Privacy Policy

Effective date: 7 August 2026

In short: We collect no personal data from the guests who scan your menu — no IP address, no cookies, no fingerprinting. From you we collect the minimum needed to run your account. Your card details never reach us. We do not sell your data.

1. Who is responsible

HAPTONE EDUCATIONAL TECHNOLOGIES RESEARCH & DEVELOPMENT - FZCO ("QRpuz", "we") is the controller for the processing described here. Address: Dubai Digital Park, Dubai Silicon Oasis, Building A1, Dubai, United Arab Emirates. Company registration number: 81025. Contact: destek@qrpuz.com.

The company is registered in the United Arab Emirates. Because the service is offered internationally, this policy is written to cover the information required by UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (PDPL), by Turkish Law No. 6698 (KVKK) for users based in Türkiye, and by the GDPR for users based in the European Economic Area.

2. Who this policy covers

3. What we process

3.1 Account information

Name, email address, optional phone number, interface language and notification preferences.

3.2 Business information

Restaurant name, phone, address, concept and logo. The address is stored encrypted in our database.

3.3 Your menu content

Categories, products, prices, descriptions and the images you upload. Once published, this content is publicly visible — a menu exists to be seen by guests.

3.4 Payment information

We never see or store your card number, expiry date or CVV. Payment is taken on the payment provider's own secure page. We retain only the amount, currency, date and status of the payment, plus an invoice number. We do not store national ID numbers, tax numbers or billing addresses.

3.5 Use of AI features

When you generate a product description or enhance a photo, your product name/description and the relevant product image are sent to our AI provider to carry out the request (section 6). That content is also stored in your account as usage history. If you do not use the AI features, this transfer never happens.

3.6 Consent records

When you accept our policies we record the time of acceptance, the version of the text you accepted, and your IP address and browser information, so we can demonstrate that consent was given.

3.7 Support requests

The subject and message content of support requests you send us are stored. Because everything you type is retained, we recommend not sharing unnecessary personal details in a ticket.

3.8 What we collect about menu visitors

No personal data. When a guest scans your QR code we record only: which menu was viewed, which product was opened, a timestamp and the selected language. No IP address, cookie, device fingerprint, browser information or referrer is stored. This data cannot be linked to individuals and is shown to you only as aggregate counts.

One exception: to prevent abuse, IP addresses are processed transiently for rate limiting only (never stored), and all site traffic passes through the network provider listed in section 6.

4. Why we process it — purposes and legal bases

We do not sell or rent your personal data, and we do not allow third parties to use it for their own marketing.

5. Cookies and browser storage

We use a single cookie: qrpuz_refresh. It keeps you signed in, cannot be read by JavaScript (httpOnly), is only sent over an encrypted connection and is refreshed every 30 minutes.

6. Who we share data with

We use the following providers to deliver the service. Each receives only the data needed for its task:

Provider Purpose Data shared
Keycloak self-hosted Authentication and session management Email address, password (one-way hashed), name
Google (OAuth) "Sign in with Google" option Only if you choose this method: your Google account email and basic profile
Stripe International card payments Business identifier (UUID), amount, currency, product name. Your card details are entered on Stripe’s own page and never reach us.
Iyzico Turkish Lira card payments Business identifier (UUID), amount, currency. Buyer fields are filled with technical placeholders — your real name, phone or ID number is not sent. Card details are entered on Iyzico’s own page.
OpenAI Product description generation and photo enhancement Only when you use an AI feature: the product name/description and the product image you upload for enhancement
Google (Gemini) Product description generation and image processing Only when you use an AI feature: product text and/or product image
OpenRouter AI model routing layer (forwards the request to the selected model) Product text and/or product image. OpenRouter forwards the request to the provider of the selected model — these may be OpenAI, Google, Anthropic or DeepSeek.
Resend Transactional email delivery Your email address and the message content (verification link, password reset, data export file)
Cloudflare Network security, TLS termination and content delivery All site traffic passes through it: IP address, browser information and request metadata are processed by Cloudflare
MinIO self-hosted Image storage (logo, product photos) The images you upload
imgproxy self-hosted Image resizing and optimisation Images displayed on the menu
GlitchTip self-hosted Error monitoring Technical error records. Personal-data attachment is disabled (IP, cookies and headers are not sent).
Google Ads Conversion tracking on the marketing site (qrpuz.com) — only if you consent via the cookie banner Click timestamp and browser identifier. Never loads unless you consent.
Microsoft Clarity Usage analytics on the marketing site (heatmaps, session recordings) — only if you consent via the cookie banner Page interactions (clicks, scrolling), browser and device information. Never loads unless you consent.
Grafana Loki self-hosted Application logs Technical log records; includes user and business identifiers (UUIDs)

Beyond these, we may disclose information to competent public authorities where we are legally required to do so.

7. International transfers

Our servers are hosted in Türkiye; your account details, business record, menu content and images are stored there.

Some of the providers in section 6 are established abroad — in particular our AI, email and international payment providers are based in the United States, and our network security provider operates a global infrastructure. Some data is therefore transferred out of the hosting country:

For these transfers we rely on the providers' contractual data protection commitments and, where required, on your consent. If the country hosting our servers changes, we will update this policy and notify you.

8. How long we keep it

9. Your rights

Depending on where you are based, under the PDPL, KVKK (in particular Article 11) or GDPR you have the right to: learn whether your data is being processed, access it and obtain a copy, have it corrected, have it erased, object to processing, request restriction of processing, receive your data in a portable format, and withdraw consent you have given.

Two of these you can exercise directly in the dashboard, without contacting us:

For any other request or complaint: destek@qrpuz.com. We respond within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the data protection authority in your country.

10. Security

No system is entirely risk-free. If you discover a vulnerability, please report it to destek@qrpuz.com.

11. Children's data

QRpuz is a service for businesses and is not directed at people under 18. We do not knowingly collect personal data from children.

12. Changes to this policy

If we update this policy we will change the effective date and, for significant changes, notify the email address on your account. Where you need to accept a new version, you will see an acceptance screen when you sign in.

13. Contact

HAPTONE EDUCATIONAL TECHNOLOGIES RESEARCH & DEVELOPMENT - FZCO
Dubai Digital Park, Dubai Silicon Oasis, Building A1, Dubai, United Arab Emirates
destek@qrpuz.com · +971 58 543 4720

Related pages: Cancellation, Refund and Disputes · Service Availability · Contact