Quarey — Restaurant Management Software
FeaturesPricingSolutionsWatch demoBlog
Login

Menu

01Features02Pricing03Solutions04Watch demo05Blog
Login to Quarey

Privacy Policy

Last Updated: August 29, 2026

This policy describes how Quarey ("we", "us") processes personal data when you use quarey.com, app.quarey.com, connected tenant subdomains (*.quarey.com), custom domains configured by tenants, and related restaurant management services (collectively, "Quarey" or the "Service"). It reflects how Quarey works today. For UK/EU visitors we include GDPR-style rights language; for Pakistan we reference PECA 2016 as a legal-basis framework.

This page is an operational disclosure — have counsel review it before relying on it for regulated markets.

1. Who we are

Quarey, with a registered office in Islamabad, Pakistan. ("Precision Hospitality Technology" is our product tagline, not a separate legal entity.) Contact: hello@quarey.com.

2. Data controller vs. processor

Quarey is a multi-tenant restaurant platform. Roles depend on whose data is involved:

  • Restaurant tenants (our customers) are typically the data controllers for their own guest, order, loyalty, and staff data collected through Quarey's POS, delivery, KDS, Accounts, Pharma/Health, and related modules.
  • Quarey acts as a data processor (or service provider) for that tenant data — we process it on documented instructions to provide the platform.
  • Quarey is the controller for account data about restaurant operators who sign up with us (billing contacts, login emails, support tickets, custom domain configuration) and for website analytics on quarey.com when consent is given.

3. Information we collect

Depending on how you or your restaurant use Quarey, we may process:

  • Contact and account details (name, email, phone, restaurant identity)
  • Business and menu data, orders, inventory, and operational logs
  • Payment and subscription metadata (processed by our payment partner; we do not store full card numbers)
  • Geolocation data — used for branch detection/routing (for example, Health & Pharma and delivery branch assignment) and for rider tracking during active delivery jobs when the rider app is in use
  • Push notification tokens (including FCM tokens) used to deliver dispatch alerts, order updates, and operational notifications to devices
  • Custom domain and DNS configuration data — where a tenant enables the Custom Domain add-on, we process the domain name and DNS records needed to route and verify that domain
  • Tax authority credentials — where a tenant enables tax integration (e.g. FBR, PRA, SRB, KPRA), branch-level credentials are stored encrypted (AES-GCM) and used solely to submit that branch's tax data to the relevant authority
  • Usage data, diagnostics, and support communications

4. How we use information

  • Provide, secure, and improve the Quarey platform
  • Route orders, manage riders, and support multi-branch operations
  • Route and verify custom domains configured by tenants
  • Submit tax data to configured authorities on a tenant's behalf, strictly as instructed
  • Process trials, subscriptions, add-ons (e.g. Extra Branch, Custom Domain), and customer support
  • Send service notifications (including push) required for operations
  • Measure website performance after cookie consent (marketing site)
  • Comply with legal obligations and protect against abuse

5. Geolocation & push notifications

Location is collected only when needed for a feature you (or your restaurant) enable — for example, assigning the correct branch or tracking an active delivery. Push tokens are stored to reach the correct device for dispatch and order updates. You can revoke OS-level location or notification permissions at any time; some delivery/rider features will stop working without them.

6. Sub-processors

We use vetted service providers to operate Quarey. Current categories include:

  • Supabase — database, authentication, and related backend services
  • Vercel — website and application hosting, edge delivery, and custom domain routing
  • Creem — subscription/payment processing, acting as Merchant of Record for plans and add-ons
  • Google (FCM) — push notification delivery to mobile devices
  • Government tax authorities (FBR, PRA, SRB, KPRA) — receive tax-relevant transaction data only for tenants that have configured that specific integration
  • Analytics providers (e.g. Google Analytics) — only after cookie consent on the marketing site

We require processors to protect data appropriately and use it only to provide their services to us.

7. Legal bases

Pakistan: We process personal data in connection with providing our services and operating our business, consistent with applicable Pakistani law, including the Prevention of Electronic Crimes Act, 2016 (PECA), where relevant to electronic systems and unauthorized access.

UK/EU (GDPR/UK GDPR): Where those laws apply, we rely on one or more of: performance of a contract (providing Quarey to a restaurant customer), legitimate interests (securing and improving the service, B2B marketing where permitted), consent (optional cookies/marketing), and legal obligation.

8. Your rights (including GDPR)

Depending on your location, you may have rights to access, correct, delete, or port personal data we hold as controller; to restrict or object to certain processing; and to withdraw consent where processing is consent-based. Restaurant guest data held inside a tenant account is generally controlled by that restaurant — contact them (or us, and we will route the request) for those records.

To exercise rights regarding Quarey account or website data, email hello@quarey.com. UK/EU users may also lodge a complaint with their local supervisory authority.

9. Data security & retention

We use industry-standard technical and organizational measures, including encryption of sensitive credentials at rest and row-level access controls scoped per tenant. No method of transmission or storage is 100% secure. We retain data for as long as needed to provide the service, meet legal/accounting requirements, and resolve disputes, then delete or anonymize it.

10. International transfers

Quarey and its sub-processors may process data in Pakistan and other countries. Where required, we use appropriate safeguards for cross-border transfers.

11. Children

Quarey is a business service and is not directed at children. We do not knowingly collect personal data from children for our own marketing.

12. Changes

We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last Updated" date.

13. Contact

Privacy questions: hello@quarey.com

Quarey - Restaurant Management Software

Restaurant POS, kitchen display, delivery, and inventory in one system — built for multi-outlet operators worldwide.

Quarey

Islamabad, PakistanRegistered office

hello@quarey.com

Follow

  • Features
  • Pricing
  • Solutions
  • Watch demo
  • Integrations
  • Who Quarey is built for
  • Onboarding
  • Security
  • Blog
  • Africa
  • Bangladesh
  • Europe
  • India
  • Indonesia
  • Malaysia
  • Nepal
  • Nigeria
  • Pakistan
  • Saudi Arabia
  • UAE
  • UK
  • USA
  • vs Toast POS
  • vs Square POS
  • vs Petpooja
  • vs Lightspeed
  • About
  • Privacy
  • Terms

© 2026 Quarey. All rights reserved.

hello@quarey.com