Privacy Policy
Last updated: January 1st, 2026
CafeQR
At CafeQR, we respect your privacy and are committed to protecting the information you provide. This Privacy Policy explains how information is collected, used, stored, and protected when café owners, staff, and customers interact with the CafeQR platform.
Overview of CafeQR
CafeQR is a QR code-based customer rewards system designed for cafés. Customers scan QR codes placed on to-go items to earn reward points, receive instant prizes, and enter monthly prize draws. Café owners use the CafeQR dashboard to manage QR codes, rewards, analytics, and subscriptions.
CafeQR is designed to collect only the minimum amount of information required to operate the rewards system accurately, fairly, and securely.
Information We Collect
- Café Owner Information: Email address, café name, authentication credentials, and billing-related identifiers required to manage subscriptions and dashboard access.
- Customer Information: Customers are not required to create accounts. An email address may be collected only when a customer claims a reward or prize.
- QR Code Scan Data: Each scan is recorded to track reward points, prize eligibility, and prevent duplicate or fraudulent claims.
- Redemption Data: Redemption status and timestamps are recorded to ensure rewards are redeemed only once.
- Analytics Data: Aggregated metrics such as scan counts, reward redemptions, and engagement trends.
How We Use Information
- To operate the CafeQR rewards, gamification, and prize systems.
- To provide café owners with analytics and engagement insights.
- To manage subscriptions, billing status, and account access.
- To prevent fraud, duplicate scans, invalid redemptions, and abuse.
- To provide customer and café owner support when needed.
Customer Experience and Anonymity
Customers can participate in CafeQR without creating accounts or passwords. Beyond the email required to deliver prizes, CafeQR does not build persistent customer profiles.
Reward histories are tied to QR scan activity and prize delivery, not to long-term personal identifiers.
Staff Access and In-Store Use
Café staff interact with CafeQR only during in-store reward redemption. Staff members scan customer prize QR codes to confirm validity and redemption status.
Staff do not have access to customer email addresses, reward histories, analytics dashboards, or billing information unless they are also the account owner.
Dashboard and Analytics
Café owners can view aggregated analytics related to scans, rewards, and engagement through the CafeQR dashboard.
Analytics do not expose customer identities beyond the email required for prize delivery.
What We Do Not Collect
- No customer passwords or login credentials
- No precise location or GPS tracking
- No advertising or behavioral profiling data
- No social media account data
- No device fingerprinting or cross-site tracking
Account Security and Authentication
CafeQR uses industry-standard encryption and authentication practices to protect accounts. Password recovery links may expire for security reasons.
Access to data is restricted to authorized systems and personnel only.
Payments and Billing
CafeQR uses Stripe to process payments securely. CafeQR does not store full payment card details.
Billing data is subject to Stripe’s privacy and security policies.
Data Storage and Retention
Data is stored on secure servers located in Canada. QR scan data and reward histories are retained to ensure accurate tracking and system integrity.
Upon subscription cancellation, data may be retained temporarily for operational or support purposes and may later be deleted or anonymized.
Cookies and Tracking
CafeQR uses only essential cookies and session data required for core functionality. No advertising or behavioral tracking cookies are used.
Legal Basis for Processing
CafeQR processes data solely to provide the services requested by café owners and customers, including rewards delivery, analytics, and account management.
Data Sharing
- No sale or rental of personal data.
- Limited sharing with trusted service providers for hosting, email delivery, and payment processing only.
- Use of aggregated, anonymized data for internal improvements.
Your Rights and Choices
- Café owners can manage account details through the dashboard.
- Customers may request deletion of their email and reward data.
Changes to This Privacy Policy
Updates to this policy will be posted on this page with a revised “Last updated” date. Continued use of the platform constitutes acceptance of the updated policy.
Contact Us
Questions or concerns about privacy can be sent to cafeqr.app@gmail.com.
© 2026 CafeQR