Last updated: February 12, 2026
This Privacy Policy describes how qrder ("we", "us", or "our") collects, uses, and protects your personal information when you use our platform and services. We are committed to protecting your privacy and handling your data transparently and in compliance with applicable laws, including the Turkish Personal Data Protection Law (KVKK, Law No. 6698).
1. Information We Collect
Account Information: When you create an account, we collect your name, email address, phone number, business name, and business address. If you subscribe to a paid plan, we collect payment information through our secure payment processors.
Business Data: We collect and store the content you create through the Service, including menu items, descriptions, images, pricing, categories, table configurations, and other business-related information.
Automatically Collected Data: When you use our Service, we automatically collect your IP address, browser type and version, operating system, device information, referring URLs, pages visited, time spent on pages, and other usage statistics.
End Customer Data: When your customers interact with your digital menu via QR codes, we may collect their device type, browser information, and browsing behavior on your menu pages. We do not collect personal information from your customers unless they voluntarily provide it through order forms.
2. How We Use Your Information
We use the collected information to: provide, maintain, and improve our Service; process transactions and manage your subscription; send you technical notices, updates, security alerts, and support messages; respond to your comments, questions, and customer support requests; monitor and analyze usage trends and activities to improve the Service; detect, investigate, and prevent fraudulent transactions, abuse, and other illegal activities; personalize your experience and deliver content relevant to your interests; comply with legal obligations and enforce our Terms of Service.
3. Information Sharing
We do not sell your personal information to third parties. We may share your information in the following circumstances:
Service Providers: We share data with trusted third-party service providers who assist in our operations, including payment processors, cloud hosting providers, analytics services, and email delivery services. These providers are contractually obligated to protect your data.
Legal Requirements: We may disclose your information when required by law, regulation, legal process, or governmental request.
Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
Public Menu Data: Restaurant menu data you publish through our Service is publicly accessible by design, as it is intended to be viewed by your customers via QR codes.
4. Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit (TLS/SSL) and at rest, regular security assessments, access controls and authentication mechanisms, and regular backups.
However, no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.
5. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you with our Service. After account deletion, we will delete or anonymize your personal data within 30 days, except where retention is required by law or for legitimate business purposes such as resolving disputes or enforcing our agreements.
Usage logs and analytics data are retained in anonymized form for up to 24 months for the purpose of improving our Service.
6. Your Rights Under KVKK
Under the Turkish Personal Data Protection Law (KVKK, Law No. 6698) Article 11, you have the following rights regarding your personal data:
• To learn whether your personal data is being processed • To request information if your personal data has been processed • To learn the purpose of processing and whether it is used in accordance with its purpose • To know the third parties to whom your personal data is transferred domestically or abroad • To request correction of incomplete or inaccurate personal data • To request deletion or destruction of your personal data under the conditions set forth in KVKK Article 7 • To request notification of correction, deletion, or destruction to third parties to whom your data was transferred • To object to any adverse result arising from analysis of your processed data exclusively through automated systems • To claim compensation for damages arising from unlawful processing of your personal data
**How to Exercise Your Rights:** You may email privacy@qrder.io or submit a request via /settings/kvkk page to exercise the above rights. We will respond to your requests within 30 days as required by KVKK Article 13.
**VUK Exception:** Financial records (order amounts, invoices, etc.) must be retained for 5 years under the Tax Procedure Law (VUK) Article 256, so these records cannot be deleted but your personal information will be anonymized. This practice falls under KVKK's "legal obligation" exception.
7. Data Controller
In accordance with the Personal Data Protection Law No. 6698, the data controller is:
**Data Controller:** qrder **Contact:** privacy@qrder.io **Address:** Istanbul, Turkey
As the data controller, we determine the purposes and means of processing your personal data, and are responsible for establishing and managing the data recording system. Your personal data is processed to provide, improve our Service, and fulfill our legal obligations.
8. Cookies
We use cookies and similar tracking technologies to enhance your experience on our platform. For detailed information about the types of cookies we use, their purposes, and how to manage them, please refer to our Cookie Policy.
9. Children's Privacy
Our Service is not directed to children under the age of 18. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information without parental consent, please contact us at privacy@qrder.io and we will take steps to delete such information promptly.
10. International Data Transfers
Your information may be transferred to and processed on servers located outside of Turkey. When we transfer data internationally, we ensure that appropriate safeguards are in place in accordance with KVKK and other applicable data protection laws. These safeguards may include data processing agreements with standard contractual clauses approved by the Personal Data Protection Board.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. We will notify you of any material changes by posting the updated policy on this page and updating the "Last updated" date. For significant changes, we will also notify you via email.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
12. Contact Information
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:
Email: privacy@qrder.io General Support: support@qrder.io
Data Controller: qrder, Istanbul, Turkey