Privacy policy

Last updated 26 September 2026

This policy explains what personal data AirQR handles, why, who we share it with and the choices you have. It applies to our website, the AirQR dashboard, and the menu, ordering and booking pages we host for restaurants.

The short version
  • We collect what we need to run AirQR for restaurants — nothing for advertising, and we never sell data.
  • For a restaurant's own account we decide how data is used. For the guest data a restaurant collects through AirQR, the restaurant decides and we act on its instructions.
  • Guests with privacy questions should contact the restaurant first; we help the restaurant respond.
  • You can ask us to access, correct or delete your data at any time by writing to abhishek@aivanaut.com. We respond within 30 days.

1. Who we are

AirQR is a restaurant management platform — digital QR menus, table and online ordering, point of sale, kitchen display, reservations, guest CRM, loyalty, offers, inventory and analytics — built and operated by Aivanaut ("AirQR", "we", "us"). We are based in India.

In this policy, "restaurant" or "you" means a business that signs up for AirQR and the people who use the dashboard on its behalf (owners, managers, cashiers, waiters, kitchen staff). "Guest" means a diner who views a restaurant's menu, places an order, books a table, joins a loyalty programme or leaves feedback through a page we host for that restaurant.

2. Our two roles

For restaurant accounts, we are the data fiduciary (controller)

When you create an AirQR account, we decide how and why your account data is used — to run the service, bill you, support you and keep the platform secure. Under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") we are the "data fiduciary" for this data; under the GDPR we are the "controller".

For guest data, we are a data processor

Restaurants use AirQR to collect information from their own guests — names, phone numbers, email addresses, orders, delivery addresses, feedback, loyalty points, birthdays and anniversaries. That data belongs to the restaurant. The restaurant is the data fiduciary (controller) and decides what to collect and how to use it; we are the "data processor" and handle it only to provide AirQR to that restaurant, on its instructions and under our Terms of service. We do not use one restaurant's guest data for another restaurant, and we do not contact guests for our own marketing.

3. What we collect

Account data

  • Your name, email address, phone number and password (stored only as a secure hash by our authentication provider).
  • The names, emails and roles of staff you invite, and which outlets they can access.
  • Billing details: plan, invoices, billing contact and payment status. Card or UPI details are handled by our payment partner — we never see or store full card numbers.
  • Messages you send us for support or sales.

Restaurant and business data

  • Business name, legal name, outlet addresses, GSTIN, FSSAI number, tax settings, currency and time zone.
  • Menus, prices, photos, descriptions, allergen and dietary labels, tables, QR codes, opening hours, offers, inventory and staff schedules.
  • Orders, bills, payments recorded, reservations and reports generated from them.

Guest data (processed for restaurants)

  • Name, phone number and email address, when a guest gives them to order, book, join loyalty or receive a receipt.
  • Order history, table number, special instructions and, for delivery orders, the delivery address.
  • Reservations, party size and notes; feedback and ratings; loyalty points and rewards.
  • Birthday or anniversary, if the guest chooses to share it with the restaurant.
  • Marketing preferences, such as whether the guest agreed to receive offers from the restaurant.

Device and usage data

When you use AirQR our servers and hosting provider record technical data: IP address, browser and device type, pages requested, timestamps and error logs. We use it to keep the service running, fix bugs, prevent abuse and understand which features are used. We do not build advertising profiles from it.

Cookies and local storage

We use only what the product needs to work. We do not use advertising or cross-site tracking cookies.

  • Sign-in session cookies — keep you signed in to the dashboard securely.
  • Workspace cookies — remember which organisation and outlet you last selected, so the dashboard opens where you left off.
  • Guest browser storage — on a restaurant's menu page, the guest's cart and a token for their recent orders are kept in the browser's local storage, so they can track an order or reorder without an account. Guests can clear this at any time from their browser settings.
  • Preference storage — small settings such as light or dark theme.

Because these are strictly necessary for the service, they do not require a consent banner. If we ever add optional analytics cookies we will ask first.

4. Why we use it, and on what basis

  • To provide AirQR — create your account, host your menus and ordering pages, route orders to the kitchen, print bills, run reports. Basis: performing our contract with you; for guest data, the restaurant's instructions.
  • To bill you — issue GST invoices and collect subscription fees. Basis: contract and legal obligations under Indian tax law.
  • To support you — answer questions, help with onboarding and fix problems, which may mean looking at your account with your permission.
  • To keep AirQR secure — detect fraud, spam and abuse, and investigate incidents. Basis: legitimate uses permitted by law and our legitimate interest in protecting users.
  • To improve AirQR — understand feature usage in aggregate and fix bugs. We do not train AI models on your data.
  • To tell you about AirQR — service emails (billing, security, important changes) are always sent; product news only if you have not opted out. Every marketing email has an unsubscribe link.
  • To comply with law — respond to lawful requests from authorities and keep records we are required to keep.

Under the DPDP Act, we rely on your consent (given when you sign up and accept this policy) and on the legitimate uses the Act allows. You can withdraw consent at any time; if you do, we may no longer be able to provide the service, and processing done before withdrawal stays lawful.

5. AI features

AirQR offers optional AI tools to import a menu from a photo or PDF, translate menus and write dish descriptions. When you use them, we send the menu content you provide (text and images of your menu) to AI model providers through OpenRouter. We send restaurant menu content only — never guest names, phone numbers, orders or other guest personal data. The content is used to return the result you asked for (for example, a structured menu or a translation). Menu content is not usually personal data, but please don't upload images or files that contain other people's personal information. We do not use your content to train AI models, and we ask OpenRouter to route requests only to providers that don't store or train on it.

6. Who we share data with

We do not sell or rent personal data. We share it only with service providers ("sub-processors") who help us run AirQR, under contracts that require them to protect it and use it only for our instructions:

  • Supabase — database, authentication and file storage (menu photos, logos).
  • Vercel — website and application hosting, and content delivery.
  • OpenRouter and the AI model providers it routes to — only for AI menu import, translation and descriptions, and only restaurant menu content.
  • Our payment partner — when you pay for a subscription, to process the payment.
  • Our WhatsApp Business messaging provider — when a restaurant enables WhatsApp notifications, to send order updates, receipts or booking confirmations to guests who gave their number.

We may also disclose data when required by law, to protect the rights or safety of people or of AirQR, or as part of a merger or sale of our business (in which case this policy continues to apply). We will tell you about any change to our sub-processors by updating this page.

Payments guests make to a restaurant — for example by UPI — go directly to the restaurant. We do not receive or hold guests' payment details.

7. Where data is stored and international transfers

Our providers run infrastructure in several countries, so your data may be stored or processed outside India, including in the United States, the European Union or Singapore. We transfer data only to countries not restricted by the Government of India under the DPDP Act. For users in the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses (and the UK addendum) or another lawful transfer mechanism offered by the provider.

8. How long we keep it

  • Account, restaurant and guest data — for as long as your account is active. If you cancel, your account stays readable for 30 days so you can export your data, and is then deleted.
  • Backups — encrypted backups rotate out within 30 days, so deleted data disappears from backups within that time.
  • Invoices and billing records — kept for 8 years, as required by Indian tax and accounting law, even after your account is deleted.
  • Server logs — kept for a short period for security and debugging, then deleted.

Restaurants can delete individual guest records at any time from the dashboard, and can export their data as CSV before they leave.

9. How we protect it

  • All traffic is encrypted in transit with HTTPS (TLS); data is encrypted at rest by our database and storage providers.
  • Row-level security in the database keeps each restaurant's data separated, so one account cannot read another's.
  • Role-based access inside each account — owners decide what managers, cashiers and kitchen staff can see and do.
  • Least-privilege access for our own team: only people who need production access have it, and we access customer data only to support you or fix a problem.
  • Passwords are hashed, never stored in plain text; secrets and keys are kept out of source code.

No system is perfectly secure. If a personal data breach affects you, we will notify you and, where required, the Data Protection Board of India and other authorities, without undue delay.

10. Your rights

Under India's DPDP Act, 2023

If you are in India, you have the right to:

  • Access — get a summary of the personal data we hold about you and how we use it, and who we have shared it with.
  • Correction and completion — fix inaccurate or incomplete data. Most account details can be edited in the dashboard.
  • Erasure — ask us to delete your data, unless we must keep it by law (for example invoices).
  • Withdraw consent — as easily as you gave it.
  • Grievance redressal — complain to our Grievance Officer, and if you are not satisfied, to the Data Protection Board of India.
  • Nominate — name another person to exercise these rights on your behalf in the event of your death or incapacity.

Under the GDPR and UK GDPR

If you are in the European Economic Area or the United Kingdom, you also have the right to data portability, to object to processing based on legitimate interests, to restrict processing, and to lodge a complaint with your local data protection authority. Similar rights may apply under other laws where you live; we honour them wherever reasonably possible.

How to make a request

Email abhishek@aivanaut.com from the address on your account (or tell us how to verify you). We may ask for proof of identity before acting. We do not charge for requests and reply within 30 days.

11. If you are a guest of a restaurant

If you ordered, booked or joined a loyalty programme at a restaurant that uses AirQR, that restaurant controls your data. Please send requests to access, correct or delete it — or to stop marketing messages — to the restaurant first. Each restaurant is responsible for its own privacy notice to guests.

If you cannot reach the restaurant, or are unhappy with its response, write to us with the restaurant's name and the phone number or email you used. We will pass your request to the restaurant and help it respond, and where appropriate we will act on it directly.

12. Children

AirQR accounts are for businesses and for people aged 18 or over. We do not knowingly collect data from children through our own website or sign-up. Restaurant pages are meant for guests who can place orders on their own or with a parent or guardian; if you believe a child's data has been given to us, contact us and we will delete it.

13. Grievance Officer

In line with the DPDP Act and the Information Technology Act, 2000 and its rules, our Grievance Officer handles privacy questions and complaints:

We acknowledge complaints within 48 hours and resolve them within 30 days of receipt.

14. Changes to this policy

We will update this policy as AirQR and the law change. The date at the top shows when it last changed. If a change is significant, we will email account owners or show a notice in the dashboard at least 15 days before it takes effect.

15. Contact us

Questions about this policy or your data:

See also our Terms of service and Acceptable use policy.