Effective 9 October 2026

App privacy policy

Request access, correction or deletion of your data

1. Who we are and what this policy covers

DNA HOLDING (AUSTRALIA) PTY LTD provides Orderbuddy Retail. This policy covers the Orderbuddy Retail POS app (Android package au.com.orderbuddy.orderbuddyretail), its web and tablet versions, and account, order and operational information handled through the connected Retail management portal and QR ordering service. Our public brochure website has a separate website privacy notice. This Retail policy is issued by DNA HOLDING (AUSTRALIA) PTY LTD; the policy naming DNAPROPERTYSERVICE PTY LTD on orderbuddy.com.au is not the policy for this app.

Orderbuddy Retail is business software for authorised merchant and store staff. The current Google Play test release connects to our Test2 environment. Use test information when testing. Test information is still subject to this policy when it identifies a person.

2. Information we handle

Account and staff information: email address, user ID, staff name or display name where supplied, merchant/store membership, role and permission records. Email/password login is handled by Firebase Authentication. Accounts are provisioned through merchant or administrator arrangements; the POS app does not offer public account creation.

Orders and customers: products, quantities, prices, order references, timestamps, table, fulfilment details, payment/refund status and transaction references. Customer names, phone numbers, email addresses and order notes are handled when entered by staff or supplied through connected customer ordering. A merchant may therefore receive customer information in the POS even when that information was entered elsewhere.

Merchant content: store details, catalogues, product descriptions, prices, floor maps, settings, and images or files you choose to upload. The app uses a system file picker for selected uploads; it does not request access to your entire photo library or address book.

Device and technical information: app/terminal identifiers, device and browser information, IP addresses processed by service infrastructure, authentication activity, synchronization and error information, and operational audit records such as who performed an action and when. These support authentication, security, troubleshooting and reliable order processing.

3. Why we use this information

We use information to authenticate staff and enforce permissions; deliver and synchronize menus, orders and store settings; process and reconcile checkout and refunds; produce receipts and reports; support offline operation; respond to support and privacy enquiries; and prevent misuse and investigate operational problems. Required account and transaction information is needed for those functions. Customer contact fields and uploaded images are used when supplied for the relevant merchant workflow. Do not enter unnecessary sensitive information into notes or uploads.

The current app does not contain advertising SDKs or Firebase Analytics/Crashlytics. Operational server logs and audit records are still used. It does not request GPS, microphone or contacts permissions. Its weather feature sends a representative city location selected from the store timezone to Open-Meteo, not the device's GPS location. Open-Meteo also receives the connection information needed to answer that request, including the requesting IP address.

4. Who receives information

Authorised merchant/store users can access information within their permissions. Customers receive the order information made available through the corresponding customer ordering workflow. Orderbuddy support and authorised service administrators may access information as needed to operate the service, resolve issues and respond to requests.

Google Firebase and Google Cloud provide authentication, database, file storage, hosting and backend processing. Their services process the information needed to perform those functions. See https://firebase.google.com/support/privacy. Open-Meteo supplies weather information; see https://open-meteo.com/en/terms.

Where a merchant enables a payment integration, its payment terminal/provider, including MX51 where configured, processes the relevant transaction. The POS uses transaction amounts, outcomes and references for checkout and reconciliation. Card entry and authorisation take place through the configured payment solution. Do not send full card numbers, security codes or PINs to our support team or enter them into order notes. Provider privacy terms also apply to its services.

Merchant-configured printers and connected devices receive the information needed for receipts, dockets or other requested output. Information may also be disclosed when required by law or to address security incidents and enforce our legal rights. The app has no advertising data-sharing feature.

5. Storage, security and international processing

Account and operational data is stored in the configured Firebase/Google Cloud services. These providers may process information outside Australia. Access controls restrict merchant/store data to authorised users and backend services. Communication with our cloud services uses HTTPS/TLS.

For offline operation and performance, the app stores downloaded operational data, settings and pending changes on the device or browser profile. The local database does not add its own database encryption layer; device security and operating-system protections matter. Protect shared devices with appropriate access controls and avoid using untrusted devices. No transmission or storage system can be guaranteed completely secure.

6. Retention and deletion

Account data is retained while the account is needed for service access and administration. Orders, payments, refunds and audit records are retained for merchant operations, reconciliation, disputes and applicable record-keeping obligations. The current system does not automatically erase all records after a fixed period. The appropriate retention period depends on the record, merchant needs and applicable obligations; it is reviewed when an access, closure or deletion request is received.

Local data may remain after signing out. Clearing app/browser data or uninstalling may remove local copies and unsynchronized changes, but does not delete cloud accounts or merchant transaction records. Synchronize pending work before clearing local storage. Deletion of cloud information is not an automatic in-app action in the current release. Backups or records that must be retained may not be erased immediately when an eligible request is processed.

7. Your choices and privacy requests

To request access, correction, account closure or deletion, email david.yang@orderbuddy.com.au with the subject “Orderbuddy Retail privacy request”. Identify the account email, merchant/store and the information concerned. Do not include passwords, full card details or identity documents unless we specifically request an appropriate secure verification method. We may need to verify identity and authority before disclosing or changing information.

Customers with questions about a restaurant or retailer's order should contact that merchant first; the merchant determines the information it enters and its business record obligations. Staff should also contact their merchant administrator about access changes. We will coordinate requests with the relevant merchant where necessary and explain if information must be retained or a request cannot be fulfilled. Sending a request does not immediately delete an account or transaction. Contact us using the details below if you have a privacy complaint or are dissatisfied with our response.

8. Children

The POS app is intended for adult merchant and staff users and is not directed to children. We do not intentionally invite children to register for POS accounts. If you believe a child's information has been provided improperly, contact us so we can review it with the relevant merchant.

9. Changes and contact

We may update this policy as the service changes. The effective date and current policy are published at https://orderbuddy.me/app-privacy.html. The app includes the policy applicable to its build; consult that URL for later updates.

Privacy contact: David Yang

Email: david.yang@orderbuddy.com.au

Phone: +61 410 820 108

DNA HOLDING (AUSTRALIA) PTY LTD

Level 31, 120 Collins Street, Melbourne VIC 3000, Australia

Back to Orderbuddy Retail ↗