Privacy Policy
Last updated: March 30, 2026
1. Scope
This Privacy Policy explains how BellQR handles personal data when restaurants use the BellQR platform and guests browse menus or submit feedback through BellQR-powered pages.
2. Controller and Processor Roles
Restaurants collect guest feedback through BellQR. For that feedback and related guest data:
- The restaurant is the data controller.
- BellQR is the data processor.
BellQR processes guest data on the restaurant's instructions so the restaurant can provide menu services, receive feedback, and review analytics.
3. Data We Process
Depending on feature use, BellQR may process:
- Restaurant account and billing information
- Menu content and configuration data
- Guest feedback submissions, ratings, and optional written comments
- Technical and usage data (for service reliability and visit-level analytics)
For BellQR menu visits specifically, BellQR links activity to a visit session (`guest_session_id`) rather than a persistent device identity.
4. Storage, Security, and Access
Feedback and account data are stored in managed infrastructure with access controls, encryption in transit, and operational safeguards. Access is limited to authorized personnel who need it to operate, support, and secure the service.
5. Data Retention
We retain personal data only as long as needed to provide the service, comply with legal obligations, resolve disputes, and enforce agreements.
Guest feedback data is retained for the restaurant while its account is active, unless the restaurant requests earlier deletion. After account closure, BellQR deletes or anonymizes personal data within a reasonable operational period, except where longer retention is legally required.
6. GDPR Rights and Requests
Where GDPR applies, data subjects may have rights including access, correction, deletion, objection, and portability. Because restaurants are controllers for guest feedback data, BellQR supports restaurants in handling these requests.
Restaurants can request data export or deletion through account support channels. Account owners can also request account deletion by contacting us.
7. Cookies and Similar Technologies
In BellQR menu flows, BellQR uses a session continuity cookie (`bellqr_session_token`) so a guest can complete one visit. This cookie is scoped to the active browser session, and BellQR enforces a maximum 24-hour server-side visit lifetime.
BellQR menu analytics are first-party and visit-scoped. BellQR does not use persistent device IDs, fingerprinting, or cross-visit recognition for these flows.
Any optional browser storage in BellQR menu flows is used solely to improve user experience features (such as saved items and feedback continuity), not to identify a device across visits.
Because BellQR menu flows are limited to strictly necessary session continuity plus visit-scoped operational analytics, BellQR does not show a cookie consent banner in these flows. See our Cookie Policy for additional detail.
For BellQR marketing pages where optional analytics cookies are used, users can grant, reject, or later change this preference at any time via Cookie Preferences.
8. Contact
For privacy questions or requests, contact: