Privacy Policy
Effective Date: August 22, 2026
"At Qrpoll, we respect the delicate relationship between local businesses and their customers. Whether you are a restaurant owner or a dining guest submitting feedback, we enforce strict zero-selling data policies and enterprise grade encryption."
This Privacy Policy outlines how Qrpoll("we", "us", or "our") handles personal information across our reputation management software, offline QR survey engines, embeddable poll widgets, and management dashboards.
1. Data Controller & Processor Roles
Under the European Union General Data Protection Regulation (GDPR) Article 28 and related international privacy frameworks, Qrpoll operates under two distinct legal roles:
Data Controller (For Business Account Owners)
When you register an account with Qrpoll to manage your venue's reviews and subscription, we act as the Data Controller for your login credentials, billing details, and workspace configuration.
Data Processor (For End-Customer Survey Responses)
When your guests scan a QR code at your venue to leave a rating (1-5 stars), write a private complaint, or submit their email/phone for discount vouchers, we act as a Data Processor on your behalf. Your business is the primary Controller of your customer database.
2. Legal Basis for Processing
Contract Performance
To provide automated review routing, SMS/email alerts for negative reviews, and generate dynamic QR codes.
Legitimate Interests
To detect and prevent fraudulent bot scans, protect platform security, and ensure reliable routing to Google Maps.
Consent
When end customers voluntarily opt in to leave their contact information (email or phone) for marketing follow-ups or loyalty incentives.
3. Information We Collect
Subscriber & Account Details
Name, business email, venue name, physical address, and billing metadata managed through our payment gateways.
Customer Feedback & Rating Metrics
Star ratings (1-5), optional feedback commentary, timestamp of scan, table/location identifier, and routed destination (Google Maps vs. Internal Ticket).
Captured Lead Information
Guest email address or mobile phone number if they deliberately choose to receive promotional vouchers or staff follow-up.
4. Data Residency & Security
Tokyo, Japan (EU Adequacy Decision)
Our primary database infrastructure is managed through Supabase located in Tokyo, Japan. Japan holds an official European Commission Adequacy Decision (GDPR Article 45), ensuring equivalent data privacy and legal protection.
Row Level Security (RLS) & TLS Encryption
All survey data is encrypted in transit (TLS 1.3) and at rest (AES-256). Multi-tenant tenant boundaries are enforced at the database level via Postgres Row Level Security.
5. Sub-processors
We partner with certified third-party vendors to deliver high availability and secure payments:
6. Your Rights
Right to Access & Export
Business subscribers can export all survey analytics and captured customer leads via CSV.
Right to Erasure (Right to be Forgotten)
End customers or subscribers can request total deletion of their records at any time.
Right to Rectification
Request corrections to any inaccurate account or survey routing configurations.
7. Data Retention
Customer survey records and scan telemetry are maintained in active database tables according to your subscription level: 30 days on Starter Free, 1 year on Reputation Growth, and unlimited / custom retention on Agency Partner plans.
8. Contact Us
For privacy inquiries, DPA requests (Data Processing Addendum), or customer data deletion requests, contact our Data Protection Officer:
support@qrpoll.cc