← Back to Khao

Privacy Policy

Last updated: 21 May 2026

1. Who We Are

Khao is a product of Devian Labs ("we", "our", "us"), a company registered in India. This Privacy Policy explains how we collect, use, and protect information when you use the Khao vendor app (the "App") or website at khao.app(the "Website").

By using Khao, you agree to the practices described in this policy. If you do not agree, please stop using the App and Website.

2. Information We Collect

2a. From Vendors (App Users)

  • Phone number — used for OTP-based authentication via Firebase.
  • Shop details — name, description, and any information you enter when creating your shop.
  • Menu content — item names, prices, descriptions, and images you upload.
  • Order data — orders placed by your customers are stored in your account.
  • Device information — device type, OS version, and app version for debugging and analytics.

2b. From Customers (Menu Viewers)

  • No account or login is required for customers to view menus or place orders.
  • We may collect basic analytics (page views, device type) via Firebase Analytics to improve the product.

2c. Payment Information

Subscriptions are processed by Google Play (Android) or the Apple App Store (iOS) through RevenueCat. We do not collect or store your payment card details. Billing is governed by the respective store's privacy policy.

3. How We Use Your Information

  • To authenticate you and maintain your session.
  • To display your shop, menu, and orders in the App.
  • To send push notifications for new orders and customer requests.
  • To improve the product using aggregated, anonymised usage data.
  • To respond to support requests.

We do not sell your personal data to third parties. We do not use your data for advertising.

4. Data Storage & Security

Your data is stored on Google Firebase (Firestore and Firebase Storage), hosted on Google Cloud servers. Firebase applies industry-standard security controls including encryption in transit and at rest.

While we take reasonable precautions, no system is completely secure. In the event of a data breach that affects your personal information, we will notify you as required by applicable law.

5. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where retention is required by law.

6. Third-Party Services

We use the following third-party services, each with their own privacy policies:

  • Firebase (Google) — authentication, database, storage, analytics.
  • RevenueCat — subscription management and billing.
  • Google Play / Apple App Store — app distribution and in-app purchases.

7. Your Rights

You have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your account and personal data.
  • Withdraw consent for optional data processing.

To exercise any of these rights, contact us at support@khao.app.

8. Children's Privacy

Khao is intended for use by business owners and is not directed at children under 13. We do not knowingly collect personal data from children.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date above and, where required, by sending an in-app notification. Continued use of Khao after changes constitutes acceptance.

10. Contact

For any privacy-related questions or requests, contact us at:
Devian Labs
Email: support@khao.app