Back
Qordrz

Privacy Policy

Last updated: September 9, 2026

1. Who we are

Qordrz ("we", "us", "our") is a QR-based digital ordering platform for physical businesses, operated at qordrz.me. This policy explains how we collect, use, store, and protect your personal data when you use our platform as a customer, merchant, or visitor.

2. Data we collect

We collect the following categories of personal data:

  • Account data: Name, email address, mobile number, and hashed password when you create an account.
  • Order data: Items ordered, order amounts, payment status, pickup PINs, table numbers, and order notes.
  • Payment data: We do not store your card numbers or UPI credentials. All payments are processed securely through Razorpay, a PCI-DSS compliant payment gateway. We only store Razorpay order and payment reference IDs.
  • Location data: Approximate location (latitude and longitude) only when a shop has delivery-zone restrictions enabled and you place an order. This is not stored permanently.
  • Device data: Push notification subscription tokens if you opt in to order-ready notifications.
  • Usage data: Pages visited, features used, error logs, and performance metrics for improving the platform.

3. How we use your data

  • To create and manage your account
  • To process and fulfill your orders
  • To send transactional emails (order confirmations, payment receipts, order-ready notifications, password resets)
  • To send daily sales summaries to merchants who opt in
  • To prevent fraud and abuse (rate limiting, audit logs)
  • To improve platform performance, fix bugs, and develop new features

We do not sell, rent, or trade your personal data to third parties. We do not use your data for advertising or profiling.

4. Data sharing

We share your data only in the following limited circumstances:

  • With the merchant you order from: Your name, mobile number, order details, and pickup PIN are shared with the shop to fulfill your order.
  • Payment processor (Razorpay): Order amounts and payment details are shared with Razorpay to process your payments.
  • Email delivery (Gmail SMTP): Your email address is used to send transactional emails via our mail service.
  • Error tracking (Sentry): Anonymous error and performance data may be sent to Sentry for monitoring platform health.
  • Legal requirements: We may disclose data if required by law, court order, or government regulation.

5. Data security

We take security seriously and implement the following measures:

  • All passwords are hashed using bcrypt before storage — we never store plaintext passwords
  • Sensitive merchant credentials (payment gateway keys) are encrypted at rest using AES-256-GCM
  • All data transmitted between your browser and our servers is encrypted via HTTPS/TLS
  • Payment signature verification uses HMAC-SHA256 with timing-safe comparison
  • API rate limiting prevents brute-force and abuse attacks
  • Role-based access control ensures merchants can only access their own shop data
  • All sensitive actions are recorded in an immutable audit log

6. Data retention

  • Account data: Retained as long as your account is active. You may request deletion at any time.
  • Order data: Retained for merchants' operational and accounting purposes. Abandoned unpaid orders are automatically deleted after 30 minutes.
  • Audit logs: Retained for security and compliance purposes.
  • Push tokens: Removed when you unsubscribe or when the subscription expires.

7. Your rights

Under the Digital Personal Data Protection Act 2023 (India), you have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate data
  • Erasure: Request deletion of your account and associated personal data
  • Grievance redressal: Raise concerns about our data handling practices

To exercise any of these rights, contact us at the email address listed below.

8. Cookies and local storage

We use browser local storage to maintain your login session (JWT token) and theme preference. We do not use third-party tracking cookies, advertising pixels, or analytics cookies. The platform functions with only essential, first-party storage.

9. Children's privacy

Qordrz is not directed at children under the age of 18. We do not knowingly collect personal data from minors. If we learn that we have collected data from a child, we will promptly delete it.

10. Changes to this policy

We may update this privacy policy from time to time. Material changes will be communicated by updating the "Last updated" date at the top of this page. Continued use of the platform after changes constitutes acceptance of the revised policy.

11. Contact

For privacy-related questions, data access requests, or concerns, contact us at:

Email: shivaganesh1080@gmail.com