Skip to content
Legal

Privacy Policy

Qdestera (“we”, “us”) runs a platform for creating QR codes, short links and digital menus at qdestera.com. This policy explains which personal data we process, why we process it and what choices you have.

Who we are and what this policy covers

This policy applies to the Qdestera website, the Qdestera app, the public pages that open when someone scans a Qdestera QR code or opens a short link, and Qdestera digital menus.

The company that operates Qdestera is responsible for your personal data as the data controller for its own purposes. Its legal name, address and contact details will be published on this page before launch.

Turkish residents can also read our KVKK information notice, which is written in Turkish under Law No. 6698.

Data we process

Account data

Your name, your email address, the identifiers of the sign-in provider you choose (Microsoft or Google), and your workspace memberships and roles. If you sign in with email and password, we store your password only as a salted hash.

Content you create

QR codes, short links, uploaded files and images, digital menus and the settings that belong to them. This content may contain personal data you add yourself, for example the contact details on a vCard.

Scan data

When someone scans a dynamic QR code or opens a short link, we record the time, the IP address, browser and device information (user agent), the referring page, and an approximate location (country, region and city) derived from the IP address.

Digital menu guest actions

Orders, waiter calls and bill requests that guests send from a digital menu, together with the table they came from.

Billing data

Subscriptions are paid through our payment provider Paddle. We receive information about your plan and payment status, but we never see or store your card number.

The free generator

The content you type into the free QR code generator on our website is used only to draw the QR image. It is not stored and no account is needed.

Why we process your data

We do not sell personal data, we do not use it for advertising and we do not make decisions about you based solely on automated processing.

  • To provide the service – sign-in, workspaces and team roles, and creating and serving QR codes, short links and menus (performance of our contract with you).
  • To show analytics – so account owners can see how their QR codes and links are scanned (performance of the contract with the account owner).
  • To keep the platform secure – preventing abuse, fraud and overload, for example through rate limiting and by disabling harmful links (our legitimate interest in a safe service).
  • To handle billing and support – managing subscriptions, answering requests and keeping records (contract and legal obligations).
  • To meet legal obligations – for example tax and accounting rules or lawful requests from authorities.

Scan data and menu guests: the business decides

When you scan a QR code or open a menu created with Qdestera, the business that owns the code or menu decides why scan data and guest actions are collected. That business is the data controller, and we process the data on its behalf and on its instructions.

If you have questions about a specific QR code or menu, please contact the business that published it. We will support that business in answering your request.

Service providers

We share personal data only with providers that help us run the service, and only as far as they need it.

We may also disclose data when the law requires it, for example to a court or a competent authority.

  • Microsoft and Google – sign-in, when you choose one of them.
  • Paddle – checkout, payments and invoicing for paid plans.
  • IP2Location.io – approximate location (country, region, city) from IP addresses for scan analytics.
  • Anthropic – optional automatic menu translation. Only the menu text is sent, and only when the menu owner uses the feature.

International transfers

Some of the providers above are located outside your country, including outside Turkey and the European Economic Area. When data is transferred abroad, we rely on the transfer mechanisms the applicable law provides, such as standard contractual clauses.

Cookies

We only use cookies that the service needs to work: keeping you signed in, protecting forms against forgery, and remembering your language, your selected workspace and the language of a menu or hosted page. We do not use advertising or tracking cookies.

If we enable website analytics, we use a cookieless, self-hosted tool. Details are in our cookie policy.

How long we keep data

We keep data for as long as your account or workspace exists, and longer only where the law requires it, for example billing records.

When a workspace is permanently deleted, its QR codes, short links, menus, files and scan data are deleted with it.

How we protect data

Connections to Qdestera are encrypted, each workspace’s data is kept strictly separate from other workspaces, and team roles (Owner, Admin, Editor, Viewer) limit who can change what. No system is perfectly secure, but we work to protect your data against loss and unauthorised access.

Your rights

Depending on where you live – for example under the GDPR or Turkey’s KVKK – you can ask to access, correct, export or delete your personal data, and object to or restrict its processing. Where processing is based on consent, you can withdraw it at any time.

You can also complain to your data protection authority. In Turkey this is the Personal Data Protection Authority (KVKK).

Children

Qdestera accounts are meant for businesses and adults. We do not knowingly create accounts for children.

Changes to this policy

If we change this policy, we will update the date at the top of this page and notify account owners of significant changes.

Contact

The data controller’s contact details, including a contact address for privacy requests, will be published on this page before launch. Until then, you can reach us through our contact page.