Ordernora

Privacy Policy

Last updated: 18 September 2026

Ordernora is operated by GANI Tech Pty Ltd ("Ordernora", "we", "us", "our").

This policy covers two different groups of people, because Ordernora sits between a restaurant and its customers: restaurant owners who sign up for Ordernora and manage their account through our portal, and callers — the restaurant's own customers — whose calls Ordernora's AI answers. Callers never create an Ordernora account or visit our website; the only notice they get is the spoken disclosure at the start of the call, which Section 3 below reflects.

1. Who we are

GANI Tech Pty Ltd operates Ordernora, an AI phone-answering and ordering service for restaurants. If you have questions about this policy or your data, contact us at support@ordernora.au.

2. What Ordernora does

A restaurant connects its phone number to Ordernora. When a customer calls, an AI voice assistant answers, takes the order, and sends it to the restaurant's point-of-sale system (Square) or a menu catalog the restaurant built by uploading photos of their menu. Restaurant owners manage their account, menu, hours, and view call/order history through our web portal.

3. Information we collect

What we do NOT collect

  • We don't collect precise GPS location from anyone.
  • We don't store full payment card numbers — card payments are handled directly by Square, our payments partner, not by us.
  • Callers are never asked to create an account, set a password, or install anything.

From restaurant owners (portal account holders)

  • Account/contact info: email address (used for one-time-code login — no password), business name, business phone number, business hours.
  • Menu data: either synced from your connected Square account, or a photo you upload that we process (using an AI vision model) into a structured menu you review and approve before it goes live.
  • Square connection: if you connect Square, we receive an authorization token that lets us read your catalog and push order/fulfillment updates back to Square. We don't receive your Square login credentials.
  • Usage data: call minutes used, number of venues, plan/subscription status.
  • Subscription payment: if you're on a paid plan, payment is processed by a third-party payment processor. We don't store your card details ourselves.

From callers (the restaurant's customers)

  • Call audio and transcript: every call is recorded and transcribed. The AI states this at the start of the call. Recordings and transcripts are used to take and verify the order, and are available to the restaurant owner to review through the portal.
  • Caller ID / phone number: used to identify the caller for the call and, if the restaurant sends an order confirmation or payment link by text message, to deliver that text.
  • Order details: items ordered, any notes given during the call (including dietary or allergy notes if mentioned), and pickup/delivery details if given.
  • Payment, if the restaurant sends a payment link: handled directly by Square when the caller completes it — we don't store card details.

4. How we use information

  • To answer calls, take orders correctly, and get them to the right place (the restaurant's Square account or dashboard).
  • To let restaurant owners review what was said on a call (recordings/transcripts) and manage their menu, hours, and billing.
  • To send order and payment-link notifications by SMS.
  • To improve reliability (e.g. diagnosing a call that failed) and for security.

AI processing: call audio is processed by third-party speech-recognition, language-model, and voice-synthesis providers solely to generate a response during that call. This data is not used by us or by those providers to train or improve their AI models — it's used for inference only, to handle that one call.

5. Cookies

The marketing site and portal use only what's needed to keep you logged in and remember basic preferences — no third-party advertising or cross-site tracking cookies.

CookiePurposeDurationHow to opt out
Session/auth cookieKeeps you logged into the portalSession / until logoutLog out, or clear browser cookies

6. Third-party processors

ProviderPurposeNotes
SquarePoint-of-sale sync, payment processing for order paymentsSquare's Privacy Policy
KudositySMS delivery (order confirmations, payment links)AU-based SMS provider
Voice AI / telephony infrastructureSpeech recognition, order-taking, and voice response, used only to handle your callsDetails available on request
SupabaseDatabase and backend hostingSupabase's Privacy Policy

7. Data retention

  • Call recordings and transcripts: retained for 90 days, then deleted.
  • Order and menu data: retained while your account is active.
  • Account data: retained until you close your account, then deleted within 90 days, except where we need to keep records longer for tax or legal reasons (Australian businesses are generally required to keep certain records for 5 years).
  • Server access logs: retained for 30 days for security and debugging.

8. Your rights (Australian Privacy Principles)

Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you can ask us to access the personal information we hold about you, correct it if it's wrong, or ask questions about how it's handled.

Contact support@ordernora.au and we'll respond within a reasonable time (aim: 30 days). If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC).

If callers (not the restaurant owner) want a copy of or the deletion of their call data, they can contact the restaurant directly, or reach us at the email above and we'll coordinate with the restaurant, since the restaurant is the primary account holder.

9. International transfers

Some of our service providers may process or store data outside Australia as part of normal cloud infrastructure operation. We only use providers that are contractually required to protect your information consistent with Australian Privacy Principle 8, or that are located in jurisdictions with comparable privacy protections.

10. Children

Ordernora is a business tool for restaurant owners and a phone-ordering service for their adult customers. It isn't directed at children, and we don't knowingly collect personal information from anyone under 16. If you believe a child's information has been collected, contact us and we'll delete it.

11. Security

  • All connections to our portal and between our systems use HTTPS/TLS encryption.
  • Call recordings and account data are encrypted at rest by our infrastructure providers.
  • We don't ask callers for passwords or store their credentials — there's nothing to leak on that front.
  • If we become aware of a data breach affecting your information, we'll notify you and the OAIC as required by the Notifiable Data Breaches scheme.

12. Changes to this policy

We'll post any changes here with an updated "Last updated" date. If a change is significant, we'll also email active account holders.

13. Contact

Email support@ordernora.au with any privacy question, request, or complaint. We aim to respond within 30 days.