LAST UPDATED — June 8, 2025

Privacy Policy

We respect your privacy and are committed to protecting it. This policy explains exactly what data we collect, why we collect it, and how you can control it.

Effective date: June 8, 2025

Overview

QR Menu Platform ("we", "us", "our") operates the website qrmenu.et and the associated restaurant management service. This Privacy Policy applies to all visitors, registered restaurant owners, and end-consumers who scan a QR code served by our platform.

By accessing or using our services you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of the platform.

Data We Collect

We collect data in three ways: information you provide directly, data collected automatically, and data from third-party sources.

2.1 Information You Provide

  • Account data — name, email address, phone number, and password hash when you create a restaurant owner account.
  • Business data — restaurant name, address, logo, menu items, prices, and category descriptions you upload to the platform.
  • Payment data — billing name and contact details. We do not store full card numbers; payments are processed by a PCI-DSS-compliant third party.
  • Support communications — messages or emails you send to our support team.

2.2 Automatically Collected Data

  • Usage data — pages visited, features used, session duration, and clickstream data.
  • Device & browser data — IP address, browser type and version, operating system, and device identifiers.
  • QR scan events — timestamp, rough geolocation (city-level derived from IP), and referring QR code ID when a diner scans a menu.
  • Cookies & local storage — see Section 6 for full details.

2.3 Data From Third Parties

  • Authentication providers — if you sign in via Google or another OAuth provider, we receive your name, email, and profile picture from that provider.
  • Analytics services — aggregated behavioural data from analytics partners (only when you consent).

How We Use Your Data

PurposeData UsedLegal Basis
Provide & operate the serviceAccount data, business dataContract performance
Process paymentsPayment & billing dataContract performance / Legal obligation
Send transactional emailsEmail addressContract performance
Improve platform featuresUsage & device data (aggregated)Legitimate interests
Personalise your dashboardUsage historyLegitimate interests
Send marketing updatesEmail addressConsent (opt-in only)
Detect fraud & abuseIP address, usage patternsLegitimate interests / Legal obligation
Comply with lawAll categories as requiredLegal obligation

Data Sharing & Disclosure

We do not sell your personal data. We may share it only in the following limited circumstances:

  • Service providers — trusted processors (hosting, email delivery, payment processing, analytics) bound by data processing agreements.
  • Restaurant owners — if you are a diner, the restaurant whose QR code you scanned may see aggregated scan analytics (never your name or device identity).
  • Legal requirements — when compelled by Ethiopian law, court order, or equivalent authority.
  • Business transfers — in the event of a merger or acquisition, personal data may transfer to the successor entity under the same privacy obligations.

Security

We implement industry-standard security measures including:

  • TLS 1.3 encryption for all data in transit.
  • AES-256 encryption for sensitive data at rest.
  • Bcrypt password hashing — we never store plaintext passwords.
  • Role-based access control within our internal team.
  • Regular security audits and vulnerability scanning.
No method of transmission or storage is 100% secure. If you discover a vulnerability, please report it responsibly to privacy@qrmenu.et.

Cookies & Tracking

We use cookies and similar technologies. You can manage your preferences at any time via the cookie banner or your browser settings.

CategoryExamplesCan You Opt Out?
Strictly NecessarySession token, CSRF token, consent recordNo — required to function
AnalyticsPage-view counters, session heatmapsYes — via consent banner
MarketingAd-network pixels, retargeting IDsYes — via consent banner
PreferencesLanguage selection, dashboard layoutYes — via consent banner

Your Rights

Depending on your location, you have some or all of the following rights over your personal data:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — request deletion of your data ("right to be forgotten").
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests.
  • Restriction — request that we limit how we process your data.
  • Withdraw Consent — where processing is based on consent, withdraw it at any time without affecting prior lawful processing.

To exercise any right, contact us at privacy@qrmenu.et. We will respond within 30 days.

Data Retention

Data TypeRetention Period
Account & business dataDuration of account + 90 days after deletion request
Payment records7 years (legal / tax obligation)
QR scan analytics24 months (rolling)
Support communications3 years
Server logs (IP, timestamps)90 days
Cookie consent records3 years

Children's Privacy

Our platform is not directed at persons under the age of 13. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us immediately and we will delete it promptly.

Policy Changes

We may update this Privacy Policy from time to time. When we make material changes, we will notify registered users by email and display a notice on the platform for at least 30 days before the change takes effect. Continued use after the effective date constitutes acceptance of the updated policy.

The "Last Updated" date at the top of this page always reflects the most recent revision.

Contact Us

For privacy-related questions, data requests, or to report a concern, reach us at:

QR Menu Platform

Addis Ababa, Ethiopia

Email: privacy@qrmenu.et