Privacy Policy
How Qmanja Loyalty collects, uses and protects the personal data of brand operators and their guests.
1. Who we are
Qmanja Loyalty is a product of Qmanja Solutions (“we”, “us”, “our”), a technology company based in India that builds software for restaurant chains. This policy describes how we process personal data through the Qmanja Loyalty platform, including our web dashboard and loyalty API.
This policy applies to:
- Brand operators — businesses and their staff who use the Qmanja Loyalty dashboard and API to run a loyalty programme.
- Loyalty guests — the end customers of those restaurant brands who participate in the loyalty programme by providing their phone number at a point of sale.
- Visitors — anyone who browses our public-facing website.
2. Data we collect
2.1 From brand operators (dashboard users)
- Account data: full name, work email address, and a hashed password when you create an account.
- Organisation data: brand name, outlet names and cities, subscription tier and status.
- Enquiry data: name, email, company, phone and message when you submit a contact form or trial request.
- Usage data: IP address, browser type, and pages visited — collected automatically via server logs when you use the dashboard.
- API key identifiers: we store the scoped API keys you generate (in hashed form). We cannot retrieve the plaintext key after it is issued to you.
2.2 From loyalty guests (your customers)
When a loyalty transaction is processed at a connected point of sale, we receive and store:
- Phone number — the sole identifier used to link a guest to their point balance. We do not require or collect a guest's name, email address, payment card details, or order contents.
- Transaction data — the outlet ID, order reference, transaction amount, points awarded or redeemed, transaction type (earn / redeem / void / expiry), timestamp, and the applied earn multiplier.
- Point balance — the running total of a guest's accumulated points with a given brand.
2.3 Automatically collected data
- Server access logs (IP address, request path, HTTP method, response status, user-agent string) retained for up to 30 days for security and debugging.
- Session cookies required for dashboard authentication (see Section 8).
3. How we use data
3.1 Brand operator data
- To create and maintain your account and subscription.
- To provide the loyalty dashboard and API services.
- To send transactional emails (OTP codes, account notifications, trial welcome messages).
- To respond to support enquiries and contact form submissions.
- To detect and prevent fraud and abuse.
- To comply with legal obligations.
3.2 Loyalty guest data
- To operate the loyalty programme on behalf of the brand operator (the data controller for the guest relationship).
- To calculate and record earn, redeem, and expiry transactions.
- To return a guest's current point balance when queried by a connected POS.
- To generate analytical reports for the brand operator (e.g., liability summaries, transaction exports).
We act as a data processor with respect to loyalty guest data. The brand operator is the data controller and is responsible for obtaining any required consents from their guests.
3.3 We do not
- Sell, rent, or otherwise trade personal data to third parties.
- Use guest transaction data for targeted advertising.
- Build marketing profiles on loyalty guests.
- Combine guest phone numbers with external data sources.
4. Data sharing
We share personal data only in the following limited circumstances:
- Google Cloud Platform — our infrastructure provider. All data is stored in Google Cloud Firestore. Google processes this data on our behalf under a Data Processing Agreement.
- Email service provider — for sending transactional emails. Email addresses are shared only for the purpose of delivering the specific email requested.
- Brand operators — a brand operator can query the point balance and full transaction history for any guest who has transacted at their outlets. They cannot access data belonging to other brands.
- Legal requirements — we may disclose data where required by applicable Indian law, court order, or to protect the rights, property, or safety of Qmanja Solutions, our users, or others.
We do not transfer personal data outside India to countries that do not provide an adequate level of data protection, except as necessary to use Google Cloud Platform services (whose data centres may be located globally).
5. Data retention
- Operator accounts: retained for the duration of the active subscription, and for up to 3 years after account closure (for legal and audit purposes).
- Loyalty guest data: retained for the lifetime of the brand’s subscription, and for up to 3 years after the brand closes its account. Guest phone numbers and transaction records are deleted together.
- Enquiry and contact data: retained for up to 2 years from the date of submission.
- Server access logs: retained for up to 30 days.
You may request earlier deletion (see Section 7).
6. Security
We take reasonable technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:
- All data encrypted at rest by Google Cloud (AES-256).
- All data in transit over TLS 1.2 or higher.
- Passwords stored as salted hashes; API keys stored in hashed form.
- Scoped API keys that limit each outlet’s access to its own data only.
- Short-lived JWT session tokens with rotate-on-use refresh tokens.
- Role-based access controls in the dashboard.
No method of electronic transmission or storage is 100% secure. If you discover a potential security vulnerability, please contact us at admin@qmanja.com before disclosing it publicly.
7. Your rights
Subject to applicable law, you have the following rights in relation to your personal data:
- Access: request a copy of the data we hold about you.
- Correction: ask us to correct inaccurate or incomplete data.
- Erasure: ask us to delete your data (subject to legal retention obligations).
- Portability: receive your data in a structured, machine-readable format.
- Objection: object to processing based on legitimate interests.
- Withdrawal of consent: where processing is based on consent, withdraw it at any time.
To exercise any of these rights, email admin@qmanja.com with your full name and the nature of your request. We will respond within 30 days.
If you are a loyalty guest of a brand that uses Qmanja Loyalty, we recommend contacting the restaurant or brand directly for data requests, as they are the data controller for your guest relationship.
8. Cookies
We use the following cookies on our platform:
- Authentication cookie (strictly necessary) — stores your login session. Required for the dashboard to function. Duration: session or up to 30 days if “stay signed in” is selected.
- Anti-forgery token (strictly necessary) — a short-lived cookie used to prevent cross-site request forgery on forms. Duration: session.
- reCAPTCHA cookies (functional) — set by Google reCAPTCHA v3 on contact forms to distinguish humans from bots. Subject to Google’s Privacy Policy.
We do not use analytics cookies, advertising cookies, or third-party tracking cookies on the dashboard or marketing site.
9. Children
Qmanja Loyalty is a business-to-business service intended for use by restaurant operators and their staff. We do not knowingly collect personal data from individuals under the age of 18. If you believe we have inadvertently collected data from a minor, please contact us immediately at admin@qmanja.com.
10. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this page and, where required by law, notify affected users by email. Continued use of the platform after the effective date constitutes acceptance of the revised policy.
11. Contact us
For questions, complaints, or data requests related to this Privacy Policy, please contact:
We aim to respond to all privacy-related enquiries within 30 calendar days.