QRFront Privacy Policy
Effective: 6 August 2026 The Korean text is the authoritative version. If this translation differs, the Korean version prevails.
QRFront processes personal data under the Personal Information Protection Act, the Act on Promotion of Information and Communications Network Utilization and Information Protection, the Act on the Consumer Protection in Electronic Commerce, and other laws of the Republic of Korea.
1. Controller
- The business that operates QRFront is the controller. Trade name, representative, address, email, phone, and privacy officer follow the business information registered in the website footer and the Control Center. If those fields are empty, use in-product support.
- For hotel-administrator accounts, the Company is the controller.
- Guest messages and requests are processed to operate that hotel. The hotel is the on-site operator; the Company processes data as needed to deliver translation, console display, and retention.
- Hotel-admin concurrent device sessions are processed for that hotel’s front-desk operations.
2. Purposes
- Hotel-admin signup, sign-in, session, and password reset
- Optional MFA (TOTP), recovery codes, email OTP recovery, and security audit
- Hotel workspace, rooms, QR, hotel services, facility cards, photos, Wi-Fi, and front-desk hours
- Auto-translation of hotel address into English when the English address field is empty (platform path)
- Guest portal, requests, chat, AI translation, and optional Web Push (in-progress request and staff reply alerts)
- Translation of facility-issue notes when languages differ (same-language notes may skip the translation API)
- Hotel-admin site-support chat delivery and translation (platform path; hotel-wallet credits are not deducted)
- Optional Web Push on the hotel front desk screen for new requests and guest chat alerts
- Floor-staff invite QR issue/revoke, display names, device sessions, request/chat access, start/complete/reply records, optional Web Push
- Trial, subscription, and credit package payments
- Transaction notices by email for failed payments, past-due renewals, and subscription cancellation
- Operational emails to platform operators (for example third-party AI API period ending, and a daily operations report of aggregated counts when enabled)
- Service improvement, incident response, abuse prevention, and legal compliance
- Storage of signup-email history to limit re-use of the same email for a new free trial after Auth deletion
- Storage of Terms / Privacy / age-consent records
We do not collect a separate marketing-consent flag at signup and do not use this flow to send advertising messages.
3. Data we collect
Hotel administrators
- Required: email, password (stored hashed), timestamps and document versions for Terms, Privacy, and age-14 confirmation
- Hotel operations: hotel name, address, English address (
address_en), country, phone, front-desk hours, floors/rooms, hotel services and facility cards and photos, Wi-Fi SSID/password (shown to guests), brand color, default language. After the first paid subscription payment, a country-lock timestamp (country_locked_at) may be stored; hotel admins cannot change country afterward, and a platform operator may change it exceptionally. - Site support: hotel-admin inquiry source and translated text, language preference
- Payments: purpose, amount, currency, status, order id, payment provider (Paddle), receipt URL, room count / credit package quantity. Full card numbers are not meant to be stored by the Company; Paddle is used. Billing address and country are collected in Paddle Checkout so Paddle can calculate tax.
- Billing notices: hotel-admin account emails may receive past-due, payment-failed, and cancellation notices.
- Security: MFA enrollment, hashed recovery codes, recovery-attempt metadata
- Optional Web Push subscription (endpoint and encryption keys) for new request and guest chat alerts on the front desk screen
- When alerts are received through the QRFront hotel app (iOS or Android), an app device push token is stored in that same subscription record instead of a browser subscription
- Logs: sign-in and API activity, platform audit logs (admin actions, no secret values)
Guests
- No guest account. Device id (cookie
qrfront_device_idand similar), hotel/room ids, chat session id - Chat source and translated text, request content, language preference
- Optional Web Push subscription (endpoint and encryption keys) for in-progress requests and staff chat replies
- Facility-issue note source text, source-language code, and a staff-facing translation when languages differ (stored on the hotel workspace). The guest list may still show the original
- The guest portal does not require an email signup. If a guest types personal data into chat, it is delivered to the hotel console.
Hotel-admin device connections
- Concurrent device sessions per hotel: hash of the device session token, User-Agent-based display name (editable), last-seen time, expiry/revoke time
- Concurrent-device cap from site settings (default 2); sign-in is refused above the cap
- Start/complete/reply records on requests and chats (admin label and time)
- Optional Web Push / app push subscriptions for the hotel-admin account
Platform usage ledger
- AI usage logs: request_id, provider, model, credit counts, success, latency, fallback flags
- Customer source text is not stored on the platform audit/usage ledger. That is separate from hotel-workspace chat and request records (including facility-note translations).
This list follows what the product actually does. We do not claim that we “do not collect email” or similar false statements.
4. Retention
- Hotel-admin accounts and hotel operations data: until account closure or service end, plus any period required for billing, disputes, or law
- Signup-email re-use prevention record (normalized email and first signup time): up to 3 years from first record. After that period the same email may sign up again, and a new 3-year window starts. Deleting the Auth user alone does not erase this record
- Consent records: as needed for disputes and legal duties
- Payment records: periods required by e-commerce and related law (contracts, withdrawal, payment and supply records)
- Billing and operational email send records: as needed to handle fee disputes and operations
- Closed chat sessions: up to about 30 days, then deleted (same idea as product FAQ and retention logic)
- Guest device cookie: up to about 30 days
- Hotel-admin device session cookie: follows browser/session expiry. device sessions end on logout or disconnect in Connection management
- Push subscriptions, including app device push tokens: deleted when hotel admins, floor staff, or guests unsubscribe or the session is revoked. The Company also revokes a subscription when the push service reports the token as no longer valid
- Locale cookie: stored in the browser; the user can delete it
- MFA recovery challenges / email OTP: expire in minutes
- Platform audit and AI usage logs: as needed for operations and security
Longer legal holds override these periods.
5. Recipients and processors
We may engage processors or transfer data in these categories:
| Category | Purpose | Examples |
|---|---|---|
| Infrastructure, auth, DB | Accounts and storage | Supabase |
| Web hosting & visit metrics | Hosting and anonymized visitor/page-view metrics | Vercel (including Web Analytics) |
| AI translation | Translate messages | NVIDIA, OpenAI, Anthropic (Claude), Google (Gemini), and similar. Actual models may change at any time under those companies’ pricing and availability |
| Payments | Charges and settlement | Paddle (test or live) |
| Web Push | Hotel-admin, floor-staff, and guest alerts | Browser push service (only if subscribed) |
| App push | Hotel-admin and floor-staff alerts | Apple (APNs), Google (Firebase Cloud Messaging) — only if subscribed through the hotel app |
| Email delivery | Billing notices, support alerts, platform operational notices (for example API period, daily operations report) | Resend or similar |
Changes of processors will be announced in this policy or a service notice. We may disclose data where a statute, investigation, or court order requires it.
We do not share guest source text across hotels. Platform operators see non-sensitive aggregates and masked identifiers. The Control Center hotel list does not show customer source text.
6. Overseas transfer
AI providers, cloud infrastructure, and push services may process data outside Korea. Items may include messages to translate, account and hotel data, technical logs, and push subscription data (app device push tokens and the notification title and body). Destinations follow each provider’s infrastructure. Transfer occurs when you translate, sign in, or save data. You may refuse before signup; the Service then cannot be used. Existing users may ask support to stop overseas processing; translation and related features may then stop.
7. Guest messages
- Messages are processed so staff can answer room requests and so AI can translate between languages.
- On a translation request, text may be sent to NVIDIA, OpenAI, Anthropic (Claude), Google (Gemini), or another configured model provider. The models used may change at any time according to those AI companies’ pricing policies and availability.
- The platform usage ledger stores request id, provider, latency, and credit counts — not source text.
- After checkout, the session is invalidated. Past chats are kept for a limited hotel-operations/audit window, then deleted.
- Hotels should tell guests not to paste passport or card numbers into chat.
- Facility-issue notes are stored in original form on the hotel workspace. If the guest language differs from the staff/hotel language, an AI translation may be stored for staff screens. Same-language notes may skip the translation API.
8. Cookies and sessions
- Essential auth cookies: hotel-admin session (Supabase)
- Locale cookie: UI language (
qrfront_locale). One of 38 supported locales; languages outside that list display in English - Guest device cookie: room session (
qrfront_device_id, about 30 days, not HttpOnly) - Hotel-admin device session cookie:
qrfront_hotel_device_session(HttpOnly, Secure, SameSite=Lax, path/). The raw credit is only in the cookie; the database stores a hash. The former floor-staffqrfront_staff_sessioninvite flow is not provided. - The Service uses Vercel Web Analytics on the hosting platform to measure anonymized visitors and page views. It is not an advertising SDK and does not use advertising cookies. We do not ship third-party advertising or behavioral analytics SDKs (for example Google Analytics or ad pixels) by default.
Blocking cookies may break sign-in or the guest session.
9. Your rights
Hotel administrators may request access, correction, deletion, suspension of processing, or withdrawal of consent as Korean law allows, via account settings, support, or the privacy officer.
Guests may start with the hotel front desk. The Company will cooperate for data stored in that hotel workspace, as the law allows.
We act without undue delay after identity checks. Data that must be kept by law may be suspended rather than erased.
10. Children under 14
Hotel-admin signup is not offered to children under 14. Signup requires confirmation of age 14 or older.
The guest portal is an in-room hotel tool. The Company does not collect guest age as a field. If a legal representative requests, the hotel and Company will cooperate on access or deletion as required by law.
11. Security measures
- HTTPS in transit
- Hashed passwords and recovery codes; MFA secrets held by the auth provider (Supabase)
- Server-only secrets (no
NEXT_PUBLIC_service keys) - Tenancy: hotel data scoped to the hotel; platform admins via
platform_admins - Maintenance/kill switches, session invalidation, audit logs
No system is perfectly secure. Incidents are notified as required by law.
12. Privacy officer
Name (or team) and contact follow the “privacy officer” and representative email/phone registered in the Control Center and shown in the footer. If empty, use product support.
Data subjects may also seek remedy from the Personal Information Dispute Mediation Committee, the KISA personal-information infringement report center (privacy.kisa.or.kr), the Supreme Prosecutors’ Office, or the National Police Agency.
13. Notice of changes
Changes are posted on the website with an effective date. Material changes may also be announced on the login screen or by email.
Addendum. This policy takes effect on 6 August 2026.
