ScanPlzHome

Legal

Privacy
Policy

ScanPlz is a QR-based menu, ordering and service app used in restaurants, cafés and hotels. This policy explains what we collect when you scan a ScanPlz code, why we collect it, and how you can get it deleted.

Last updated: 5 August 2026

Who we are

ScanPlz (“ScanPlz”, “we”, “us”) provides the guest-facing QR menu and ordering service available at scanplz.com. When you scan a QR code at a venue, you use ScanPlz to browse that venue’s menu, place orders, call staff and leave feedback.

For the data you submit to a venue — your orders, service requests and feedback — that venue is the controller of the data and ScanPlz is the processor acting on its behalf. For your ScanPlz account (if you create one) we are the controller.

Privacy contact: [email protected].

What we collect

1. Without an account

You can browse a menu and order without signing in. In that case we store:

  • An anonymous session identifier — a random ID kept in your browser’s local storage (scanplz_session_id) so a cart and an order stay attached to the right device. It is not linked to your identity.
  • The scanned QR code — stored in a short-lived, httpOnly cookie (scanplz_qr_code, 10 minutes) so we know which venue and table you are at as you navigate.
  • Your cart — held in your own browser storage, not on our servers, until you place an order.
  • Order details you submit — items, quantities, notes, any tip, and the table or venue the order belongs to.
  • Service (bell) requests and feedback — the request type, ratings, and any comment you write.

2. If you create an account or sign in

  • Email address, and a password if you sign up with one (stored only as a hash).
  • Profile details you choose to give us: first name, last name, gender and date of birth.
  • Your order history and any loyalty points balance held for you.
  • If you sign in with Facebook, Google or Apple: the identifier that provider gives us for you, plus your name and email address where the provider shares them. We use this only to create and recognise your ScanPlz account. We never post to your social profile, never read your friends or contacts, and never receive your social password.

3. Usage and technical data

  • First-party product analytics: which menu, category or item you viewed, searches and filters you used inside the menu, items added to the cart, and orders placed. These events carry the anonymous session ID and the venue ID, and are sent to our own servers — we do not use third-party advertising or tracking networks.
  • Standard technical data handled by our hosting and API layer: IP address, browser user-agent, request timestamps and error logs, used for security, abuse prevention and debugging.

We do not collect precise location, we do not sell personal data, and we do not use your data for third-party advertising. Camera access, when you use the in-app QR scanner, happens entirely on your device — no image ever leaves your phone.

Why we use it

PurposeLegal basis (GDPR)
Showing the right menu and taking your orderPerformance of a contract
Account creation, sign-in and order historyPerformance of a contract
Service requests and feedback to the venueLegitimate interests of the venue
Product analytics and improving the appLegitimate interests
Fraud prevention, security and abuse limitsLegitimate interests / legal obligation
Keeping records of transactionsLegal obligation

Who we share it with

  • The venue you scanned. Your order, service request and feedback are shown to that venue’s staff so they can serve you.
  • Infrastructure providers that host and deliver the service on our instructions (cloud hosting, content delivery, image delivery, error monitoring).
  • Identity providers (Meta, Google, Apple) only when you choose to sign in with them.
  • Authorities where we are legally required to disclose.

We never sell or rent personal data.

How long we keep it

  • Anonymous session identifiers and cart data: until you clear your browser storage.
  • The QR cookie: 10 minutes.
  • Account data: until you delete your account.
  • Orders and payment records: retained for the period required by the venue’s tax and accounting obligations, in anonymised form once you delete your account.
  • Technical logs: a short rolling window for security and debugging.

Your rights

Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal data, and to object to processing based on legitimate interests.

  • Access and correction: sign in and open your account page.
  • Deletion: follow the steps on our data deletion page — you can delete your account yourself in the app, or ask us to do it for you.
  • Anything else: email [email protected] and we will respond within 30 days.

You also have the right to complain to your local data protection authority.

Security and transfers

All traffic is encrypted in transit over HTTPS. Passwords are stored only as salted hashes, and session tokens are held in httpOnly cookies that JavaScript cannot read. Our infrastructure providers operate globally, so your data may be processed outside your country under appropriate safeguards such as the EU Standard Contractual Clauses.

Children

ScanPlz is not directed at children under 13, and we do not knowingly collect their personal data. If you believe a child has given us data, contact us and we will delete it.

Changes to this policy

We will update this page when our practices change and revise the “last updated” date above. Material changes will be highlighted in the app.

Privacy PolicyDelete your data[email protected]