Privacy Policy
This Privacy Policy explains how QRMENUS, the operator of the website qrmenus.ge ("QRMENUS", "we", "us"), collects, uses, stores and protects personal data in connection with the Service. We process personal data in accordance with the Law of Georgia on Personal Data Protection and, where applicable, the EU General Data Protection Regulation (GDPR). Capitalised terms not defined here have the meaning given in our Terms of Service.
1. Our Role
- Controller. We act as the data controller for personal data of Customers and their authorised users (account holders), for data submitted through our contact form and for data relating to visitors of the Website.
- Processor. When a Guest views a Customer's menu, we process the related usage data on behalf of that Customer in order to provide statistics. In this case the Customer is the controller and we act as its processor.
2. Personal Data We Process
2.1. Account holders
- Account data: email address and password. Passwords are stored only in hashed form by our authentication provider; we never see them in plain text.
- Business data: business name, address, phone number, opening hours, links to social networks and maps, logo and cover images, and menu content. This information is mostly business information, but it may include personal data where, for example, an individual entrepreneur uses their own name or phone number.
- Subscription data: plan, trial and subscription dates, payment status and payment records. We do not receive or store full payment card details; where payments are made by card, they are processed by a licensed payment provider.
- Technical and security data: login times, IP address and browser information processed in server and authentication logs.
2.2. Guests (menu visitors)
Guests do not need an account and we do not ask for their name, email or phone number. To produce honest statistics, we process:
- a random device identifier generated and stored in the Guest's browser, which is not linked to the Guest's identity;
- usage events: menu opened, QR code scanned, dish viewed, dish marked as a favourite, with the time, the business, the dish and the selected language;
- technical data, such as IP address and browser type, processed by our hosting providers for delivery and security purposes.
2.3. Contact form and correspondence
Name, email address, subject, priority and the content of your message, and any data contained in emails you send us.
2.4. AI menu import
Files you upload for AI import (PDF, photo, Word or CSV) and the menu data extracted from them. Please do not upload files containing personal data other than menu content.
3. Purposes and Legal Bases
- Providing the Service (account, dashboard, public menu, QR codes, AI import, statistics): performance of the contract with the Customer.
- Subscription management, reminders before expiry and service notices: performance of the contract.
- Responding to enquiries and support: our legitimate interest in answering requests, or steps taken at your request before entering into a contract.
- Security, fraud prevention, troubleshooting and improving the Service, including aggregated analysis: our legitimate interests, which we balance against your rights.
- Accounting and tax records: compliance with our legal obligations.
- Marketing communications: only with your consent, which you may withdraw at any time.
We do not sell personal data, do not use it for third-party advertising and do not carry out automated decision-making that produces legal or similarly significant effects.
4. Cookies and Browser Storage
We do not use advertising cookies or third-party analytics trackers. The Service uses the browser's local storage only for functions necessary for its operation, namely:
- keeping you signed in (authentication session);
- remembering your interface language and light or dark theme;
- the random device identifier described in Section 2.2, used to count unique visits and favourites;
- remembering interface settings, such as hidden notices.
Our hosting and security provider may set strictly necessary cookies to protect the Website against attacks. Fonts are loaded from Google Fonts, which involves the transfer of your IP address to Google. You can delete stored data at any time in your browser settings; this may sign you out and reset your preferences.
5. Recipients and Processors
We share personal data only with service providers that help us operate the Service and that are bound by contractual confidentiality and data protection obligations:
- Supabase: database, authentication and file storage. Data is hosted in the European Union (Frankfurt, Germany).
- Cloudflare: hosting, content delivery network and protection against attacks.
- Anthropic: artificial intelligence processing of files uploaded for AI menu import.
- FormSubmit: delivery of messages sent through the contact form to our email.
- Google: email (Gmail) used for correspondence and service notices, and Google Fonts.
- Payment providers: when online payment is enabled, the licensed bank or payment institution processing the payment.
We may also disclose personal data where required by law, at the lawful request of public authorities, or to establish, exercise or defend legal claims.
6. International Transfers
Some of our providers process data outside Georgia, including in the European Union and the United States. Where data is transferred to a country that is not recognised as ensuring an adequate level of protection, we rely on appropriate safeguards provided by law, such as standard contractual clauses offered by the provider, and on the additional security measures of those providers.
7. Retention
- Account and menu data: for as long as the Account exists. After a deletion request, we delete it within 30 days, except data we must keep by law. Copies in backups are overwritten within a further 30 days.
- Guest usage events: for up to 26 months, after which they are deleted automatically.
- AI import technical records (file name, status, extracted result): for up to 12 months. The uploaded file is used only for extraction.
- Contact form messages and correspondence: for up to 24 months after the last communication.
- Payment and accounting records: for the period required by the tax and accounting legislation of Georgia.
- Security logs: for the limited period set by our providers, generally not exceeding 90 days.
8. Security
We apply appropriate technical and organisational measures to protect personal data, including encrypted connections (HTTPS/TLS), hashed passwords, database-level access rules that isolate each business's data from other businesses, restricted administrative access and the use of reputable infrastructure providers. No method of transmission or storage is completely secure; if a personal data breach occurs that is likely to affect your rights, we will notify you and the competent authority as required by law.
9. Your Rights
Subject to the conditions set by law, you have the right to:
- obtain information on whether and how your personal data is processed, and access a copy of it;
- request the correction, updating or completion of inaccurate or incomplete data;
- request the deletion or destruction of your data, or the restriction (blocking) of its processing;
- receive your data in a structured, machine-readable format and have it transmitted to another controller (data portability), where applicable;
- object to processing based on our legitimate interests and to direct marketing;
- withdraw consent at any time, without affecting the lawfulness of processing before withdrawal;
- lodge a complaint with the Personal Data Protection Service of Georgia, or, if you are in the European Union, with your local supervisory authority.
To exercise your rights, email us at [email protected]. To protect your data, we may ask you to confirm your identity, for example by writing from the email address of your Account. We will respond within the time limits set by law, generally within ten working days.
Guests who wish to exercise rights regarding data collected while viewing a menu may contact the relevant business or us; we will assist the business in responding.
10. Children
The Account features of the Service are intended for persons aged 18 and over. Public menus can be viewed by anyone, but we do not knowingly collect identifying personal data from children.
11. Changes to this Policy
We may update this Privacy Policy from time to time. The current version is always available on this page with its effective date. We will notify account holders of material changes by email or through the dashboard before they take effect.
12. Contact
For any questions about this Privacy Policy or the processing of your personal data, contact us at [email protected] or through the contact form.