Pune Woman Orders Food via QR Code, Gets Late-Night Message From Restaurant Staff for ‘Friendship’
Pune, 15th May 2026: A routine dining experience at a trendy restaurant on Fergusson College (FC) Road turned into a disturbing privacy nightmare for Pune-based content creator and influencer Rishika Dutta, igniting widespread outrage over customer data protection in India’s booming digital dining ecosystem.
On April 28, 2026, Dutta visited Social, a popular restaurant and bar chain on FC Road. Like thousands of customers do daily, she scanned the QR code placed on her table to browse the menu, place her order, and complete the payment — a contactless process that has become standard post-pandemic. What she didn’t anticipate was that her phone number, entered during the digital transaction, would allegedly end up in the hands of a restaurant staff member.
Later that night, Dutta received unsolicited messages from an unknown number. The sender, reportedly identified as Shaikh Shafi, a staff member who had served her table, introduced himself by referencing the drinks he had served her and expressed a desire to “do friendship.” He also asked personal questions, including her age. Shocked and uncomfortable, Dutta realized the contact had come directly from the restaurant’s internal system.
In her viral Instagram reel, Dutta shared screenshots of the conversation and narrated the incident, warning followers: “Got a late-night text from a number I didn’t recognise — turns out visiting a certain spot on FC Road came with more than just a good time. Your data shouldn’t follow you home. Stay aware!” The reel quickly gained traction, with many users resharing it and expressing similar fears.
Restaurant’s Response
Following Dutta’s complaint and the ensuing social media backlash, the management of Social issued a public apology. They stated that the employee had been terminated immediately across all branches and promised to review and strengthen their internal data handling processes to prevent future breaches. However, Dutta reportedly sought a formal written confirmation of the action and a direct apology, claiming the restaurant was initially reluctant to provide documented proof.
Broader Implications: Digital Convenience vs. Privacy
The incident has struck a nerve among netizens, particularly women, who highlighted the vulnerabilities of QR code-based systems. Many pointed out that customers often unknowingly share phone numbers (sometimes linked to Aadhaar or other IDs for payments) without realizing who within a large staff team might access that data.
Social media reactions ranged from calls for stricter data protection laws to personal anecdotes of similar harassment. Experts and users have urged restaurants to implement better safeguards, such as anonymized ordering options, strict access controls on customer databases, and transparent privacy policies. Some have even suggested reverting to physical menus in sensitive contexts or adding explicit consent mechanisms for data sharing.
This case comes amid growing national conversations around digital privacy, the Personal Data Protection Bill, and women’s safety in public and semi-public spaces. It underscores a key tension in “Digital India”: while technology offers convenience and efficiency, it can also enable misuse if robust safeguards and accountability are absent.
Rishika Dutta’s decision to speak out has not only highlighted her personal ordeal but also served as a wake-up call for diners and businesses alike.
As one user commented, “We scan QR codes without a second thought — but our safety shouldn’t be the price we pay for convenience.”
