In short: We collect no personal data from the guests who scan your menu — no IP address, no cookies, no fingerprinting. From you we collect the minimum needed to run your account. Your card details never reach us. We do not sell your data.
1. Who is responsible
HAPTONE EDUCATIONAL TECHNOLOGIES RESEARCH & DEVELOPMENT - FZCO ("QRpuz", "we") is the controller for the processing described here. Address: Dubai Digital Park, Dubai Silicon Oasis, Building A1, Dubai, United Arab Emirates. Company registration number: 81025. Contact: destek@qrpuz.com.
The company is registered in the United Arab Emirates. Because the service is offered internationally, this policy is written to cover the information required by UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (PDPL), by Turkish Law No. 6698 (KVKK) for users based in Türkiye, and by the GDPR for users based in the European Economic Area.
2. Who this policy covers
- Business users — restaurant owners and staff with a QRpuz account.
- Menu visitors — guests who scan the QR code to view a menu. See section 3.8; we do not process personal data about this group.
3. What we process
3.1 Account information
Name, email address, optional phone number, interface language and notification preferences.
3.2 Business information
Restaurant name, phone, address, concept and logo. The address is stored encrypted in our database.
3.3 Your menu content
Categories, products, prices, descriptions and the images you upload. Once published, this content is publicly visible — a menu exists to be seen by guests.
3.4 Payment information
We never see or store your card number, expiry date or CVV. Payment is taken on the payment provider's own secure page. We retain only the amount, currency, date and status of the payment, plus an invoice number. We do not store national ID numbers, tax numbers or billing addresses.
3.5 Use of AI features
When you generate a product description or enhance a photo, your product name/description and the relevant product image are sent to our AI provider to carry out the request (section 6). That content is also stored in your account as usage history. If you do not use the AI features, this transfer never happens.
3.6 Consent records
When you accept our policies we record the time of acceptance, the version of the text you accepted, and your IP address and browser information, so we can demonstrate that consent was given.
3.7 Support requests
The subject and message content of support requests you send us are stored. Because everything you type is retained, we recommend not sharing unnecessary personal details in a ticket.
3.8 What we collect about menu visitors
No personal data. When a guest scans your QR code we record only: which menu was viewed, which product was opened, a timestamp and the selected language. No IP address, cookie, device fingerprint, browser information or referrer is stored. This data cannot be linked to individuals and is shown to you only as aggregate counts.
One exception: to prevent abuse, IP addresses are processed transiently for rate limiting only (never stored), and all site traffic passes through the network provider listed in section 6.
4. Why we process it — purposes and legal bases
- Performance of a contract: creating your account, publishing your menu, managing your subscription, billing.
- Legitimate interests: service security, fraud and abuse prevention, debugging, product improvement.
- Consent: using the AI features, opting in to marketing messages. You can withdraw consent at any time.
- Legal obligation: retention of financial records and consent evidence.
We do not sell or rent your personal data, and we do not allow third parties to use it for their own marketing.
5. Cookies and browser storage
We use a single cookie: qrpuz_refresh. It keeps you
signed in, cannot be read by JavaScript (httpOnly), is only sent over an encrypted
connection and is refreshed every 30 minutes.
- On the product side (the app.qrpuz.com dashboard and digital menus) we use no advertising, tracking or analytics cookies. There is no Google Analytics, Meta Pixel or comparable third-party tracker on the dashboard or menu pages.
- Menu pages set no cookies at all. The guest's browser only holds a technical flag that prevents the same scan being counted twice in one visit; it is discarded when the tab closes.
- In the dashboard your browser also stores your language choice and interface preferences such as "don't show this notice again". These are not sent to us.
- On this marketing site (qrpuz.com), if you click "Accept" on the cookie banner at the bottom of the page, Google Ads conversion tracking and Microsoft Clarity (usage analytics and heatmaps) start running; if you click "Reject" or leave the banner untouched, these tools never load. Your choice is stored in this browser and can be changed at any time by clearing your browser storage.
6. Who we share data with
We use the following providers to deliver the service. Each receives only the data needed for its task:
| Provider | Purpose | Data shared |
|---|---|---|
| Keycloak self-hosted | Authentication and session management | Email address, password (one-way hashed), name |
| Google (OAuth) | "Sign in with Google" option | Only if you choose this method: your Google account email and basic profile |
| Stripe | International card payments | Business identifier (UUID), amount, currency, product name. Your card details are entered on Stripe’s own page and never reach us. |
| Iyzico | Turkish Lira card payments | Business identifier (UUID), amount, currency. Buyer fields are filled with technical placeholders — your real name, phone or ID number is not sent. Card details are entered on Iyzico’s own page. |
| OpenAI | Product description generation and photo enhancement | Only when you use an AI feature: the product name/description and the product image you upload for enhancement |
| Google (Gemini) | Product description generation and image processing | Only when you use an AI feature: product text and/or product image |
| OpenRouter | AI model routing layer (forwards the request to the selected model) | Product text and/or product image. OpenRouter forwards the request to the provider of the selected model — these may be OpenAI, Google, Anthropic or DeepSeek. |
| Resend | Transactional email delivery | Your email address and the message content (verification link, password reset, data export file) |
| Cloudflare | Network security, TLS termination and content delivery | All site traffic passes through it: IP address, browser information and request metadata are processed by Cloudflare |
| MinIO self-hosted | Image storage (logo, product photos) | The images you upload |
| imgproxy self-hosted | Image resizing and optimisation | Images displayed on the menu |
| GlitchTip self-hosted | Error monitoring | Technical error records. Personal-data attachment is disabled (IP, cookies and headers are not sent). |
| Google Ads | Conversion tracking on the marketing site (qrpuz.com) — only if you consent via the cookie banner | Click timestamp and browser identifier. Never loads unless you consent. |
| Microsoft Clarity | Usage analytics on the marketing site (heatmaps, session recordings) — only if you consent via the cookie banner | Page interactions (clicks, scrolling), browser and device information. Never loads unless you consent. |
| Grafana Loki self-hosted | Application logs | Technical log records; includes user and business identifiers (UUIDs) |
Beyond these, we may disclose information to competent public authorities where we are legally required to do so.
7. International transfers
Our servers are hosted in Türkiye; your account details, business record, menu content and images are stored there.
Some of the providers in section 6 are established abroad — in particular our AI, email and international payment providers are based in the United States, and our network security provider operates a global infrastructure. Some data is therefore transferred out of the hosting country:
- When you use the AI features — your product text and product image. If you do not use them, this transfer never happens.
- When we email you — your email address and the message content.
- When you pay by international card — payment metadata (not your card details).
- Every time you visit the site — connection metadata, because traffic passes through our network security provider.
For these transfers we rely on the providers' contractual data protection commitments and, where required, on your consent. If the country hosting our servers changes, we will update this policy and notify you.
8. How long we keep it
- Account and menu data: for as long as your account is open.
- Raw menu view records: 90 days, then deleted automatically. Only aggregate counts that cannot be linked to a person remain.
- Application logs: 30 days.
- Invoice and payment records: for the period required by financial regulations — even if your account is deleted.
- Consent records: retained as evidence of consent; the IP address and browser information they contain are cleared when your account is deleted.
- Change-history records: retained for security and legal audit purposes.
9. Your rights
Depending on where you are based, under the PDPL, KVKK (in particular Article 11) or GDPR you have the right to: learn whether your data is being processed, access it and obtain a copy, have it corrected, have it erased, object to processing, request restriction of processing, receive your data in a portable format, and withdraw consent you have given.
Two of these you can exercise directly in the dashboard, without contacting us:
- Download your data — Account → Privacy & Security. Your profile, consent records, business details, menus and products are emailed to you.
- Delete your account — Account → Privacy & Security. A 30-day waiting period starts, during which you can change your mind. When it ends, your name, email and phone number are anonymised, your business record is closed and your identity account is deleted. Financial records and legal audit records are retained as described above.
For any other request or complaint: destek@qrpuz.com. We respond within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the data protection authority in your country.
10. Security
- All connections are encrypted (TLS); passwords are one-way hashed.
- Business address data is additionally encrypted in the database.
- Each business's data is isolated from every other; this isolation is enforced at code level by automated tests.
- We record who changed what and when; sensitive operations are auditable.
- Notifications from payment providers are signature-verified.
- API keys are held only in environment variables and are never stored in the database.
- Personal-data collection is disabled in our error monitoring tool, and image content is never written to logs.
No system is entirely risk-free. If you discover a vulnerability, please report it to destek@qrpuz.com.
11. Children's data
QRpuz is a service for businesses and is not directed at people under 18. We do not knowingly collect personal data from children.
12. Changes to this policy
If we update this policy we will change the effective date and, for significant changes, notify the email address on your account. Where you need to accept a new version, you will see an acceptance screen when you sign in.
13. Contact
HAPTONE EDUCATIONAL TECHNOLOGIES RESEARCH & DEVELOPMENT - FZCO
Dubai Digital Park, Dubai Silicon Oasis, Building A1, Dubai, United Arab Emirates
destek@qrpuz.com ·
+971 58 543 4720
Related pages: Cancellation, Refund and Disputes · Service Availability · Contact