QoreGlow

Privacy Policy

Effective: 2026-09-17 · Last updated: 2026-09-17 · Version: 1.0 (pilot)

QoreGlow provides a table-ordering platform used by restaurants. This policy explains the categories of information processed through the platform, why they are processed, and how requests and enquiries can be raised. It applies to restaurant owners and their staff who hold QoreGlow accounts, and to diners who scan a table QR code to order.

Roles of the restaurant and QoreGlow

The restaurant decides to use the platform for its own tables, menu and service, and controls the information created in the course of that service. QoreGlow provides and operates the technology on the restaurant's behalf and processes information in order to deliver, secure and improve the service.

Restaurant account information

When a restaurant account is created, the platform stores the information needed to operate it:

  • Full name, email address and, where provided, phone number.
  • Preferred language (English or Arabic).
  • Sign-in credentials held by the authentication service; passwords are never visible to QoreGlow staff.
  • Membership of a restaurant and, for staff, of specific branches, together with the assigned role (owner, branch manager, kitchen, waiter or cashier).

Restaurant business information

The platform stores the operational content a restaurant enters or generates: restaurant and brand names, logos, branches, tables and their QR codes, menu categories, items, options and prices, orders and their status history, table visits and bills, service requests, operational analytics, and subscription and plan information. This content belongs to the restaurant.

Guest and table-order information

Guests do not create an account and are not asked for a name, phone number or email address in order to place a table order. What the platform stores for a table visit is operational rather than identifying:

  • The table visit itself: which table, when it opened, activity and closing time, bill number and payment state.
  • A random device code stored in the guest's own browser so that the same phone stays attached to the same table visit. It is a random string, not a name or an account.
  • Orders placed from the table: items, options, quantities, any special instructions typed by the guest, prices and totals.
  • Service requests such as calling a waiter or asking for the bill, and the timestamps of each step.

Special instructions written by guests

The special-instructions field is optional and free text. It is intended for preparation notes such as "no onions". Guests should not enter personal or sensitive information there; whatever is entered is sent to the restaurant's kitchen and stored with the order.

Technical and security information

To keep the service available and protected, the platform records sign-in activity handled by the authentication service, administrative audit records of sensitive actions, diagnostic and error records, counters used to limit abusive or excessive requests, and metadata about files uploaded by restaurants such as menu images and logos.

Payments

QoreGlow does not process online card payments and does not collect card numbers, bank details or wallet credentials through the platform. Guest payment happens offline with the restaurant — at the counter or with a waiter. The platform only records that a visit was marked as paid, the method the restaurant selected and the amount recorded by restaurant staff.

Why information is processed

Processing is carried out to provide the service requested by the restaurant, to pursue the legitimate operation and security of the platform, and to comply with applicable legal requirements. Consent is not treated as the basis for ordinary service operation.

  • To deliver the ordering, kitchen, service and billing features the restaurant has subscribed to.
  • To authenticate users and keep accounts and restaurant data separated and secure.
  • To detect, prevent and investigate misuse, fraud and abusive traffic.
  • To operate, troubleshoot and improve the service, including aggregate usage measurement.
  • To administer restaurant subscriptions, plans and entitlements.
  • To meet obligations that apply to the service under applicable law.

Sharing

Information is shared with the restaurant whose tables, menu and orders it concerns, and with the technology providers that host and operate the platform — cloud hosting, database, authentication, file storage and email delivery for account messages. These providers act on QoreGlow's instructions. Information may also be disclosed where required by a competent authority or applicable law. QoreGlow does not sell personal information and does not share it with advertising networks.

Security

The platform enforces access control at the database level so each restaurant reaches only its own data, requires authentication for staff features, restricts platform administration to authorised QoreGlow personnel, applies request rate limits, keeps uploaded files in private storage, and serves the application over encrypted connections with hardened browser security policies. No service can guarantee absolute security, and access to a restaurant's account also depends on the restaurant protecting its own credentials.

Retention

Information is retained only for as long as reasonably necessary for the operation of the service, the security of the platform, the contractual relationship with the restaurant, and any applicable legal or regulatory requirement. A formal retention schedule is being prepared and will be published in this policy once approved. Specific periods are not stated here because none have been approved yet.

Your requests and rights

Subject to applicable law, including the Personal Data Protection Law of the Kingdom of Saudi Arabia, individuals may ask to access information relating to them, to have inaccurate information corrected, to have information deleted where the request can lawfully be met, to raise a privacy enquiry, or to make a complaint. Automated self-service privacy tools are not part of the platform yet; requests are handled by the QoreGlow team through the privacy contact below. Requests concerning a specific restaurant's own records may need to be directed to that restaurant, and QoreGlow will assist it in responding.

Cookies and browser storage

The platform uses only storage that is strictly necessary for it to work: the sign-in session for staff accounts, the random table-visit device code for guests, the draft cart on the guest's own device, and preferences such as language, selected branch and kitchen sound. There are no advertising cookies, no third-party trackers and no optional analytics scripts.

Children

The platform is designed for restaurants and their staff, and for diners ordering at a table. It is not directed at children, and QoreGlow does not knowingly create accounts for them.

Changes to this policy

This policy may be updated as the service develops. The effective date and version shown at the top of the page always identify the current wording, and material changes will be communicated to restaurant account holders.

Contact

Legal entity
Qoreventa Global Company
Support
Contact@qoreglow.com
Privacy requests
Contact@qoreglow.com
Phone
+966 55 414 5001