Privacy Policy
Last updated: September 27, 2026
This Privacy Policy explains how ThaiQROrder ("we", "our") collects and uses information when you use our service at https://www.thaiqrorder.com/en, the ThaiQROrder app for shops, the owner portal at https://www.thaiqrorder.com/owner, shop websites at your-name.thaiqrorder.com, and the customer menu pages reached by scanning a restaurant's QR code.
1. Who we are
ThaiQROrder is a software-as-a-service platform that lets Thai restaurants and small businesses accept orders through QR codes. Customers scan a QR code on a table to view a menu and place an order directly with the restaurant. We do not operate the restaurants themselves; we provide the software.
2. Information we collect
2.1 Business owners
When a restaurant owner signs up and uses the app or the owner portal, we collect:
- Phone number (used as the primary identifier and for OTP login)
- Store name, website address, category, region, address and map location, and the contact details the shop enters
- Menu items, categories, prices, and optional images uploaded by the owner
- Business hours, table settings, the shop's PromptPay number, and a PromptPay QR image if uploaded
- Login activity and IP address for security purposes
- A push notification token (via Firebase / Google) used to deliver new-order alerts to the owner app
- Staff details the owner enters (names, phone numbers, pay rates and clock-in/out times); the shop controls this data and we process it on its behalf
2.2 Customers placing orders
Customers do not create an account. We keep only what an order or a booking needs:
- Ordering at the table by QR: table number, items, options, total and any notes. No name or phone number is asked for
- When a customer taps "I have paid": the time and amount reported, so the shop can check the transfer
- Pickup or delivery orders on a shop website: name, phone number and, for delivery, the delivery address, so the shop can reach the customer and deliver
- Table bookings on a shop website: name, phone number, email, party size, date, time and notes, so booking updates can be emailed
- Language preference and cart contents (stored locally in the browser)
2.3 Website visitors
When you visit our marketing pages, we collect standard server logs (IP address, browser user agent, referrer, requested URLs) for security and reliability. We use Cloudflare as a CDN / WAF, which may process request metadata on our behalf.
2.4 Contact form
If you submit an inquiry through our contact page, we collect the name, email, optional phone, subject, and message you provide, together with your IP address and a Cloudflare Turnstile anti-bot token.
3. How we use information
- To deliver the QR ordering service and route orders to the correct restaurant
- To authenticate business owners via one-time codes sent by SMS
- To send transactional notifications (order and booking alerts to the shop's app, booking status emails to customers, and webhooks a shop has set up)
- To provide analytics, billing, and support
- To prevent abuse, spam, and security incidents
4. Payments
Customer payments for food orders are handled directly between the customer and the restaurant (typically via PromptPay, cash on delivery, or in-store payment). ThaiQROrder does not process, store, or have access to your bank details, card numbers, or PromptPay transactions. Monthly subscription fees paid by business owners to ThaiQROrder are billed separately.
5. Sharing
We do not sell personal data. We share information only with:
- The restaurant a customer ordered from or booked with (the details of that order or booking)
- Infrastructure providers we use to run the service (hosting, database, CDN, email, SMS, file storage, push notifications via Firebase / Google)
- Law enforcement or regulators when required by law
6. Cookies and local storage
We use minimal cookies: for signing in to the owner portal and admin, and to remember page preferences. The customer menu uses localStorage to remember language preference and cart contents between page loads on the same device. No third-party advertising cookies are set.
7. Data retention
Business owner accounts and their menu data are retained while the account is active. Order records are retained for at least one year for accounting and dispute resolution. When a store is deleted, associated assets (QR codes, menu images, store images) are removed from our storage. Contact form submissions are retained for up to 12 months.
8. Security
Traffic is served over HTTPS. Passwords and session tokens are hashed or encrypted. Database access is restricted to authorised personnel. We apply security updates regularly and review our infrastructure for vulnerabilities. However, no system is perfectly secure, and we cannot guarantee absolute security.
9. Your choices
You may:
- Request a copy of the personal data we hold about you
- Ask us to correct or delete your personal data
- Withdraw consent to non-essential processing at any time
Requests can be submitted through our contact page.
10. Children
ThaiQROrder is intended for businesses and adult customers. We do not knowingly collect personal information from children under 13. If you believe a child has submitted information to us, please contact us and we will remove it.
11. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of the page indicates when the policy was last changed. Continued use of the service after changes constitutes acceptance.
12. Contact
Questions about this Privacy Policy can be submitted through our contact page.