QRFront

Privacy Policy

Effective 2026-08-15

The Korean text is the official version and prevails if translations differ. This page follows your device or selected UI language among the 38 supported locales; other languages display in English.

QRFront Privacy Policy

Effective: 15 August 2026 The Korean text is the authoritative version. If this translation differs, the Korean version prevails.

QRFront processes personal data under the Personal Information Protection Act, the Act on Promotion of Information and Communications Network Utilization and Information Protection, the Act on the Consumer Protection in Electronic Commerce, and other laws of the Republic of Korea.

1. Controller

  1. The business that operates QRFront is the controller. Trade name, representative, address, email, phone, and privacy officer follow the business information registered in the website footer and the Control Center. If those fields are empty, use in-product support.
  2. For hotel-administrator accounts, the Company is the controller.
  3. Guest messages and requests are processed to operate that hotel. The hotel is the on-site operator; the Company processes data as needed to deliver translation, console display, and retention.
  4. Floor-staff device sessions and push subscriptions are processed for that hotel’s floor work. Floor staff are not hotel-admin accounts.

2. Purposes

  • Hotel-admin signup, sign-in, session, and password reset
  • Optional MFA (TOTP), recovery codes, email OTP recovery, and security audit
  • Hotel workspace, rooms, QR, hotel services, facility cards, photos, Wi-Fi, and front-desk hours
  • Auto-translation of hotel address into English when the English address field is empty (platform path)
  • Guest portal, requests, chat, and AI translation
  • Hotel-admin site-support chat delivery and translation (platform path; hotel-wallet tokens are not deducted)
  • Floor-staff invite QR issue/revoke, device sessions, request/chat access, optional Web Push
  • Trial, subscription, and token-pack payments
  • Service improvement, incident response, abuse prevention, and legal compliance
  • Storage of Terms / Privacy / age-consent records

We do not collect a separate marketing-consent flag at signup and do not use this flow to send advertising messages.

3. Data we collect

Hotel administrators

  • Required: email, password (stored hashed), timestamps and document versions for Terms, Privacy, and age-14 confirmation
  • Hotel operations: hotel name, address, English address (address_en), country, phone, front-desk hours, floors/rooms, hotel services and facility cards and photos, Wi-Fi SSID/password (shown to guests), brand color, default language
  • Site support: hotel-admin inquiry source and translated text, language preference
  • Payments: purpose, amount, currency, status, order id, payment provider (Paddle), receipt URL, room count / token-pack quantity. Full card numbers are not meant to be stored by the Company; Paddle is used.
  • Security: MFA enrollment, hashed recovery codes, recovery-attempt metadata, bot-protection tokens if configured
  • Logs: sign-in and API activity, platform audit logs (admin actions, no secret values)

Guests

  • No guest account. Device id (cookie qrfront_device_id and similar), hotel/room ids, chat session id
  • Chat source and translated text, request content, language preference
  • The guest portal does not require an email signup. If a guest types personal data into chat, it is delivered to the hotel console.

Floor staff

  • Not a hotel-admin email account. Invite code (QR/link), hotel id, hash of the device session token, last-view time
  • Optional Web Push subscription (endpoint and encryption keys). The Company sends notifications with VAPID keys via the browser push service
  • Access to that hotel’s requests and chats. Hotel-admin translation APIs are not opened to floor-staff cookies

Platform usage ledger

  • AI usage logs: request_id, provider, model, token counts, success, latency, fallback flags
  • Customer source text is not stored on the platform audit/usage ledger

This list follows what the product actually does. We do not claim that we “do not collect email” or similar false statements.

4. Retention

  • Hotel-admin accounts and hotel operations data: until account closure or service end, plus any period required for billing, disputes, or law
  • Consent records: as needed for disputes and legal duties
  • Payment records: periods required by e-commerce and related law (contracts, withdrawal, payment and supply records)
  • Closed chat sessions: up to about 30 days, then deleted (same idea as product FAQ and retention logic)
  • Guest device cookie: up to about 30 days
  • Floor-staff session cookie: follows browser/session expiry. Invite tokens expire or can be revoked after the period set at issue
  • Push subscriptions: deleted when the staff member unsubscribes or the session is revoked
  • Locale cookie: stored in the browser; the user can delete it
  • MFA recovery challenges / email OTP: expire in minutes
  • Platform audit and AI usage logs: as needed for operations and security

Longer legal holds override these periods.

5. Recipients and processors

We may engage processors or transfer data in these categories:

CategoryPurposeExamples
Infrastructure, auth, DBAccounts and storageSupabase
AI translationTranslate messagesNVIDIA, OpenAI, Anthropic (Claude), Google (Gemini), and similar. Actual models may change at any time under those companies’ pricing and availability
PaymentsCharges and settlementPaddle (test or live)
Bot protectionSignup/login abuseCloudflare Turnstile, if configured
Web PushFloor-staff alertsBrowser push service (only if subscribed)

Changes of processors will be announced in this policy or a service notice. We may disclose data where a statute, investigation, or court order requires it.

We do not share guest source text across hotels. Platform operators see non-sensitive aggregates and masked identifiers. The Control Center hotel list does not show customer source text.

6. Overseas transfer

AI providers and cloud infrastructure may process data outside Korea. Items may include messages to translate, account and hotel data, and technical logs. Destinations follow each provider’s infrastructure. Transfer occurs when you translate, sign in, or save data. You may refuse before signup; the Service then cannot be used. Existing users may ask support to stop overseas processing; translation and related features may then stop.

7. Guest messages

  1. Messages are processed so staff can answer room requests and so AI can translate between languages.
  2. On a translation request, text may be sent to NVIDIA, OpenAI, Anthropic (Claude), Google (Gemini), or another configured model provider. The models used may change at any time according to those AI companies’ pricing policies and availability.
  3. The platform usage ledger stores request id, provider, latency, and token counts — not source text.
  4. After checkout, the session is invalidated. Past chats are kept for a limited hotel-operations/audit window, then deleted.
  5. Hotels should tell guests not to paste passport or card numbers into chat.

8. Cookies and sessions

  • Essential auth cookies: hotel-admin session (Supabase)
  • Locale cookie: UI language (qrfront_locale). One of 38 supported locales; languages outside that list display in English
  • Guest device cookie: room session (qrfront_device_id, about 30 days, not HttpOnly)
  • Floor-staff session cookie: qrfront_staff_session (HttpOnly, Secure, SameSite=Lax, path /). The raw token is only in the cookie; the database stores a hash
  • We do not currently ship a third-party advertising or analytics SDK (for example Google Analytics or ad pixels) by default. If that changes, this policy will be updated and any required consent collected.

Blocking cookies may break sign-in or the guest session.

9. Your rights

Hotel administrators may request access, correction, deletion, suspension of processing, or withdrawal of consent as Korean law allows, via account settings, support, or the privacy officer.

Guests may start with the hotel front desk. Floor staff may ask the hotel administrator to delete sessions or push subscriptions. The Company will cooperate for data stored in that hotel workspace, as the law allows.

We act without undue delay after identity checks. Data that must be kept by law may be suspended rather than erased.

10. Children under 14

Hotel-admin signup is not offered to children under 14. Signup requires confirmation of age 14 or older.

The guest portal is an in-room hotel tool. The Company does not collect guest age as a field. If a legal representative requests, the hotel and Company will cooperate on access or deletion as required by law.

11. Security measures

  • HTTPS in transit
  • Hashed passwords and recovery codes; MFA secrets held by the auth provider (Supabase)
  • Server-only secrets (no NEXT_PUBLIC_ service keys)
  • Tenancy: hotel data scoped to the hotel; platform admins via platform_admins
  • Maintenance/kill switches, session invalidation, audit logs

No system is perfectly secure. Incidents are notified as required by law.

12. Privacy officer

Name (or team) and contact follow the “privacy officer” and representative email/phone registered in the Control Center and shown in the footer. If empty, use product support.

Data subjects may also seek remedy from the Personal Information Dispute Mediation Committee, the KISA personal-information infringement report center (privacy.kisa.or.kr), the Supreme Prosecutors’ Office, or the National Police Agency.

13. Notice of changes

Changes are posted on the website with an effective date. Material changes may also be announced on the login screen or by email.

Addendum. This policy takes effect on 13 August 2026 and was amended on 15 August 2026.

QRFront
QR Front

The most intuitive next-gen smart room web solution for hotels

© 2026 QR Front Inc. All rights reserved.
Company name
StrayKitty Studio
Representative
Hangi Woo
Business registration no.
358-17-02448
Mail-order report no.
2025-GyoungNamKimhae-0624
Business address
GyoungNam-do Kimhae-si Uamro 36
Email
admin@qrfront.com
Phone
+825065040003
Privacy officer
Hangi Woo