit.
- Grievances or support requests you submit.
- Free-text you type into AI-assisted search, including the date-planning chat.
- For Staff and job applicants: citizenship or identity document scans, CV and application materials, and employment details such as attendance, role, and schedule.
- For Merchants: business registration details, and photographs of printed menus uploaded to the menu-scanning feature.
3.2 Information Collected Automatically
- Device and usage data: device type, operating system, app version, crash logs, and general usage analytics.
- Firebase Cloud Messaging (FCM) tokens used to deliver push notifications, tracked separately for Customer and Staff accounts.
- Approximate location data, where you grant location permission, used to show nearby restaurants.
- Locally cached data on Staff devices to support offline functionality, such as a Waiter's pending orders during a connectivity outage.
3.3 Information From Third Parties
- Payment confirmation data from eSewa and Khalti. We do not store your full payment card or wallet credentials; we receive only the confirmation and reference data needed to reconcile the transaction.
- Authentication data if you sign in using a third-party identity provider, where offered.
4. How We Use Your Information
- To create and manage your Account and authenticate access to role-appropriate features.
- To process orders, reservations, waitlist entries, and payments, and to generate invoices and transaction records.
- To operate Table Sessions and bind orders to the correct table and Customer.
- To provide support and respond to grievances.
- To send operational notifications, such as order-ready and waitlist alerts, and — where you have opted in — marketing communications.
- To detect, prevent, and investigate fraud, abuse, and security incidents.
- To improve and develop the Service, including through aggregated or de-identified analytics.
- To comply with legal obligations, including under the Privacy Act, 2075, tax laws, and labour laws applicable to Merchants.
- To power AI-assisted search and menu scanning, which involves sending data to a third-party AI provider as described in Section 7.
5. Legal Basis for Processing
Under the Individual Privacy Act, 2075 (2018), personal data may generally be collected and processed only with the consent of the data subject, for the purpose for which it was collected. We therefore process your personal data primarily on the basis of your consent, given by using the Service, creating an Account, or otherwise providing data to us, and in limited cases on the basis of: performance of a contract, meaning fulfilling an order or reservation you requested; compliance with a legal obligation, such as tax, labour, or law enforcement requirements; and our legitimate interests in operating, securing, and improving the Service, including the staff monitoring described in Section 9, provided those interests do not unjustifiably override your fundamental privacy rights under Article 28 of the Constitution.
6. How We Share Information
- With the relevant Merchant, to the extent necessary to fulfil your order, reservation, or waitlist request, and to enable that Merchant's staff to do their jobs.
- With payment processors, eSewa and Khalti, to process your payment.
- With Google, as the provider of the Gemini AI models used for AI-assisted search and menu scanning, as described in Section 7.
- With Google Firebase, for push notification delivery and crash diagnostics.
- With our transactional email provider, to deliver account, billing, and support emails.
- With professional advisors, auditors, or regulators where required by law.
- In connection with a merger, acquisition, or sale of assets, subject to confidentiality protections.
- With your consent, or at your direction.
We do not sell personal data to third parties for their own independent marketing purposes.
7. AI Features and Third-Party AI Processing
The Service uses artificial intelligence models operated by Google ("Gemini") for two features. In both cases, data is sent to Google's servers outside Nepal for processing.
AI-assisted search and date planning. When you use natural-language search or the date-planning chat, the text you type is sent to Google for processing so that search tags can be generated. We do not send your name, email address, phone number, account identifier, precise location, order history, or payment data with the query. Because this is a free-text field, please avoid typing personal or sensitive information into it — anything you type is sent as written.
Menu scanning (Merchants only). When a Merchant uses the menu-scanning feature, the photograph of the printed menu is sent to Google so that dish names and prices can be extracted. Merchants should be aware that the whole image is transmitted, including anything else visible in the photograph, and should avoid capturing people or documents that are not part of the menu.
We retain a record of AI search queries and conversations to operate and improve the feature. Unreviewed records are deleted after 90 days, and stored conversation transcripts are removed after 180 days. AI-generated results are not independently verified for accuracy by MeroBites; see Section 4.1 of our Terms and Conditions for the related disclaimer.
8. Data Location and Cross-Border Transfers
Your operational and billing data — Accounts, orders, invoices, menus, staff records, and tax records — is stored on servers located in Nepal, on infrastructure operated by MeroBites. This includes all records relevant to tax and electronic-billing obligations under Nepali law.
A limited set of data is processed outside Nepal by the third parties named in Section 6:
- Text you type into AI search, and menu photographs submitted by Merchants, are processed by Google (Section 7).
- Device push-notification tokens and crash diagnostics are processed by Google Firebase.
- Email addresses and message content for transactional email are processed by our email provider.
Nepal's current framework, including the Individual Privacy Act, 2075 (2018), does not impose a comprehensive codified cross-border transfer regime comparable to GDPR-style adequacy or standard contractual clauses. The Privacy Act does require that data be used only for the purpose for which it was collected, and the Data Center and Cloud Service (Operation and Management) Directives, 2025 (2081) impose requirements relevant to cloud hosting that may affect certain categories of data. Where data is processed outside Nepal, we require those providers to maintain appropriate contractual and technical safeguards. We will update this Policy if Nepal adopts more specific cross-border transfer requirements, including under the Data Act, 2079 (2022).
9. Restaurant Staff and Employment-Related Data
9.1 Purpose of Processing Staff Data
- To verify identity and eligibility to work, using submitted citizenship documents.
- To monitor, log, and audit staff activity within the platform — including attendance events, operational actions such as order submissions, bill approvals and status updates, and system access — for payroll accuracy, operational management, regulatory compliance, security oversight, and quality control. Staff are informed of this monitoring through the Terms and Conditions and, where applicable, through their employment arrangement with the Merchant. This is carried out on the basis of legitimate interests in the secure and accurate operation of a restaurant management system, and compliance with applicable labour and accounting obligations in Nepal.
- To assign shifts and track operational activity relevant to restaurant management.
- To evaluate job applications, using submitted CVs and application data.
- To calculate salary, bonuses, deductions, and advances based on recorded attendance and activity.
- To support Merchants in meeting obligations under the Labour Act, 2074 (2017) and the Contribution Based Social Security Act, 2074 (2017), including SSF-related recordkeeping, recognising that SSF registration and contribution remain the Merchant's own statutory obligation as employer.
9.2 Sensitive Nature of Staff Data
Identity documents and employment data are sensitive. Access within the Service is restricted by role-based access controls. Staff should refer to Section 6 of our Terms and Conditions regarding the scope of their own data access permissions.
9.3 Retention of Staff Data
Attendance, salary, and identity verification records are retained as long as necessary to comply with applicable labour, tax, and accounting obligations in Nepal, and to resolve employment or compensation disputes. See Section 17 for indicative retention periods.
10. Merchant Access to Customer Data
Merchants can access Customer order history, contact details necessary for order fulfilment, and reviews and ratings relating to their own restaurant, as needed to operate their business through the Service. Merchants must not use Customer data obtained through the Service for purposes unrelated to fulfilling orders, operating their loyalty program, or other legitimate restaurant operations, without separately obtaining the Customer's consent. As set out in Section 2, where a Merchant processes Customer data for its own independent purposes it is independently responsible for that processing under the Individual Privacy Act, 2075 (2018).
11. Your Rights
Subject to applicable law, including the Individual Privacy Act, 2075 (2018), your rights may include:
- Access — you may request a copy of the personal data we hold about you.
- Rectification — you may request correction of inaccurate personal data, with supporting evidence where applicable, consistent with Section 28 of the Privacy Act.
- Deletion — you may request deletion of your Account and associated personal data, subject to our right to retain data required for legal, tax, or dispute-resolution purposes.
- Objection and withdrawal of consent — you may withdraw consent to certain processing, such as marketing communications, at any time, without affecting the lawfulness of processing carried out before withdrawal.
To exercise these rights, contact privacy@merobites.com. We will respond within a reasonable time and in accordance with applicable law. If you believe your privacy rights under the Privacy Act, 2075 have been violated, you may also pursue a complaint before the District Court within the statutory limitation period, currently 3 months from the relevant incident.
12. Children's Privacy
The Service is not intended for use by children without appropriate parental or guardian consent and supervision, as described in Section 3.1 of our Terms and Conditions. We do not knowingly collect personal data from children in a manner inconsistent with that Section. Restaurant Staff accounts require a minimum age of 18, as described in Section 3.2 of the Terms.
13. Cookies and Local Storage
Our website sets no cookies and uses no analytics, advertising, or visitor-tracking services. On the subscription page only, your sign-in token is held in browser session storage so you are not asked to sign in twice; it is cleared when you close the tab.
Our app stores data on your device to function: your sign-in session, app preferences, a push-notification token, and — for restaurant staff — a local copy of operating data so the app keeps working during an internet outage. Local data is synced and cleared in normal operation and removed when you log out or remove the account from the device.
You may clear this data through your browser or device settings, or by uninstalling the app, though doing so will affect functionality that depends on it. Our separate Cookies and Local Storage notice sets this out in full.
14. Data Security
We use industry-standard safeguards, including encryption in transit, access controls, and row-level security database policies, consistent with our obligations under the Individual Privacy Act, 2075 (2018) and the Electronic Transactions Act, 2063 (2008). No method of transmission or storage is completely secure. Locally cached data on Staff or Customer devices used for offline functionality should be protected by you through standard device security practices, such as a device lock and not sharing credentials. In the event of a data breach affecting your personal data, we will take reasonable steps to investigate, mitigate harm, and notify you and any relevant authority as required by applicable law.
15. Push Notifications
We store Firebase Cloud Messaging tokens, tracked separately for customers and staff, to deliver alerts such as order-ready notifications or waitlist assignments. Tokens are linked to your account but do not independently reveal your identity.
We distinguish two categories of notification. Operational Notifications include order status updates, waitlist alerts, reservation confirmations, and other messages necessary for the Service to function; these cannot be fully switched off while you have an active order or session. Marketing Communications include promotional offers, loyalty campaign updates, and restaurant recommendations. You may opt in to or out of Marketing Communications at any time through your in-app notification preferences without affecting Operational Notifications. We will obtain your explicit consent before sending Marketing Communications where required by law.
16. Marketing Communications
Where you have opted in, we — and separately, individual Merchants in respect of their own loyalty programs — may send promotional emails, SMS messages, loyalty campaign updates, and other marketing communications. You may opt out at any time via your in-app preferences or the unsubscribe mechanism in the communication itself, without affecting operational notifications necessary for active orders.
17. Data Retention
We retain personal data as long as necessary to operate the Service, comply with legal obligations including tax and labour recordkeeping, resolve disputes, and enforce our agreements. Locally cached data on your device, such as offline order data on a waiter's device, is periodically synchronised and cleared as part of normal app operation, and is removed when you log out or remove an account from the device.
As indicative guidance, we apply the following retention periods, which may be extended where required by a specific legal obligation or an ongoing dispute:
- Transaction invoices and financial records — approximately 7 years, per Nepal accounting and tax obligations under the VAT Act and IRD norms.
- Customer grievance and complaint records — approximately 3 years, for dispute resolution and E-Commerce Act compliance.
- AI search queries and conversation records — 90 days for unreviewed records; stored transcripts removed after 180 days.
- Inactive customer accounts with no login or transaction — approximately 2 years, then reviewed for deletion.
- Unsuccessful job application materials such as CVs and documents — approximately 12 months after the recruitment process.
- Staff identity documents, attendance and salary records — duration of employment plus a minimum of 5 years, per the Labour Act 2074, Social Security Act 2074, and tax recordkeeping.
- Locally cached or offline device data — cleared on sync, logout, or device removal.
These periods are subject to review and may be adjusted to reflect changes in applicable law or regulatory guidance, including any future rules under the Data Act, 2079 (2022).
18. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via in-app notice or email and take effect after posting. Continued use of the Service after such notice indicates acceptance of the revised Policy.
19. Complaints and Regulatory Contact
If you have a concern about how we handle your personal data, please contact us first at privacy@merobites.com so we can investigate and address it. You may also raise concerns with the Department of Commerce, Supplies and Consumer Protection in respect of e-commerce obligations, or pursue judicial remedies under the Individual Privacy Act, 2075 (2018), including filing a complaint with the competent District Court within the applicable limitation period.
20. Contact Us
- Privacy inquiries: privacy@merobites.com
- General support: support@merobites.com
- Legal notices: legal@merobites.com