This Privacy Policy explains how Served HQ handles personal data for platform users, business staff, customers who interact with Served HQ-powered pages, and visitors to our public website.
Optional analytics and campaign measurement
When you accept analytics, we record the source of your first marketing-site visit in that browser session, campaign labels, the landing page and referring website hostname. If you create an account, we associate that source with account creation, menu publication and subscription payment outcomes to understand which channels help businesses find Served HQ. On public business menus, a consented signed-out visit may record that the menu has been used; it does not establish a sale.
Our acquisition report does not retain raw advertising click IDs, search queries or full referring URLs. These reporting records are retained for up to 395 days. Operational account and billing records have their own retention requirements. You can accept, reject or withdraw optional analytics using Cookie settings. Withdrawal stops subsequent collection in that browser; it does not automatically remove earlier consented records. Without a captured consented visit, new account and business outcomes appear as unattributed.
1. Data roles
For business account and platform administration data, Served HQ generally acts as controller. For customer data submitted to a specific business through menus, bookings, orders, loyalty or forms, the business is usually the controller and Served HQ acts as processor or service provider, except where we process data for security, fraud prevention, legal compliance, analytics, billing or platform operations.
2. Information we collect
- Account data: name, email, password credentials, verification status, role, business association and support messages.
- Business data: business name, address, contact details, settings, service/menu content, logos, images, domains, opening hours, add-ons, bundles and billing status.
- Customer data: details submitted through a business page, including order, booking, loyalty, contact, service address, delivery or collection information where enabled.
- Payment data: payment status, customer references, checkout identifiers, invoices, subscription metadata and connected account status. Full card data is handled by payment providers where applicable.
- Technical data: IP address, browser, device, operating system, pages visited, timestamps, referrers, logs, cookies, session identifiers and security events.
- QR and analytics data: scan timestamps, QR code identifiers, approximate technical context, source or campaign information and aggregated engagement reporting.
3. IP addresses, logs and device data
We may collect and store IP addresses and related technical logs to operate the service, protect accounts, detect abuse, investigate fraud, rate-limit requests, diagnose errors, measure QR activity, comply with legal obligations and maintain security. IP data may sometimes be considered personal data.
Businesses may receive analytics or security views that include QR scan trends, visit counts, timestamps, sources, approximate location signals or technical metadata where this is necessary to provide the feature. We do not intend businesses to use IP addresses to identify individuals unless there is a lawful basis and a legitimate operational or security need.
4. How businesses can see customer details
Businesses can view customer details submitted to their own workspace, such as order names, contact details, booking or reservation requests, selected services, service addresses, loyalty records, notes, fulfilment information and payment status. This access exists so the business can provide the requested service, handle support, comply with records obligations, manage loyalty and understand operational activity.
Businesses are responsible for limiting staff access, using strong passwords, training their team, exporting data responsibly and responding to customer privacy requests that relate to their business operations.
5. How we use data
- Provide, maintain and improve Served HQ.
- Create accounts, authenticate users and manage permissions.
- Process orders, bookings, loyalty activity, QR scans and business settings.
- Send transactional emails, service updates, security notices and support replies.
- Enable billing, subscriptions, connected payments, invoices and payment provider checks.
- Prevent fraud, abuse, security incidents, policy breaches and unlawful activity.
- Comply with legal, tax, accounting, regulatory, dispute and enforcement obligations.
- Produce aggregated or anonymised insights that do not reasonably identify an individual.
6. Sharing data
We may share data with hosting providers, email providers, payment providers, messaging providers, analytics and security tools, support systems, professional advisers, authorities where legally required, and businesses whose customers submitted the relevant information. We do not sell personal data.
7. SMS and text message communications
Where a business enables text message (SMS) features, a customer's phone number may be used to send transactional messages (such as booking confirmations, reminders and order updates) and, where the business holds appropriate consent, marketing messages, using a third-party messaging provider that Served HQ selects and may change at any time.
- We do not sell phone numbers or use them to send messages on behalf of any business or party other than the business the customer submitted their details to.
- Message and data rates set by the recipient's mobile carrier may apply. A customer can typically opt out of future text messages by replying "STOP" or using another opt-out method offered in the message, and can contact the relevant business directly for help.
- We retain records connected to consent and message delivery for as long as reasonably necessary to demonstrate compliance with messaging laws and to operate the messaging feature.
8. Retention
We keep data for as long as needed to provide Served HQ, maintain records, support businesses, resolve disputes, prevent abuse, comply with law and enforce agreements. Businesses may also have their own retention obligations for customer, order, booking and tax records.
QR codes and short links. When a business deletes a QR code, we keep it for 30 days before its short link and scan history are permanently removed, giving a window to restore it if the deletion was a mistake. If a business has more active QR codes than its current plan allows (for example after downgrading), we notify the business and give it the opportunity to choose which QR codes to remove, with reminders over a period of up to 6 months. If no action is taken, we will email the business a clear, specific list of which QR codes are due to be removed and when, before any are permanently deleted.
9. Customer rights
Depending on applicable law, individuals may have rights to access, correct, delete, restrict or object to certain processing, request portability, or complain to a regulator. Requests about a specific order, booking, loyalty account or text message may need to be handled by the business that owns that customer relationship.
10. Security
We use reasonable technical and organisational measures to protect data, but no online service is completely risk-free. Businesses must protect their own devices, accounts, staff access, exports and customer communications.