Private links, secret links and account security
What is public and what is private in AirQR, how to hide your menu with Private links, and how to keep staff logins safe.
Your menu is public on purpose, like any website. Everything behind it (orders, bills, guests, staff, costs and reports) is visible only to your own signed-in staff. This article explains what guests can see, how Private links hide your pages from search, and the simple habits that keep your account safe.
What can the public see, and what stays private?
Public by design (anyone with the link or QR code):
- Your menu: dishes, prices, photos, dietary info, offers shown on the menu, opening hours, address, and the UPI ID used for payment.
- Your online ordering page: the same menu plus delivery areas, fees and pickup times.
- Your table booking page: free time slots only, never other people's bookings.
Never shown to guests: cost prices, recipes, stock, internal notes, staff, guest lists, other people's orders, loyalty data and sales.
Private to your business: everything in the dashboard needs a signed-in staff member of your business with the right role, and (for staff limited to some outlets) access to that outlet. Changing a link or number in the address bar can't reach another business's data; it just shows "not found". AirQR doesn't list restaurants anywhere; a menu can only be reached through its own QR code or link.
How do guests order safely without an account?
Guests never sign up. They order with the QR code and, for takeaway and online orders, a name and phone number.
- Table ordering needs the table's QR code. Each table code is a random secret, not a table number, so someone at home can't order to "table 5" by guessing. The same applies to calling a waiter or asking for the bill.
- Secret links. A guest's own order page, the order-ready TV screen and older staff invites use long random links that can't be guessed. Receipts and kitchen tickets need a staff sign-in.
- Limits against pranks. Takeaway and online orders need a real-looking phone number and are rate-limited. Owners can add pay-first rules and block numbers. See Order protection.
Don't post a guest's order page link or the order-ready screen link publicly.
What are Private links and how do I turn them on?
Private links stop people from opening your menu, ordering or booking pages by guessing or editing a web address, and ask search engines not to list them. Use it if you don't want your menu findable on Google.
- Go to Avatar menu → Settings → Outlet tab.
- Find Private links and switch on Only people with your QR code or link can open your pages.
- Read the confirmation and press Turn on private links.
What happens:
- Your menu, online ordering and booking pages move to a new, unguessable address (your name plus random characters).
- Printed QR codes keep working. Nothing to reprint.
- Links you shared directly stop working: WhatsApp messages, Instagram bio, your website, and Google Business Menu, Order or Reserve buttons. Copy the new link from Guest menu link on the same page and update them.
- Search engines are asked not to list these pages.
Private links are set per outlet. The Outlets page shows a Private link badge on outlets that use them.
How do I get a new private link or switch back?
- New link: if your private link was shared more widely than you wanted, press New link under the switch, then Create new link. The current private link stops working immediately. Printed QR codes keep working.
- Switch back: turn the switch off and press Use a readable link. Your pages go back to the readable address (for example /m/your-restaurant-outlet), the private link stops working, and search engines may list your menu again. If another outlet is already using the readable address, this outlet keeps its current link and AirQR tells you so.
How do I keep staff logins safe?
- Never share one login. Add each person from Admin → Staff with Add staff. Floor staff can be PIN only (name, mobile and PIN, no login) and use the shared time clock with their own PIN; give a login (email and password) only to people who need to sign in themselves. Never leave the owner account signed in on a counter device.
- Give the smallest role that fits. Kitchen staff see only the kitchen display; cashiers can't change the menu or settings; only the owner can change the plan. You can also make your own roles with exactly the permissions a job needs. See Staff roles: who sees what.
- Logins are set up by you, not by email links. Owners and managers create a staff login with an email and password on the Staff page and give the password in person; nothing is emailed. Generated passwords are shown once. Reset or remove a login from the person's ⋯ menu. Owners' logins are created and reset only by AirQR.
- Deactivate leavers the same day. In Admin → Staff, open the ⋯ menu next to the person and tap Deactivate. Their access ends immediately and they leave the time clock; their history stays in your reports.
- Limit managers to their outlets. See Multiple outlets.
- Time clock PINs are personal. Never write them down at the counter.
- Passwords must be at least 8 characters, and common ones (like
password123) are refused. Repeated wrong sign-ins and password resets are slowed down automatically. Everyone can change their own password from their menu (Change password), and every login created, reset or removed is recorded in the audit log (never the password itself).
What if a link, token or device is compromised?
| Problem | What to do |
|---|---|
| Private menu link shared too widely | Settings → Outlet → Private links → New link. |
| Order-ready TV screen link leaked | Regenerate it in Settings → Printing. |
| Print bridge token leaked | Revoke it in Settings → Printing and add the bridge again. |
| A staff member left or a phone was lost | Admin → Staff → Remove the person. |
| Someone places prank orders | Block their number. See Order protection. |
If you think someone got into your account, contact support at once: call +91 96573 22724 or email support@airqr.in.
New to AirQR?
See AirQR in a short demo with your own menu. Already a customer? Sign in to follow these steps in your dashboard.
Still stuck? Contact support at support@airqr.in.