This Privacy Policy explains what information QR398 collects, why, and how it is stored and protected. It applies to restaurant owners who create an account, and to customers who view a menu through QR398.
When a business creates a QR398 account, we store the information needed to operate the Service on their behalf:
| Data | Why We Collect It |
|---|---|
| Business name, phone number, address, cuisine type, tagline | Displayed on your public menu page and used to identify your account. |
| Email address | Used as your login identifier and for account-related communication, such as trial expiry reminders. |
| Logo, cover banner, and dish images | Displayed on your branded menu page, stored either on our server or via Cloudinary if configured. |
| Brand colors and font preferences | Used purely to render your menu page in your chosen visual style. |
| Subscription and payment status (trial dates, paid-until date, submitted UPI transaction reference) | Used to determine access to the Service and to verify payments. We do not collect or store your card number, bank account number, or UPI PIN — only the transaction reference you choose to submit. |
Your password is never stored in readable form. It is processed through a one-way cryptographic hashing function (PBKDF2-HMAC-SHA256 with a unique random salt per account) before being saved — meaning even QR398 itself cannot look up or recover your actual password. We can only verify a login attempt against the stored hash, not reveal the original password.
We also keep a security log of login attempts (successful and failed), password reset requests, and key account actions (such as account deletion), for the purpose of detecting and preventing abuse. This log records the IP address, the action taken, and a timestamp — it does not record your password or its hash.
Menu data — your categories, dishes, descriptions (in English, Telugu, and/or Hindi), prices, and dietary tags (vegetarian/non-vegetarian, bestseller, spicy, available/unavailable) — is stored so it can be displayed to customers who scan your QR code or visit your menu link. This data is visible publicly to anyone who has your menu link or QR code, by design, since the purpose of the Service is to display your menu to customers.
On the Pro plan, additional data is collected specifically to operate table-wise ordering and kitchen/waiter workflows:
Each time your public menu page is loaded, we record a single anonymous tally: one count, against your restaurant, for that calendar day. This powers the "Views Today / Last 7 Days / Last 30 Days" chart on your dashboard.
QR398 uses a single session cookie to keep a restaurant owner (or admin) logged in after entering their password. This cookie:
Repeated failed login attempts on an account trigger a temporary lockout that lengthens the more it keeps happening — this protects against automated password-guessing while avoiding unnecessarily long lockouts for a single mistyped password on a shared restaurant device.
Customers viewing a public menu page are not issued any login or tracking cookie — there is no account to log into on that side of the Service, so no session cookie is created for them.
We do not use third-party advertising cookies, and we do not sell or share visitor data with advertisers.
QR398 may use the following third-party services as part of operating the platform:
These providers may process data strictly as needed to provide their respective service to us; we do not permit them to use your data for their own independent purposes.
We retain your account data for as long as your account remains active. If you choose to delete your account from your dashboard settings, your restaurant profile, menu, categories, dishes, uploaded images (stored locally), analytics history, payment records, and — for Pro-plan restaurants — tables, orders, order items, staff accounts, and audit logs are all permanently and immediately deleted, and this action cannot be undone. Note that images stored via the optional Cloudinary integration, if used, are not automatically removed as part of this process.
We apply a range of technical safeguards to protect the data described above, including encrypted password storage, parameterized database queries to prevent injection attacks, rate limiting on sensitive actions, CSRF protection on all account-changing actions, and secure session cookies. No system can guarantee absolute security, but we take these protections seriously and apply them consistently across the platform.
As a restaurant account holder, you may access and update most of your information directly from your dashboard settings at any time. You may request a copy of your account data, or request that we delete it on your behalf, by contacting us using the details below — or by using the account deletion option in your dashboard.
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
If you have questions about this Privacy Policy or how your data is handled, please contact us at [email protected].