Privacy Policy
This Privacy Policy explains how QRIOAPP collects, uses, shares, and protects personal data when you visit the QRIOAPP marketing website, create an Account, subscribe to a Plan, or use the QRIOAPP dashboard and related management tools.
The Service is operated by Andrii Fomin, Individual Entrepreneur, registered in Ukraine ("QRIOAPP," "we," "us," or "our"). For support, contact info@qrioapp.co.
1. Scope of this Policy
This Policy applies to individuals who use QRIOAPP on behalf of a business Customer, including restaurant owners, employees, contractors, and other authorized Account users.
QRIOAPP is a SaaS platform that allows Customers to create and manage:
- digital menus accessible by URL or QR code;
- public restaurant pages;
- menu content and translations;
- AI-assisted menu translations;
- AI-assisted menu imports from images or documents;
- restaurant information, images, opening hours, and other content;
- Guest feedback features.
This Policy does not apply to individuals who only visit public restaurant pages, digital menus, or Guest feedback forms. Information about that processing is provided in the separate Guest Privacy Notice.
Where a Customer submits personal data to QRIOAPP through the Service, the Customer may act as the controller of that data and QRIOAPP may process it on the Customer's behalf. Such processing may also be governed by our Data Processing Addendum or other agreement with the Customer.
2. Information We Collect
We collect information directly from you, automatically when you use QRIOAPP, and from service providers involved in delivering the Service.
Account information
We may collect:
- your name;
- email address;
- authentication information;
- Account role and permissions;
- Account and login status.
Passwords are stored using secure authentication mechanisms and are not available to us in readable form.
Business and Customer Content
We process information that you choose to add, upload, or manage through your Account, including:
- restaurant or business name;
- address and contact information;
- descriptions and opening hours;
- logos and images;
- menu items, categories, prices, ingredients, and translations;
- uploaded images, files, and documents;
- other restaurant or business content.
Some Customer Content is intended to be published on public restaurant pages or digital menus. You are responsible for ensuring that you have the right to submit and publish Customer Content through QRIOAPP.
Subscription information
When you purchase or manage a paid Plan, we may receive information from Paddle, including:
- selected Plan;
- subscription status;
- renewal or cancellation date;
- transaction identifiers;
- limited billing and tax information.
QRIOAPP does not receive or store full payment-card details.
Usage and technical information
We may automatically collect:
- dashboard and feature activity;
- AI feature usage;
- browser and device information;
- IP address;
- approximate country or region;
- session and authentication information;
- security events;
- diagnostic information;
- performance and error logs.
Support communications
When you contact us, we process the information contained in your request, including your email address, message, attachments, and related communications.
3. How and Why We Use Information
Providing the Service
We use information to:
- create and manage Accounts;
- authenticate users;
- provide dashboard functionality;
- store and manage Customer Content;
- publish content selected by Customers;
- provide AI-assisted menu import and translation;
- manage subscriptions, Plans, and Account access;
- provide support.
Where applicable, this processing is necessary to perform our contract with you or the Customer you represent.
Security and service reliability
We use information to:
- protect Accounts and the Service;
- detect fraud, spam, abuse, and unauthorized access;
- investigate security incidents;
- diagnose technical problems;
- maintain backups and service availability;
- enforce our Terms of Service.
We generally rely on our legitimate interests in maintaining a secure and reliable SaaS platform.
Product improvement
We may use usage, diagnostic, and feedback information to understand how QRIOAPP is used and to improve its functionality, usability, and performance. We generally rely on our legitimate interests in developing and improving the Service. Where required, we obtain consent before using optional analytics technologies.
Billing and legal compliance
We use information to:
- manage subscriptions and Account entitlements;
- maintain transaction and business records;
- handle disputes, refunds, and chargebacks;
- comply with tax, accounting, court, regulatory, and other legal obligations;
- establish, exercise, or defend legal claims.
Regional pricing and configuration
We may use your IP address to estimate your country or region and display an appropriate currency, Plan price, regional offer, or checkout configuration. Country detection is approximate and may not always identify your location correctly.
Communications
We may send service-related communications, including Account and security notices, billing and subscription information, changes affecting the Service, support responses, and important legal or policy updates. These communications are necessary to operate your Account and are not promotional marketing messages.
We may send marketing communications where permitted by law. You may unsubscribe from marketing emails using the unsubscribe option provided in the message.
We do not sell personal data.
4. Payments
Paid subscriptions are sold and processed by Paddle, which acts as the Merchant of Record. Paddle processes payment details, billing information, invoices, taxes, refunds, and chargebacks under its own terms and privacy notice.
QRIOAPP receives only the subscription and transaction information reasonably necessary to activate, manage, and support your Plan. We do not receive or store full payment-card details.
5. Cookies, Analytics, and Advertising
QRIOAPP uses strictly necessary technologies to provide:
- authentication and sessions;
- Account security;
- fraud and abuse prevention;
- preference storage;
- protection against unauthorized requests.
These technologies are necessary for the Service to function.
We may also use optional analytics and advertising technologies on the QRIOAPP marketing website and Account dashboard, including Google Analytics, Google Ads, and Meta advertising technologies. These services may help us understand use of the website and dashboard, measure registrations and purchases, evaluate advertising campaigns, and improve QRIOAPP.
We do not intentionally send Account passwords, payment-card details, Guest feedback, or sensitive personal data to analytics or advertising providers.
Where consent is required:
- optional analytics and advertising technologies are not activated until consent is provided;
- rejecting optional technologies does not prevent access to core Account functionality;
- consent can be changed or withdrawn using the cookie controls available on the website.
These technologies are not used on Guest-facing public restaurant pages, menus, or feedback forms unless described in the Guest Privacy Notice.
6. AI and Document Processing
QRIOAPP uses third-party AI and document-processing services to provide menu translation and menu import features. When you use these features, relevant Customer Content may be sent to our AI providers, including menu text, images, uploaded documents, and menu structure and related data.
Our current AI and document-processing providers may include OpenAI and Microsoft Azure AI services.
Where available under the relevant business service and configuration, we use provider settings or terms under which Customer Content is not used to train general-purpose AI models. Providers may retain or process limited information as described in their applicable business terms, including for security, abuse prevention, service operation, and legal compliance.
Do not submit personal data, confidential information, sensitive information, or third-party material to AI-assisted features unless you are authorized to submit it, its processing is reasonably necessary, and its submission complies with applicable law and your obligations to other persons.
AI-generated or extracted results may be incomplete or inaccurate. Customers should review results before publishing or relying on them.
7. How We Share Information
We may share personal data with service providers that help us operate QRIOAPP, including providers of:
- cloud hosting and infrastructure;
- databases, file storage, and backups;
- authentication;
- transactional email;
- payments and subscription management;
- AI and document processing;
- analytics and advertising;
- monitoring and error logging;
- security and abuse prevention;
- customer support;
- approximate IP-based country detection.
Depending on the service, these providers may process personal data on our behalf or independently under their own privacy notices.
We may also disclose information:
- when required by law, regulation, court order, or lawful government request;
- to investigate fraud, abuse, or security incidents;
- to protect the rights, property, or safety of QRIOAPP, our Customers, or others;
- in connection with a merger, acquisition, financing, reorganization, or sale of all or part of the business;
- with your direction or consent.
We may change providers as QRIOAPP evolves. We will update this Policy if a change materially affects how personal data is processed.
8. Legal Bases
Where the GDPR, UK GDPR, or a similar data-protection law applies, we rely on one or more of the following legal bases.
Contract
Processing necessary to create and manage your Account, provide the Service, manage your Plan, publish Customer-selected content, and provide support.
Legitimate interests
Processing necessary for our legitimate interests in securing QRIOAPP, preventing fraud and abuse, diagnosing technical problems, maintaining and improving the Service, understanding product usage, managing our relationship with Customers, and establishing or defending legal claims. We consider the effects of such processing on your rights and interests before relying on legitimate interests.
Legal obligations
Processing necessary to comply with applicable tax, accounting, regulatory, court, fraud-prevention, and other legal requirements.
Consent
Processing based on your consent, including certain uses of analytics cookies, advertising technologies, optional marketing communications, and other optional features where consent is legally required. You may withdraw consent at any time. Withdrawal does not affect processing that occurred before consent was withdrawn.
9. International Processing
QRIOAPP is operated from Ukraine and uses service providers that may process personal data in the European Economic Area, the United Kingdom, the United States, Ukraine, and other countries. These countries may have data-protection laws different from those in your country.
Where required by applicable law, we rely on legally recognized safeguards for international data transfers, such as adequacy decisions, Standard Contractual Clauses, or another legally permitted transfer mechanism. You may contact us for additional information about the safeguards relevant to your personal data.
10. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy. Unless a longer period is required or justified:
- Account data and Customer Content are retained while the Account is active and ordinarily for up to 90 days after Account closure;
- support communications are retained for as long as necessary to respond to the request, maintain reasonable support records, and resolve disputes;
- technical, diagnostic, and security logs are retained for the period reasonably necessary for security, troubleshooting, and service operation;
- analytics and advertising data are retained according to our configured settings and the applicable provider's policies;
- transaction, tax, accounting, fraud-prevention, and legal records may be retained for the period required by applicable law or necessary to resolve disputes and establish legal claims.
Some information may remain temporarily in backups after deletion until the relevant backups are overwritten through our normal backup cycle. We may retain anonymized information that no longer identifies an individual.
11. Your Rights
Depending on your location and applicable law, you may have the right to:
- access your personal data;
- correct inaccurate or incomplete personal data;
- request deletion of your personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- object to direct marketing;
- receive certain personal data in a structured, commonly used, machine-readable format;
- withdraw consent where processing is based on consent;
- lodge a complaint with a competent data-protection authority.
These rights may be subject to legal conditions and exceptions. To exercise your rights, contact info@qrioapp.co.
We may request reasonable information to verify your identity and protect your Account before acting on a request. Where QRIOAPP processes personal data solely on behalf of a Customer, we may direct your request to that Customer or assist the Customer in responding.
12. Required and Optional Information
Certain information, such as an email address and authentication information, is required to create and use an Account. Business information and Customer Content are generally optional; however, some QRIOAPP features may not function correctly unless the necessary information is provided. Failure to provide payment or billing information to Paddle may prevent you from purchasing or renewing a paid Plan.
13. Security
We use reasonable technical and organizational measures designed to protect personal data, including access controls, encryption in transit, monitoring, security logging, and measures appropriate to the nature of the Service. However, no online service, transmission method, or storage system can guarantee absolute security.
You are responsible for protecting your Account credentials and for notifying us promptly if you believe your Account has been compromised.
14. Children
QRIOAPP is a business service and is not directed to children. We do not knowingly collect personal data directly from children. If we learn that personal data has been collected from a child contrary to applicable law, we will take reasonable steps to delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time. If a change materially affects how we process personal data, we will provide appropriate notice through QRIOAPP, by email, or by another reasonable method where required by law. The current version and its effective date will be available on qrioapp.co.
16. Contact
For privacy questions, requests, or complaints, contact:
Operator: Andrii Fomin, Individual Entrepreneur
Country of registration: Ukraine
Email: info@qrioapp.co