Overview
QR Menu Platform ("we", "us", "our") operates the website qrmenu.et and the associated restaurant management service. This Privacy Policy applies to all visitors, registered restaurant owners, and end-consumers who scan a QR code served by our platform.
By accessing or using our services you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of the platform.
Data We Collect
We collect data in three ways: information you provide directly, data collected automatically, and data from third-party sources.
2.1 Information You Provide
- Account data — name, email address, phone number, and password hash when you create a restaurant owner account.
- Business data — restaurant name, address, logo, menu items, prices, and category descriptions you upload to the platform.
- Payment data — billing name and contact details. We do not store full card numbers; payments are processed by a PCI-DSS-compliant third party.
- Support communications — messages or emails you send to our support team.
2.2 Automatically Collected Data
- Usage data — pages visited, features used, session duration, and clickstream data.
- Device & browser data — IP address, browser type and version, operating system, and device identifiers.
- QR scan events — timestamp, rough geolocation (city-level derived from IP), and referring QR code ID when a diner scans a menu.
- Cookies & local storage — see Section 6 for full details.
2.3 Data From Third Parties
- Authentication providers — if you sign in via Google or another OAuth provider, we receive your name, email, and profile picture from that provider.
- Analytics services — aggregated behavioural data from analytics partners (only when you consent).
How We Use Your Data
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Provide & operate the service | Account data, business data | Contract performance |
| Process payments | Payment & billing data | Contract performance / Legal obligation |
| Send transactional emails | Email address | Contract performance |
| Improve platform features | Usage & device data (aggregated) | Legitimate interests |
| Personalise your dashboard | Usage history | Legitimate interests |
| Send marketing updates | Email address | Consent (opt-in only) |
| Detect fraud & abuse | IP address, usage patterns | Legitimate interests / Legal obligation |
| Comply with law | All categories as required | Legal obligation |
Security
We implement industry-standard security measures including:
- TLS 1.3 encryption for all data in transit.
- AES-256 encryption for sensitive data at rest.
- Bcrypt password hashing — we never store plaintext passwords.
- Role-based access control within our internal team.
- Regular security audits and vulnerability scanning.
Your Rights
Depending on your location, you have some or all of the following rights over your personal data:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion of your data ("right to be forgotten").
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Restriction — request that we limit how we process your data.
- Withdraw Consent — where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
To exercise any right, contact us at privacy@qrmenu.et. We will respond within 30 days.
Data Retention
| Data Type | Retention Period |
|---|---|
| Account & business data | Duration of account + 90 days after deletion request |
| Payment records | 7 years (legal / tax obligation) |
| QR scan analytics | 24 months (rolling) |
| Support communications | 3 years |
| Server logs (IP, timestamps) | 90 days |
| Cookie consent records | 3 years |
Children's Privacy
Our platform is not directed at persons under the age of 13. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us immediately and we will delete it promptly.
Policy Changes
We may update this Privacy Policy from time to time. When we make material changes, we will notify registered users by email and display a notice on the platform for at least 30 days before the change takes effect. Continued use after the effective date constitutes acceptance of the updated policy.
The "Last Updated" date at the top of this page always reflects the most recent revision.
Contact Us
For privacy-related questions, data requests, or to report a concern, reach us at:
Also see our Terms & Conditions.
← Back to Home