1. Introduction
At SuchiQR ("we", "us", or "our"), protecting the privacy and security of restaurant owners, staff members, restaurant dining guests, and support contacts is paramount. This Privacy Policy details how we collect, process, store, and safeguard personal information across our website and software services at suchiqr.app.
2. Information We Collect
2.1 Restaurant Owners and Team Members: When you register an account, set up a restaurant shop, or subscribe to a plan, we collect:
- Name and email address (authenticated securely via Clerk).
- Restaurant name, address, food categories, and menu item pricing.
- Subscription and billing metadata — Razorpay subscription and transaction IDs, plan, cycle, and GST invoice details. Card numbers, UPI PINs, and bank credentials are never stored on SuchiQR servers; they stay with Razorpay.
2.2 Merchandise Requests (Restaurant Owners): When you submit a physical merchandise request (QR stands, stickers, printed goods), we collect:
- Shipping address, recipient name, and delivery phone number.
- The WhatsApp/phone number you ask us to confirm the order on.
- Your design choices — the QR configuration (colours, patterns, logo) or any artwork file you upload — and any notes you add to the request.
- Order status, courier partner, and tracking ID as the order is fulfilled.
2.3 Support Inquiries: When you contact our support team (contact form or a 1-on-1 setup-call booking), we store your name, email address, optional phone number and restaurant name, your message, and any preferred call slot you pick, so our team can respond and schedule your call.
2.4 Restaurant Diners (Zero-Login Architecture): When a dining guest scans a table QR code and submits a food order:
- Table number and ordered dishes with item notes.
- Order timestamp and server-recomputed order total.
- No customer passwords, diner accounts, or payment cards are ever requested.
3. How We Use Your Information
- To render fast, high-performance digital menus for dining guests.
- To route real-time order alerts to Discord channels, Telegram groups, and kitchen display feeds.
- To compute sales analytics and top-selling menu items for restaurant owners.
- To process subscription renewals and GST invoices through Razorpay.
- To review and respond to merchandise requests, contact you on your chosen WhatsApp/phone number to finalize orders, produce and ship the confirmed goods, and keep your order tracking up to date.
- To respond to support inquiries and schedule requested 1-on-1 setup calls.
4. Sharing With Third Parties
We share personal data only as needed to deliver the Service:
- Courier partners (BlueDart, Delhivery, DTDC, India Post, or similar): for confirmed merchandise orders only, we share the recipient name, delivery address, and phone number required to deliver your parcel — nothing else.
- Razorpay (payment aggregator): processes subscription payments and holds your payment mandates. Razorpay receives the transaction data it needs; we never see or store your card/UPI credentials.
- Clerk (identity provider, SOC-2 Type II): authenticates merchant accounts.
- Alert channels (Discord/Telegram) are your own accounts as a merchant — order alerts flow to the destinations you configure, under your control.
Merchandise payments are collected offline after order confirmation; no payment credentials for merchandise ever pass through or are stored on SuchiQR systems. We do not sell or rent personal data to anyone.
5. Data Security & Storage Architecture
All database queries use strict PostgreSQL Tenant Isolation, ensuring one restaurant owner or staff member can never view or access another restaurant's data. All data is encrypted in transit (TLS 1.3/HTTPS) and at rest. Identity management is secured via Clerk (SOC-2 Type II compliant).
Internal access is role-scoped: only authorized SuchiQR operators can access merchandise order and support data, each restricted to the panel their role grants (order operations or support), with every action on an order recorded in an audit trail. Merchandise artwork uploads are validated and stored in per-restaurant isolated storage.
You may request deletion of your account and restaurant data at any time from Dashboard ➔ Settings ➔ Danger Zone; deleting your account removes your shop data, menu content, merchandise order records, and support inquiries from our systems, except where retention of transaction records is required by tax law.
6. Grievance Officer & Contact
If you have any questions or data requests under India's DPDP Act 2023, please reach out to our privacy team:
SuchiQR Privacy & Grievance Officer
Email: support@suchiqr.app