Legal
Privacy Policy
Last updated July 17, 2026
This policy explains what information QRaveLabs collects when you use our QR ordering and kitchen management service, how we use it, who we share it with, and - importantly - how long we keep it and when we delete it.
Who we are
QRaveLabs (“QRaveLabs”, “we”, “us”) provides a QR-code ordering and kitchen management platform for cafes, restaurants, bars, and food stalls. This policy applies to the QRaveLabs website, dashboard, kitchen board, and customer ordering pages.
Information we collect
We collect only what the service needs to run:
- Account & business details - your business name and type, the owner’s name and email, and staff logins you create. Passwords are stored only as a salted hash, never in plain text.
- Content you create - menu items, categories, add-ons, tables and their QR codes, orders, and any images you upload (your logo and menu photos).
- Customer order data - when a guest scans a table QR and orders, we process the items, any name or note they provide, and the order total, including any VAT, discounts, or tips the business records when settling the bill. Guests are not required to create an account; shared table ordering uses a random device token stored in the guest’s browser instead of any personal profile.
- Device location (only when required by the restaurant) - if a business turns on “on-site ordering only”, the guest’s browser asks for location permission and checks the distance to the venue on the device itself. The coordinates are never sent to our servers and are never stored - only the pass/fail result is used, at the moment of ordering.
- Payment information - subscription payments are handled by our payment processor (Xendit). We do not store your full card number; we keep only a reference to your subscription and its status. Guest bills are paid directly to the restaurant at the venue - QRaveLabs records the order and settlement amounts for the business’s records but never processes a guest’s card.
- Technical data - secure cookies to keep you signed in, and basic server logs for security and troubleshooting.
How we use your information
- To provide and operate the ordering, kitchen, and admin features.
- To process your subscription and send service-related notices.
- To keep the service secure and isolate each business’s data.
- To respond to your support requests.
We do not sell your personal information or your customers’ data.
Service providers we share with
We share data only with the processors that make the service work, under their own security and privacy terms:
- Xendit - subscription billing and payment processing.
- Supabase - database and image storage.
- Vercel - application hosting and delivery.
- Upstash - request rate limiting, to protect the service from abuse. No personal content is stored there.
- Google Maps - only when a business adds a map link to its ordering page; the embedded map is loaded from Google under Google’s own privacy terms.
Data retention & deletion
How long we keep your data depends on the kind of account and the status of your subscription.
In short:
- Active accounts - we keep your account and all the content you add for as long as your subscription is active.
- Demo accounts - demo workspaces reset daily. Any content you add to a demo (menu items, categories, add-ons, tables, orders) is automatically removed 24 hours after it is created. The original sample data provided with the demo stays.
- Free trials & lapsed subscriptions - if your free trial ends or your subscription lapses, your account is locked but your data is retained for 30 days. Renew any time in that window and everything is exactly as you left it.
- After the 30-day window - the content you added (menu, categories, add-ons, tables, orders, and uploaded menu photos) is permanently deleted. Your account itself is kept, so you can sign back in, renew, and start again with a clean workspace.
You can also delete individual items at any time from your dashboard. To close your account entirely and have all associated data erased, contact us at support@qravelabs.com.
How we protect your data
- Passwords are stored as salted hashes, never in readable form.
- Every business’s data is isolated so one account can never read or change another’s.
- Data is transmitted over encrypted connections (HTTPS).
Your rights & choices
You can access, correct, or delete the information in your account directly from the dashboard. You may also email us to request a copy of your data or to have your account and data deleted. We’ll respond within a reasonable time. If you’re in the Philippines, these rights include those under the Data Privacy Act of 2012 (RA 10173); we honor equivalent rights under other applicable privacy laws.
Cookies & device storage
We use essential cookies to keep signed-in users authenticated (a session cookie and a security token). Guests joining a shared table get a random identifier kept in their browser’s local storage so the table’s cart can stay in sync - it identifies the device, not the person, and can be cleared like any browsing data. We do not use advertising or third-party tracking cookies.
Children
QRaveLabs is a tool for businesses and is not directed to children. We do not knowingly collect personal information from children.
Changes to this policy
We may update this policy as the service evolves. When we do, we’ll revise the “last updated” date above and, for material changes, notify account owners.