Privacy
OrderLah privacy policy
Effective 1 October 2026 · Published by OrderLah · hello@orderlah.app
This policy explains what OrderLah does with information, in plain words. It covers the OrderLah app for Android and for iPhone and iPad (both com.orderlah.app) in every mode — Hub, counter, kitchen, display, payment phone and Remote Admin — the customer ordering page your Hub serves, the merchant portal, and the orderlah.app website. Where Android and iPhone or iPad behave differently, it says which is which.
The short version
OrderLah is an offline-first point-of-sale app. Your menu, your orders and your takings live on your own devices, and we do not keep a copy of your order book — unless your outlet takes its orders through our servers instead of a Hub tablet. A few things do reach our servers, and each one has its own paragraph below:
- your OrderLah account, your licence, and the settings and staff list your Hub publishes to that account;
- your customers’ orders, if you switch on ordering from outside the shop through our relay — we pass them on and do not keep them;
- takings summaries, while you look at Reports in the merchant portal — passed through, not kept;
- online card payments, if you connect a payment provider — we keep a record of each one;
- delivery-platform orders, if you connect a platform — passed through, not kept;
- the menu you import with Snap existing menu, if you use it — photographs, PDF pages and pasted text are read by an AI service and not kept;
- questions you ask Ask OrderLah that your tablet cannot answer by itself, once you allow AI answers — an AI service may help answer them, and we keep the conversation for 30 days;
- dish photos, if you use AI Photo Studio — given a new look by an AI service and not kept.
There is no advertising in OrderLah and no crash-reporting service, and we do not sell information. On Android, the readers for QR codes and delivery slips come from Google’s ML Kit, which sends Google some diagnostics — that has its own paragraph too.
This website
orderlah.app sets no cookies and runs no advertising or analytics product — no Google Analytics, no Meta pixel, no tag manager. Its pages, fonts and scripts all come from this domain. The interactive demo runs in your browser and creates no order anywhere.
What we do measure, and how
We count how people find OrderLah and how far they get, so that we know where to spend a small marketing budget. It is our own counting, and it is deliberately thin:
- Your browser makes a random key for itself and keeps it, with a note of how you first arrived, in this site’s storage in your browser. It is not taken from your device and it is not a fingerprint.
- With it we record which pages you opened, which buttons you pressed, the campaign or referral link you arrived on, and what you chose on interactive tools such as the savings calculator. We record that you started filling in the enquiry form, but nothing you type in it until you send it.
- If another site linked you here, we record that site’s name and nothing else — not the page you came from and not anything in its address.
- We record the country a page is about — /sg is a page about Singapore — and whether your screen is phone, tablet or desktop sized. We do not look up your location, and we do not store your internet address with any of this. (Our web server’s short access log is the one exception; see “How long data is kept”.)
- If you later send the enquiry form, or create an OrderLah account, from the same browser, we link that key’s records — how you first and last arrived, the landing page and referring site of each visit, your screen size and how many visits — to your enquiry or your account, and keep them with it.
- Nothing is shared with an advertising platform. OrderLah can be set up to do that, and it is not. If that ever changes, what would be sent is an event name, an amount and its currency, a country, the campaign that brought you, and an irreversible reference — never your email address, your phone number or your business’s name.
- Raw event records are deleted after 400 days, and so is the key’s record for a browser that never sent an enquiry or made an account.
If you would rather not be counted, blocking api.orderlah.app in your browser’s content blocker stops all of it, and every page on this site still works.
The enquiry form
If you fill in the form, the answers reach OrderLah so we can reply to you: your name, your business, a number to call, and whatever else you choose to tell us, such as your email address, your city and how many outlets you have. We use them to contact you about OrderLah and for nothing else, and they are not used for advertising. Our security log also records that the form was sent, with the network address it came from. If you would rather not use the form, email hello@orderlah.app directly — it reaches the same people.
We keep an enquiry until you ask us to delete it. To ask, email hello@orderlah.app from the address you gave us, or tell us the phone number you used. There is no button for this yet, so a person at OrderLah removes your details by hand, together with the website records linked to that enquiry. The line in our security log saying a form was sent stays, because that log is never edited.
Personalised demos
A link like orderlah.app/demo/your-shop is a sample menu we typed in to show you what OrderLah could look like for your business. It creates no account, no shop and no licence, it holds no customer data, and it can be switched off on request. We count how often it is opened. If it shows your logo, your browser fetches the logo from wherever your own website keeps it — the one picture on this site that does not come from this domain.
Who is responsible for which information
OrderLah is a tool a restaurant or stall runs on its own devices. When a shop records information about its customers — a phone number on a loyalty card, a note on an order, a name that came with a delivery-platform order — the shop is responsible for that information and for handling it lawfully. Where such information passes through our servers (the relay, online card payments, delivery-platform orders), we handle it for the shop and for nothing else.
For your OrderLah account and the other records on our servers described below, OrderLah is responsible.
What OrderLah stores on your device
| Information | Why it exists | Where it is kept |
|---|---|---|
| Menu items, categories, prices, photos | To take orders | On the device |
| Orders: items, quantities, special requests, table, order type, status, times, totals, how it was paid, any payment reference the customer typed, and which staff member took it | To run service and produce reports | On the device |
| Staff accounts: name, role, permissions, PIN | To control who can do what | On the device. PINs are kept only as one-way codes, never as the digits. A staff member’s name and role also reach our servers if the outlet is linked to an OrderLah account — see “Your outlet’s settings and setup”. The PIN and the permissions never leave the device |
| Loyalty cards: the identifier the staff types or the customer enters (a phone number or a table label) and the stamp history, and — only if staff save one — the WhatsApp number the card’s receipts go to | To run a stamp-card scheme, and to send a member’s receipt on WhatsApp | On the device. Shown on screens as its last four digits |
| Printer, network and display settings | To keep the setup working | On the device |
| Shop activity log: who signed in, cancelled an order, changed a price | Your own record of your own shop | On the device. Never sent to us |
| Backup files | To recover after a crash or a device swap | In the app’s private documents folder (orderlah_backups/). Not encrypted. If you switch it on, also an encrypted copy in a folder you choose |
Order and queue data is held in a local database whose contents are encrypted with an AES-256-GCM key made for that install and kept apart from the database file. If that key cannot be created or read on a particular device, OrderLah keeps working with the data unencrypted rather than refuse to take orders — keeping service running is treated as the higher duty. So a device lock screen is always worth having.
Device backups. On Android, OrderLah’s data is left out of the phone’s or tablet’s own backup. On iPhone and iPad, if iCloud Backup or a backup to a computer is switched on, iOS includes OrderLah’s data — the shop’s database and its automatic backup files — in that backup. Apple or your computer holds that copy, not us, and it stays there until that backup is replaced.
What leaves the device
Your local network
Counter, kitchen and display devices exchange orders with your Hub over your Wi-Fi or hotspot, and your Hub serves the ordering page to phones that scan your QR code. That traffic stays on your local network and is not routed through us — unless you switch on ordering through our relay, described below.
This traffic is not encrypted. On Android, iPhone and
iPad alike it cannot be: a Hub is reached at an address like
192.168.1.42, no certificate authority will ever vouch for
one, and the app has no setting that turns encryption on. So anyone
already on the same Wi-Fi could in principle see orders passing between
your own devices, and read the code a device uses to join your Hub.
Run your stall on a Wi-Fi network with a password only you and
your staff know, and do not put your Hub on a guest network or
a public hotspot you do not control.
Your OrderLah account
Running a shop needs no account. An OrderLah account, if you have one, lives on our servers: your email address; your password, kept only as a one-way code we cannot turn back into the password; your name if you give one; the businesses you create (name, registered name, country and type of business) and their outlets (name, and address if you give one); who belongs to each business and in which role; the devices you activate (the name shown for each, an identifier the device makes for itself, which app version it runs, and when and from which network address it last checked in); your licences; and which OrderLah terms and privacy notice you agreed to, when, with the network address and the app or browser you agreed from. Nothing about an order, a customer or your takings is in any of it.
Sign-ins. Each sign-in is recorded: when it started, when it was last used, when it ends, the network address it came from and the browser or app that made it — which is what lets every sign-in be ended at once when a password changes. That record is deleted 7 days after the sign-in expires or is ended. That is at most about 8 days after signing in to the merchant portal, and at most 37 days after the app or Hub last renewed its sign-in. Sign-in attempts, successful or not, with the email address and network address used, are deleted after 30 days. The merchant portal keeps you signed in with one cookie that only the portal can read and that ends with your sign-in.
Our security log. We also keep a security log of what is done to an account, a business and its devices — sign-ins, changes, device activations, reports opened — and of every licence check-in and connection your Hub makes to us, each with the time and the network address it came from. An internet address can show roughly where a device was. The security log has no expiry date, because “was this account misused?” is a question asked long after the fact.
Team members. If you add a colleague to your business in the merchant portal, we create an OrderLah account under the email address you give, if they do not already have one, and our security log records who added whom and with which role. Please tell your colleague before you add them. They can delete that account the same way you can.
Signing in with Google
If you choose “Continue with Google”, the sign-in happens on a Google page, between you and Google: in your phone’s own browser on Android, and in a Safari sheet inside the app on iPhone and iPad. The app never handles your Google password and cannot read that page. Google tells our server your email address, whether Google has checked it, and a permanent identifier for the account, which we use to create or find your OrderLah account and for nothing else. We ask Google for nothing more — not your name, not your contacts, calendar or Drive — and we store no Google password or token. On an iPhone or iPad, “Continue with Google” is offered only beside “Sign in with Apple”.
Signing in with Apple (iPhone and iPad)
If you choose “Sign in with Apple”, your iPhone or iPad shows Apple’s own sign-in sheet and confirms it is you with Face ID, Touch ID or your passcode; the app never sees your Apple ID password. Apple then gives the app a signed token, which our server checks with Apple before trusting it. From that we keep a permanent identifier Apple issues for your Apple ID and OrderLah, and the email address Apple gives us. If you chose “Hide My Email”, that address is a private relay address Apple made and forwards to you, and we never learn your real one. Apple shares your name only the first time you sign in, and only if you let it; we use it as the display name of a new account and for nothing else. We also keep one token Apple issues at sign-in, encrypted, for a single purpose: telling Apple to end OrderLah’s access when you delete your account or remove Apple as a way to sign in. An Apple ID whose email address already belongs to an OrderLah account is not joined to it automatically — you sign in as usual and add Apple from your account screen.
Your licence, and the country your Hub connects from
Your Hub — and only your Hub — checks its licence with us about every six hours while it is online, and when the app is opened. It also keeps a connection open to us so a change to your licence reaches it straight away, and asks once a day for announcements from OrderLah. Counter tablets, kitchen screens, displays, payment phones and your own Remote Admin phone do none of this: they talk only to your Hub. Each check-in and each connection goes into our security log, with the time and the network address it came from.
An OrderLah licence is sold for one outlet in one country — that decides your price, your currency and which OrderLah company invoices you — and a Hub is a tablet that can be carried anywhere. So when your Hub checks its licence, we also record the country our network provider worked out from the internet address the check came from:
- It is a two-letter country code and nothing finer. Not a coordinate, not a city, not your address.
- It comes from the internet address the check arrived from — the same thing every website you visit can see — and not from your tablet. OrderLah asks for no location permission of any kind and uses no location service on the device, for this or anything else.
- The country record is a running total: for each of your outlets, one line per country saying how many times and on how many separate days its Hub was seen there, and when the first and last of those were. It keeps no day-by-day record. (The security log above is separate, and does keep each check-in’s time and address.)
- Only your Hub adds country lines. Travelling with your own phone adds none — though signing in to your OrderLah account from anywhere, including the merchant portal, is recorded in the security log with its network address.
- It is never about a customer: customers do not check licences.
- Nothing is ever switched off, blocked or charged differently because of it. Working out a country from an internet address is unreliable — Johor and Singapore are fifteen minutes apart, and mobile networks route one country’s data through the other — so if the country we see stops matching the country your outlet is registered in, a person at OrderLah looks into it and, if we need to, asks you. Your till, your kitchen screens and your customers’ ordering page are untouched throughout.
- Lines nothing has added to for 400 days are deleted, except while a question about that outlet is still open. Lines for a tablet you removed or a shop you closed go sooner.
This applies only to an outlet activated against OrderLah’s own servers. A merchant running their own private server has nothing checking in with us.
Paying for a licence
Nothing in the app takes a payment: there are no in-app purchases and no Google Play or App Store billing. When a licence is paid for, the payment provider handles the card and we never see the card number. We keep a record of each purchase — the plan, the price, the currency, the country and the provider’s reference — and issue a tax invoice that carries your business name, your outlet, its address and your email address.
Your outlet’s settings and setup
If your outlet is linked to an OrderLah account, your Hub publishes its configuration to us: your shop’s name, address and currency, and whether the address prints on receipts; which order types and payment methods you accept; your tax, service charge, rounding and table settings; whether QR ordering is on, your public ordering address and whether ordering is paused; which OrderLah features the outlet has switched on; how many menu items and categories you have; which app version the Hub runs; and your staff list — each person’s name, their role, and whether they are enabled. It also publishes how far through setup the outlet is: which steps are done, and when setup started and finished.
Your staff’s PINs and their individual permissions are never sent, and neither is anything about an order. We use this to show your setup in the merchant portal and to the OrderLah team who help merchants get started, to notice an outlet that is stuck partway through setup, and to decide which getting-started emails are still useful to you. If your outlet is not linked to an account, none of this is published.
Reports in the merchant portal
When you, or a team member you allowed, open Reports in the merchant portal, our server asks each of your Hubs for a summary of the period you chose, through our relay: takings by day and by hour, payment methods, order types, best-selling categories and items, and sales per staff member by name. If you entered product costs in the portal, those go to the Hub with the request so it can work out margins. The summary passes through our relay and server to your browser and is not stored on the way. Our security log records who opened a report, and when.
Online ordering through our relay, if you switch it on
By default a customer’s phone talks to your Hub directly over your own Wi-Fi. If you publish a public ordering address through OrderLah’s relay so customers can order from outside the shop, their orders travel through our server on the way to your Hub. We pass them on; we do not keep a copy. The relay keeps only your ordering page and its pictures — menu photos, your logo, the cover photo and your payment QR images — in memory, for up to 24 hours, so customers can still read the menu if your Hub drops off for a moment. It never keeps anyone’s order, receipt, order status or loyalty card, and it writes nothing to disk unless the deployment is explicitly run with an order queue, in which case an order waits there only while your Hub is unreachable. The web server in front of the relay keeps a short access log (see “How long data is kept”). Leave the relay address empty and none of this applies.
The public address has to be https://. An older http:// address stays on the settings screen so you can replace it, but it is not used for QR codes or partner webhooks, and it is never rewritten to https:// — type the https:// address instead. Shop Wi-Fi ordering stays on ordinary http, on your own network, and is a different hop — it is not encrypted, and it does not travel through us.
The customer ordering page
Your Hub serves the page a customer opens when they scan your QR code. To place an order, the page asks a customer for nothing about themselves — no name, no email address, no phone number and no account. What they may type goes to your Hub with the order: special requests on a dish, and at payment a short reference, such as the last four digits of a card or a name, so you can match a transfer. If you run a stamp card, a customer may type their phone number to find or start their card; your Hub keeps it on the loyalty card.
When the customer uses your public ordering address, all of that — the loyalty phone number included — passes through our relay on its way to your Hub, and the relay does not keep it. Receipts and order-status pages opened through your public address pass through in the same way and are never cached. The relay also tells your Hub the customer’s internet address, so the Hub can stop anyone flooding it with requests.
The page keeps the customer’s basket and their own list of orders — with the links that open each order’s status and receipt — in their own browser, on their phone. Display fonts are bundled and runtime font fetching is switched off, so neither a staff device nor a customer’s phone contacts a third-party font server. The page carries a small “Powered by OrderLah” mark that by default opens this website in a new tab when tapped; nothing is sent when the page loads, and the address it opens says nothing about your shop, your table or the order. Switch the link off in Settings → Menu display if you would rather it were plain text.
Online card payments, if you connect a provider
Taking cards online is something you switch on by connecting HitPay, Fiuu or Stripe. When a customer pays online, these reach our servers:
- from your Hub, the amount, the order reference and the payment method, so the payment can be created and matched back to the right order, with the network address of the request — for a shop run from a Hub, that is your Hub’s own address;
- the customer’s own network address when they come back from the provider’s payment page, which stays in our server log for up to 30 days;
- from the provider, the card’s brand, its last four digits, whether it is debit or credit, the country that issued it, the wallet used, and with HitPay the name the payer entered;
- a copy of each message the provider sends us about a payment, exactly as it was sent. It can include what the provider collected from the payer, such as an email address, a name, a phone number or a billing address. We keep those messages for 400 days;
- for a refund, the amount and the reason your staff typed;
- with Tap to Pay on a staff member’s phone, the amount, the order and table labels, and which staff member and phone collected it.
We keep the payment record itself for good, because it is the record of money that moved — including after your account is deleted. We never receive a card number, an expiry date or a security code; those are typed on the provider’s own page. Connect no provider and none of this applies: cash, a printed PayNow or DuitNow QR and a card machine you already own involve our servers not at all.
Delivery platform orders, if you connect one
Photographing a printed slip (on Android), pasting its text or typing an order in stays on your device. Connecting GrabFood, Foodpanda or Shopee so the platform itself posts orders is a different door: the address the app copies into a partner console is your public (relay) address, not the shop Wi-Fi, and only when that address is https://. The app will not copy an http:// public address or the shop Wi-Fi address. An http:// URL already pasted into a partner console keeps receiving that platform’s posts until you replace it there — changing the app does not encrypt requests still sent to the old address.
The signed message travels through our relay on the way to your Hub — the same path a QR order takes. Those are two separate hops: the platform talks to the public address over HTTPS, and your Hub talks to the relay over an encrypted connection. We pass it on so the kitchen can cook; we do not keep a copy, we do not cache that path, and we do not write it to the relay’s order queue, so an unreachable Hub is told to try later and the platform retries. The body is whatever that platform sent. A customer’s name is read when one is present; street address and phone number are not fields we read, but if they are in the message they pass through with the rest of it. Your Hub then keeps the raw message with the order, up to 4,000 characters, and in your own backups. Connect no platform, or only photograph slips, and none of the relay hop applies.
Menus you import with Snap existing menu
Importing the menu you already have is optional; you can type your menu instead. If you use it, what leaves your Hub depends on what you give it, and everything that does leave goes to OrderLah over an encrypted connection:
- Photographs you take or choose are read by a third-party AI service working for us, which sends back a draft menu for you to check. The capture screen says so too.
- A PDF is drawn into page images on your tablet, and those pages are read in the same way as photographs. The file itself is not sent.
- A spreadsheet — a CSV or Excel file, including an export from another till — is read on your tablet. Only when the tablet cannot tell what a column holds does it send the sheet’s header row and five sample rows, never the rest of the sheet, so the AI service can suggest which column is which; you choose every column yourself in the end. We keep which column held what — not the headers or the rows — for up to 30 days, so that asking again gets the same answer.
- Menu text you paste is read by the AI service, and the paste screen says so. We keep a fingerprint of the text and how many dishes were found, not the text.
- Translating dish names, if you ask for it, sends those names to the AI service. The translations are shown beside your own names as suggestions you can copy, and are not saved into your menu. We keep the suggestions, not your names, for up to 30 days, so that asking again does not count twice.
Nothing becomes part of your menu until you have checked the draft and confirmed it. We keep no copy of the photographs or the PDF. We keep a short record of each import: which outlet and device sent it, how many photographs and requests it took, how long it took, whether it worked, how much of the AI service it used, and how many categories and dishes were found. The copies on your tablet are deleted when the import finishes or is cancelled. How long the AI service itself keeps what it was sent is set by its own terms, not by us, so we do not promise here that it keeps nothing.
Ask OrderLah, if you use it
Ask OrderLah is the question box on your Hub and in the merchant portal. It is optional, and AI answers are offered only where OrderLah has switched them on.
What stays on your tablet. Questions about your own shop — sales and orders, the kitchen, finding a dish on your menu, your printers, your licence, or preparing a price change — are answered on the tablet from its own data, and do not leave it. On a counter, a kitchen screen or a Remote Admin phone, Ask OrderLah only ever answers this way, or from the User Guide built into the app.
What your Hub sends, once you allow it. Before the first question that would leave the tablet, Ask OrderLah asks whether to allow AI answers. Choose Not now and every answer stays on the tablet; you can turn AI answers on or off later on the same screen. A note under the question box says that an AI service may help write answers, and asks you not to type customers’ personal details. Once AI answers are allowed, a question the tablet cannot answer is sent to OrderLah over an encrypted connection, with:
- the screen you asked from, the date, the app’s version, the kind of device and the mode it runs in;
- the role and permissions of the staff member signed in — not their name;
- which OrderLah features your outlet has switched on;
- for a troubleshooting question, the results of the tablet’s own diagnostic checks (not its logs), a few facts about your setup, such as whether printing is on, and, if you name an order, whether it was found, held for payment, cancelled, released to the kitchen and its ticket sent — not what was in it or who ordered it;
- for a price change the tablet could not read, the names of your menu’s categories and dishes — never their prices.
In the merchant portal, your question goes to OrderLah with the page you asked from, the date and the outlet you chose. To answer a question about sales, from the portal or passed on by your Hub, our servers ask your Hubs for the figures through our relay, the way Reports does.
When an AI service helps. Many questions are answered from OrderLah’s own guides and your figures without any AI service. When one helps write an answer, it is sent the parts of OrderLah’s guides that matched the question, the question itself with the kind of device and app version it came from, the conversation so far (the last few questions and answers, and a short summary of earlier ones), and, to explain a change in sales, your shop’s figures for the periods being compared — totals, best-selling dishes, and how orders were paid and served. For a price change your tablet could not read, it is sent the request and your menu’s category and dish names. It is never sent your customers’ contact details, passwords, payment credentials or your order book. If that AI service is unavailable, a second AI service working for us may answer instead. How long either keeps what it was sent is set by its own terms, not by us.
What we keep. Each conversation — your questions and our answers, which can quote your figures — is kept for 30 days after its last question, so you can come back to it. We keep a record of each request, with what its answer was based on, for 30 days, and a record of each use of an AI service — which feature, how much of the service it used, how long it took and what it cost, never the words — for up to 400 days. An answer may also be saved for up to 30 days so that the same question is not asked twice; one built from your shop’s data is only ever given back to your business. Questions asked on your Hub belong to your outlet; questions asked in the portal also name the person who asked them. A price change Ask OrderLah prepares is only a draft: nothing on your menu changes until a person with permission to manage the menu confirms it on your Hub.
When a business is closed — for example when its only owner deletes their OrderLah account — its conversations, prepared changes, saved answers and request records are erased with it, and its records of AI use stay without anyone’s name. Deleting your own OrderLah account erases the questions you asked, and their request records, from every business, including one that carries on without you.
Dish photos, if you use AI Photo Studio
AI Photo Studio is optional; taking, cropping and rotating a dish photo never uses it. If you choose a look and tap Create, that one dish photo — resized, and without its camera details — is sent to OrderLah over an encrypted connection and edited by a third-party AI image service working for us, which sends back one new photo for you to compare; the studio screen says so too. If you choose the My Stall look and pick photos of your stall, those are sent with it. Your logo and your shop’s name are never sent: the app places them on the new photo itself. Nothing about your customers or your orders is sent. We keep no copy of any photo. We keep a short record of each request: which outlet, device and staff account asked, which look, which AI service and model answered, how long it took, whether it worked, what the service reported using, and our own estimate of what it cost us. Nothing on your menu changes until you tap Use This Photo, and your original photo stays on your Hub so you can restore it. How long the AI service itself keeps what it was sent is set by its own terms, not by us, so we do not promise here that it keeps nothing.
WhatsApp receipts, if you use them
Your staff can send a customer their receipt on WhatsApp. The number is typed by your staff or taken from the customer’s loyalty card; it is never put on the order or the receipt, and it is kept only if your staff choose to save it on that loyalty card. A saved number can be removed from the card at any time, for example when the customer asks.
- With the WhatsApp app (the default), the till opens WhatsApp on your own device with the customer’s chat and a short message containing the receipt link. Nothing passes through us; what WhatsApp does with the message is under your agreement with WhatsApp.
- With WhatsApp Business, if you connect your own WhatsApp Business account, your Hub sends the customer’s number and the receipt as a PDF to OrderLah over an encrypted connection, and we pass them to Meta (WhatsApp) to send from your business number. We keep neither the number nor the receipt: our security log records that a receipt was sent, for which order, with only the last four digits of the number. Your WhatsApp Business access token is kept on our servers encrypted, is never shown again, and is erased if you delete your account. Meta keeps the message and the file under its own terms.
Photos you add
The photos you add — menu photographs for Snap existing menu, dish photos, photos of your stall for AI Photo Studio, the ordering-page cover photo and your logo — are saved without the details a phone writes into a photo about where and when it was taken and with which camera, before they are shown to customers or sent to OrderLah. That applies to JPEG photos, the kind a phone camera takes; a picture in another format that the app keeps as it is, such as a PNG logo, is stored exactly as you chose it. The original of your cover photo is also kept exactly as you chose it, on your Hub only and never shown to anyone, so that you can reposition it later. Photos added with an earlier version of the app keep whatever details they had until you replace them.
Referral rewards
If you share your referral link from the merchant portal, we record which businesses signed up through it and the rewards they earned you. You see counts, never the other business’s details. Where reward payouts are switched on, you give us the account holder’s name and the bank account number to pay into; we pass them to our payout provider or keep them encrypted, and anywhere they are shown, only the last few digits of the account number appear. If you refer businesses to us as an agent or partner, we also keep the contact email and phone number you gave us.
Emails we send you
We email the address on your account about things you need to know: confirming your email address, signing in and resetting a password, deleting an account, your licence and payments for it (including a reminder before a licence ends), reward payouts, changes to OrderLah’s terms or privacy notice, and security. Those cannot be switched off. We may also send getting-started tips, product news and marketing emails; you can switch each of those off in the merchant portal under Settings → Messages from OrderLah. We use records of how merchants get started — when an account, a business and an outlet were created and when a tablet was first activated — to understand where people get stuck, and to decide which of those emails are still useful.
Remote Assist, if you ask OrderLah Support for help
Remote Assist is optional, and it starts only when you press Start Remote Assist under Settings → Help & Support on a device connected to OrderLah Cloud. Starting it sends OrderLah the device’s name, type and app version, what you said the problem is about, any note you typed, and — only if you tick the box, which starts unticked — a diagnostics report. After that, OrderLah Support can see or do nothing on the device unless you allow it there, one thing at a time:
- Diagnostics — the state of the Hub, the network, the printer, the licence and the device. Never orders, customers, takings, passwords, PINs, or card or bank details.
- Error logs — recent technical errors from the app, with passwords, PINs, access keys, card numbers, email addresses and phone numbers removed on the device before they are sent.
- Your screen, on Android only — after you allow it in OrderLah, Android asks you again. Only OrderLah’s own screens are sent, and nothing while a PIN, password or payment-key screen is open or while OrderLah is in the background. Support can point at your screen but cannot tap or type. On iPhone and iPad you can instead send a screenshot you have seen first.
- Suggested fixes — support can suggest one of a fixed list, such as printing a test ticket; each runs only if you tap Allow.
A notice stays on your screen for the whole session, and End stops everything at once. A session ends by itself after 30 minutes unless you extend it. Your shared screen and screenshots are held in our server’s memory only while the session is open, and are never written to disk or recorded; diagnostics and error logs are deleted when the session ends. We keep a record of each session — when it was, which device, what it was about, what you allowed, the messages and the fixes — for one year, and you can see it in the merchant portal under Help. Deleting your OrderLah account deletes the Remote Assist records of every business it closes.
Google ML Kit on Android
On Android, the readers that turn a QR code or a photographed delivery slip into text come from Google’s ML Kit and run on the device: the picture is not sent anywhere. ML Kit does send Google information about the device, the app and how the reader performed; Google says it uses this for diagnostics and usage analytics, sends it encrypted and does not share it. The iPhone and iPad app uses Apple’s own reader instead and does not include ML Kit. OrderLah adds no analytics, advertising or crash-reporting software of its own to the app.
Nothing else
Beyond what is described above — your account and licence, your outlet’s settings, the relay, portal reports, the payment and delivery integrations you connect, the menus you import with Snap existing menu, dish photos you send to AI Photo Studio, Ask OrderLah questions once you allow AI answers, WhatsApp Business receipts if you connect it, referral rewards, Remote Assist when you ask for it and ML Kit’s diagnostics on Android — the app sends no order, customer or takings data off your devices.
Who we share information with, and where it is processed
We do not sell information, and we do not give it to advertisers or data brokers. We use other companies to run parts of OrderLah, and each gets what its job needs:
- DigitalOcean hosts our servers.
- Cloudflare carries the requests that reach our servers and your public ordering address — including customers’ orders sent through the relay — serves this website, and works out the country described under “Your licence, and the country your Hub connects from”.
- An email-delivery provider sends the emails described above.
- A third-party AI service working for us reads the menu photographs, PDF pages and menu text you send with Snap existing menu, suggests spreadsheet columns and translations, and helps answer Ask OrderLah questions. A second AI service may stand in when the first is unavailable.
- A third-party AI image service gives the dish photos you send with AI Photo Studio their new look.
- HitPay handles payments for OrderLah licences, and, where reward payouts are switched on, sends them.
- The payment providers you connect for your own shop — HitPay, Fiuu or Stripe — get what they need from us to create and match your customers’ payments, under your own agreement with them.
- Meta (WhatsApp), if you connect WhatsApp Business, gets the customer’s number and the receipt to send from your number, under your own agreement with Meta.
- Google and Apple, if you choose to sign in with them, under their own privacy policies; and on Android, Google’s ML Kit as described above.
- An off-site storage provider may hold encrypted copies of our database backups.
We may also give information to a court, a regulator or the police where the law requires us to.
Not every one of these companies is in Singapore or Malaysia — Cloudflare, Google and Apple, for example, run their services around the world — so information we hold, or pass on for you, can be processed in other countries.
Device permissions and why they are asked for
| Permission | Used for | Leaves the device? |
|---|---|---|
| Camera | Scanning QR codes (activating, pairing, joining a shop, loyalty cards), photographing a printed delivery slip on Android to fill in an order, photographing your menu for Snap existing menu, and photographing dishes and your stall | QR codes and slips: no — they are read on the device (on Android by Google’s ML Kit, which sends Google the diagnostics described above, never the picture). Menu photographs for Snap existing menu, and the dish and stall photos you send to AI Photo Studio: yes, as described above, and not kept |
| Photos | Choosing dish pictures, payment QR images, an ordering-page cover, a logo, stall photos for AI Photo Studio, and menu photographs for Snap existing menu. On Android, OrderLah asks for no photo or storage permission — Android’s own photo picker hands back just the picture you chose | Only the menu photographs you send through Snap existing menu, and the dish and stall photos you send to AI Photo Studio, as described above |
| Bluetooth | Finding and printing to receipt printers | No |
| Network state | Knowing whether there is a network before talking to your Hub, to us or to the relay. The Wi-Fi state permission is also declared, but nothing in the app reads it today | No |
| Notifications | Telling staff that an order has arrived or needs them | No |
| Location | Never asked for. OrderLah requests no location permission — fine, coarse or background — and the Bluetooth permission it does ask for is marked as never being used for location. The country described above comes from an internet address at our network provider, not from your device | Not applicable |
| Wake lock | Keeping the device’s processor and Wi-Fi awake while OrderLah watches for orders, or serves as the Hub, with the screen off | No |
| Foreground service (data sync, connected device) | Keeping the connection to your Hub open while the app is in the background, so a counter or kitchen tablet does not miss an order because Android put it to sleep (data sync), and letting the Hub tablet keep serving your counters, kitchen screens and printers with its screen off (connected device). It is why a notification sits in your tray during service | Local network only |
| Change network state | Required by Android 14 and later before the Hub’s connected-device service may start. OrderLah does not change your network settings | No |
| Vibrate | Alerting the kitchen to a new order in a room loud enough that a sound alone is not enough | No |
| Foreground service (screen sharing) | Showing your OrderLah screen to OrderLah Support during a Remote Assist session you started, on Android only, after you allow it in OrderLah and again in Android’s own screen-sharing dialog. A notification with a Stop button stays in your tray while it runs | Yes — to OrderLah Support, during that session only, and never recorded |
OrderLah does not start itself when the device is switched on: after a restart, open OrderLah and it picks up where it left off.
On iPhone and iPad the table above applies with these differences. There is no foreground service and no background mode: iOS gives the app no way to keep a Hub serving in the background, so an iPhone or iPad running as the Hub serves your other devices and your QR ordering page only while OrderLah is open on its screen, and the app says so. iOS asks separately before OrderLah may send notifications, reach devices on your local network, or use Bluetooth, the camera or your photo library; saving a QR code or receipt image to Photos asks for add-only access, and only when you choose Save Image. QR codes are read by Apple’s own reader, and reading a delivery slip from a photo is not offered. The answers to “Leaves the device?” are otherwise the same.
Backups and exports
Automatic backups are written to the app’s own private folder on the device, and OrderLah uploads none of them. They are not encrypted, and on iPhone and iPad they are part of the device’s own backup if that is switched on. If you choose to share or export a backup, it leaves the device by whatever route you pick. A backup file contains your orders, menu, staff list and loyalty cards, so treat it as sensitive and store it somewhere safe. It does not carry your staff’s PIN codes.
A copy off the tablet, if you ask for one. On an Android or desktop Hub you can switch on a copy of each automatic backup to a folder you choose — a memory card, a USB drive, or a folder a cloud-drive app offers on the device. It is off until you switch it on. Each copy is encrypted on the device, before it is written, with a recovery key that is shown to you once and never sent to us; without that key nobody can open the copies, including us. If the folder belongs to a cloud-drive app, that app’s provider holds the encrypted copies under your account with them, not us. Switching it off leaves the copies already in the folder where they are.
How long data is kept
On your devices, data stays until you delete it — by deleting records in the app, or by uninstalling the app or clearing its data in the device’s own settings, which removes the local database, its encryption key and its backups. The one exception is a copy already inside an iPhone or iPad backup, described above. The shop activity log expires on its own: it keeps up to 90 days, or the most recent 5,000 entries if that comes first, and deleting your OrderLah account leaves it exactly where it is.
If you made an OrderLah account, it is on our servers and is not removed by uninstalling. Ask for it to be deleted at orderlah.app/delete-account, from inside the app, or from the merchant portal — the next section says what that does and what is kept afterwards.
On our servers, the periods are these:
- A deletion confirmation link is good for 2 hours; a confirmed deletion waits 30 days before anything is destroyed; the record that a deletion happened is kept for one year.
- Sign-in records go 7 days after the sign-in expires or is ended, and sign-in attempts after 30 days, as described under “Your OrderLah account”.
- The security log has no expiry date.
- Country lines go after 400 days with nothing added to them, and within six hours of a tablet being removed or an outlet closed — either way, not while a question about that outlet is still open. Deleting your OrderLah account removes them in the same step that closes the business.
- Messages from a payment provider about a payment are kept for 400 days. Payment records themselves are kept for good.
- Website event records go after 400 days. Records linked to an enquiry or an account are kept with it, including after the account is deleted.
- An enquiry is kept until you ask us to delete it.
- Our web servers keep an access log of each request — the internet address, the time, the page or path asked for (never anything after a ?) and the browser or app name — for 14 days, and our application log keeps the address and path for up to 30 days. That includes customers who order through your public address, and the path can show which table they ordered from.
- A Remote Assist session record is kept for one year. The screen and screenshots shared during it are never stored, and diagnostics and error logs are deleted when the session ends.
- Ask OrderLah conversations go 30 days after their last question, and the record of each request after 30 days. A record of each use of an AI service, which holds no words, is kept for up to 400 days. Saved answers, spreadsheet column matches and translation suggestions go within 30 days.
- Our database is backed up, encrypted, every day. Our server keeps those backups for up to eight weeks, and a copy may also be kept with an off-site storage provider, so a record deleted from the database can remain inside an older backup until that backup is removed.
Deleting your OrderLah account
orderlah.app/delete-account is where anybody can ask for their OrderLah account and the data held against it to be deleted. It takes one email address and needs no sign-in and no app. The same request is in the OrderLah app (com.orderlah.app) under Settings → App & system → OrderLah account → “Delete my OrderLah account…”, and in the merchant portal, for anybody already signed in.
- We email a confirmation link to that address. It is good for 2 hours, and nothing is scheduled until it is used.
- Once it is confirmed, deletion happens 30 days later. You can stop it during those 30 days: simply signing back in stops it, and the email we send when the clock starts carries a link that stops it in one press. Nothing is destroyed until the 30 days are up.
- A business you are the only owner of is closed along with your account, and its tablets stop working. A business you share with another owner carries on — you are simply removed from it.
What is erased. Your account, your sign-ins and your ways to sign in; for a business you were the only owner of, every way in — its devices’ sign-ins, its activation codes, its relay connections, and every device authorisation, revoked — and what that business leaves that nobody will use again: the staff names, roles and shop address its Hub last published to us, how far its setup got, its country lines, its Ask OrderLah conversations, prepared price changes, saved answers and request records, your payment provider keys (the connection is switched off), and the bank account and account holder’s name entered for referral payouts, unless a payout to them is still on its way. The Ask OrderLah questions you asked yourself are erased from every business, including one that carries on without you; the records of AI use, which hold no words, stay without your name until they expire. If you used Sign in with Apple, we also ask Apple to end OrderLah’s access to your Apple ID, keep asking until it accepts, and then destroy the stored token.
What is kept afterwards. A business you were the only owner of is closed, not erased: its record stays so the tax invoices that name it still mean something. These records outlive the account, and the app shows the same list before you confirm:
- Tax invoices for licences you bought. OrderLah is required by law to keep these.
- Which version of OrderLah’s terms and privacy notice you agreed to, and when — with the network address and the app or browser you agreed from.
- The security log of sign-ins and of changes made to your account.
- The closed record of a business you were the only owner of — its registered details, and its outlets with their addresses. They stay marked closed because tax invoices still name them.
- Which tablets were authorised to a closed outlet, and when, with the names they were given and the network address each was last seen at. They are revoked, so they cannot sign in again.
- The record of which country a closed outlet was billed in. The live location readings that produced that decision are deleted.
- Your licences and their history: trials, purchases, reminders, and each time a tablet checked its licence, with the network address it checked from.
- Records of online payments customers made to a closed outlet, as the payment provider reported them. These can include the card brand, the last four digits and the name of the person who paid. Your payment provider keys are erased.
- The orders, menus and tables of a closed outlet that took orders through OrderLah’s servers rather than a Hub tablet.
- The costs, expenses and budgets entered on the merchant portal’s Finance pages. You can erase them there before you delete your account.
- Referral and reward records: your referral code and the contact details given with it, who you referred, and the rewards and payouts recorded, including the account holder’s name on a payout already sent. The bank details you entered for payouts are erased, unless a payout to them is still on its way.
- The sales enquiry and website visit records from before you signed up, including the name, phone number and email address given with an enquiry.
We keep these to meet tax and accounting duties, to show which agreement was made, as the record of money that moved, and to look into misuse — not for marketing, and not to keep serving you.
The record of the deletion itself is kept for one year: a request id, a one-way digest of the email address, the timestamps and the network address the request came from. The email address itself is held only while the request is live and is blanked when the deletion completes. A request made through the public page is recorded whether or not the address has an account with us, so that the page cannot be used to find out which addresses do; for an address we do not know, the record holds the digest, the timestamps and the network address. The digest cannot be turned back into the address, though it can confirm an address someone already has.
None of this touches your tablet. Your menu, your orders, your takings and your backups are on your own devices, so deleting your OrderLah account does not erase your till. The only records of your shop’s trade on our side are the ones named above — online payments, and the orders of an outlet that took them through our servers. To clear a tablet too, uninstall OrderLah or clear its data in the device’s own settings, after exporting anything you still want.
If you cannot use the page, email hello@orderlah.app from the address you sign in with and ask — it ends in the same place.
Children
OrderLah is a business tool for restaurant and hawker operators. It is not meant for children, and we do not knowingly collect information from them.
Your rights
Your information sits in two places and you reach each one differently, so this section says which is which.
Your shop’s own data, on your own devices
Your menu, your orders, your takings and your loyalty cards are kept on your tablets. The only copies on our servers are the ones this policy describes — your outlet’s settings and staff names and roles, online payments, orders taken through our servers, and Ask OrderLah conversations for 30 days — and report summaries only pass through while you look at them. So for data on your tablets there is nothing for us to hand over, correct or delete on your behalf, and nothing you need our permission for. You read and change it in the app; on your Hub’s home screen, Business → Reports exports your sales and orders as CSV and System & Support → Backup / Restore exports the lot; uninstalling the app or clearing its data destroys it.
A single loyalty card. The app cannot yet remove one loyalty card, or the phone number on it. Today the only way is to erase OrderLah’s data on the Hub — uninstall the app, or clear its data in the tablet’s own settings — which removes everything else on it too, and restoring a backup brings the card back. If a customer asks you to remove their number, write to hello@orderlah.app and we will talk it through with you. We cannot do it for you, because we cannot reach your tablet.
Your OrderLah account and licence, on our servers
This is the part we do hold: the account you sign in with, the businesses and outlets under it, which tablets are activated, your licence and its dates, which country each outlet is registered in and the country counts described above, the invoices for licences, the record of which OrderLah terms you agreed to, and the security log.
Most of that you can read yourself in the merchant portal, which is also where you correct your account details and your business and outlet details. Your financial setup — product costs, operating expenses and budgets typed into the portal — can be downloaded as a file and erased in one action from the portal’s Finance page, and you do that yourself before deleting your account; account deletion does not do it for you. Which tablets are authorised is managed in the app itself, on the Hub, where they are approved and removed.
The security log is the exception. It is not shown in the portal, so ask us for it at hello@orderlah.app and we will send you what it holds about your account.
Deletion has three routes and they end in the same place: orderlah.app/delete-account, which needs no sign-in and no app; the account screen in the OrderLah app; and the account panel in the merchant portal. “Deleting your OrderLah account” above says what that erases and what is kept.
For access, correction, a copy of your server-held records, deleting an enquiry, or any other request about your information, write to hello@orderlah.app from the address you sign in with. The same address answers questions about this policy. Tell us what you are asking for; we may need to check you are who you say you are before we act on it, and we will say so rather than go quiet.
If you are a customer of a shop that uses OrderLah
The shop keeps your orders, and any loyalty card, on its own tablets, and decides what to keep. Ask the shop first. If you ordered through the shop’s public address or paid online, you can also write to hello@orderlah.app about what passed through our servers.
Changes to this policy
If this policy changes we will update this page and move the effective date at the top. Material changes are also summarised under What’s new on the app’s Google Play and App Store listings, against the release that carries them. If you installed OrderLah directly rather than from a store, this page and its effective date are the record.