Built for the DPDP Act

DPDP-compliant restaurant software for personal data

India’s Digital Personal Data Protection Act asks you to protect personal data and honour a person’s rights over it builds both into how PII is stored.

The short answer

CountStand treats customer and staff personal data as regulated: every piece of PII is encrypted at rest with AES-256-GCM, and an HMAC blind index lets you find a record without ever decrypting the raw value. Access is written to an audit log, and DPDP’s core rights are one-click operations, export everything held on a person, or erase it on request, for customers and staff alike.

AES-256-GCM
PII encrypted at rest
HMAC
blind-index lookup, no exposure
Erase + export
DPDP rights, one click
01 / What you get

What DPDP compliance needs from your software

Personal data protected at rest, and a person’s rights honoured on request.

PII encrypted at rest

Phone numbers, names and other personal details are stored under AES-256-GCM encryption, so a stolen database file is ciphertext, not a contact list ready to leak or sell.

Blind index, so lookup stays private

An HMAC blind index lets the system match a phone number to a record without decrypting the stored value, so everyday search never exposes the raw personal data it is protecting.

Erase and export on request

The DPDP right to erasure and right to access are built in: delete everything held on a customer or staff member, or export their full record, when they ask.

Access logged, grievances routed

A full audit log records who read personal data, and a named grievance-officer channel gives data principals a real person to write to, both things the Act expects you to have.

What does the DPDP Act require a restaurant to do?

India’s Digital Personal Data Protection Act treats the phone numbers, names and staff details a restaurant collects as personal data it holds in trust. In the Act’s language you are a data fiduciary: you must protect that data, use it for the purpose it was given, and honour the person’s rights over it, including the right to see what you hold and the right to have it erased.

CountStand turns those obligations into features rather than a policy PDF. Personal data is encrypted the moment it is stored; access to it is logged; and the two rights people exercise most, access and erasure, are buttons, not a fortnight of manual database surgery. Because the same rules cover staff PII as well as guests, one workflow answers a request whether it comes from a diner or an employee.

How can you look up a customer if their data is encrypted?

Encryption usually forces a trade-off: lock the data down and you can no longer search it. A blind index removes that trade-off. CountStand stores a keyed HMAC fingerprint of a value like a phone number alongside the encrypted record, and searches match on the fingerprint. The system finds the right guest without decrypting anyone’s number to do it, so everyday lookups never undo the privacy the encryption provides.

When a data principal exercises a right, the same design pays off. An access request exports the full record the fingerprint points to; an erasure request removes it and leaves the audit trail of the deletion, not the data. A named grievance officer is the human endpoint the Act wants, someone a customer or staff member can contact if they believe their personal data has been mishandled.

03 / Questions

Asked by owners like you

Is CountStand compliant with India’s DPDP Act?

It is built around the Act’s duties: personal data is encrypted at rest, access is logged, and the rights to access and erasure are one-click for both customer and staff subjects. A named grievance officer gives data principals a channel to raise concerns.

How is customer personal data stored?

PII is encrypted at rest with AES-256-GCM, so the stored form is ciphertext. An HMAC blind index sits alongside it so records can still be searched by phone number without decrypting the underlying value.

Can I delete or export a person’s data on request?

Yes, that is the DPDP right to erasure and right to access, and both are built in. You can export the full record held on a customer or staff member, or erase it, and the deletion itself is logged.

Who is the grievance officer?

DPDP asks a data fiduciary to name a contact for data principals. CountStand provides a grievance-officer channel, so a customer or staff member has a real person to write to if they think their personal data has been misused.

Hold personal data the way DPDP expects

Encryption, audit and subject rights on every plan, begin a 30-day free trial.

30-day free trial · No card · From ₹999/mo per outlet