This policy explains what the AQ Bistro app collects, why, and what control you have over it. It covers the AQ Bistro Android application and the account you create inside it.
Request account and data deletion
1. Information we collect
Information you give us
| Data | When | Why |
|---|---|---|
| Name | Registration | To identify you on your orders and at the counter |
| Email address | Registration | Sign-in, order confirmations, account recovery |
| Password | Registration | Handled entirely by Google Firebase Authentication. We never see or store it. |
| Phone number (optional) | Profile | Contacting you about an order |
| Date of birth — day and month only (optional) | Profile | Issuing a birthday voucher |
| Delivery address | Delivery orders | Fulfilling the delivery |
| Reviews and ratings (optional) | After an order | Improving our food and service. If you tick “show my review on the AQ Bistro website”, the review, your star rating and your first name may be shown publicly on our website; untick it and the review stays private to AQ Bistro staff. |
Information created by using the app
| Data | Why |
|---|---|
| Order history — items, notes, totals, order type, table number | Preparing your order and showing you past orders |
| Loyalty points, tier, daily check-ins, mission progress | Running the rewards programme |
| Vouchers issued to you and whether they have been used | Preventing a voucher being spent twice |
| Your referral code and who invited you | Crediting referral bonuses |
Information collected automatically
| Data | Collected by | Why |
|---|---|---|
| Notification token for your device | Firebase Cloud Messaging | Sending order updates and offers |
| App usage events, device model, OS version, approximate location derived from IP address, and an app instance identifier | Google Analytics for Firebase | Understanding which parts of the app are used |
| Crash reports and diagnostic logs | Firebase Crashlytics | Finding and fixing crashes |
| App start-up and network timing | Firebase Performance Monitoring | Keeping the app responsive |
Camera
The app requests camera access for one purpose: scanning the QR code on a table so your order reaches the right table. Images are processed on your device to read the code and are never stored, uploaded or transmitted. You can decline the permission and still use every other part of the app.
2. What we do not collect
- Payment card details. The app does not process card payments. Payment is made at the counter, in cash, or through your own e-wallet app. We never see your card or wallet credentials.
- Precise location. The app does not request or use GPS location.
- Contacts, photos, files, microphone, or call data.
3. How we use your information
- To take, prepare and fulfil your orders
- To operate your account and the loyalty programme
- To send you order status updates and, if you have not opted out, occasional offers
- To keep the app secure and prevent abuse of vouchers and points
- To diagnose crashes and improve the app
We do not sell your personal data, and we do not share it with advertisers or data brokers.
4. Where your data is stored and who can access it
Order and profile records are stored in Google Cloud Firestore in the
asia-southeast1 region (Singapore). Other Firebase services, including authentication, analytics and diagnostics, may process data in other locations described by Google. Google processes this data on our behalf
as our service provider. Google's own privacy terms apply to their handling of it:
firebase.google.com/support/privacy.
Order confirmation and account emails are delivered through Gmail's mail servers (Google LLC).
Within AQ Bistro, access is limited by role. Counter and kitchen staff can see the orders they need to prepare and can look up a customer by phone number. Reviews, sales reports and staff administration are restricted to the owner account.
5. How long we keep it
- Account data — until you delete your account.
- Order history — retained for business and tax record-keeping. When your account is deleted, retained orders have the customer identifier, contact details, referral and voucher references, and free-text notes removed.
- Crash and analytics data — retained according to Google Firebase's default retention periods.
6. Your choices and rights
Delete your AQ Bistro account
Without the app: email alqaswah@outlook.com from your registered email address with the subject AQ Bistro account deletion. Ask us to delete your account and associated data. We verify ownership before processing the request. Never include your password. This request route also works after uninstalling the app.
You can delete your account from inside the app at any time: Account → Delete account. This permanently removes your profile, sign-in account, points balance, personal vouchers, mission progress, check-ins, feedback, referral links and device notification registrations. It cannot be undone. Records we are required to keep for tax and accounting purposes are retained in a form that no longer identifies you.
A temporary security lock containing your former account identifier is kept after deletion to prevent reuse of old sign-in tokens. It expires after 24 hours and is removed by daily cleanup, normally within 48 hours. It is not used for marketing or to restore your profile.
Other controls
- Notifications — turn off in your device settings at any time.
- Camera — decline or revoke in your device settings; only QR scanning stops working.
- Advertising ID — collection is disabled in this Android release.
- Access or correction — edit your profile in the app, or contact us for anything you cannot change yourself.
Under Malaysia's Personal Data Protection Act 2010 you may request access to, or correction of, your personal data, and may withdraw consent to our processing of it. Contact us at the address above.
7. Security
Data is transmitted over encrypted connections (HTTPS/TLS) and stored encrypted at rest by Google Firebase. Access to customer records is restricted by server-enforced security rules, not merely hidden in the app interface. Passwords are managed by Firebase Authentication and are never visible to us.
No system is perfectly secure. If a breach affects your personal data, we will notify affected users and the relevant authority without undue delay.
8. Children
The app is not directed at children under 13, and we do not knowingly collect their personal data. If you believe a child has created an account, contact us and we will delete it.
9. Changes to this policy
If we change this policy we will update the date at the top of this page, and for significant changes we will notify you in the app.