← AQ Bistro home

Privacy Policy

AQ Bistro mobile application · Last updated 12 September 2026

This policy explains what the AQ Bistro app collects, why, and what control you have over it. It covers the AQ Bistro Android application and the account you create inside it.

Who we are. AQ Bistro (Al-Qaswah Ummi’s Cuisine Sdn Bhd), 9G, Jalan Teknologi 3/6B, Taman Sains, Uptown Kota Damansara, 47810 Petaling Jaya, Selangor, Malaysia. For any question about this policy or your data, contact alqaswah@outlook.com.

Request account and data deletion

1. Information we collect

Information you give us

DataWhenWhy
NameRegistrationTo identify you on your orders and at the counter
Email addressRegistrationSign-in, order confirmations, account recovery
PasswordRegistrationHandled entirely by Google Firebase Authentication. We never see or store it.
Phone number (optional)ProfileContacting you about an order
Date of birth — day and month only (optional)ProfileIssuing a birthday voucher
Delivery addressDelivery ordersFulfilling the delivery
Reviews and ratings (optional)After an orderImproving our food and service. If you tick “show my review on the AQ Bistro website”, the review, your star rating and your first name may be shown publicly on our website; untick it and the review stays private to AQ Bistro staff.

Information created by using the app

DataWhy
Order history — items, notes, totals, order type, table numberPreparing your order and showing you past orders
Loyalty points, tier, daily check-ins, mission progressRunning the rewards programme
Vouchers issued to you and whether they have been usedPreventing a voucher being spent twice
Your referral code and who invited youCrediting referral bonuses

Information collected automatically

DataCollected byWhy
Notification token for your deviceFirebase Cloud MessagingSending order updates and offers
App usage events, device model, OS version, approximate location derived from IP address, and an app instance identifierGoogle Analytics for FirebaseUnderstanding which parts of the app are used
Crash reports and diagnostic logsFirebase CrashlyticsFinding and fixing crashes
App start-up and network timingFirebase Performance MonitoringKeeping the app responsive

Camera

The app requests camera access for one purpose: scanning the QR code on a table so your order reaches the right table. Images are processed on your device to read the code and are never stored, uploaded or transmitted. You can decline the permission and still use every other part of the app.

2. What we do not collect

3. How we use your information

We do not sell your personal data, and we do not share it with advertisers or data brokers.

4. Where your data is stored and who can access it

Order and profile records are stored in Google Cloud Firestore in the asia-southeast1 region (Singapore). Other Firebase services, including authentication, analytics and diagnostics, may process data in other locations described by Google. Google processes this data on our behalf as our service provider. Google's own privacy terms apply to their handling of it: firebase.google.com/support/privacy.

Order confirmation and account emails are delivered through Gmail's mail servers (Google LLC).

Within AQ Bistro, access is limited by role. Counter and kitchen staff can see the orders they need to prepare and can look up a customer by phone number. Reviews, sales reports and staff administration are restricted to the owner account.

5. How long we keep it

6. Your choices and rights

Delete your AQ Bistro account

Without the app: email alqaswah@outlook.com from your registered email address with the subject AQ Bistro account deletion. Ask us to delete your account and associated data. We verify ownership before processing the request. Never include your password. This request route also works after uninstalling the app.

You can delete your account from inside the app at any time: Account → Delete account. This permanently removes your profile, sign-in account, points balance, personal vouchers, mission progress, check-ins, feedback, referral links and device notification registrations. It cannot be undone. Records we are required to keep for tax and accounting purposes are retained in a form that no longer identifies you.

A temporary security lock containing your former account identifier is kept after deletion to prevent reuse of old sign-in tokens. It expires after 24 hours and is removed by daily cleanup, normally within 48 hours. It is not used for marketing or to restore your profile.

Other controls

Under Malaysia's Personal Data Protection Act 2010 you may request access to, or correction of, your personal data, and may withdraw consent to our processing of it. Contact us at the address above.

7. Security

Data is transmitted over encrypted connections (HTTPS/TLS) and stored encrypted at rest by Google Firebase. Access to customer records is restricted by server-enforced security rules, not merely hidden in the app interface. Passwords are managed by Firebase Authentication and are never visible to us.

No system is perfectly secure. If a breach affects your personal data, we will notify affected users and the relevant authority without undue delay.

8. Children

The app is not directed at children under 13, and we do not knowingly collect their personal data. If you believe a child has created an account, contact us and we will delete it.

9. Changes to this policy

If we change this policy we will update the date at the top of this page, and for significant changes we will notify you in the app.