1. Introduction
QFLOW ("we," "us," or "our"), a product of Odysense Technologies W.L.L., is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, website, and related services (collectively, the "Service"). By using the Service, you consent to the data practices described in this policy.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, phone number, restaurant name, and business details when you register for an account.
- Payment Information: Billing details and payment method information processed securely through our third-party payment processors (Stripe, Tap). We do not store full card numbers on our servers.
- Menu Content: Menu items, descriptions, images, prices, and categories you upload to the platform.
- Communications: Information you provide when contacting our support team or submitting inquiries through our website.
2.2 Information Collected Automatically
- Usage Data: Pages visited, features used, click patterns, session duration, and navigation paths.
- Device Information: Browser type, operating system, device identifiers, screen resolution, and IP address.
- Location Data: Approximate location based on IP address (we do not collect precise GPS location).
- Order Data: Customer ordering patterns, popular items, and transaction histories associated with your restaurant.
3. How We Use Your Information
- To provide, operate, and maintain the Service
- To process transactions and send related information including receipts and confirmations
- To personalize and improve your experience with analytics and recommendations
- To communicate with you about updates, security alerts, and support messages
- To detect, prevent, and address technical issues, fraud, and security incidents
- To comply with legal obligations and enforce our Terms of Service
- To generate aggregated, anonymized analytics and insights for your restaurant dashboard
4. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience:
- Essential Cookies: Required for authentication, session management, and security. Cannot be disabled.
- Analytics Cookies: Help us understand how the Service is used, identify popular features, and improve performance.
- Preference Cookies: Remember your settings and display preferences across sessions.
You can manage non-essential cookies through your browser settings. Disabling cookies may affect certain features of the Service.
5. Third-Party Services
We share information with the following categories of third-party service providers:
- Payment Processors: Stripe and Tap process payments on our behalf. They are PCI DSS compliant and have their own privacy policies.
- Cloud Infrastructure: Our platform is hosted on secure cloud infrastructure with data encryption at rest and in transit.
- Analytics Providers: We use analytics tools to understand usage patterns and improve the Service.
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
6. Data Retention
We retain your personal data for as long as your account is active or as needed to provide you with the Service. After account deletion, we retain certain data for up to 90 days for backup and recovery purposes, and may retain anonymized, aggregated data indefinitely for analytics. Transaction records are retained for 7 years to comply with financial regulations in Qatar.
7. Data Security
We implement industry-standard security measures including:
- TLS 1.3 encryption for all data in transit
- AES-256 encryption for data at rest
- Regular security audits and penetration testing
- Role-based access controls and multi-factor authentication
- Automated threat detection and monitoring
- PCI DSS Level 1 compliance for payment processing
8. Your Rights (GDPR & Qatar Data Protection)
Depending on your location, you may have the following rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data, subject to legal retention requirements.
- Right to Data Portability: Request your data in a structured, machine-readable format.
- Right to Restrict Processing: Request limitation of how we process your data.
- Right to Object: Object to processing based on legitimate interests or direct marketing.
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, please contact us at privacy@qflow.app. We will respond within 30 days.
9. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
10. International Data Transfers
Your data may be transferred to and processed in countries outside of Qatar. We ensure appropriate safeguards are in place, including standard contractual clauses and data processing agreements, to protect your data in accordance with this Privacy Policy.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or in-app notification. Continued use of the Service after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact:
Odysense Technologies W.L.L.
Email: privacy@qflow.app
Address: Doha, Qatar