Last updated: 12 June 2026
This policy explains which personal data Qaro processes, for what purpose, with whom it is shared and what your rights are. It applies to the website, the web application and the "Qaro Serveur" mobile application.
The data controller is Qaro Sàrl (CHE-187.788.885), Chemin de Richesson 35, 1000 Lausanne 26, Switzerland. For any question about your data: support@qaro.ch.
When you order at a restaurant via Qaro, that restaurant is also a controller of the data related to your order. Qaro then acts as the provider of the technical solution.
Guests (diners) who order and pay via a QR code:
Restaurant staff (servers, managers, administrators):
Technical data: information strictly necessary for operation and security (session cookies, technical logs in the event of an error).
We process this data to:
We never sell your data. It is accessible to the restaurant where you order, and to technical providers (processors) acting on our behalf:
Your data is hosted in Switzerland (database in Zurich) and in the European Union (application hosting in Frankfurt, Germany). Some providers may process data outside these areas; where applicable, appropriate safeguards (standard contractual clauses) govern these transfers.
Data related to orders and payments is kept for as long as the applicable accounting and tax obligations require (in principle 10 years in Switzerland, art. 958f CO). Staff accounts are kept as long as access is active, then deleted or anonymized. Data provided solely for a receipt/notice is kept only for as long as strictly necessary.
In accordance with the Swiss Federal Act on Data Protection (nFADP) and, where applicable, the GDPR, you have the right to access, rectify, erase, restrict, object to and port your data. To exercise these rights, write to support@qaro.ch.
You may also lodge a complaint with the competent authority (in Switzerland, the Federal Data Protection and Information Commissioner — FDPIC).
We implement appropriate technical and organizational measures: encryption of communications (HTTPS), isolation of access by restaurant, permission controls and encrypted storage of sensitive data. As no system is infallible, we cannot, however, guarantee absolute security.
The service uses only necessary technical cookies (in particular to maintain the session of professional accounts). We do not use advertising cookies or marketing tracking tools.
The service is intended for restaurant guests and their staff. We do not knowingly collect data about children separately from an order placed at the restaurant.
We may update this policy. The applicable version is the one published on this page, with its update date shown at the top of the document.
Qaro Sàrl — Chemin de Richesson 35, 1000 Lausanne 26, Switzerland — support@qaro.ch.