Last updated: September 6, 2026
QRMenuNow ("we", "us", or "our") operates the qrmenunow.com website and the QR menu and ordering services provided to restaurants, cafes, bars, and hotels ("Service"). This Privacy Policy explains how we collect, use, disclose, and protect information when you visit our website or use our Service, and describes your rights under applicable data protection laws, including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
We may collect the following categories of information:
If you are located in the European Economic Area (EEA), UK, or Switzerland, we process your personal data on the following legal bases: performance of a contract (providing the Service you signed up for), legitimate interests (improving and securing our Service), consent (for optional cookies and marketing communications), and compliance with legal obligations.
We do not sell your personal information. We may share information with:
Our website may use cookies and similar technologies to operate correctly and, where enabled, to understand how visitors use our site. These may include:
Where required by law (including under the EU ePrivacy Directive and GDPR), we will ask for your consent before setting non-essential cookies, and you can withdraw consent at any time. You can also control cookies through your browser settings, including blocking or deleting them, though this may affect site functionality.
We retain personal data for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. Menu and order data associated with a venue account is generally retained for the duration of the subscription and a reasonable period afterward, unless deletion is requested sooner.
To exercise any of these rights, contact us at [email protected]. We will respond within the timeframes required by applicable law.
Our servers and service providers may be located outside your country of residence, including outside the EEA. Where we transfer personal data internationally, we take steps to ensure appropriate safeguards are in place, consistent with applicable data protection law.
We use reasonable technical and organizational measures, including encrypted connections (HTTPS/TLS), to protect personal data against unauthorized access, alteration, disclosure, or destruction. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Our Service is intended for business use by venue owners and their adult customers. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal data, please contact us so we can delete it.
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
If you have questions about this Privacy Policy or how we handle your data, contact us at [email protected] or via our Contact page.