QRFront Terms of Service
Effective: 15 August 2026 The Korean text is the authoritative version. If this translation differs, the Korean version prevails.
1. Purpose
These Terms govern use of QRFront (the “Company” or “Service”): hotel QR guest portal, front-desk console, floor-staff mobile web, QR printing, AI multilingual translation, and related features, and the rights and duties of the Company, hotel administrators (members), floor staff, and guests.
2. Definitions
- “Hotel administrator” means a business or staff member who creates an account by email and operates a hotel workspace. Hotel admin screens use the
/adminpath. - “Guest” means a person who scans a hotel room QR and uses the guest portal. Guests do not create a QRFront account.
- “Floor staff” means housekeeping, runners, and similar on-floor workers who join
/staffby scanning an invite QR issued by a hotel administrator. Floor staff are not hotel-admin accounts (hotel_users/ Supabase Auth) and do not sign in daily with email and password. - “Tokens” are digital units that meter AI translation API usage, including a hotel-wallet grant and paid token packs.
- “Demo” is a preview without a sales contract. Data may be sample data and may differ from production.
- “Platform operator” means a person with Control Center access. That surface is not mixed with hotel admin.
3. Publication and changes
- The Company posts these Terms and the Privacy Policy on the website.
- The Company may amend the Terms within the law and will announce the effective date and changes.
- Continued use after an amendment takes effect is treated as acceptance, except where a separate consent is required by law.
4. The Service
- The Service includes:
- A room-QR guest web portal (hotel service guides, facility cards, requests, chat, Wi-Fi, and similar). No app-store install and no guest signup - A hotel-admin front-desk, request, and chat console (/admin) - Floor-staff mobile web (/staff: Home, Requests, Chat). This is not a native app; it runs in the browser (and as a home-screen PWA) - Batch room/QR creation and printing - Multilingual UI (38 locales on the supported list) and AI translation (engine allowlist is separate from UI; currently about 28 languages) - Subscription and token billing, hotel settings (including address and front-desk hours), staff-access invite QR, and optional MFA
- Features may be added, changed, or paused. Material reductions of paid features will be announced in a reasonable way.
- AI translation may use NVIDIA, OpenAI, Anthropic (Claude), Google (Gemini), and similar models, on a free-pool path, a paid path, and a fallback on failure. The models, providers, and routing actually used may change at any time according to those AI companies’ pricing policies and availability, and the Company’s operations settings. Auto-translation of a hotel address into English, and translation of hotel-admin site-support chat, may use a platform path and may not deduct hotel-wallet tokens.
- The Company does not provide PMS integration, Web Push in a plain iOS Safari tab, or hotel-admin translation APIs (
/api/translate) to floor-staff cookies.
5. Accounts
- Hotel-admin signup is limited to persons 14 or older and requires email, password, and agreement to these Terms and the Privacy Policy.
- Authentication uses Supabase Auth. Where bot protection (e.g. Turnstile) is configured, it must be completed.
- Members may optionally enable TOTP MFA, recovery codes, and email OTP recovery. When MFA is on, an extra code is required at sign-in.
- Members are responsible for email, password, and recovery codes. Suspected misuse must be reported promptly.
- The Company may refuse or limit signup or use for maintenance, closed signup, false information, or legal/Terms violations.
6. Hotel administrator duties
- Keep hotel name, contacts, rooms, Wi-Fi, hotel services, facility cards, photos, and front-desk hours accurate and lawful.
- The hotel is the on-site operator for guest use and is primarily responsible for guest handling, requests, and unlawful or harmful content.
- Manage room QR codes so they are reasonably available only to actual guests.
- Keep hotel-admin accounts and floor-staff invite QR codes separate; revoke invites and sessions when staff leave or a device is lost.
- Keep payment method, room count, subscription status, and token balance consistent with actual operations.
7. Guest use
- Guests use the portal in a browser with no app install and no QRFront account.
- Multiple devices may share one room session during a stay cycle. A new stay cycle (for example a new device scan after check-in time) may invalidate the prior session.
- Guests must not send illegal, obscene, harassing, or infringing messages.
- The guest portal is part of the hotel’s on-site service. The Company is not a party to the hotel–guest lodging contract.
7-2. Floor staff use
- Floor staff start a hotel-scoped device session by scanning a time-limited invite QR from Staff access on their own phone. Join is one-time; daily email login is not required.
- Floor staff may view and handle that hotel’s requests and chats. They cannot access hotel-admin settings, billing, invite issuance, or the platform Control Center.
- The session is kept in an HttpOnly cookie (
qrfront_staff_session). The server stores a hash, not the raw token. - Web Push is optional. It can be enabled on supported browsers such as Android Chrome. On iPhone, push may work only after Add to Home Screen (PWA); an ordinary Safari tab may not receive it. While the app is open, lists may also refresh on a short poll.
- Hotel administrators may revoke invites and end sessions. Lost devices must be revoked promptly.
- Floor staff must not export guest or other-hotel information without authority.
8. Trial and paid subscription
- New hotels may use a free trial for the period set by the Company (operations setting, typically about one month). Start conditions (such as registering a payment method) follow the billing screens.
- QRFront Service is priced annually by room-count bands (rounded up in tens of rooms), generally in USD, subject to a maximum (e.g. 1000 rooms).
- When a trial ends or payment fails, operations features may be limited. Hotel data is retained or deleted under the Privacy Policy and law.
- Demo/preview is not a paid contract.
9. AI translation tokens
- AI translation is billed separately from the subscription. Same-language chat may use no tokens; only successful translation usage is deducted.
- A free token grant may be added to the hotel wallet when a trial starts. The Company may also run a shared free pool, which is separate from hotel wallets.
- Extra usage is purchased in token packs (e.g. 10 million tokens). Unused balance does not expire monthly and rolls over.
- When tokens run out, translation may pause. Other subscription features follow the product description.
- Tokens are digital content available on grant. Once use (deduction) has begun, withdrawal of offer may be limited under Korea’s e-commerce consumer protection law.
10. Payments
- Charges run through Paddle, the payment gateway (PG) the Company connects. Test (sandbox) and live charges may coexist. Test payments may not move real funds.
- Amounts are recalculated on the server from room count and purpose (subscription, trial setup, token packs). Client-supplied amounts are not trusted.
- Tax, FX, and Paddle (PG) fees follow the checkout display and applicable law.
- Receipts and history are available in hotel billing and in the Company’s payment records.
11. Withdrawal and refunds
- These Terms do not waive withdrawal or refund rights required by the e-commerce act and other law.
- After a subscription is paid, if the Service has been used even once (including even one server call), no refund is given.
- Where digital content has already been supplied or used (tokens granted and used, subscription period consumed), withdrawal may be limited as the law allows.
- Unused prepaid amounts, double charges, and system-error charges are handled after verification under law and internal policy.
- Even without a self-serve refund button, members may request a refund via Clause 20. Operators may record a payment as refunded. Clause 11.2 still applies: no refund after even one use.
- If use is limited for a member’s breach or abuse, unused term or tokens need not be refunded except where law requires it.
12. AI disclaimer
- AI translation is statistical and is not warranted for accuracy, completeness, or fitness for a particular purpose. Errors, omissions, delay, and unsuitable wording can occur.
- Emergencies, medical/legal/safety instructions, and payment or contract terms must be confirmed by a human.
- NVIDIA, OpenAI, Anthropic (Claude), Google (Gemini), and other providers may fail, throttle, change pricing or policy, or change models. The models in use may change at any time.
13. Third-party processing
The following types of processors may handle data:
- Infrastructure, auth, and database: Supabase and similar
- AI translation: NVIDIA, OpenAI, Anthropic (Claude), Google (Gemini), and similar. Actual models may change at any time under those companies’ pricing policies
- Payments: Paddle (test or live). Full card numbers are not stored by the Company
- Bot protection: Cloudflare Turnstile and similar, if configured
- Web Push: the browser push service, if a floor-staff device subscribed
Details are in the Privacy Policy.
14. Acceptable use
Members and guests must not:
- Violate law, infringe rights, or send obscene, hateful, or violent content
- Attack the service, scrape without permission, or bypass accounts, QR, or sessions
- Abuse AI for spam, malware, or automation abuse
- Commit payment fraud or abuse tokens / the free pool
- Collect others’ personal data or trade secrets without authority
The Company may end sessions, suspend accounts, and cooperate with authorities.
15. Intellectual property
- Software, marks, UI, and documentation belong to the Company or licensors.
- Photos and text uploaded by a member remain with the member or rightful owner. The member grants the Company a license needed to operate the Service.
- Chat and translations are for that hotel’s operations. The Company does not store customer source text on the platform audit/usage ledger (it may store metadata such as request id, provider, latency, and token counts).
16. Interruptions
- The Company may suspend the Service for maintenance, outages, force majeure, third-party failure, legal duty, or security response.
- Control Center maintenance mode, signup/chat/AI kill switches, and hotel expiry may stop features immediately.
- Reasonable notice is given when practicable; urgent security or outages may proceed without prior notice.
17. Termination
- Members may request termination through in-product steps or support.
- The Company may limit or terminate for Terms breach, long inactivity, non-payment, or product shutdown.
- Deletion after termination follows the Privacy Policy and legal retention duties.
18. Limitation of liability
- To the extent permitted by law, the Company limits liability for free trials, demos, AI output, hotel–guest disputes, and member-posted content.
- The Company’s aggregate liability is limited to fees (including token packs) the hotel paid in the three months before the claim arose, except that this cap is not asserted for willful misconduct or gross negligence.
- Indirect loss, lost profits, lost opportunity, and data-recovery cost are disclaimed to the extent the law allows.
- Nothing in this clause reduces mandatory consumer-protection rights.
19. Governing law and venue
- These Terms and the service contract are governed by the laws of the Republic of Korea.
- Disputes are brought in the courts with jurisdiction under the Korean Civil Procedure Act. If a business address is registered, the court at that location may also have jurisdiction.
- Korean law applies to overseas users, subject to any local mandatory rules that cannot be waived.
20. Contact
Use the representative email or phone in the website footer, or the business information registered in the Control Center. If those fields are empty, use in-product support channels.
Addendum. These Terms take effect on 13 August 2026 and were amended on 15 August 2026.
