1. Scope and identity
This Privacy Policy explains how the QRelia hospitality software service processes personal information when people visit qrelia.uk, create or use a Venue account, administer menus and operations, subscribe, contact support, scan a QRelia QR code, submit a Guest order or use an optional connected Device.
QRelia is operated by Lukas Slivka under the QRelia name from the United Kingdom. The privacy contact is support@qrelia.uk.
This Policy covers QRelia’s own processing. A Venue may also provide its own privacy notice covering how it uses Guest, staff, payment, CCTV, booking, loyalty or other information outside QRelia.
2. Controller and processor roles
QRelia as controller
QRelia is normally the controller for information used to manage its website, enquiries, Venue-account relationship, authentication and security, subscription billing, service communications, support, diagnostics, abuse prevention, legal obligations and product administration.
QRelia as processor
For personal information entered or generated through a Venue’s Customer App, Receiver, staff accounts, operational reports and Devices, the Venue is normally the controller and QRelia is normally its processor. This includes Guest order details, location references, service notes, course assignments and staff operational activity.
3. Information we process
Venue account and staff information
- name, email address, business contact details and Venue affiliation;
- account identifier, role, permissions, confirmation status, login and security information;
- subscription plan, trial status, invoices, payment status, Stripe customer/payment-method references and billing history;
- support messages, feedback, onboarding information and administrative actions.
Venue configuration and content
- Venue name, address, timezone, branding, logo, social links and booking links;
- areas, rooms, tables or other locations and their QR-code references;
- menus, categories, items, modifiers, images, prices, availability, allergens, preparation stations and service courses;
- Receiver, analytics, QR Print Studio and Device settings.
Guest, basket and order information
- the Venue, area and exact location associated with a QR scan or manually selected ordering journey;
- basket items, quantities, modifiers, wine size, prices, requests and item notes;
- serving mode, service course, guest number and any first name or label entered for item assignment;
- order identifier, status, estimated waiting time, timestamps and course-progress information;
- browser/session information needed to maintain the basket, ordering window and live status.
Device and technical information
- Device identifier, name, setup/provisioning status, firmware version, claim time and last-seen/heartbeat information;
- operational status, selected profiles, animations and order-state signals sent to the Device;
- IP address, browser type, operating-system information, request timestamps, error details, security logs and diagnostic events;
- cookie and local-storage values used for authentication, security, basket continuity, preferences and consent records.
QRelia does not ordinarily receive full Venue subscription card numbers. Stripe processes card and payment-authentication details under its own privacy practices. QRelia does not process Guest-order payments as part of the standard ordering service unless a separate payment feature is expressly enabled.
4. Where information comes from
Information may come from:
- you, when you register, configure a Venue, place an order, enter a request or contact support;
- the Venue and its authorised owners, administrators and staff;
- your browser or Device when it communicates with QRelia;
- Stripe, Brevo and other providers used for billing, transactional communication, hosting, security or support;
- integrations or data imports authorised by a Venue; and
- public business sources where reasonably needed to verify or contact a Venue.
5. Purposes and lawful bases
| Purpose | Typical information | Lawful basis where QRelia is controller |
|---|---|---|
| Provide and administer the Venue service | Account, role, Venue, subscription and support data | Contract; steps requested before contract |
| Authenticate users and protect tenants | Login, session, IP, role, anti-forgery and security events | Legitimate interests in secure, reliable service; legal obligation where applicable |
| Bill the Venue and keep financial records | Plan, invoice, payment status and Stripe references | Contract; legal obligation; legitimate interests in debt and dispute management |
| Send transactional service communications | Email, account, subscription, security and support information | Contract; legitimate interests; legal obligation |
| Diagnose, maintain and improve QRelia | Logs, errors, feature usage, performance and de-identified statistics | Legitimate interests in operating and improving the service |
| Prevent misuse and establish legal claims | Security, account, payment, support and audit information | Legitimate interests; legal obligation; establishment, exercise or defence of legal claims |
| Optional marketing | Business contact and communication preferences | Consent where required, or legitimate interests where permitted with an opt-out |
Where QRelia acts as processor, the Venue determines the lawful basis for Guest and staff processing and instructs QRelia through its authorised use of the Platform.
Where we rely on legitimate interests, those interests include running a secure multi-tenant SaaS service, preventing fraud and abuse, supporting Venues, maintaining records, understanding service performance and improving hospitality workflows. We consider the necessity and impact on individuals before relying on this basis.
6. Dietary, allergy and other sensitive information
A Guest or Venue may enter dietary, allergy, health, religious or other information in a request, note or guest-assignment field. Some of this may be special-category personal data and requires additional protection.
Venues should collect only what is genuinely needed for the immediate hospitality service, avoid detailed medical histories, restrict staff access and identify both an Article 6 lawful basis and an Article 9 condition where required. QRelia processes this information on the Venue’s instructions and does not use it for advertising or unrelated profiling.
7. QR access, cookies and browser storage
QRelia uses cookies, sessions and browser storage where necessary to operate its websites and applications. Depending on the surface and user journey, these technologies may:
- authenticate Venue users and protect forms and sessions;
- remember the correct tenant, area and location opened from a QR code;
- maintain a Guest basket, live order continuity and the time-limited ordering window;
- remember a theme or display preference;
- record whether the essential-storage notice has been acknowledged; and
- support security, load management, diagnostics and fraud prevention.
The current QRelia Guest ordering experience is designed not to use advertising or cross-site behavioural-tracking cookies. If QRelia or a Venue introduces optional storage or similar technology that legally requires consent, it should not be activated before valid consent is obtained.
On the public QRelia marketing website, Google Analytics 4 may be loaded only after the visitor selects “Accept all”. It is used to understand page usage and navigation patterns, not to provide guest-order advertising. The visitor can choose “Essential only”, reopen Cookie settings later and withdraw the analytics choice. Google may process analytics identifiers, browser and device information, approximate location derived from network information, page paths, referral information and interaction events according to Google’s service terms.
Browser controls can remove or block storage, but doing so may sign a user out, clear the basket, lose preferences or prevent ordering from working correctly.
8. Sharing and service providers
Personal information may be shared with:
- the relevant Venue and its authorised staff, so they can receive, prepare, serve, manage and report on orders;
- Stripe for Venue subscription billing and payment-method services;
- Brevo or another configured communication provider for transactional email;
- Google Analytics, only where the visitor has consented on the public marketing website;
- hosting, database, backup, domain, security, monitoring and technical-support providers;
- professional advisers, insurers, accountants or auditors where reasonably required;
- courts, regulators, law enforcement or public authorities where disclosure is required or lawfully justified;
- a purchaser, investor or successor in a genuine restructuring, incorporation, financing or sale, subject to appropriate confidentiality and data-protection safeguards.
QRelia does not sell personal information. QRelia does not allow a Venue to access another Venue’s tenant data except where explicitly authorised for support or legally required.
9. International transfers
Some service providers may process or make information accessible outside the United Kingdom. Before QRelia initiates a restricted transfer, it will use an applicable UK adequacy regulation, appropriate safeguards such as the UK International Data Transfer Agreement or UK Addendum, or another lawful transfer mechanism. A transfer-risk assessment and supplementary measures will be used where required.
More information about a material transfer or safeguard can be requested at support@qrelia.uk, subject to security and commercial confidentiality.
10. Retention and deletion
QRelia keeps personal information only for as long as reasonably necessary for the purpose collected, the Venue’s instructions, security, backups, legal obligations, accounting, dispute management and establishment or defence of claims.
- Venue accounts and subscriptions: for the active relationship and afterwards for the period needed for tax, accounting, security and legal records.
- Guest and operational data: according to the Venue’s service needs, configuration and instructions, subject to legal and technical requirements.
- Browser baskets and sessions: for the operational period set by the application or until the user clears browser data.
- Security and diagnostic logs: for a limited period proportionate to investigation, service reliability and abuse-prevention needs.
- Backups: until overwritten or securely removed through normal backup cycles.
- Support and complaints: for as long as needed to resolve the matter and maintain an appropriate record.
When information is no longer needed, it is deleted, anonymised or made inaccessible. Deletion from active systems may not immediately remove every backup copy, but retained backup data remains protected and is not restored for ordinary use.
11. Security
QRelia uses reasonable technical and organisational measures appropriate to the Platform’s risks. These may include tenant-aware data access, authentication and roles, encrypted network transport, anti-forgery protections, access restrictions, logging, backups, subscription and provisioning controls, software maintenance and incident response.
No internet service is completely secure. Venues and users must protect credentials, local networks, browsers, exports, QR materials and Devices; grant minimum necessary access; and promptly report suspected unauthorised access or data loss.
12. Your data-protection rights
Subject to the law and circumstances, you may have the right to:
- be informed about processing;
- request access to your personal information;
- correct inaccurate or incomplete information;
- request erasure;
- request restriction of processing;
- receive certain information in a portable format;
- object to processing based on legitimate interests or direct marketing;
- withdraw consent at any time where consent is the basis, without affecting earlier lawful processing; and
- raise concerns about solely automated decisions producing legal or similarly significant effects.
Rights are not absolute. We may need to verify identity, clarify the request, protect another person’s rights or retain information where law permits or requires it. We will not charge a fee unless a request is manifestly unfounded or excessive and the law allows a reasonable fee.
13. Requests and data-protection complaints
How to make a request
Email support@qrelia.uk with enough information to identify the relevant Venue, account, order or interaction. For Guest-order data, contacting the Venue first is usually the fastest route because the Venue is normally the controller.
How to make a complaint
Put “Data protection complaint” in the subject line and explain what happened, the relevant dates, the Venue or account involved and the outcome sought. QRelia will provide a clear complaints route, acknowledge the complaint within 30 days, investigate it appropriately and communicate the outcome without undue delay.
You may also complain to the UK Information Commissioner’s Office. Its current contact and complaint information is available at ico.org.uk. We would appreciate the opportunity to address the concern first, but this does not restrict your right to contact the ICO.
14. Analytics, forecasts and automated processing
QRelia may automatically calculate operational statistics, best sellers, completion rates, service-time measures, preparation-station results, weather overlays and forecasts. These outputs assist Venue management and do not by themselves make decisions producing legal or similarly significant effects about a person.
QRelia may use aggregated or de-identified usage information to understand performance and improve the Platform. Information is not treated as anonymous if a person can still reasonably be identified from it.
15. Children and age-restricted service
Venue administration and subscriptions are not intended for children. The Guest ordering interface may be encountered by families or younger guests, but QRelia does not knowingly require a child to create a personal account for ordinary QR ordering.
The Venue is responsible for age checks and lawful service of alcohol or other age-restricted products. QRelia’s interface, QR scan or order submission is not proof of age or authority to purchase.
16. Venue privacy responsibilities
A Venue using QRelia should:
- provide an accurate privacy notice to Guests and staff;
- identify lawful bases and, where applicable, special-category conditions;
- collect only necessary information and avoid using free-text fields for excessive personal data;
- control staff roles, exports, Receiver visibility and access to order history;
- set and document appropriate retention and deletion practices;
- respond to rights requests and complaints and involve QRelia where processor assistance is needed;
- maintain appropriate operational and device security; and
- notify QRelia promptly of suspected cross-tenant access, compromise or personal-data breach involving the Platform.
17. Changes to this Policy
We may update this Policy when QRelia’s features, providers, data uses or legal obligations change. The effective date at the top will be updated. Material changes may also be notified through the Platform or account email where appropriate.
A new use of personal information that is incompatible with the original purpose will not be introduced merely by changing this page; QRelia will identify an appropriate lawful basis and provide any additional notice or consent required by law.
18. Contact details
Service: QRelia
Operator and privacy contact: Lukas Slivka
Country of establishment: United Kingdom
Email: support@qrelia.uk
Website: qrelia.uk