Legal

Privacy Policy

Last updated: 19 July 2026

ORDRX ("we", "us") provides self-ordering kiosk software for hospitality venues: an Android kiosk app, a web dashboard for venue staff, and the cloud service that connects them. This policy explains what information we handle and why. We are based in Australia and handle personal information in accordance with the Australian Privacy Act 1988 and the Australian Privacy Principles.

The short version: the kiosk app collects no personal information from customers placing orders. Card payments are processed entirely by Square — card details never touch ORDRX software. We collect only the business account details venues give us, and the order data needed to run their kiosks.

Information we collect from venues (our customers)

  • Account details — business name, and the name, email address and optional phone number of staff who use the dashboard.
  • Billing — subscriptions are processed by Stripe. We store your plan and subscription status; your card details are held by Stripe, not us.
  • Square connection — when you connect your Square account via OAuth we store encrypted access tokens so your kiosks can read your catalog and create orders. We never see your Square password.

Information handled by the kiosk app

  • Orders — the items a customer selects, an optional table number, and the order total. This is business data for the venue; we do not ask customers for their name, contact details or any account.
  • Payments — taken on a Square Terminal. Card data is captured and processed by Square's hardware and services under Square's privacy policy. ORDRX never receives card numbers.
  • Device identifiers — each kiosk generates a random identifier so the venue can manage it from their dashboard. It is not linked to any person.
  • Peripherals — if the venue configures a receipt printer, the app uses network, Bluetooth or USB access solely to print order tickets. No personal data is involved.

What we do not do

  • No advertising, and no sale or sharing of data for advertising.
  • No tracking of kiosk customers, no analytics SDKs in the kiosk app, and no collection of location, contacts, photos or files.
  • No card or bank details stored on our systems.
  • No third-party fonts, scripts or embeds on this website — everything it loads is served from our own domain.

How we use information

We use venue account data to operate the service: authenticating staff, syncing menus from Square, processing orders, sending service emails (account verification, password resets, enquiry replies) and billing. Order data belongs to the venue and is used to display, fulfil and report on their own sales.

Storage and security

Data is stored on cloud infrastructure with encryption in transit (TLS). Square tokens are encrypted at rest. Passwords are stored as salted hashes. Access to production systems is limited to ORDRX operators, and administrative actions are audit-logged.

Third parties we rely on

  • Square — catalog, orders and card payments.
  • Stripe — subscription billing for venues.
  • Railway — cloud hosting.
  • Resend — transactional email delivery.

Retention and deletion

We keep venue data while the account is active. Venues can ask us to delete their account and associated data at any time; we remove it from production systems, subject to records we must keep for tax and legal obligations.

Your rights

Venue staff may access and correct their details in the dashboard, or contact us to access, correct or delete personal information we hold. If you have a privacy concern we have not resolved, you may contact the Office of the Australian Information Commissioner (oaic.gov.au).

Contact

ORDRX — info@ordrx.com.au

We may update this policy from time to time; the latest version will always be at this address.