Legal
Privacy Policy
Last updated: 13 August 2026 · support@cafenex.com
This Privacy Policy explains how CafeNex (“CafeNex”, “we”, “us”, or “our”) collects, uses, shares, and protects information when you use our gaming cafe management software, websites, mobile applications (including the CafeNex staff / notifier Android app), PC station agent, APIs, and related services (collectively, the “Services”). By accessing or using the Services, you agree to this Policy. If you do not agree, please do not use the Services.
1. Who we are
CafeNex provides cloud-based and on-premises-assisted software for gaming cafes, PC bangs, console lounges, and similar businesses. Our product includes station session management, billing and POS, kitchen / food orders, bookings, expenses, user/gamer profiles, notifications, analytics, multi-location tools, and optional PC station agent software.
- Product website: https://cafenex.com
- Privacy / support contact: support@cafenex.com
- WhatsApp support: +91 88278 10080
- Services may be accessed via cafenex.com, tenant cafe subdomains/custom domains, mobile apps published under package identifiers such as com.cafenex.app, and desktop agents.
2. Scope — who this policy covers
This Policy applies to:
- Cafe owners, managers, staff, and operators who create accounts and use CafeNex to run their venues (“Business Users”).
- End customers / gamers whose data is entered into CafeNex by a cafe (“End Users”), to the extent we process that data on behalf of the cafe.
- Visitors to our public marketing site, SEO pages, ROI calculator, and related public tools.
- Users of the CafeNex Android / iOS staff apps, PWA, magic login links, and push notifications.
- Devices running the CafeNex Station Agent or similar client software on gaming PCs.
3. Roles: controller vs processor
Depending on the context:
- For Business User account data, billing, support tickets, and product analytics about how you use CafeNex, CafeNex generally acts as a data controller.
- For End User / gamer data that a cafe stores in CafeNex (names, phone numbers, session history, orders, payments recorded by the cafe, etc.), the cafe is typically the data controller and CafeNex acts as a processor / service provider processing data on the cafe’s instructions.
- Cafes are responsible for providing their own privacy notices to their customers where required by law, and for obtaining any required consents for SMS, WhatsApp, or marketing.
4. Information we collect
We collect information in the following categories. Exact fields depend on features you enable and data you choose to enter.
4.1 Account and identity data (Business Users)
- Name, email address, phone number, password or authentication secrets (stored hashed / via secure auth flows).
- Cafe / business name, address, GST or tax identifiers if you provide them, logo and branding assets.
- Role and permissions (owner, manager, cashier, kitchen, etc.) under our RBAC system.
- Two-factor authentication settings and recovery information when enabled.
- Magic login / setup tokens used for secure device onboarding.
4.2 Cafe operations and business data
- Stations (PC, PS5, Xbox, etc.), station types, rates, packages, and session timers.
- Sessions (start/stop/pause/extend), prepaid and postpaid usage, accessories billed with sessions.
- Food / kitchen orders, menu items, add-ons, inventory-related records if used.
- Bookings and reservations.
- POS sales, invoices, payment method labels (cash, UPI, card, wallet, split payments), discounts, and refunds recorded in the product.
- Expenses and operational notes entered by staff.
- Gamer / member profiles created by the cafe (name, phone, visit history, balances) when the cafe uses those modules.
- Reports, analytics aggregates, and export files you generate.
- Feature flags, subscription plan, trial status, and multi-location / multi-tenant configuration.
4.3 Mobile app, devices, and notifications
- Device identifiers and Firebase Cloud Messaging (FCM) push tokens so we can deliver alerts (kitchen orders, session auto-pause, urgent floor alerts, general notifications).
- Device type / platform (Android, iOS), app version, and basic device metadata needed for support and reliability.
- Notification preferences, permission states, and in-app reliability settings you configure.
- Deep-link and notification interaction data (for example, opening a station from a push alert).
- Locally played alert sounds and notification channels are configured on-device; custom sound files ship with the app and are not uploaded to Firebase as separate “sound assets.”
4.4 Station agent and PC client data
- Station registration identifiers linking a PC to a cafe station record.
- Agent version, health/heartbeat, lockdown / kiosk-related configuration, crash or diagnostic logs when reported.
- Game library / installed title scan results if the agent’s scanning features are enabled by the cafe.
- Session lock state and commands issued from the control panel to the station.
4.5 Technical, log, and usage data
- IP address, browser type, device OS, language, referrer, and approximate location derived from IP.
- Server logs, error reports, API request metadata, and performance metrics.
- Cookies, local storage, and similar technologies on the web product and marketing site.
- Realtime connection status (WebSockets / broadcasting) for live dashboard updates.
4.6 Payments and subscriptions
- Subscription plan selection, billing cycle, invoices, payment status, and renewal history for CafeNex SaaS fees.
- Payment gateway references (for example Razorpay payment IDs). Full card numbers are processed by the payment provider, not stored by CafeNex as complete PAN data.
- Commerce / settlement metadata if you use platform commerce features.
- Manual payment confirmations or offline subscription notes entered by CafeNex support when applicable.
4.7 Marketing and public tools
- Information you submit in contact forms, WhatsApp chats, email, demos, or support tickets.
- ROI calculator / audit inputs (cafe details, equipment, costs, owner contact) when you use those tools.
- Newsletter or marketing preferences if you opt in.
5. How we use information
- Provide, operate, and maintain the Services (sessions, billing, POS, kitchen, bookings, expenses, users, multi-location).
- Authenticate users, enforce roles/permissions, and secure accounts.
- Send transactional messages and push notifications essential to cafe operations (orders, pauses, alerts).
- Process subscriptions, invoices, and related commercial transactions.
- Improve reliability, debug issues, prevent abuse, fraud, and security incidents.
- Provide customer support and onboarding.
- Generate product analytics and aggregated insights that do not identify individual End Users where possible.
- Comply with legal obligations and enforce our Terms and Refund Policy.
- With consent or as otherwise permitted, send product updates and marketing communications (you may opt out of non-essential marketing).
6. Legal bases (where applicable)
Where data-protection laws require a legal basis (for example GDPR-style regimes), we rely on one or more of: performance of a contract (providing the Services you subscribed to); legitimate interests (securing and improving the product, preventing fraud); consent (where required for certain marketing or optional features); and legal obligation.
7. How we share information
We do not sell your personal information. We may share data with:
- Service providers / subprocessors: cloud hosting, databases, email, error monitoring, analytics, Firebase / Google Cloud Messaging for push delivery, payment gateways (e.g. Razorpay), and similar vendors under contractual safeguards.
- Cafe staff and roles you authorize within your tenant.
- Your payment provider when you pay for CafeNex or process cafe payments through integrated flows.
- Professional advisors (legal, accounting) under confidentiality when needed.
- Authorities when required by law, court order, or to protect rights, safety, and security.
- A successor entity in connection with a merger, acquisition, or asset sale, subject to continued protection of the data.
8. International transfers
Servers, backups, or subprocessors may be located in India and/or other countries. Where data is transferred internationally, we take steps designed to provide appropriate safeguards consistent with applicable law and vendor practices.
9. Data retention
- Account and cafe operational data is retained while your subscription / account is active and for a reasonable period afterward for backups, dispute resolution, fraud prevention, and legal compliance.
- Push tokens may be rotated or removed when devices re-register, log out, or become inactive.
- Logs and security records may be retained for shorter operational windows.
- You (as a Business User) may delete or request deletion of certain records through the product or by contacting support; some residual copies may remain in encrypted backups until those cycles expire.
- If you close your cafe tenant, we may delete or anonymize data after any contractually required retention period, except where we must keep records (e.g. invoices).
10. Security
We implement technical and organizational measures appropriate to the risk, which may include HTTPS/TLS in transit, access controls and RBAC, hashed passwords, secure token storage on mobile (e.g. platform secure storage), server-side authorization, and operational monitoring. No method of transmission or storage is 100% secure; you are responsible for protecting staff credentials, device locks, and cafe-side physical access to stations.
11. Your rights and choices
- Access, correction, and update of account profile data via the product settings or support.
- Request deletion of personal data we control, subject to legal and legitimate retention needs.
- Withdraw consent for optional marketing communications.
- Control mobile notification permissions in OS settings; note that disabling notifications may impair kitchen/session alerts.
- End Users should primarily contact the cafe that collected their data; we will assist cafes with reasonable processor requests.
- To exercise rights, email support@cafenex.com with enough detail to verify your request.
12. Children
CafeNex is a business / staff-oriented product and is not directed at children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children for the purpose of creating staff accounts. Cafes that serve minors are responsible for complying with applicable local laws regarding customer data.
13. Cookies and similar technologies
Our websites and web app use cookies and local storage for authentication sessions, preferences, security, and analytics. You can control cookies through browser settings; disabling essential cookies may break login or core features.
14. Third-party links and integrations
The Services may link to third-party sites or integrate third-party tools (payment gateways, messaging, game metadata providers, etc.). Their privacy practices are governed by their own policies. We encourage you to review them.
15. Android / Google Play specific disclosures
- The CafeNex mobile app may request permissions such as Internet access, notifications (including POST_NOTIFICATIONS on modern Android), vibration, boot completion receivers for reliable alerts, and related operational permissions.
- Push delivery uses Google Firebase Cloud Messaging. Google’s processing is subject to Google’s terms and privacy policy.
- App access is generally limited to authorized cafe staff. Reviewers or support staff may be given temporary credentials only as needed for app review or troubleshooting.
- Data safety answers in Google Play are intended to be consistent with this Policy; if wording differs slightly due to form constraints, this Policy provides the fuller description.
16. Changes to this Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of the page will change when we do. Material changes may also be communicated via email, in-app notice, or website banner. Continued use of the Services after the effective date constitutes acceptance of the updated Policy where permitted by law.
17. Contact
For privacy questions, requests, or complaints, contact us at support@cafenex.com or via WhatsApp support listed on cafenex.com. We will aim to respond within a reasonable period.
Need help with billing or privacy?
Email support@cafenex.com or message us on WhatsApp.
