1. Who we are
QR Express is operated by BYTEGEARS LTD, registered in England and Wales under company number 12638514, with its registered office at 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom.
BYTEGEARS LTD is the data controller for information about website visitors, sales leads, venue account users, account administration, and billing. When QR Express processes a diner’s details to provide ordering, payment, loyalty, or related services for a venue, the venue is normally the data controller and BYTEGEARS LTD acts as its processor.
For privacy questions or requests, email contact@qrexpress.co.uk.
2. Information we collect
Website visitors and sales leads
When you contact us, start a signup, or send a plan enquiry, we may collect your name, business and contact details, venue count, current system, preferred billing period, launch timing, campaign or referrer information, and anything you add to the message field.
With your consent, we also collect limited website analytics such as pages viewed, approximate location, referrer, device, and browser information. See our Cookie Policy.
Venue account users
We process account contact details, business and billing information, authentication data, product settings, usage logs, and support correspondence. Payment providers hold full card details; QR Express receives only the metadata needed to identify and manage the transaction.
Diners and guests
Depending on the features configured by a venue, we may process a diner’s name or contact details, order content, table or collection details, loyalty activity, transaction metadata, timestamps, and device information. We process this information on the venue’s instructions.
3. Why we use information
We use personal data to:
- provide and secure QR Express, manage accounts, and fulfil our contracts;
- respond to enquiries and help venues choose, set up, and use the service;
- process orders and related venue workflows on a venue’s instructions;
- meet legal, accounting, and fraud-prevention obligations;
- send requested or consented marketing, which you can opt out of at any time; and
- understand and improve our website when you consent to analytics.
Our lawful bases are performance of a contract, legitimate interests, consent, and legal obligation, depending on the activity.
4. Who receives information
We disclose personal data only where it is needed to operate the service or meet a legal obligation. Recipients may include:
- Cloudflare and other hosting, content-delivery, and infrastructure providers;
- PostHog’s EU service for consented analytics and our self-hosted website statistics service;
- payment providers selected for a customer or diner payment flow;
- email and communications infrastructure used to deliver requested messages;
- professional advisers acting under confidentiality duties; and
- regulators, courts, or public authorities where the law requires it.
Our sales enquiries are routed through infrastructure we control to our internal systems. A current list of processors is available on request.
5. International transfers
BYTEGEARS LTD is based in the United Kingdom and serves customers in the UK and EEA. Where personal data crosses borders, we use a lawful transfer mechanism, such as an adequacy decision, the UK transfer addendum, or the European Commission’s Standard Contractual Clauses, as applicable.
6. How long we keep information
- Unconverted sales leads: 24 months after the last meaningful interaction. We may retain a minimal suppression record to respect an opt-out.
- Active venue accounts: for the life of the account. After closure, ordinary account, operational, order, and diner data remains available for a 30-day read-only export period, then is deleted or anonymised.
- Contracts, invoices, payment records, and evidence needed for legal claims: 6 years.
- Routine support correspondence: 24 months after a case closes. Dispute, security, and payment evidence may be retained for 6 years.
- Event-level analytics: 14 months. Genuinely anonymous aggregate statistics may be kept without a fixed expiry.
- Encrypted rolling backups: no more than 90 days. Backups are access-restricted, and deleted data is removed again if a backup is restored.
7. Your rights
Depending on the circumstances, you can ask us to provide, correct, delete, restrict, or transfer your personal data, or object to its use. You can withdraw consent at any time without affecting earlier lawful processing.
Email contact@qrexpress.co.uk to make a request. If your request concerns data held by a venue, we may direct you to that venue. You can also complain to the UK Information Commissioner’s Office at ico.org.uk.
8. Security
We use technical and organisational safeguards appropriate to the risk, including encryption in transit, access controls, credential protection, monitoring, and backups. No online service can guarantee absolute security.
9. Children
QR Express is a business service for hospitality operators and is not directed at children. If you believe a child has given us personal data inappropriately, contact us so we can investigate and remove it.
10. Changes and contact
We may update this policy as our service or legal obligations change. The date above shows the latest revision.
BYTEGEARS LTD
27 Old Gloucester Street, London, WC1N 3AX, United Kingdom
Email: contact@qrexpress.co.uk