Privacy Policy
Last updated: 8/13/2026
1. What We Collect
From Restaurant Accounts: name, email, password (hashed, never stored in plain text), business details, branding assets, and billing information (processed by Stripe; we do not store full card numbers).
From Customers who scan a restaurant's QR code: full name, phone number, email address, and delivery order details, submitted voluntarily to claim a reward. We verify email addresses via a one-time code sent at the time of claim.
2. How We Use It
Customer data submitted through a restaurant's page is used to: operate that restaurant's loyalty program (issue and track rewards, prevent duplicate claims), and, where a Customer opts in, allow that restaurant to send them promotional communications. We do not sell Customer or Restaurant Account data to third parties.
3. Who Can See What
A Restaurant Account can see the data of Customers who participated through their own page only — our platform enforces strict separation between restaurants, and one restaurant cannot access another's customer data. Platform administrators may access data as needed for support, security, or to operate the service.
4. Data Storage and Security
Data is stored with Supabase (PostgreSQL) and processed through Vercel's hosting infrastructure. Passwords are hashed with bcrypt. Admin sessions use signed, HTTP-only cookies. We take reasonable technical measures to protect data but cannot guarantee absolute security.
5. Email Communications
We use Resend to send transactional emails (welcome emails, password resets, verification codes). Restaurant Accounts may send promotional emails to Customers who have explicitly opted in through the claim form.
6. Payment Data
Subscription payments are processed by Stripe. We do not store full payment card details on our servers.
7. Your Rights
Customers and Restaurant Accounts may request access to, correction of, or deletion of their personal data by contacting the relevant restaurant (for Customer data submitted through their page) or us directly (for Restaurant Account data), subject to legitimate business and legal retention requirements.
8. Cookies
We use essential cookies for authentication (admin sessions, language preference) and do not use third-party advertising or tracking cookies.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date above.
10. Contact
Questions about this Privacy Policy can be sent to the contact address listed on our homepage.
This document is a general template and does not constitute legal advice. We recommend having it reviewed by a lawyer familiar with your jurisdiction's data protection laws (e.g. UAE PDPL) before relying on it for a live commercial product handling real customer data.