Privacy Policy
Last updated 23 September 2026
This explains what Counterpoint collects, why, and what we will never do with it. It covers two different groups: the cafes who use the software, and the guests who order from a table.
If you are a guest ordering from a table
You are using software the cafe has chosen. The cafe controls your data; we host it.
What is collected
- Your order — items, options, notes, which table, and the time.
- Your phone number — only if you enter one, and only to send a receipt or match you to previous visits.
- Feedback — the rating and comment you leave, if you leave one.
What is not
- No account. No sign-up, no password, no email.
- No card details. We never see or store them.
- No advertising or tracking cookies. No pixels, no analytics scripts, no third-party trackers of any kind.
- No location beyond the table you scanned.
Your feedback
Ratings and comments go to the cafe only. They are not published, not shared, and not posted to any review site.
If you run a cafe
What we hold
- Account — your name, email, password (hashed, never readable), role.
- Business — cafe and outlet names, addresses, phone numbers, tax settings.
- Operational — menu, tables, orders, bills, payments, staff records.
- Audit trail — who discounted, voided, changed a price or rotated a QR code.
Why
To run the Service for you. That is the only reason. We do not profile you, do not sell anything to you on the basis of it, and do not share it with anyone except the providers below.
Cookies
We set exactly one cookie, and only for people who sign in:
qrmenu_session— keeps you signed in. httpOnly, Secure, SameSite=Lax, expires after 12 hours.
Guests ordering from a table are not given any cookie. There is no consent banner because there is nothing to consent to.
Who else touches the data
- Our server host — the machine the software and database run on.
- Cloudflare — DNS, and traffic routing if enabled.
- Groq — only when an AI feature is used, and only the text needed for that request: a dish name, an uploaded menu’s text, or a summary of your own figures. No customer records are ever sent. It is not used to train models. Switching the feature off stops this entirely.
- A payment gateway, if you enable online payment. Card details go to them, never to us.
Security
- Everything travels over HTTPS.
- Passwords are hashed with bcrypt. Staff PINs are hashed too. Neither is readable by us, by your manager, or by anyone with database access.
- Password reset links are stored only as a hash, expire in 30 minutes, and work once.
- Each cafe’s data is scoped by tenant, and every action checks ownership before touching a record.
- The database is not reachable from the internet.
No system is perfectly secure. If we discover a breach affecting your data, we will tell you what happened and what we are doing about it.
How long it is kept
- Orders and bills — kept while your account is active, as your financial record.
- Guest phone numbers — kept until you delete them, or 24 months after their last visit.
- After you leave — available for export for 30 days, then deleted.
Your rights
You can ask us for a copy of your data, to correct it, or to delete it. Write to support@orbixot.com and we will respond within 30 days.
If you are a guest, ask the cafe you visited first — they control the record. If they cannot help, write to us.
Children
The Service is for businesses. We do not knowingly collect data from anyone under 18 beyond an order placed at a table.