Legal
Privacy Policy
How TablesQR collects, uses, and protects information for restaurant accounts and guest diners.
Last updated: 10 July 2026
1. Who we are
TablesQR ("we", "us") provides digital menu and table-ordering software for restaurants. We are based in Bangalore, India. For privacy requests, contact support@tablesqr.com.
This policy covers (a) restaurant owners and team members who use the dashboard, and (b) guests who open a public menu or place an order via QR or link. It should be read with our Terms of Service and Cookie Policy.
2. Information we collect
Account and restaurant users
- Identity and contact data: name, email address, phone number.
- Authentication data: passwords (stored by our auth provider), email verification codes (hashed or handled by providers), session cookies.
- Restaurant data: restaurant name, slug, city, settings, branding images, menu categories and items, prices, dietary tags, table labels, team memberships and roles.
- Operational data: orders, order items, table sessions, kitchen status updates, coupons and usage, analytics aggregates where your plan includes them.
- Billing data: plan, trial status, subscription identifiers, invoices/metadata from Razorpay. We do not store full card numbers on TablesQR servers.
- Support data: messages you send via contact or in-app support, including optional page URL context.
Guests
- Information needed to run a table session and order (for example table identifier, session token, order contents, optional guest name or phone, coupon codes).
- Technical data such as IP address and basic device/browser signals used for security and rate limiting.
Automatically collected
- Log and diagnostic data when you use the website or APIs.
- Cookies and similar technologies described in our Cookie Policy.
3. How we use information
- Provide, secure, and improve TablesQR (menus, QR links, ordering, KDS, billing, team access).
- Verify accounts, prevent abuse, and enforce plan limits.
- Process subscriptions, trials, coupons, and payment events via Razorpay.
- Send service messages (security, billing, product notices). Marketing messages, if any, are optional and can be declined where required.
- Respond to support requests and legal obligations.
4. Legal bases (where GDPR or similar laws apply)
If you are in the EEA/UK or another region that requires a “legal basis,” we typically rely on: performance of a contract (providing the service you signed up for); legitimate interests (securing the platform, improving features, preventing fraud) balanced against your rights; consent where we ask for it (for example certain cookies or optional fields); and legal obligation where we must retain or disclose information.
For users in India, we process personal data for the purposes described above in line with the Digital Personal Data Protection Act, 2023 (DPDP) and applicable rules, including providing the service you request and complying with law.
6. International transfers
Our primary operations are in India. Providers may process data in other countries. Where required, we use appropriate safeguards offered by those providers (such as standard contractual clauses or equivalent mechanisms).
7. Retention
We keep account and restaurant data while your account is active and for a reasonable period afterward for backups, disputes, billing records, and legal compliance. Order and session data is retained as needed for restaurant operations and analytics on eligible plans. You may request deletion of your account; some records (for example payment history) may be kept where the law requires.
8. Security
We use technical and organisational measures appropriate to a SaaS product of this type (including encrypted transport, access controls, signed guest URLs in production, and database access policies). No method of transmission or storage is 100% secure.
9. Your rights (DPDP, GDPR, and similar)
Depending on where you live, you may have rights to:
- Access personal data we hold about you.
- Correct inaccurate data.
- Request deletion or erasure (subject to legal exceptions).
- Withdraw consent where processing is consent-based.
- Object to or restrict certain processing.
- Data portability for data you provided, where applicable.
- Lodge a complaint with a supervisory authority (for example an EU/UK data protection authority, or India’s Data Protection Board when applicable).
Restaurant users can update many details in Account Settings and the restaurant dashboard. For other requests, email support@tablesqr.com. We may need to verify your identity before acting. Guests should also contact the restaurant for order-specific questions; we can assist with platform-held session data where feasible.
10. Children
TablesQR is aimed at businesses and adult diners. We do not knowingly collect personal data from children under 18 for account registration. If you believe a child has provided data, contact us and we will take appropriate steps.
12. Changes
We may update this policy periodically. The “Last updated” date at the top will change when we do. Material changes may also be communicated in the product or by email.
Questions? Email support@tablesqr.com or visit our contact page.