Mohar
How Mohar WorksFor RestaurantsMembership
Log inJoin Mohar →
How Mohar WorksFor RestaurantsMembership
Join Mohar →Log in
Legal

Privacy Policy

Effective 5 August 2026 · moharapp.com

This describes what personal data Mohar collects — from you as an owner, and from the staff you invite — why we collect it, who can see it, and how long we keep it. It's written to describe what the product actually does, not a generic template.

On this page
  1. 1. Who we are
  2. 2. Scope of this policy
  3. 3. Data we collect
  4. 4. Photos and selfies, specifically
  5. 5. How we use your data
  6. 6. Who can see it, inside Mohar
  7. 7. Third parties we share data with
  8. 8. How long we keep it
  9. 9. Security
  10. 10. Your rights
  11. 11. If you're a staff member
  12. 12. Children
  13. 13. Where your data is stored
  14. 14. Grievance Officer
  15. 15. Changes to this policy

01Who we are

Mohar is operated by Kananbala Samantaray, an individual based in Hyderabad, Telangana, India, acting as the Data Fiduciary for the personal data described in this policy under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"). Contact us at support@mohar.app with any question about your data.

02Scope of this policy

This policy covers the Mohar owner/manager dashboard (moharapp.com) and the Mohar staff mobile app. It applies to two kinds of people: owners and managers, who sign up and manage their workspace directly, and staff members, whose accounts are created for them by their employer using an invite code (see Section 11if that's you).

03Data we collect

From owners, at signup

  • Full name
  • Business email address
  • Mobile number
  • Business/restaurant name

About staff, entered by their employer

  • Full name and mobile number (used to generate their invite code and log in)
  • Role (e.g. kitchen staff, service staff, manager)
  • A 4-digit PIN, which is hashed before storage — Mohar never stores or displays a staff member's actual PIN, including to their own manager

Created through day-to-day use, by staff

  • Attendance check-ins: a timestamp, shift, and a selfie photo (see Section 4)
  • An optional profile photo
  • Checklist responses: values entered, notes, and photos attached as evidence
  • Issue reports: description, category, severity, and photos or short videos attached
  • Leave requests: dates and a reason, submitted for manager approval

Compliance documents, uploaded by owners/managers

  • Audit records and supporting documents — e.g. GST registration, staff health certificates, pest control records — used to track regulatory compliance per outlet

04Photos and selfies, specifically

Attendance selfies and profile photos are photographs of a person's face. We treat this category with particular care:

  • Attendance selfies are automatically deleted 7 days after they're taken — both the image file and the reference to it are permanently removed by an automated daily process. The purpose of an attendance selfie is to confirm who checked in and that hygiene gear was worn at that moment; there is no reason to keep the photograph beyond that.
  • All photos in Mohar — selfies, profile photos, checklist evidence, issue photos — are stored in access-controlled storage. They are not publicly accessible by URL; each one requires a short-lived, authenticated link generated at the moment someone with legitimate access views it.
  • A staff member's attendance selfie is visible only to their own account and to owners/managers of the same outlet — never to other staff, and never to owners/managers of a different outlet.

05How we use your data

  • To operate your account — logging you in, showing your outlets, checklists, and issues
  • To verify attendance and hygiene-gear compliance at check-in
  • To compute each outlet's compliance score, from audit, checklist, issue, and attendance signals
  • To send transactional emails — OTP codes, checklist alerts, leave request notifications
  • To process payment for your subscription, via Razorpay
  • To respond to support requests and, where legally required, to comply with regulatory obligations

We do not sell your data, or your staff's data, to anyone.

06Who can see it, inside Mohar

RoleCan see
OwnerEvery outlet in their workspace, and all staff/checklist/issue/attendance data within it
ManagerThe outlet(s) they're assigned to, and staff data within those outlets only
StaffTheir own attendance, checklist history, issue reports, and leave requests

07Third parties we share data with

We use a small number of service providers to run Mohar. Each only receives the data it needs to perform its function, and none are permitted to use your data for their own purposes:

ProviderData involvedPurpose
SupabaseAll account, checklist, attendance, issue, and photo dataDatabase and file storage hosting
RazorpayBilling name, email, phone, and payment detailsPayment processing — Mohar never receives your full card number
ResendEmail addressDelivering transactional emails
SentryTechnical error data, with PINs, tokens, and photo URLs stripped out before sendingError monitoring, so we can find and fix bugs

08How long we keep it

DataRetention
Attendance selfies7 days, then automatically and permanently deleted
Profile photosUntil you remove or replace it, or your account is deleted
Checklist, issue, and audit records (text, non-selfie photos)For as long as your workspace is active, since this is your own operational record — kept afterward only as long as reasonably needed for account wind-down or a legal obligation
Account details (name, email, phone)Until you request deletion, or your account has been inactive and unpaid long enough that it's closed

09Security

  • PINs are hashed, never stored or shown in plain text
  • Photos are stored in a private bucket with access-controlled, short-lived signed links — never a permanent public URL
  • Access to each outlet's data is enforced by role — a manager cannot see a different outlet's staff data, and staff cannot see each other's attendance or issues
  • Payment details are handled entirely by Razorpay; Mohar never stores your card number

No system is perfectly secure, and we can't guarantee against every possible incident — but the measures above reflect real, current safeguards, not aspirational ones.

10Your rights

Under the DPDP Act, you have the right to:

  • Ask what personal data we hold about you
  • Ask us to correct inaccurate data
  • Ask us to erase your data, subject to what we're legally required to retain
  • Withdraw consent for processing that depends on it
  • Raise a grievance if you believe your data has been mishandled (see Section 14)

To exercise any of these, email support@mohar.app. We'll respond within 15 days.

11If you're a staff member

Your account was created by your employer (an outlet owner or manager), using your name and mobile number, so you could log in with an invite code. Your employer is responsible for having your permission to add you. Once your account exists, the data you generate day-to-day — attendance, checklist responses, issue reports — is visible to your own outlet's owner/manager, as described in Section 6. It is notvisible to staff at other outlets, or to owners/managers who don't manage your outlet.

If you want your account or data removed, you can ask your employer, or contact us directly at support@mohar.app.

12Children

Mohar is intended for use by adults working in food service businesses. We do not knowingly collect data from anyone under 18. If you believe a minor's data has been entered into Mohar, contact us and we'll remove it.

13Where your data is stored

Our infrastructure providers (Supabase, Sentry, Resend, Razorpay) may process or store data on servers located outside India, as part of their own global hosting infrastructure. Each provider is contractually bound to only process data for the purposes described in Section 7.

14Grievance Officer

In accordance with the Information Technology Act, 2000, the DPDP Act, 2023, and the rules made thereunder, the Grievance Officer for Mohar is:

Grievance Officer
Kananbala Samantaray
Email: support@mohar.app
Location: Hyderabad, Telangana, India

We aim to acknowledge grievances within 24 hours and resolve them within 15 days.

15Changes to this policy

We'll update this page if what we collect or how we use it changes — for example, if a new feature starts collecting a new kind of data. The "Effective" date at the top will reflect the most recent update.

Terms of UsePrivacy PolicyCancellation & Refunds
Mohar

The operating system for food outlets — food safety, staff management and issue tracking, all in one secure dashboard.

Product
How Mohar WorksFor RestaurantsMembership
Account
Join MoharLog in
Support
support@mohar.app
© 2026 Mohar — The Operating System for Food Outlets.
Terms of UsePrivacy PolicyCancellation & Refunds