Privacy Policy

Last updated 2 September 2026

Published by BETRRR · Sole Proprietorship · Udyam Reg. No. UDYAM-KR-26-0063253
Flat/Door/Block No. 1-26, Irfan Manzil, Janata House Colony, Gangolli, Kundapura, Udupi District, Karnataka 576216, India

1. Scope

This policy covers the Betrrr consumer app and website at https://betrrr.app — where you find events, book tickets, browse restaurants, order at a table and hold Betrrr Credits.

Restaurants, their managers and their staff sign in to a separate product at restaurant.betrrr.app and are covered by its own privacy policy. Where you book or order at a restaurant, each policy applies to its own side of that record: this one to your account and your booking, theirs to the restaurant’s.

BETRRR, a sole proprietorship registered in India under Udyam Registration Number UDYAM-KR-26-0063253, is the data fiduciary for the personal data described here under the Digital Personal Data Protection Act, 2023, and the body corporate responsible for it under the Information Technology Act, 2000 and the rules made under it.

2. Data we collect, and the purpose

  • Your account. Mobile number and name; an email address where you give one. The number is how you sign in — we send a one-time code to it — and how we send you a booking confirmation. No password is stored for a Betrrr account.
  • Bookings and orders. The tickets you hold, the tier and event they are for, restaurant reservations, table orders and bills. These are the record of what you booked and the basis of any refund.
  • Payment records. The amount, the method, the time, and the reference our payment partner returns. Card and UPI credentials are handled as described in clause 5; we do not keep them.
  • Betrrr Credits. Your balance and the entries that moved it — what was earned, spent or refunded.
  • Your city, and location if you offer it. The city you pick is remembered in your browser. If you tap to use your current location, your browser asks your permission first and the coordinates are sent to our server once, to name the city and to sort restaurants by distance. We do not track your location in the background and we do not keep a history of where you have been.
  • What you type into booking search. If you describe a booking in your own words (“table for four on Friday night”), that sentence is read to pull out a date, a time and a party size. See clause 5.
  • Support messages. What you write to us, so we can answer it.
  • Technical logs. Server access logs recording request time, path, response status, user agent and IP address, kept for security and for diagnosing faults.

We collect nothing on a hunch that it may be useful later. If a field is on this list it is because a screen, a ticket or a refund needs it.

3. Lawful basis

Your account, bookings, payments and credits are processed because they are necessary to provide the service you asked for — performance of our contract with you, and the consent you give when you create an account and make a booking.

Security logs and rate-limiting data are processed on the basis of our legitimate need to keep the service available and to prevent misuse. Financial records are retained because the law requires it, whatever consent is later withdrawn.

4. What we do not do

  • There are no advertising or analytics trackers in this app. No Google Analytics, no advertising pixels, no third-party scripts watching what you tap. An earlier version of this page described analytics cookies; there were none then either, and the claim has been removed rather than left standing.
  • We do not sell personal data, and we do not disclose it to anybody for their own marketing.
  • We do not use your bookings to train machine-learning models.
  • We do not build an advertising profile of you, and nothing on Betrrr is priced differently because of who you are.

5. Processors and disclosure

We engage the processors below. Each receives only the data its function requires, under contract, and none of them may use it for their own purposes.

  • Razorpay — payment collection and refunds. Paying by UPI sends only the amount and your UPI ID. Where card payment is offered, the card details you type pass through our server to Razorpay over an encrypted connection and are forwarded, never written to our database or our logs; the card number is not retained by us at any point.
  • MSG91 — delivery and verification of one-time sign-in codes, and transactional SMS such as a booking confirmation, a cancellation or a refund notice. One-time codes are generated and verified by MSG91; we do not store them.
  • Supabase — the managed PostgreSQL database and file storage behind the platform, operated under our own domain at db.betrrr.app.
  • Ola Maps — turning coordinates into a city name, and searching for places. Called from our server with our key, so your browser does not talk to them directly.
  • Resend, alongside our own mail servers — transactional email such as confirmations and receipts.
  • Groq — reads a booking request you type in your own words and returns a date, a time and a party size. It receives that sentence, up to 500 characters, and a list of cities and venues. It does not receive your name, your number, your account or your booking history, and its output is not used to make any decision about you — it only fills in the form you are looking at, which you can correct before booking.

Where you book a table or order at a restaurant, the restaurant is shown what it needs to seat you and serve you — your name, the party size, the time and the order. It is a separate business and handles that under its own obligations.

Beyond these, we disclose personal data only where we are legally obliged to — a valid order from a court or an authority acting under law — or where it is necessary to establish or defend a legal claim. Betrrr personnel access customer data only to operate and support the service.

Tapping “Directions” opens Apple Maps or Google Maps with the venue’s address in the link. That is you leaving Betrrr for another app; we send them the destination, never your identity or your location.

6. Where data is processed

Our database, file storage, payments, SMS and maps are processed in India. Some of the services above — notably email delivery and the booking interpreter — run on infrastructure outside India, so personal data may be transferred there for those functions. We do not transfer personal data to any territory restricted by the Central Government under the DPDP Act.

7. What never leaves your browser

Some of what the app remembers about you is not sent to us at all. Your saved list and your in-app notifications are held in your own browser and stay on the device you made them on — which is also why they do not follow you to another phone. The full list is in the cookie and storage notice.

8. How long we keep it

  • Account records — while your account is open, and for 90 days after you close it, after which they are deleted or irreversibly anonymised.
  • Financial records — bookings, payments, refunds and invoices are kept for 8 years from the end of the financial year they fall in, as required of books of account. Closing your account does not shorten this.
  • Support messages — 12 months after the enquiry is resolved.
  • Server access logs — up to 30 days, unless a specific entry forms part of an active security or fraud investigation.
  • Sessions — a sign-in lasts until you sign out or clear your browser data; the token is re-checked by the server on every request.

9. Security

Everything travels over TLS. Credentials for third-party integrations are encrypted at rest under a key held outside the database. Hardening headers are applied to every response, and cross-origin access is restricted to our own applications.

What your account may see and do is decided by the server on every request, not by hiding controls in the interface.

If a personal data breach occurs, we will notify the Data Protection Board and every affected user as the DPDP Act requires, describing what happened, its likely consequences, and what we are doing about it.

10. Your rights

Under the DPDP Act you may ask us for a summary of the personal data we hold about you and how it is processed; to correct, complete or update it; to erase it, except where we must keep it by law; and to nominate somebody to exercise these rights if you die or become incapacitated. Where processing rests on consent you may withdraw it — which will usually mean closing the account, because the service cannot be provided without the data it runs on.

Write to support@betrrr.app or use the contact form. We respond within 30 days. We may need to verify who you are before acting, and an unused ticket is cancelled when the account holding it is deleted.

Please keep what you give us accurate, and do not submit somebody else’s personal data to Betrrr unless you are entitled to.

11. Children

Betrrr is not directed at children and we do not knowingly create accounts for anyone under 18. Some events are age-restricted by the organiser or the venue, and that restriction is theirs to enforce at the door. If you believe a child’s personal data has reached us, tell us and we will erase it.

12. Grievances

Complaints about how your personal data has been handled go to our Grievance Officer, Mohammed Irfan, at support@betrrr.app or +91 86601 62689. We acknowledge within 48 hours and resolve within 30 days. If you are not satisfied with the outcome, you may complain to the Data Protection Board of India.

13. Changes

When this policy changes we update the date at the top. If a change materially affects how your personal data is handled, we tell account holders directly rather than relying on you to notice.

Questions about any of this? Write to us.