Last updated: 19 August 2026

Privacy policy and processing of personal data

This policy explains what personal data is collected when you use the masaqr website and QR ordering product, why and on what legal basis it is processed, who it is shared with, and what rights you have. The Azerbaijani version is the operative one in case of any discrepancy.

1. Data controller

The controller for the processing of personal data is masaqr MMC. For any question or request relating to processing, contact info@masaqr.az or +994103339637.

Legal name
masaqr MMC
Tax ID (VÖEN)
1806305972

2. What data is collected

a) Technical data (automatic). Recorded server-side on every request to the site and the product: IP address, browser and device type, operating system, date and time of the request, the page requested, and the referring address. These logs are needed to run the site, to keep it secure and to prevent abuse.

b) Analytics data. Page views, session duration, navigation paths and general device metrics. This data is used in aggregate and is not used to identify a specific person.

c) Contact and demo-request data. What you provide voluntarily when you write to us or request a demo: name, email, phone, restaurant/company name, and the content of your message.

d) Order and payment data (inside the product). When you order via QR: table number, order contents, amount, transaction date and status, whether the payment succeeded, and the content of any refund request.

3. Purposes and legal bases

  • Providing the service — accepting the order, routing it to the kitchen, executing payment, issuing the receipt. Basis: performance of a contract.
  • Payment security and fraud prevention — detecting suspicious transactions. Basis: legitimate interest and legal requirement.
  • Support and refund requests — investigating your request. Basis: performance of a contract.
  • Improving the site, analytics — understanding which sections are read. Basis: consent (for analytics cookies) and legitimate interest (for aggregate statistics).
  • Compliance with legal obligations — retaining the records required by accounting, tax and payment legislation. Basis: statutory requirement.

Your data is not used for automated decision-making or profiling. It is not sold to third parties for advertising.

4. Cookies and analytics

The site uses two kinds of cookies:

  • Necessary (technical) cookies — to make the page work, to keep the selected language and the session. The site does not function without them, so they do not require consent.
  • Analytics cookies — to count visit statistics. These are set only with your consent, and you can withdraw that consent at any time.

You can delete or block cookies in your browser settings. Blocking necessary cookies may break parts of the site.

5. Who it is shared with

Your data is shared only with parties necessary to deliver the service, and only to the extent necessary:

  • The Venue (restaurant/café) — the contents of your order, table number and payment status. The Venue processes this data under its own responsibility.
  • The payment provider — to execute the card transaction and any refund.
  • Hosting and infrastructure suppliers — to host the site and product and to store log records.
  • The analytics supplier — for aggregate statistics.
  • Competent state authorities — only where legislation requires it, and only to the extent required.

All suppliers are bound by terms requiring confidentiality and use strictly for the stated purpose.

6. International transfers

Servers of hosting and analytics suppliers may be located outside the Republic of Azerbaijan. Where that is the case, transfers take place only where appropriate contractual data-protection terms are in place.

7. Retention periods

  • Server logs and technical records — up to 12 months, then deleted or anonymised.
  • Analytics data — kept in aggregate form; raw session records up to 14 months.
  • Contact and demo-request correspondence — up to 24 months after the request is closed.
  • Order and payment records — for the period required by accounting and tax legislation; this may be longer than the periods above.

Once the period expires, data is deleted or irreversibly anonymised.

8. Security measures

Data in transit is encrypted (HTTPS/TLS). Access is granted only to people whose role requires it, and is logged. Payment data is processed by a provider certified against the card industry security standards (PCI DSS).

No system is entirely secure. In the event of a personal-data breach, both the competent authority and the affected individuals are notified within the period required by law.

9. Your rights

In relation to your personal data you have the right to:

  • know what data is processed and obtain a copy of it;
  • have inaccurate or incomplete data corrected;
  • request erasure — unless legislation requires the data to be kept;
  • request restriction of processing;
  • object to processing based on legitimate interest;
  • withdraw a consent you have given, at any time;
  • lodge a complaint with the competent state authority.

Send your request to info@masaqr.az. We respond within 30 calendar days. We may ask for additional information to verify your identity — this is to make sure your data is not disclosed to someone else.

10. Children’s data

The product is not directed at people under 18, and personal data is not knowingly collected from them. If we learn that such data has been collected, it is deleted immediately.

11. Changes to this policy

This policy may be updated. The revision date is shown at the top of the page. Material changes are announced by a separate notice on the site. If a new kind of processing requiring consent is added, your consent is asked again.

12. Contact

For any question about privacy and the processing of personal data: info@masaqr.az · +994103339637 · WhatsApp. Refund rules are covered in a separate document: Refund policy.