Yes Sir Yes Ma’am

Privacy Policy

Last updated: September 15, 2026

Yes Sir Yes Ma’am (“we”, “us”, “our”) provides a menu, order, and business-management platform for food carts, cafes, and restaurants (“Vendors”) at yessiryesmam.com and order.yessiryesmam.com (collectively, the “Service”). This Privacy Policy explains what information we collect from Vendors and their staff who use the Service, how we use it, and the choices you have.

1. Who this applies to

The Service is a business tool used by Vendors and their staff to register a business account, manage a menu, record orders, and log how each order was paid for their own bookkeeping. This policy covers information collected directly from Vendor accounts and users who sign in to the Service. It does not cover a Vendor’s own end customers unless they interact directly with our Service.

We do not process, collect, or receive any payment a Vendor’s customer pays the Vendor — that transaction happens entirely between the Vendor and their customer, outside the Service. The only payment we process directly is the subscription fee a Vendor pays us to use the Service, described in Section 12 below.

2. Information we collect

  • Account and business information: business name, owner name, phone number, email address, city, and business logo, provided when a Vendor registers or updates their profile.
  • Operational data: menu items, prices, categories, orders, order items, the payment method a Vendor records against an order (e.g. cash, UPI, or card, for the Vendor’s own record-keeping — the Service does not process or collect payments on the Vendor’s behalf), expenses, and related business records a Vendor creates while using the Service.
  • Authentication data: login credentials (stored using industry-standard hashing) and session identifiers used to keep you signed in securely.
  • Technical data: standard web server logs (IP address, browser type, timestamps) used for security and troubleshooting.

3. Phone number use and WhatsApp OTP verification

When a Vendor registers on the Service or needs to verify their phone number, we send a one-time passcode (OTP) to the phone number provided, delivered via the WhatsApp Business Platform. This number is used solely to:

  • Verify that the Vendor controls the phone number provided at registration;
  • Authenticate account-related actions that require confirming identity; and
  • Contact the Vendor about their account when necessary (e.g. security or service notices).

We do not use your WhatsApp number to send marketing or promotional messages unless you have separately opted in. Your phone number is shared with our messaging provider only to the extent necessary to deliver the OTP message, and is not sold or shared with unrelated third parties.

4. How we use information

  • To create and secure your Vendor account and authenticate sign-ins;
  • To operate core features of the Service — menu management, order recording, and letting a Vendor log the payment method used for their own records;
  • To communicate service-related updates, security alerts, and support responses;
  • To maintain the security, integrity, and reliability of the Service; and
  • To comply with legal obligations.

5. Cookies and sessions

The Service uses session cookies to keep you signed in and to protect against cross-site request forgery. These cookies are strictly necessary for the Service to function and are not used for third-party advertising or cross-site tracking.

6. Data sharing

We do not sell Vendor or business data. We share information only with service providers who help us operate the Service under confidentiality obligations — for example, hosting infrastructure and the WhatsApp Business Platform used to deliver OTP messages — or when required by law.

7. Data retention

We retain account and operational data for as long as a Vendor account remains active, and for a reasonable period afterward as needed for legal, accounting, or security purposes. Vendors may request deletion of their account and associated data as described below.

8. Your rights and choices

Vendors can review and update their business profile directly within the Service. To request access to, correction of, or deletion of your account data, contact us using the details below.

9. Security

We apply reasonable technical and organizational measures — including encrypted password storage, access controls, and secure transport (HTTPS) — to protect information against unauthorized access, alteration, or loss. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Children’s privacy

The Service is intended for business use by adults operating a food business. It is not directed at, and we do not knowingly collect information from, children.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Last updated” date above. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.

12. Mobile app (Android and iOS)

We offer a YesSirYesMam Vendor mobile app for Android and iOS that provides the same account, menu, order, and subscription features as order.yessiryesmam.com. The app collects and processes the same account and operational data described above, plus the following mobile-specific items:

  • Authentication token storage: after you sign in, the app stores your session token in the device’s secure, encrypted keystore (iOS Keychain / Android Keystore) so you stay signed in. This token is not accessible to other apps and is removed when you sign out.
  • Photo library access: if you choose to set or update your business logo, the app requests access to your photo library to let you pick an image. We only access the specific photo you select; we do not scan or upload your full photo library.
  • Payment checkout (Razorpay): we charge Vendors a subscription fee to use the Service; that fee is processed through Razorpay’s secure checkout, opened inside the app. This is the only payment the Service ever processes — we do not process, collect, or receive any payment between a Vendor and the Vendor’s own customers. Razorpay’s checkout page may request microphone or camera permissions on some devices as part of its own fraud-prevention and payment-verification checks; this is controlled by Razorpay, not by our app, and we do not separately record audio or video, or receive any audio/video data ourselves. See Razorpay’s Privacy Policy for details on their processing.
  • Push/update notifications: the app does not use third-party push notification services. It periodically checks our servers for available app updates and shows an in-app prompt; no data beyond your app version is sent for this check.

The mobile app does not access your device’s location, contacts, microphone, or camera directly, and does not collect advertising identifiers. Uninstalling the app removes all locally stored data, including the secure authentication token; your account data on our servers is unaffected and remains governed by the rest of this Privacy Policy.

13. Contact us

For questions about this Privacy Policy or to make a data request, contact us at info@amrsoftec.com.