QR Food Menu
Home Features Pricing Demo Blog Contact Login Start Free Trial
← Back to Home

Privacy Policy

Last updated: June 21, 2026 · Effective date: April 23, 2026

Your privacy matters to us. This Privacy Policy explains how QR Food Menu handles information in connection with our digital menu platform.

1. Who We Are

QR Food Menu is a Software-as-a-Service (SaaS) digital menu platform operated by Needinfotech, with offices at E-557, Budh Nagar, Inderpuri, New Delhi — 110012, India. In this policy, "we", "us", and "our" refer to Needinfotech. For privacy-related questions, contact us at support@needinfotech.com.

2. Information We Collect

We collect the following categories of information when you use the Service:

  • Account information: Restaurant name, contact email, password (stored hashed using bcrypt), phone number, and any settings you provide during signup.
  • Menu content: Categories, items, descriptions, prices, dietary tags, and images you upload — stored on our servers so they can be served to your customers.
  • Billing information: Subscription plan, billing dates, and transaction references. Card and payment-account details are processed by PayU and are not stored on our servers.
  • Usage and device data: IP address, browser type, operating system, referring URL, page views, and timestamps. We use this for security, fraud prevention, and improving the Service.
  • Customer scans: When a diner scans your QR code, we may log anonymised page views (no personal identifiers) to provide menu analytics in your dashboard.
  • Communications: Emails or support requests you send to us.

3. How We Use Your Information

We use your information to:

  • Provide, maintain, and improve the Service
  • Authenticate accounts and prevent unauthorised access
  • Process subscription payments and send billing notifications
  • Send service-related emails (password resets, plan changes, important notices)
  • Provide customer support
  • Detect, investigate, and prevent fraud, abuse, or security incidents
  • Comply with legal obligations

We do not sell your personal information or your customers' data to third parties, and we do not use your menu data to train artificial intelligence models.

4. Legal Bases for Processing (GDPR, UK GDPR & PDPA)

If you are located in the European Economic Area, the United Kingdom, or Thailand, we rely on the following lawful bases under the EU GDPR, UK GDPR, and Thailand's Personal Data Protection Act (PDPA):

  • Contract: Processing necessary to deliver the Service you signed up for.
  • Legitimate interests: Securing the Service, preventing fraud, and improving our product.
  • Consent: Marketing communications, where you have opted in. We set strictly necessary cookies only and use no analytics or marketing cookies, so no cookie consent is required. You may withdraw any consent you have given at any time.
  • Legal obligation: Tax, accounting and compliance requirements.

5. Cookies & Similar Technologies

We use strictly necessary cookies only. These are required for the Service to function — keeping you signed in, securing forms against cross-site request forgery, and remembering basic display preferences. We do not use analytics or marketing cookies, we do not load third-party advertising or analytics trackers (such as Google Analytics, Google Tag Manager or the Meta Pixel), and we do not track you across other websites. Because no non-essential cookies are set, there are no cookie preferences to configure; the notice you see on your first visit is for transparency only.

Category Examples Purpose Typical duration
Strictly necessary QRFM_SESSID, CSRF token Login sessions, security and core functionality. Cannot be switched off. Session / up to 2 hours
Preferences googtrans, menu_lang Remembers your chosen menu language. Your cookie-notice acknowledgement is stored in your browser's local storage, not a cookie. Up to 12 months

Public restaurant menus (the pages diners reach by scanning a QR code) carry no third-party advertising or analytics tags — only our own first-party, anonymous visit counts, which set no advertising cookies. In line with India's Digital Personal Data Protection Act, 2023, we do not use your data for cross-context behavioural advertising.

6. Third-Party Service Providers

We use a small set of trusted sub-processors that may process your data on our behalf:

  • PayU — payment processing (payu.in/privacy-policy)
  • Google Fonts & Google Translate — typography and on-the-fly menu translation. Google may receive your IP address when assets are loaded.
  • QR code generator API — generates QR images on demand.
  • Web hosting / CDN provider — stores and serves the Service infrastructure.
  • Transactional email provider — delivers password resets and billing emails.

7. International Data Transfers

Our servers and some of our sub-processors are located outside India and the EEA. Where personal data is transferred internationally, we rely on appropriate safeguards such as Standard Contractual Clauses or the recipient country's adequacy decision, as applicable.

8. Data Security

We take reasonable technical and organisational measures to protect your information, including:

  • HTTPS/TLS encryption for all traffic between your browser and our servers
  • Bcrypt password hashing for account credentials
  • Rate limiting and brute-force protection on login endpoints
  • HttpOnly, Secure, SameSite session cookies
  • Regular software updates and security reviews
  • Restricted internal access on a need-to-know basis

No system is 100% secure. If we become aware of a personal-data breach affecting you, we will notify you without undue delay as required by law.

8a. Guest Orders

When a diner places an order from a restaurant's menu, we store the order itself — items, quantities, total, table number, an optional first name and an optional note — on behalf of that restaurant.

We do not ask a diner for a phone number, and we do not store one. Orders are handed off through WhatsApp from the diner's own device, so the diner's number goes directly to the restaurant's WhatsApp inbox and never reaches our systems. We hold no contact list of diners and send diners no marketing of any kind.

For the order data we do hold, the restaurant is the data controller and we act as its processor. A diner who wants an order record corrected or erased should contact the restaurant directly; you may also contact us using the details below and we will pass the request on.

Order records are automatically deleted after 180 days.

9. Data Retention

We retain your account and menu data for as long as your account is active. If you cancel your subscription, your data is retained for up to 90 days to allow reactivation, after which it is permanently deleted from active systems. Backups are rotated and overwritten in the normal course of operations. Billing records may be kept for longer where required by tax or accounting law.

10. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data ("right to be forgotten")
  • Export your data in a portable format
  • Object to or restrict certain processing
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with a supervisory authority (e.g. your local data-protection regulator)

To exercise any of these rights, email support@needinfotech.com. We will respond within 30 days.

United States (California, Virginia, Colorado, Connecticut and other states). If you are a US resident, you have the right to know what personal information we collect, to access and delete it, and to correct it. We do not sell or share personal information, and we do not use it for targeted (cross-context behavioural) advertising: we set no marketing or advertising cookies and load no advertising trackers. There is therefore no "sale" or "sharing" to opt out of. We do not discriminate against you for exercising any of these rights.

Australia. We handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988. You may request access to or correction of your personal information, and may complain to us or to the Office of the Australian Information Commissioner (OAIC). Where we disclose information to overseas recipients (Section 7), we take reasonable steps to ensure it is handled consistently with the APPs.

11. Children's Privacy

The Service is intended for restaurant operators and is not directed at children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email and reflected in the "Last updated" date at the top of this page. Your continued use of the Service after the effective date of any change indicates your acceptance of the updated policy.

13. Contact Us

For questions about this Privacy Policy or to exercise your data rights, contact:

Needinfotech — QR Food Menu
E-557, Budh Nagar, Inderpuri,
New Delhi — 110012, India
Email: support@needinfotech.com

QR Food Menu

QR FOOD MENU is a division of NEEDINFOTECH. Make a digital menu for your restaurant or bar and connect better with your customers. Your menu is now at their fingertips!

Quick Links

  • Terms & Conditions
  • Privacy Policy
  • Support

Contact Us

Needinfotech E-557, Budh Nagar,
Inderpuri, New Delhi,
Pin Code – 110012, (India)
support@needinfotech.com
© 2026 QR Food Menu. All rights reserved  |  Powered by NEED INFOTECH
Terms Privacy Cookie Preferences
We value your privacy

We use cookies to keep you signed in, run core features, and — through Google Analytics — understand how the site is used, so we can improve it. Read our Privacy Policy.