Privacy Policy
Last updated: 26 August 2026
TokenQ is a QR token-queue ordering service for food shops (“vendors”). This page explains what information we collect from customers who order, from vendors and their staff, and how we use and protect it. We keep it short and honest.
1. Information from customers who place an order
- Name — shown to the shop staff so they can call your order. You may use a nickname.
- Phone number (optional) — only if you type it. It is shown to the shop so they can reach you about your order. We never send marketing messages to it.
- Order details — the items, quantities, total and order status.
- A random device identifier stored in your browser, used only to show you your own orders again and to limit prank orders. It is not linked to any account.
We do not require an account, login, OTP, email or app install to order. Customer names and phone numbers are visible to the vendor whose shop you ordered from, and to nobody else.
2. Information from vendors and their staff
- Shop name, menu, prices, photos, opening status and UPI ID as entered by the owner.
- Staff login email addresses and encrypted passwords (managed by Supabase Auth).
- Order history, which the owner can see in the day summary.
3. How we use it
Only to run the service: showing menus, routing orders to the kitchen, updating token status, and producing the vendor’s daily summary. We do not sell or rent any data. We do not run advertising. We do not share customer data with other vendors.
4. Where it is stored
Data is stored with Supabase (PostgreSQL) in the Mumbai, India region and served through Vercel. Connections are encrypted (HTTPS). Database access is locked down so that each shop’s staff can only see their own shop’s data, and customers can only see their own order page.
5. Cookies and local storage
We use browser storage for essentials only: your cart, your name for next time, the device identifier above, and staff sign-in sessions. No advertising or third-party tracking cookies.
6. Retention and deletion
Order records are kept so that vendors can see their sales history. A customer may ask a vendor, or us, to remove their name and phone number from past orders. A vendor who leaves TokenQ can ask us to delete their shop’s data entirely; we do so within 30 days.
7. Children
TokenQ is not directed at children under 13 and we do not knowingly collect their data.
8. The TokenQ Partner app
The Android app used by vendor staff is the same web service wrapped for the Play Store. It collects nothing beyond what is described above and requests no special device permissions other than optional notifications and vibration for order alerts.
9. Changes
If this policy changes materially we will update the date above and inform active vendors on WhatsApp.
Questions about this page? WhatsApp us at +91 95675 19968. TokenQ is a product of Glyphora, Kerala, India.