1. Roles
- Restaurant account data (name and e-mail of restaurant users, restaurant details, sign-in records): processed by Utku Berberoğlu ("we") as controller, to provide and secure the Platform, and shared with the partner that serves the restaurant.
- Data the restaurant processes (guest orders, delivery names, phone numbers and addresses, staff accounts, caller numbers): the restaurant is the controller; we process it only on the restaurant's behalf to run the Platform.
2. What the Platform processes
- Account data: name, e-mail, hashed password, role, language, acceptance of terms.
- Order data: items, quantities, prices, table or room, notes, order status and times.
- Delivery and phone orders: customer name, phone number, address and location if entered; for caller ID, the incoming phone number.
- Courier location while a delivery is active, shared with the restaurant and the customer.
- Technical data: IP address and device data in server logs for security and troubleshooting.
Guests viewing a QR menu do not need an account. The QR menu does not set tracking cookies.
3. Purposes and legal bases
Providing the service the restaurant subscribed to (contract), security and abuse prevention (legitimate interest) and legal obligations such as tax record keeping where they apply (GDPR Art. 6(1)(b), (c), (f); KVKK Art. 5(2)).
4. Recipients
Authorised users of the same restaurant; the partner serving the restaurant for support; couriers and customers for active deliveries; and our service providers - hosting (servers in the European Union), e-mail delivery, push notifications for the mobile apps, map tiles and AI-assisted menu translation (menu text only, no personal data). We do not sell personal data.
5. Retention
Data is kept while the restaurant account is active and then deleted or anonymised, except records that must be kept for legal reasons (for example order totals for tax purposes) for the period the law requires. Server logs are kept for a short period.
6. Your rights
Guests and customers should contact the restaurant first, as it controls their data. Restaurant users can contact their partner or us through the qrdip contact form to exercise rights of access, correction, deletion, restriction, portability and objection (GDPR Art. 15-21; KVKK Art. 11), and may complain to their data protection authority.
7. Security and changes
Traffic is encrypted (HTTPS), passwords are hashed, access is role-based and each restaurant's data is isolated from other restaurants. No system is completely secure. We may update this notice; the current version is published on this page.