1. Introduction and Scope
This Cookie Policy explains how QRestAI uses cookies and similar technologies (local storage, session storage, pixels/beacons) across the following surfaces:
- Operator Panel (panel.qrestai.com): management panel for restaurant/business operators
- Admin Panel (admin): platform super-admin panel
- Public Restaurant Pages (QR menus / landing pages published via qrestai.com): menus that end-user guests view by scanning a QR code
This Policy has been prepared in line with Law No. 6698 on the Protection of Personal Data (KVKK) and the "Guide on Cookie Practices" (Çerez Uygulamaları Hakkında Rehber) issued by the Turkish Personal Data Protection Authority (first published July 2022, updated version 2025). The confidentiality dimension of cookies is further assessed under the principles of confidentiality of electronic communications set out in Law No. 5809 on Electronic Communications. For users accessing from the EU, the principles of the ePrivacy Directive 2002/58/EC (as amended by 2009/136/EC) are also observed.
For your rights regarding personal data processed via cookies and our general data processing practices, please refer to the Privacy Policy / Information Notice. This Cookie Policy forms an integral part of that Information Notice.
2. What Is a Cookie?
A cookie is a small text file saved to your device (computer, phone, tablet) via your browser when you visit a website. Cookies allow the site to recognise you on subsequent visits or during navigation within the same session, to remember your preferences, and to securely perform its essential functions.
In this Policy, the term "cookie" also covers the following technologies that serve technically similar functions:
- Local Storage (localStorage) and Session Storage (sessionStorage): HTML5 mechanisms that store data in the browser.
- Pixels / Beacons: small images or code fragments that measure page views or interactions.
By duration, cookies fall into two types:
- Session cookies: deleted when the browser is closed.
- Persistent cookies: remain on your device until a set expiry date or until you delete them.
By origin, cookies are either first-party (placed directly by QRestAI domains) or third-party (placed by another domain).
3. Why We Use Cookies
QRestAI uses cookies for the following purposes:
- Session and authentication: so you can log in securely to the operator and admin panels and keep your session active.
- Security: to prevent attacks such as cross-site request forgery (CSRF).
- Remembering preferences: functional choices such as your language/locale preference and display settings.
- Service functionality: to deliver functions you explicitly request, such as preserving the cart/order state on public menu pages.
- Performance measurement: first-party measurement and error monitoring to understand how the Service is used. In measurement data, IP addresses are masked via hashing; raw IPs are not stored.
The Service's own usage measurement is performed via first-party event logging based on hashed IPs; no external ad network is used for that measurement. Separately, cookies from advertising measurement providers may be used on the marketing pages only, and only with your explicit consent (see Sections 4.4 and 5). These cookies are never used on restaurant menu pages under any circumstances.
4. Cookie Categories
Under the KVKK "Guide on Cookie Practices", a cookie is exempt from explicit consent only when it satisfies at least one of the following two criteria:
- (A) the sole purpose of the cookie is to carry out the transmission of a communication over an electronic communications network; or
- (B) the cookie is strictly necessary to provide a service the user has explicitly requested (e.g. logging in, viewing the cart).
For all cookies that do not meet these criteria (functional, performance/analytics, marketing), the user's explicit consent is obtained before the cookies are placed.
4.1 Mandatory / Strictly Necessary Cookies: No Consent Required
These cookies are essential for the core functions of the Service to operate and cannot be disabled. They do not require explicit consent because they satisfy criteria (A) and/or (B) above; this Policy nonetheless fulfils the duty to inform. Scope: session management, authentication, CSRF/security protection, language/locale preference, and cart/order state on public menu pages.
4.2 Functional Cookies: Subject to Explicit Consent
These provide a more personalised experience by remembering your preferences (e.g. display preferences, last-used settings). Disabling them does not break core functions but may reduce convenience.
4.3 Performance / Analytics Cookies: Subject to Explicit Consent
These measure how the Service is used in an aggregate, first-party manner (pages visited, error rates, performance metrics). IP addresses are masked via hashing during measurement. This category covers first-party measurement only; measurement cookies belonging to advertising platforms are a separate category (see Section 4.4).
4.4 Advertising Cookies: Subject to Explicit Consent
Cookies from advertising measurement providers are used to measure whether our advertising works and to manage ad delivery. This category also covers those same providers' measurement-only cookies: none of them is loaded into your browser unless you consent to this category.
The scope is limited in two ways:
- It operates on the marketing pages only (home, pricing, features, about, contact and the legal pages).
- It never operates on restaurant menu pages or on restaurants' own domains, under any circumstances.
If you have not consented, no cookie is written and no identifier about you is used. In that state the provider's measurement scripts are loaded on the page and a cookieless signal reaches the provider; that signal is limited to the fact that a visit happened and stores nothing in your browser. Consenting switches cookies and identifiers on, and withdrawing switches them back off; cookies already placed can be deleted from your browser settings.
The Meta pixel has no cookieless mode, so it sends no event at all unless you consent.
Your consent to this category also covers reporting your registration and, where applicable, your subscription to the relevant advertising platform as a conversion, together with the identifier of the advertisement you clicked. That report is sent from our servers and is detailed in the Privacy Policy / Information Notice.
4.5 Cookie Table
The table below summarises the cookies and similar storage technologies used, by function/purpose.
| Cookie / Function | Purpose | Duration | Type | Category |
|---|---|---|---|---|
| Session authentication | Secure login to the panels and keeping your session active | Session / up to 30 days | First-party, HTTP-only | Mandatory |
| Security (CSRF) | Protection against cross-site request forgery (CSRF) | Session | First-party, HTTP-only | Mandatory |
| Login redirect | Redirecting you to the correct page after login | Session | First-party | Mandatory |
| Secure login-flow verifier | Security verification of the login flow | Short-lived (minutes) | First-party, HTTP-only | Mandatory |
| Language/locale preference | Remembering your selected language/region | Up to 1 year | First-party | Mandatory |
| Cart/order state | Preserving cart/order state on the public menu page | Session | First-party | Mandatory |
| Cookie consent record | Storing your cookie preferences/consent record | Up to 12 months | First-party | Mandatory |
| Interface preferences | Remembering display and interface preferences | Up to 6 months | First-party | Functional |
| Delivery addresses saved on the device | Suggesting the delivery address on the next order when the guest chooses "remember on this device"; not sent to the server | Until the guest deletes it or it goes unused for a long time | First-party, browser storage | Functional (guest's choice) |
| Measurement (hashed-IP) | First-party, hashed-IP visit/interaction measurement | Up to 12 months | First-party | Performance/Analytics |
| Advertising measurement | Measuring advertising performance and managing ad delivery | Varies by provider, typically between 90 days and 2 years | Third-party | Advertising |
Note: The durations above may vary according to the current configuration.
5. Third-Party Cookies
The Service's own usage measurement is performed first-party, via event logging based on hashed IPs; no external ad network is used for that measurement.
Separately, the advertising measurement cookies described in Section 4.4 are third-party cookies, placed on the marketing pages only and only with your explicit consent. Within the scope of their own services, these providers may recognise you across different websites. That is precisely why the category is off by default and why refusing it is as easy as accepting it.
A limited number of external service providers used for the operation of the Service (e.g. error monitoring) may set their own technical cookies. When such a third-party cookie is actually used, a row specifying the provider, purpose and duration is added to the table above. Details about data processing agreements (DPAs) with these providers are set out in the Privacy Policy / Information Notice.
6. Cookie Management and Rejection
You have full control over cookies that are subject to consent. These cookies are not loaded before your explicit consent is obtained.
6.1 Cookie Preference Panel
On your first visit, you are shown a cookie information banner. In line with the KVKK Guide, this banner offers equally prominent "Accept All", "Reject All" and "Manage Preferences" options. Categories that require consent (functional, performance/analytics, marketing) appear in the panel off (unselected) by default and are activated only with your active consent. No pre-ticked boxes are used.
You may reopen your preferences at any time via the "Cookie Preferences" link in the footer of the relevant page to withdraw or change your consent. Your consent records are kept in a manner that can be submitted to the Authority upon request.
6.2 Browser Settings
You can also manage, block or delete cookies through your browser settings:
- Google Chrome: Settings → Privacy and security → Cookies and other site data
- Mozilla Firefox: Settings → Privacy & Security → Cookies and Site Data
- Safari: Preferences → Privacy → Manage Website Data
- Microsoft Edge: Settings → Cookies and site permissions
Blocking mandatory/strictly necessary cookies in your browser may prevent core functions such as login and the cart from working.
7. Retention Periods
The retention period for each cookie is stated in the table in Section 4.5 above. General principles:
- Session cookies are deleted when the browser is closed.
- Persistent cookies are kept for the period stated in the table or until you delete them.
- The consent record cookie retains your preferences for 12 months; at the end of this period, your consent is requested again.
- Delivery addresses saved on the device exist only when the guest chooses so; they can be deleted at any time with "Delete my addresses on this device" in the menu or by clearing browser data.
- The durations of advertising measurement cookies are set by the relevant provider; the table gives the typical range.
- Server-side retention periods for analytics event data collected via cookies (e.g. 90 days for raw events, longer periods for aggregated data) are explained in the Privacy Policy / Information Notice.
8. Relationship with KVKK and Data Subject Rights
Some data processed via cookies (e.g. device/session identifiers, hashed IPs) may constitute personal data under the KVKK. The legal basis for this processing is:
- Mandatory cookies: the exemptions under KVKK Art. 5(2) and the "strictly necessary" criterion in the Cookie Guide (no explicit consent required).
- Functional, performance/analytics and marketing cookies: explicit consent under KVKK Art. 5(1).
Under KVKK Art. 11, as a data subject you have the right to: learn whether your personal data is being processed and request information about it; learn the purpose of processing and whether the data is used in accordance with that purpose; request the correction, erasure or destruction of incomplete/incorrectly processed data; and object to any outcome to your detriment that arises from the analysis of your data solely by automated means.
For detailed information on the exercise of these rights, the categories, transfer and retention of data, and the supervisory authority for complaints (the Turkish Personal Data Protection Authority), and for the application method, please refer to the Privacy Policy / Information Notice. For your requests: [email protected].
9. Updates
This Cookie Policy may be updated due to changes in legislation, updates to the KVKK Guide, or changes to the cookies we use. The current version is always published on this page. For material changes affecting cookie categories where renewed consent is required, the cookie banner is shown again.
Contact: [email protected], [email protected]