Privacy Policy

Effective Date: August 22, 2026

Privacy Philosophy

"At Qrpoll, we respect the delicate relationship between local businesses and their customers. Whether you are a restaurant owner or a dining guest submitting feedback, we enforce strict zero-selling data policies and enterprise grade encryption."

This Privacy Policy outlines how Qrpoll("we", "us", or "our") handles personal information across our reputation management software, offline QR survey engines, embeddable poll widgets, and management dashboards.

1. Data Controller & Processor Roles

Under the European Union General Data Protection Regulation (GDPR) Article 28 and related international privacy frameworks, Qrpoll operates under two distinct legal roles:

Data Controller (For Business Account Owners)

When you register an account with Qrpoll to manage your venue's reviews and subscription, we act as the Data Controller for your login credentials, billing details, and workspace configuration.

Data Processor (For End-Customer Survey Responses)

When your guests scan a QR code at your venue to leave a rating (1-5 stars), write a private complaint, or submit their email/phone for discount vouchers, we act as a Data Processor on your behalf. Your business is the primary Controller of your customer database.

3. Information We Collect

Subscriber & Account Details

Name, business email, venue name, physical address, and billing metadata managed through our payment gateways.

Customer Feedback & Rating Metrics

Star ratings (1-5), optional feedback commentary, timestamp of scan, table/location identifier, and routed destination (Google Maps vs. Internal Ticket).

Captured Lead Information

Guest email address or mobile phone number if they deliberately choose to receive promotional vouchers or staff follow-up.

4. Data Residency & Security

Tokyo, Japan (EU Adequacy Decision)

Our primary database infrastructure is managed through Supabase located in Tokyo, Japan. Japan holds an official European Commission Adequacy Decision (GDPR Article 45), ensuring equivalent data privacy and legal protection.

Row Level Security (RLS) & TLS Encryption

All survey data is encrypted in transit (TLS 1.3) and at rest (AES-256). Multi-tenant tenant boundaries are enforced at the database level via Postgres Row Level Security.

5. Sub-processors

We partner with certified third-party vendors to deliver high availability and secure payments:

Supabase Inc.Database & Auth (Tokyo, Japan)
Vercel / CloudflareGlobal Edge & CDN Infrastructure
Lemon SqueezyInternational Merchant of Record
PayOSVietnamese Banking & QR Checkout

6. Your Rights

1

Right to Access & Export

Business subscribers can export all survey analytics and captured customer leads via CSV.

2

Right to Erasure (Right to be Forgotten)

End customers or subscribers can request total deletion of their records at any time.

3

Right to Rectification

Request corrections to any inaccurate account or survey routing configurations.

7. Data Retention

Customer survey records and scan telemetry are maintained in active database tables according to your subscription level: 30 days on Starter Free, 1 year on Reputation Growth, and unlimited / custom retention on Agency Partner plans.

8. Contact Us

For privacy inquiries, DPA requests (Data Processing Addendum), or customer data deletion requests, contact our Data Protection Officer:

support@qrpoll.cc