

QUARTROS — PRIVACY POLICY
Effective date: June 25, 2025
Last updated: June 25, 2025
Website: https://quartros.in
Contact: info@quartros.in
================================================================
This Privacy Policy describes how Quartros (“we,” “us,” or “our”) collects, uses, stores, shares, and protects information when you use the Quartros mobile application (the “App”) on Android devices.
The App is a business-to-business (B2B) restaurant operations platform intended for authorized restaurant staff (such as waiters, kitchen staff, managers, administrators, and HR personnel) employed by or contracted with restaurants that subscribe to Quartros (“Restaurant” or “Tenant”). The App is not intended for use by children and is not directed at the general public as a consumer application.
By downloading, installing, or using the App, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the App.
NOTE: Requesting data deletion: To delete your account or associated personal data, email info@quartros.in with the subject “Data Deletion Request.” See Account and Data Deletion for details.
1. WHO WE ARE (DATA CONTROLLER)
----------------------------------------------------------------
For purposes of applicable privacy laws, Quartros is the data controller for information processed through the App and our backend services.
Product name — Quartros
Website — https://quartros.in
Privacy contact — info@quartros.in
Support contact — info@quartros.in
NOTE: Note for Restaurant operators: Your Restaurant may also act as an independent controller for certain customer and employee data you enter into the App. Section 8 explains this relationship.
2. SCOPE OF THIS POLICY
----------------------------------------------------------------
This policy applies to:
• The Quartros Android mobile application
• Our API and cloud backend used by the App (e.g., https://api.quartros.in)
• Push notification delivery infrastructure connected to the App
This policy does not cover:
• Third-party payment apps you may open from the App (such as UPI wallet apps)
• Websites or services operated by your Restaurant outside Quartros
• The separate guest-ordering experience your Restaurant may offer to its diners (if applicable)
3. INFORMATION WE COLLECT
----------------------------------------------------------------
We collect information in the categories below. Some information is provided by you or your Restaurant administrator; some is collected automatically when you use the App.
3.1 Account and Staff Information
When you log in or when your Restaurant administrator creates your account, we may process:
• Full name
• Mobile phone number (used as login identifier)
• Staff role (e.g., waiter, kitchen, manager, admin, HR)
• Branch / outlet assignment
• Employment-related data visible in the App (such as salary configuration, leave records, and attendance status), as configured by your Restaurant
Authentication credentials: You sign in using a phone number and passcode. Passcodes are stored on our servers in hashed form. Session tokens are issued to keep you signed in.
3.2 Restaurant and Business Information
Depending on your role and Restaurant configuration, the App may process:
• Restaurant / outlet name, address, contact details, GSTIN, FSSAI number, and billing settings
• Menu items, pricing, tables, stock/inventory, offers, and operational configuration
• Restaurant logo images uploaded for receipts and bills
• Subscription and licensing information for Quartros services
3.3 Customer Information (Entered by Restaurant Staff)
Restaurant staff may use the App to create and manage diner/customer records, including:
• Customer name
• Mobile phone number
• Email address (optional)
• Date of birth / birthday (optional)
• Loyalty card identifiers and QR codes
• Loyalty points, stored balance, order count, and spending history
• Order and payment details linked to the customer
Important: This customer information is generally entered and controlled by the Restaurant. Quartros processes it on the Restaurant’s behalf to provide the service.
3.4 Order, Payment, and Operational Data
When you use the App during restaurant operations, we may process:
• Orders (items, quantities, modifications, status, timestamps)
• Table or service location labels (e.g., “Table 5”, “Terrace”) — not GPS coordinates
• Payment method selections and transaction references
• Bills, receipts, discounts, offers applied, and tax details
• Kitchen/production workflow events and alerts
• Attendance check-in/check-out records and shift/roster data
• Internal notes and operational logs generated through normal App use
3.5 Device and Technical Information
We may automatically collect or generate:
• Device push notification token (Firebase Cloud Messaging / FCM token on Android) to deliver order and operational alerts
• Device platform type (e.g., Android)
• Network connectivity status (to queue requests when offline and retry when online)
• App version and basic diagnostic logs (e.g., error messages, connection failures)
• Saved printer pairing details (such as Bluetooth printer name and MAC address) stored locally on your device for receipt printing
• Local app preferences and session cache (such as selected branch, notification onboarding state, and UI acknowledgements)
3.6 Camera and Photos (On-Device Processing)
The App may request access to:
• Camera — to scan customer loyalty QR codes. The camera feed is used to decode QR data on your device; we do not use the camera for facial recognition, and we do not routinely upload raw camera images to our servers as part of QR scanning.
• Photos / media library — to let authorized users upload a Restaurant logo image for bills and receipts. Uploaded images are transmitted to our servers and associated with the Restaurant account.
3.7 Bluetooth, USB, and Location-Related Permissions
The App supports thermal receipt printers and may request:
• Bluetooth / Bluetooth Admin / Bluetooth Connect / Bluetooth Scan — to discover and connect to paired printers
• USB host access — for compatible USB thermal printers
• Location permissions on Android — required by the Android operating system for Bluetooth device discovery on many devices. We do not use these permissions to collect or store your GPS location on our servers. Location permission is used only to enable Bluetooth printer scanning/connectivity as permitted by Android.
3.8 Clipboard Access
The App may copy certain text to your device clipboard at your direction (for example, a UPI payment ID), so you can paste it into a payment app. We do not continuously read clipboard contents in the background.
4. HOW WE USE INFORMATION
----------------------------------------------------------------
We use collected information to:
• Provide and operate the App — authentication, order management, billing, kitchen workflows, stock, reporting, attendance, and related restaurant operations
• Enable real-time features — live order updates via WebSocket connections and push notifications
• Print receipts — connect to Bluetooth/USB thermal printers you configure
• Support Restaurants — troubleshooting, service reliability, and customer support
• Maintain security — fraud prevention, access control, session management, and abuse detection
• Improve the service — diagnose errors, monitor uptime, and enhance performance
• Comply with law — respond to lawful requests and enforce our terms
We do not use your information to serve third-party advertising in the App, and we do not sell personal information.
5. LEGAL BASES FOR PROCESSING (WHERE APPLICABLE)
----------------------------------------------------------------
Depending on your jurisdiction, we rely on one or more of the following legal bases:
• Contract — processing necessary to provide the App and Quartros services to your Restaurant and authorized staff
• Legitimate interests — securing our systems, preventing misuse, and improving reliability, balanced against your rights
• Legal obligation — compliance with applicable laws, tax, or regulatory requirements
• Consent — where required for optional permissions (such as notifications, camera, photos, or Bluetooth), which you may withdraw through device settings
For customer data entered by Restaurants, the Restaurant is typically responsible for determining the appropriate legal basis under applicable law.
6. HOW WE SHARE INFORMATION
----------------------------------------------------------------
We may share information only as described below:
6.1 With Your Restaurant (Tenant)
Information you enter or generate in the App is available to authorized users within your Restaurant’s Quartros account according to role permissions.
6.2 With Service Providers (Processors)
We use trusted third-party providers to help operate the App, including:
Provider — Purpose — Typical data involved
Google Firebase Cloud Messaging (FCM) — Deliver push notifications to Android devices — Device push token, notification payload metadata
Cloud hosting / infrastructure providers — Host API, database, and file storage — Account, business, order, and customer data stored by the service
Expo / EAS (build and notification infrastructure) — App build and notification tooling where applicable — Device identifiers/tokens as needed for notification delivery
These providers are permitted to process data only to perform services for us and are required to protect it appropriately.
6.3 For Legal and Safety Reasons
We may disclose information if we believe in good faith that disclosure is necessary to:
• Comply with applicable law, regulation, legal process, or governmental request
• Enforce our agreements or protect the rights, property, or safety of Quartros, Restaurants, users, or others
• Detect, prevent, or address fraud, security, or technical issues
6.4 Business Transfers
If Quartros is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to continued protection consistent with this policy.
We do not sell or rent personal information to third parties for their marketing purposes.
7. DATA STORAGE, SECURITY, AND RETENTION
----------------------------------------------------------------
7.1 Where Data Is Stored
Information is stored on secure servers operated by us or our infrastructure providers. Data may be processed and stored in India and/or other countries where our providers maintain facilities. Where required, we implement appropriate safeguards for cross-border transfers.
7.2 Local Storage on Your Device
The App stores certain data locally on your device using secure storage mechanisms (such as AsyncStorage), including:
• Authentication session token
• Selected branch ID
• Push notification token (cached)
• Saved thermal printer connection details
• Limited offline request queue and UI preferences
You can remove most local data by logging out and/or clearing the App’s storage from Android settings. Uninstalling the App removes local data from the device.
7.3 Security Measures
We implement administrative, technical, and organizational measures designed to protect information, including:
• Encrypted transport (HTTPS/TLS) for network communication
• Hashed passcodes
• Role-based access controls
• Authentication tokens for API access
• Rate limiting and security headers on our servers
No method of transmission or storage is 100% secure. Please use a strong passcode and do not share your login credentials.
7.4 Retention
We retain information for as long as necessary to:
• Provide the App and Quartros services to your Restaurant
• Meet contractual, accounting, tax, or legal obligations
• Resolve disputes and enforce agreements
Retention periods may vary by data type and Restaurant subscription status. When data is no longer needed, we delete or anonymize it in accordance with our retention practices, unless law requires longer retention.
8. RESTAURANT AS CONTROLLER; STAFF AND CUSTOMER RIGHTS
----------------------------------------------------------------
8.1 Restaurant Responsibilities
If you are restaurant staff, your Restaurant decides which features to use and what customer/employee information to enter. The Restaurant is responsible for:
• Providing appropriate notice to its staff and customers, where required
• Collecting information lawfully (including valid consent where needed)
• Responding to customer requests regarding customer records the Restaurant controls
8.2 Your Rights
Depending on applicable law (including India’s Digital Personal Data Protection Act, 2023, where applicable), you may have rights such as:
• Access — request information about personal data we process about you
• Correction — request correction of inaccurate information
• Erasure — request deletion, subject to legal/contractual limits
• Withdraw consent — for permission-based processing via device or in-app controls
• Grievance redressal — lodge a complaint with us and, where applicable, with supervisory authorities
To exercise rights related to your staff account, contact us at info@quartros.in. For customer records, contact the Restaurant that collected the data; we will assist the Restaurant where required.
We will verify requests and respond within timelines required by applicable law.
8.3 Account and Data Deletion
You can request deletion of your account and the personal data associated with it.
How to request deletion. Send a request by email to info@quartros.in with the subject line “Data Deletion Request.” Please send it from the email or phone number linked to your account, and include enough detail for us to identify the relevant account or records (such as your name, registered phone number, and Restaurant name).
How requests are handled. Deletion requests are currently processed on demand by the Quartros platform team. We verify the request, then delete or anonymize the associated personal data, subject to the retention limits described in Section 7.4 (for example, records we must keep for accounting, tax, or legal obligations). We aim to action verified requests within 30 days, or the period required by applicable law.
Staff accounts and customer records. Your Restaurant administrator can also deactivate or remove staff accounts directly; you may additionally contact us to delete personal data tied to your staff account. Because customer information is controlled by the Restaurant (see Section 8.1), requests to delete customer records should be directed to the Restaurant that collected them, and we will assist the Restaurant in fulfilling such requests where required.
What deletion covers. A completed deletion removes or anonymizes the personal data we hold for the account, except data we are required or permitted to retain under applicable law or for legitimate business purposes (such as financial records and fraud prevention).
Self-service deletion (coming soon). We are building an in-app and online option to submit deletion requests directly. Until it is available, the email process above is the way to request deletion.
9. PERMISSIONS AND YOUR CHOICES
----------------------------------------------------------------
You can control many permissions through Android settings:
Permission — Why the App requests it — Your choice
Internet / Network state — Connect to Quartros servers — Required for core functionality
Notifications — Order and operational alerts — Optional; can be disabled in system settings
Camera — Scan loyalty QR codes — Optional; required only for QR features
Photos / media — Upload Restaurant logo — Optional; required only when uploading
Bluetooth (+ related) — Connect to thermal printers — Optional; required only for printing
Location (Android) — Bluetooth printer discovery — Optional; required only for Bluetooth printing on many Android devices
USB — USB thermal printer support — Optional
If you deny optional permissions, some features may not work, but core login and order features may still function depending on your role and Restaurant setup.
You may log out at any time to end your session and remove the auth token from the device (push token deregistration is attempted on logout).
10. PUSH NOTIFICATIONS
----------------------------------------------------------------
With your permission, we send push notifications about restaurant operations (for example, new orders or kitchen alerts) using Firebase Cloud Messaging (FCM). Notification payloads may include order identifiers and summary text needed to open the relevant screen in the App.
You can disable notifications in Android system settings at any time.
11. CHILDREN’S PRIVACY
----------------------------------------------------------------
The App is intended for adult restaurant staff in a business context. It is not directed to children under 13 (or the minimum age required in your jurisdiction), and we do not knowingly collect personal information from children. If you believe a child has provided personal information through the App, contact info@quartros.in and we will take appropriate steps to delete it.
12. THIRD-PARTY LINKS AND PAYMENT APPS
----------------------------------------------------------------
The App may display payment details (such as UPI IDs) or open external payment applications installed on your device. Those third-party services are governed by their own privacy policies. Quartros does not control and is not responsible for their practices.
13. INTERNATIONAL USERS
----------------------------------------------------------------
The App is primarily designed for Restaurants operating in India, but may be accessed from other locations. If you use the App outside India, you understand that information may be transferred to and processed in countries that may have different data protection laws than your country.
14. CHANGES TO THIS PRIVACY POLICY
----------------------------------------------------------------
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice (such as in the App or via your Restaurant administrator). Continued use of the App after changes become effective constitutes acceptance of the updated policy.
15. CONTACT US
----------------------------------------------------------------
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, contact:
Quartros Privacy Team Email: info@quartros.in Support: info@quartros.in Website: https://quartros.in
For grievances under Indian law, you may also write to our Grievance Officer at the same email address with the subject line “Privacy Grievance.”
This document is provided for operational and app-store compliance purposes. It does not constitute legal advice. Consider having qualified counsel review it for your specific business structure, jurisdictions, and data flows before publication.