Privacy Policy
1 Introduction & Overview
Welcome to Qrvo ("we", "our", or "us"), operated under the laws of Pakistan. Qrvo is a modern SaaS platform that enables restaurant owners, staff, and diners to interact seamlessly through contactless QR-code menus, real-time table ordering, kitchen display systems, and automated billing.
This Privacy Policy describes how Qrvo collects, uses, processes, stores, and protects personal and transactional information when you visit our website at https://qrvo.online, use our dashboard, scan QR codes at partner restaurants, or subscribe to our services.
By accessing or using Qrvo, you acknowledge that you have read, understood, and agree to the data collection and processing practices described in this policy.
2 Information We Collect
We collect only the minimum information necessary to deliver, secure, and improve our restaurant management and digital ordering services. The data collected depends on how you interact with Qrvo:
๐ Restaurant Owners & Staff
- โข Google Account Details: Name, verified email address, and Google user ID obtained securely through Google OAuth 2.0.
- โข Business Information: Restaurant name, branch details, seating/table layouts, currency, menu items, and staff role allocations.
- โข Subscription Records: Plan status (Trial, Pro, Expired), Safepay transaction tracker IDs, and billing period timestamps.
๐ฝ๏ธ Diners & Restaurant Guests
- โข No Account Needed: Diners scan table QR codes directly from their mobile browser without creating a personal account or downloading an app.
- โข Session & Order Data: Table number, selected menu items, customization modifiers, order status, and optional group member display names.
- โข Feedback & Ratings: Rating scores and comments submitted after meals.
๐ Technical & Anti-Abuse Verification Data
To protect restaurant partners from fake or unauthorized orders, our systems collect transient device identifiers, client IP addresses (used for optional in-restaurant Wi-Fi subnet verification), browser user-agent strings, and request timestamps.
3 Payment Processing via Safepay
Qrvo utilizes Safepay (Safepay Payments (Pvt) Ltd) as our authorized third-party payment gateway provider for processing subscription fees.
๐ณ State Bank of Pakistan (SBP) Compliance & PCI-DSS
Safepay is a fully licensed Payment System Operator (PSO) and Payment Service Provider (PSP) regulated by the State Bank of Pakistan. All payment processing, 3-D Secure card authentications (Visa, Mastercard, PayPak, UnionPay), and mobile wallet transactions (Easypaisa, JazzCash, Raast) are conducted directly within Safepay's secure, PCI-DSS Level 1 certified environment.
What Qrvo Never Stores:
- We never collect, handle, or store complete credit/debit card numbers.
- We never collect or store CVV/CVC security codes or card PINs.
- We never store mobile wallet PINs or OTPs.
Qrvo only receives cryptographic transaction tracker tokens, payment status confirmations (e.g., PAID), and reference numbers via secure HMAC-SHA256 verified webhooks to activate your restaurant's Pro subscription.
4 How We Use Your Information
We use the data we collect solely for lawful, legitimate business purposes, including:
- โก Service Fulfillment Routing orders in real-time from customer tables to restaurant kitchen displays and cashier terminals.
- ๐ Anti-Abuse & Order Verification Verifying diner presence via table session tokens, waiter approvals, and optional Wi-Fi subnet checks.
- ๐ Business Analytics Providing restaurant owners with operational insights such as popular dishes, peak hours, and order volume.
- ๐ฉ Account Communications Notifying owners about subscription renewal dates, trial status, system updates, and customer support inquiries.
5 Data Sharing & Disclosure
Qrvo does not sell, rent, or trade your personal or business data to advertising networks or third-party brokers under any circumstances.
We share information only with trusted service partners strictly necessary to run the platform:
6 Data Isolation & Security Measures
We employ robust technical and organizational security controls to protect your data:
-
Multi-Tenant Scoping:
All database queries are strictly scoped by
restaurant_idto ensure one restaurant cannot access another restaurant's orders, revenue data, or customer records. - Encryption in Transit: All data transmitted between your browser, restaurant terminals, and Qrvo servers is protected using TLS 1.3 encryption (HTTPS/WSS).
- Role-Based Access Control (RBAC): Restaurant accounts differentiate between Owner, Cashier, Floor Staff, and Kitchen roles to restrict administrative operations.
- Ephemeral Customer Sessions: Diner sessions at tables automatically expire when bills are settled or sessions are terminated.
7 Cookies & Device Storage
Qrvo uses strictly essential cookies and local storage tokens necessary for the operation of the service:
- Session Cookies: Maintain authenticated staff/owner sessions and secure CSRF protection.
- Table Tokens: Maintain the diner's active cart and ordering session while connected to a specific restaurant table.
- Theme Preferences: Store your preference for dark or light mode.
We do not use invasive cross-site tracking cookies or third-party behavioral advertising cookies.
8 Your Rights & Data Retention
Restaurant owners and staff members may review, update, or request deletion of their account records at any time.
- Access & Correction: You can modify your menu, restaurant details, and staff assignments directly from the Qrvo Dashboard.
- Account Deletion: You may request full account and restaurant data deletion by contacting support.
- Data Retention: Order history and sales receipts are retained for your restaurant's accounting and reporting needs until you close your account or request data purging.
9 Updates to This Privacy Policy
We may periodically update this Privacy Policy to reflect enhancements in our platform, new features, or evolving regulatory requirements. Whenever significant changes occur, we will update the "Effective Date" at the top of this page and post a prominent notice on our website or dashboard.
10 Contact & Privacy Inquiries
If you have questions, feedback, or privacy-related requests regarding this Privacy Policy or how Qrvo handles your data, please contact our team: