Who this policy covers
This policy applies to QwikPass websites, restaurant workspaces, guest queue passes, invoices, online-order pages and related support. A restaurant using QwikPass controls the business and customer information it enters. YK Builds operates the QwikPass platform and processes that information to provide the service.
Information we process
- Organization and restaurant information: business names, outlet locations, menus, prices, taxes, invoice settings, operating hours and plan details.
- Owner and staff information: name where provided, email address, authentication identifiers, role, Outlet assignments, security events and access changes.
- Guest and transaction information: private queue identifiers, optional name and phone number, order items, payment method confirmation, invoice details and preparation status.
- Loyalty information: when a customer chooses to identify a counter invoice by mobile number and the restaurant has activated loyalty, QwikPass automatically applies the Organization's configured earn rules and maintains an Organization-scoped keyed lookup, masked contact display, points balance and immutable earn, redeem or correction entries.
- Device and service information: limited browser, network, diagnostic and security data needed to operate, protect and troubleshoot QwikPass. QwikPass uses Firebase App Check with reCAPTCHA Enterprise to distinguish genuine web clients from automated abuse.
- Messages: delivery identifiers and status events for transactional email, WhatsApp or SMS. QwikPass does not use an invoice or queue phone number for marketing without separate consent.
Why we use information
We use information to authenticate authorized users, isolate Organization and Outlet access, operate queues and orders, generate private invoices, deliver requested transactional notifications, calculate usage, prevent abuse, provide support and improve reliability. We do not sell personal information.
Optional public-site analytics
With your permission, we use Google Analytics 4 on qwikpass.in public pages to understand page visits, public-link clicks, product-video engagement and successful support or Enterprise inquiries. We do not send form answers, contact details, private URLs, invoice or order tokens, or restaurant-workspace activity to Google Analytics. Analytics is off until you choose to allow it; declining does not limit QwikPass. You can change your choice through “Analytics choices” in the public-site footer. Google may process permitted analytics data under its own privacy terms.
Service providers and payment boundaries
QwikPass uses service providers to run the product, including Google Cloud and Firebase for backend, authentication, App Check and data services; Netlify for the public web application; ZeptoMail for automated transactional email and Zoho Mail for the QwikPass support mailbox; Meta WhatsApp Cloud API for opted-in WhatsApp messages when that channel is activated; and Razorpay for optional one-time QwikPass service-credit purchases and restaurant-connected online payments when enabled. These providers process information under their own terms and privacy practices.
Optional one-time QwikPass service-credit payments are received by YK Builds through Razorpay. Open Access does not create a plan subscription. Restaurant customer payments settle to the restaurant’s connected Razorpay account where online checkout is enabled. QwikPass stores provider references, delivery events and transaction status—not card numbers, CVV or banking credentials.
Retention and deletion
We keep information while needed to provide and secure the service, meet legitimate business obligations, resolve disputes and comply with applicable accounting, tax or legal retention requirements. Monthly usage counters can reset without deleting the underlying restaurant record. Issued invoices are immutable records and are not routinely auto-deleted; a public capability link may be revoked or replaced independently from the protected invoice record.
Security and audit records may be retained separately from active workspace data. A restaurant may request closure of its QwikPass Organization, but invoices, payment references, fraud-prevention records, security events and backups may remain for a required or defensible period.
Loyalty points do not expire in the initial product release while the Organization remains active, but this does not authorize indefinite unrelated use of the customer’s contact information. Access, correction, closure and deletion requests remain subject to identity verification, the restaurant’s obligations and applicable law.
Security and choices
QwikPass uses authenticated, role-scoped access for protected workspaces, private capability links for guest records, encryption in transit, provider-managed encryption at rest, audit trails and optional authenticator MFA. No internet service can guarantee absolute security.
Guests can join a digital queue without providing a name, phone number or account. Phone numbers remain optional at the counter. If a customer provides one to identify the invoice and the restaurant has activated loyalty, the configured points program applies automatically to that identified transaction; the counter shows this before payment. Browser notifications and managed WhatsApp or SMS updates require the user’s choice or applicable consent. Transaction and loyalty contact details are not marketing consent.
Access, correction and questions
Restaurant owners can correct operational information in their workspace. Staff should contact their Organization owner about role or account data. For privacy questions, access or deletion requests, email security@qwikpass.in. We may verify identity and authority before acting on a request.
Updates
We may update this policy as QwikPass changes. Material updates will be identified by a revised effective date and, where appropriate, communicated to Organization owners.
