Last updated · 12 July 2026
Privacy Policy
This Privacy Policy explains how Qaris (“we”, “us”, “our”) collects, uses, stores, and shares personal data when you visit sufra.qaris.dev or qaris.dev, contact us, create a Sufra account, or use the Sufra restaurant operations platform (the “Service”). By using the Service or contacting us, you acknowledge this Policy.
1. Who we are
Sufra is a hospitality operations product provided by Qaris. For privacy questions, the data controller for website inquiries and account administration data we process directly is Qaris.
When a restaurant (“Venue”) uses Sufra, the Venue is typically the controller of guest and staff operational data processed inside its Sufra workspace. In that case, Qaris acts as a processor on the Venue’s documented instructions, except where we process data for our own legitimate purposes described below (for example billing, security, and product improvement).
2. Data we collect
Depending on how you interact with us, we may process:
- Identity and contact data — name, email address, phone number, restaurant/business name, city or neighborhood, and message content when you email or call us.
- Account data — owner and staff login identifiers, role (owner, waiter, kitchen), business ID, and authentication metadata.
- Venue configuration — menus, categories, tags, tables, QR settings, branding, language preferences, and business-day settings you enter into Sufra.
- Operational data — table sessions, orders, order status history, notes, checkout totals calculated in-app, and related timestamps.
- Technical data — IP address, device/browser type, approximate location derived from IP, cookies or similar identifiers, and security logs needed to operate and protect the Service.
- Communications — emails, support messages, and verification codes related to account or contact flows.
3. Guest ordering data
Guests who scan a table QR code may create a temporary table session and submit orders. We process session tokens, table identifiers, ordered items, and related timestamps to deliver the order to the Venue’s staff and kitchen tools.
Sufra does not process guest card payments. Payment collection remains the Venue’s responsibility through its own cash or card process. Do not send payment card numbers to us by email.
4. Why we process data (legal bases)
We process personal data only where we have a valid basis, including:
- Contract — to provide, configure, and support Sufra for Venues under our Terms of Service or a setup agreement.
- Legitimate interests — to secure the Service, prevent abuse/spam, improve reliability, and respond to serious misuse, balanced against your rights.
- Consent — where required for optional cookies or marketing communications (you may withdraw consent at any time).
- Legal obligation — where Georgian or other applicable law requires retention, disclosure, or cooperation with authorities.
5. How we use data
- Provide and operate Sufra workspaces, menus, tables, kitchen boards, and related features.
- Authenticate users, manage staff roles and permissions, and protect accounts.
- Respond to setup inquiries and support requests sent to contact@qaris.dev or by phone.
- Filter abusive, incomplete, or automated contact messages and protect our systems from spam and attacks.
- Monitor availability, diagnose faults, and improve the Service.
- Comply with law and enforce our Terms of Service.
6. Cookies and similar technologies
We use necessary cookies and similar storage to keep you signed in, remember language preference, and maintain secure sessions. These are required for the Service to function.
If we later use non-essential analytics or marketing cookies, we will update this Policy and, where required, request consent before enabling them.
7. Sharing and processors
We do not sell personal data. We share data only with trusted processors who help us run the Service (for example hosting, database, authentication, and transactional email providers), under contracts that require confidentiality and appropriate security.
We may disclose data if required by law, court order, or to protect the rights, safety, and integrity of Qaris, Venues, users, or the public.
Venue owners control staff accounts inside their workspace. Staff may access operational data according to roles the Venue assigns.
8. International transfers
Our infrastructure or processors may store or process data outside Georgia. Where we transfer personal data internationally, we use appropriate safeguards required by applicable law (such as contractual protections with processors).
9. Retention
We keep personal data only as long as needed for the purposes above: active account and Venue data for the life of the subscription plus a reasonable wind-down period; security and abuse logs for a limited period; and inquiry emails as needed to handle the request and defend legal claims.
Venues may delete or request deletion of workspace content subject to technical limits and legal retention duties. After account closure we delete or anonymize data within a commercially reasonable time unless law requires longer retention.
10. Security
We use administrative, technical, and organizational measures appropriate to the risk, including access controls, encrypted transport (HTTPS), tenant isolation controls, and authentication protections. No method of transmission or storage is 100% secure; you must keep passwords and staff credentials confidential.
11. Your rights
Subject to Georgian personal data protection law and other applicable law, you may have the right to request access, correction, deletion, restriction, or objection to certain processing, and to receive a portable copy of data you provided where applicable.
Venue guests and staff should first contact the Venue for operational data the Venue controls. For data we control directly (for example website inquiries or Qaris account admin records), email contact@qaris.dev with the subject line “Privacy request” and enough detail for us to verify and fulfill the request.
You may also lodge a complaint with the relevant supervisory authority in Georgia or your country of residence where applicable.
12. Children
Sufra is designed for restaurant businesses and adult staff. We do not knowingly collect personal data from children under 16. If you believe a child provided data to us, contact us and we will take appropriate steps to delete it.
13. Changes to this Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Material changes will be posted on this page. Continued use of the Service after the update means you accept the revised Policy, except where consent is required by law.