For guests, app users and website visitors
SUFRA — PRIVACY POLICY
Version 1.1 — Effective 14 September 2026
| Version | 1.1 | Effective date | 14 September 2026 |
|---|---|---|---|
| Privacy contact | privacy@sufra.tech | Governing privacy law | Qatar Law No. 13 of 2016 |
This Policy is issued under Law No. 13 of 2016 Concerning Personal Data Privacy Protection (the “Data Protection Law”) and applicable binding directions and guidance in the State of Qatar. It is incorporated by reference into any Sufra guest terms that expressly refer to it, but it does not replace a separate consent where the law requires one or reduce any mandatory privacy right.
Key points
| Topic | Summary |
|---|---|
| Who is responsible | Sufra is controller for account registration, Sufra-wide profiles, consent records, Platform security, Sufra analytics and Sufra communications. A restaurant or merchant is an independent controller for the Personal Data it receives or collects for its own bookings, orders, visits, service and permitted marketing. |
| What we collect | Account and contact details; profile and preference information; booking, order, visit and spend records; device and usage data; support communications; consent and security records; and insights derived from use of the Services. |
| Special Nature Personal Data | Allergy, health, religious and children’s data may receive special protection. We use designated controls, obtain explicit consent where required and do not activate processing that needs regulatory permission until the required permission and safeguards are in place. |
| Restaurants | Data is disclosed only for an Interaction and only to the extent necessary for that Interaction, your choices and applicable law. A Merchant should not see another Merchant’s order, spend or visit records. |
| Marketing | Marketing requires a current, valid opt-in for the relevant sender, channel and purpose. Service and security messages are not marketing. You can withdraw marketing consent at any time. |
| International processing | Your data is stored on Amazon Web Services in the Asia Pacific (Mumbai) region, India — outside Qatar. Other providers may also process data abroad. We assess each transfer and apply safeguards consistent with Qatar law. |
| Your rights | You may withdraw consent, object, request erasure where the legal conditions apply, correct inaccurate data, access your data and request a copy. You may also complain to the competent authority. |
| Contact | privacy@sufra.tech for Sufra-controlled processing. For a Merchant’s independent processing, contact that Merchant using its published privacy details or ask Sufra to help route the request. |
Who we are and how responsibility is allocated
Sufra Technology W.L.L., Commercial Registration No. 233626, Building 15, Street 2322, Zone 51, Floor 2, Qatar Science & Technology Park, Doha, State of Qatar (“Sufra”, “we”, “us” or “our”), operates the Sufra platform and related guest services (the “Services”).
The word “Merchant” includes a restaurant, hospitality venue or other business using Sufra. “Interaction” means a booking, order, visit, check-in, QR or menu interaction, or matched transaction that requires Personal Data to provide the selected service. “Personal Data” means information relating to an identified or reasonably identifiable natural person.
Sufra as controller
Sufra determines the purposes and means of processing for guest registration and authentication, Sufra-wide account and profile management, consent and privacy-choice records, Platform security, fraud prevention, support, service analytics, recommendations, product improvement and Sufra’s own communications. Sufra is the controller for those activities.
Merchants as independent controllers
When Personal Data is disclosed to a Merchant for a booking, order, visit, service request, matched transaction or permitted marketing, or where the Merchant independently collects Personal Data from you, that Merchant determines its own purposes and means and acts as an independent controller. It is responsible for its lawful purpose or consent, privacy notice, staff access, security, retention, processors, marketing and response to your rights. A Merchant’s own privacy notice applies to that processing.
Sufra as processor in limited cases
Where Sufra handles Merchant-controlled Personal Data solely on the Merchant’s documented instructions to provide a configured feature, Sufra acts as processor under the relevant data-processing terms. The factual use of the data determines the role; a contractual label does not override the facts.
Scope of this Policy
This Policy applies to individuals who create or use a guest account, use the Sufra app or website, open a Sufra-powered digital menu, communicate with Sufra, or interact with a Merchant through the Services. It also applies, in a limited way, to Merchant personnel whose business contact details and Platform activity are processed for access, support, audit and security.
It does not govern a Merchant’s independent website, loyalty programme, in-venue CCTV, Wi-Fi, payment system, delivery platform or other service that is not controlled by Sufra. It also does not govern employment or candidate data, which should be covered by a separate notice.
This Policy is a notice, not a blanket consent. Where consent is required, Sufra or the relevant Merchant will ask for it in a clear and specific form. You may decline optional processing without losing unrelated parts of the Services.
Personal Data we may collect
The data collected depends on the features you choose, the Merchant you interact with and the device or channel you use. We seek to collect only data relevant and adequate for a disclosed lawful purpose.
| Category | Examples | Typical source |
|---|---|---|
| Account and contact | Name, verified mobile number, account identifier, login or one-time-code records, and preferred language. | You; an authentication or communications provider. |
| Optional profile | Birthday or date of birth, preferred locations, accessibility preferences and information you choose to add to your profile. | You. |
| Preferences and Special Nature data | Food and seating preferences; allergen, intolerance, dietary, health or religious information where a designated feature is lawfully enabled. | You; exceptionally, a Merchant acting within its own controller responsibilities. |
| Booking, order and visit | Venue, date and time, party size, booking status, menu selections, item modifications, special requests, check-in, visit frequency and service communications. | You; the Merchant; its POS, booking or operational systems. |
| Spend and transaction references | Amounts, discounts, transaction status, visit count and a reference used to match a Merchant transaction to your account. | The Merchant or an integrated system. |
| Merchant service notes | Objective notes relevant to service, such as seating or beverage preferences, subject to the restrictions in this Policy. | Authorised Merchant personnel. |
| Device and technical | IP address, device type, operating system, app version, approximate time zone, identifiers, crash reports, security events and access logs. | Your device; the app; security and hosting systems. |
| Usage and cookies | Screens and menus viewed, searches, feature use, QR interactions, session information, cookie or SDK identifiers and preference settings. | Automatically when you use the Services, subject to required choices. |
| Communications | Support requests, complaints, feedback and correspondence with Sufra. | You; the relevant Merchant where it forwards an issue. |
| Consent, privacy and compliance | Consent wording and timestamp, channel and scope, withdrawals, objections, suppression records, rights requests and required compliance records. | You; Sufra; the relevant Merchant. |
| Derived insights | Taste profile, cuisine or item affinities, predicted preferences, service analytics, fraud indicators and de-identified statistics. | Generated from data described above. |
How we obtain Personal Data
- Directly from you when you register, complete your profile, adjust settings, place a booking or order, scan or use an interactive menu, submit a request, or contact support.
- From the Merchant and its authorised systems when it confirms or fulfils an Interaction, records an objective service preference, or matches a transaction to your account.
- From providers that support authentication, messaging, hosting, security, analytics or another enabled feature, subject to their role and our contracts.
- Automatically from your device, browser, app, cookies or similar technologies, subject to the choices described below.
- By deriving a limited insight from your prior interactions, such as a taste profile, service preference or fraud indicator.
If you provide Personal Data about another person, you must be authorised to do so and must give them any notice or obtain any consent required by law. Do not submit another person’s Special Nature Personal Data unless a designated lawful process expressly permits it.
Why we process Personal Data
Under the Data Protection Law, processing generally requires your consent unless it is necessary to achieve a disclosed lawful purpose for Sufra or another lawful recipient. We document the applicable basis and do not rely on consent where there is no real choice.
| Purpose | Main data | Basis under Qatar law |
|---|---|---|
| Create, authenticate and secure an account | Account, contact, device, security and consent records. | Your consent and/or processing necessary for the lawful purpose of providing and securing the requested account. |
| Provide a booking, order, visit or other Interaction | Account identifier, relevant profile fields, booking/order details, service messages and Merchant transaction records. | Your consent and/or processing necessary for the lawful purpose of delivering the requested service to you and the relevant Merchant. |
| Share selected data with an interacting Merchant | Only the fields needed for the Interaction and enabled by your choices. | Your specific choice or consent and/or necessity for the disclosed lawful purpose of the Interaction. |
| Process Special Nature Personal Data | Allergy, health, religious or children’s data where enabled. | A permitted reason, explicit consent or other required condition, a risk assessment and any permission required from the competent authority. |
| Personalise the Services and build a taste profile | Orders, visits, stated preferences and usage signals. | Your consent or a disclosed lawful purpose where processing is necessary and proportionate; you can request correction or reset. |
| Operate, support and improve the Services | Usage, device, support, performance and de-identified analytics. | Necessary lawful purposes including service quality, troubleshooting and product development, with de-identification where reasonably possible. |
| Prevent fraud, abuse and security incidents | Account, device, logs, risk indicators and relevant transaction references. | Necessary lawful purposes of protecting users, Merchants, Sufra and the integrity of the Services; legal obligations where applicable. |
| Send marketing | Contact details, consent record, channel and relevant engagement data. | Prior, express and current opt-in consent for the relevant sender, channel and purpose. |
| Meet legal, regulatory and claims requirements | Records relevant to a lawful request, complaint, audit, dispute or legal obligation. | A legal obligation, binding direction or necessary lawful purpose of establishing, exercising or defending rights. |
Withdrawing consent stops the relevant consent-based processing going forward. It does not make earlier lawful processing invalid, prevent us from keeping a withdrawal or suppression record, or require deletion of a record that must be kept for another lawful purpose.
Special Nature Personal Data and children
Under Qatar law, information about health, physical or mental condition, religion, ethnic origin, children, marital relations and criminal offences may be Personal Data of a special nature. Allergy, intolerance and some dietary information may therefore require enhanced controls even when you provide it voluntarily.
Allergy and dietary features
- These fields are optional unless the selected service cannot safely be provided without the information. A refusal does not affect unrelated features.
- Where required, Sufra asks for a separate, explicit consent and records the purpose, Merchant disclosure and withdrawal mechanism.
- Sufra will not activate or continue a processing activity that requires regulatory permission until the required assessment, safeguards and permission or approval are in place.
- Special Nature Personal Data must be entered only in designated fields. Merchant personnel must not place health, religious or children’s data in free-text service notes.
- We do not use allergy or health information for direct marketing or unrelated profiling.
Children
Guest accounts are intended for individuals aged 18 or over unless Sufra has expressly launched a child-appropriate service with a lawful guardian-consent process and any required regulatory permission. If you are under 18, do not create an account or submit Personal Data through the Services without that approved process.
A parent or legal guardian may contact privacy@sufra.tech to request access, correction, suspension or deletion of a child’s Personal Data where the law permits. If Sufra learns that child data was collected outside an approved process, it will restrict the processing, investigate and delete or otherwise handle the data as required by law.
Disclosure to Merchants
A Merchant does not receive unrestricted access to Sufra’s guest database. Data is disclosed only in connection with an Interaction, your privacy choices and a disclosed lawful purpose. Merely browsing a public menu should not, by itself, require disclosure of your name or full profile unless an interactive feature clearly tells you otherwise before disclosure.
| Interaction or choice | Data that may be disclosed | Recipient scope |
|---|---|---|
| Booking, order or service request | Account identifier and, where needed, name; booking/order details; relevant service preferences; contact route needed to fulfil the request. | Only the Merchant handling that request and authorised processors supporting it. |
| Personalised visit | Optional name, birthday or profile fields enabled for that purpose; relevant taste and service preferences. | Only the interacting Merchant and only while needed for the stated purpose. |
| Allergy or dietary support | Only the designated Special Nature fields covered by the lawful process, consent and permissions. | The interacting Merchant personnel who need the information to provide the service. |
| Matched transaction | Pseudonymous account or match identifier, Merchant-specific items, amount, date, visit count and spend history. | The Merchant or restaurant group to which that transaction belongs. |
| Direct marketing | Contact detail and consent scope for the specific Merchant, channel and purpose. | Only the Merchant covered by the current consent. A phone number is not a licence for unrelated use. |
A Merchant should not receive another Merchant’s orders, spend, visit history or staff notes. Any cross-Merchant profile element should be limited to information you entered, a Sufra-derived preference that is lawfully used, or information you specifically directed Sufra to share.
Privacy controls may allow you to turn particular identity, profile or marketing disclosures on or off. Marketing must remain a separate choice and should default to off. A withdrawal stops new disclosures for the withdrawn purpose, but a Merchant may retain limited records it must keep for law, an existing transaction, a complaint, a legal claim or suppression of further marketing.
Merchant service notes
Authorised Merchant personnel may record an objective note needed to provide consistent service. The Merchant acts as controller for the note and must ensure it is relevant, accurate, fair, secure and retained only as long as necessary.
- Permitted examples include a seating preference, preferred water, a language preference or another non-sensitive service choice.
- Notes must not contain insults, subjective judgments, discriminatory labels, financial assumptions, private conversations, or information about nationality, politics, criminal allegations or conduct unrelated to the service.
- Health, allergy, religious and children’s data must not be placed in free text; it belongs only in an approved designated field.
- A Merchant must restrict staff access, maintain auditability and respond to correction or deletion requests concerning its notes.
Sufra may provide technical controls, investigate misuse, restrict or delete a note where authorised, and suspend a Merchant’s access. Those controls do not make Sufra the controller of every Merchant note.
Taste profile and automated processing
If the feature is enabled, Sufra may use your orders, visits, clicks and stated preferences to create a taste profile or recommend venues and menu items. The profile is intended to personalise the Services and help you discover relevant options. You may request access, correction or reset through the available settings or privacy@sufra.tech.
Sufra does not use the taste profile to make a decision that, by itself, produces a legal effect or similarly significant effect on you. It does not determine a Merchant’s price, credit, employment or access to an essential service. If Sufra introduces materially different automated decision-making, it will provide a clear explanation and obtain any consent or permission required before use.
Marketing and service communications
Marketing from Sufra
Sufra sends promotional messages only where it holds a current, valid opt-in for the relevant channel and purpose. Consent must be an affirmative choice and not a pre-ticked box, silence or bundled acceptance of unrelated terms.
Marketing from a Merchant
A Merchant may send marketing using Sufra-sourced Personal Data only where a current consent covers that Merchant, the channel and the marketing purpose, or where the Merchant independently demonstrates another basis expressly permitted by applicable law. The Merchant is an independent controller for its message and must maintain consent and suppression records.
Required message standards
- The message must identify the sender, make its marketing nature clear, provide valid contact details and contain a simple, effective opt-out.
- The sender must stop promptly after withdrawal or objection and retain only the minimum suppression record needed to prevent further marketing.
- A disclosed mobile number or a past opt-in does not prove that consent remains current. The sender must honour the latest consent status available to it.
- A Merchant must not combine Sufra-sourced data with another list to bypass your choice or market on behalf of an unrelated affiliate, franchisor or third party.
Booking confirmations, order-status updates, security alerts, privacy notices and similar messages necessary to provide or protect the requested service are service communications, not marketing. They may continue while you use the relevant service even if you opt out of marketing.
Cookies, SDKs and similar technologies
The website and app may use cookies, software development kits, local storage, pixels or similar technologies. A current cookie or in-app notice should identify the specific technology, provider, purpose and duration in use.
| Type | Purpose | Choice |
|---|---|---|
| Strictly necessary | Authentication, session continuity, security, fraud prevention, load balancing and saving a privacy choice. | Used only to the extent necessary for the requested service or lawful security purpose. |
| Functional | Remember language, layout or non-essential preferences. | Used after the required choice; disabling may remove that convenience. |
| Analytics and performance | Understand feature use, crashes, performance and service improvement. | Used only after opt-in where required; reports should be de-identified or aggregated where reasonably possible. |
| Marketing | Measure or personalise promotional activity across services. | Used only after a specific opt-in. Sufra will not infer consent from browser use alone. |
You can use the cookie banner, in-app settings or device/browser controls to change non-essential choices. Blocking necessary storage may prevent an account or secure session from working. Device settings may not remove an existing server-side consent or suppression record, so use the Sufra privacy controls as well.
Service providers and other recipients
Sufra uses carefully selected providers only to the extent necessary for an enabled service. Depending on the current technical architecture, providers may support cloud hosting and backup, authentication, SMS or WhatsApp communications, push or email delivery, customer support, monitoring, security, analytics, integration and professional services. Payment processing for the Platform is provided by Tap Payments.
A provider acting as processor may handle Personal Data only on documented instructions, under written confidentiality, security, deletion, assistance and data-protection obligations. Sufra remains responsible for the processor obligations that applicable law places on Sufra. A current list of material providers, processing locations and roles is available on request from privacy@sufra.tech.
We may also disclose Personal Data:
- to a Merchant or its authorised processor as described in this Policy;
- to courts, law-enforcement, regulators or another competent authority where a valid law, order or binding direction requires it;
- to professional advisers, auditors or insurers subject to confidentiality and a legitimate need to know;
- to protect the rights, safety, property or security of users, Merchants, Sufra or another person, where the disclosure is lawful and proportionate; or
- in connection with a genuine merger, financing, restructuring or sale of all or part of the business, subject to due diligence controls, confidentiality, required notices and continued protection.
Sufra does not sell Personal Data to data brokers. Sufra may create and use aggregated or de-identified information for analytics, benchmarking, security, product development and reporting only where no Guest, Merchant or other person is reasonably identifiable and re-identification is not attempted.
International processing and cross-border transfers
Some hosting, communications, security, support or other providers may process Personal Data outside the State of Qatar. Cross-border processing includes remote access, viewing, retrieval, use or storage from another country.
Before a material transfer, Sufra assesses the data, purpose, recipient, location, access, risks and required protections. Where applicable, Sufra provides notice, uses contractual commitments, encryption, access control, logging, minimisation and other safeguards intended to maintain protection consistent with Qatar law. Sufra will not deliberately structure a transfer that violates the Data Protection Law or causes gross damage to individual privacy.
Because providers and regions may change for security, resilience or service reasons, this Policy does not hard-code an unverified hosting region. The current primary regions and material processors are disclosed through Sufra’s then-current provider list or on request. Sufra will give notice before a material change where reasonably practicable and will obtain any fresh consent required by law.
Retention and deletion
Sufra keeps Personal Data only for the period necessary for the purpose disclosed, an applicable legal obligation, security, a complaint or the establishment, exercise or defence of a claim. We apply an internal retention schedule based on the nature, sensitivity, risk and legal context of each record.
| Record | Retention approach |
|---|---|
| Account and profile | Kept while the account is active and for the limited period needed to complete closure, prevent fraud, resolve requests and meet legal obligations. Optional profile fields are deleted or de-linked when no longer needed. |
| Bookings, orders, visits and spend | Kept while needed to provide history and support, then according to the applicable transaction, dispute and legal-retention criteria. The Merchant sets its own lawful period for its copy. |
| Special Nature Personal Data | Kept only while the approved purpose, required permission and valid condition continue; reviewed more frequently and deleted or restricted when the basis ends. |
| Security, device and usage logs | Kept for a proportionate period needed to investigate security, fraud, reliability and abuse; shorter periods are used where the same purpose can be achieved. |
| Consent, withdrawal and suppression | Kept while the choice applies and for the period reasonably needed to prove compliance and prevent messages after opt-out. |
| Support, complaint and legal records | Kept until the matter is closed and for the applicable period needed for audit, legal obligations or claims. |
| Backups | Removed through the ordinary secure backup-rotation cycle. Until overwritten, a deleted record is isolated from ordinary use and accessed only for restoration, security or legal necessity. |
| De-identified data | May be kept for longer only while individuals and Merchants are not reasonably identifiable and re-identification is not attempted. |
Closing an account stops ordinary account use but does not necessarily delete every record immediately. Sufra may retain the minimum data needed for law, security, suppression, a completed transaction or a claim. A Merchant’s independent copy is controlled by that Merchant; Sufra will assist with routing a request but cannot silently erase records in another controller’s systems.
Security and personal data incidents
Sufra implements administrative, technical and organisational safeguards proportionate to the nature and importance of the Personal Data. They may include encryption in transit and at rest where appropriate, role-based and least-privilege access, authentication, logging, environment separation, secure development, vulnerability management, backup, incident response, staff confidentiality and processor due diligence.
No system can be guaranteed completely secure. If an incident may cause serious damage to Personal Data or individual privacy, the relevant controller will assess and make notifications to the competent authority and affected individuals without undue delay and within seventy-two (72) hours where applicable binding regulatory guidance requires that period. The notice may be staged where facts are still being investigated, as permitted by law.
A Merchant is responsible for incidents in systems or processing it controls and must coordinate with Sufra where the same incident affects the Platform. Sufra is responsible for incidents in processing for which Sufra is controller and will assist a Merchant where Sufra is acting as processor.
Protect your account by locking your device, using only trusted links, never sharing a one-time code and reporting suspected misuse promptly to privacy@sufra.tech or info@sufra.tech.
Your privacy rights
Subject to the Data Protection Law and any permitted limitations, you may exercise the following rights against the controller responsible for the relevant processing:
| Right | What it means |
|---|---|
| Withdraw consent | Withdraw a prior consent for future processing. A suppression or audit record may be retained where necessary. |
| Object | Object where processing is unnecessary for the purpose, excessive, discriminatory, unfair or unlawful. |
| Erasure or omission | Ask for deletion where the purpose has ended or all justification for retaining the data has ceased, subject to legal and claims exceptions. |
| Correction | Ask to correct inaccurate Personal Data and provide reasonable evidence of the accurate information where needed. |
| Access and information | Ask whether and why data is processed, review the Personal Data and receive information about relevant disclosures. |
| Copy | Request a copy of Personal Data. Sufra ordinarily provides an electronic copy without charge, but may apply a service charge only to the extent permitted by law. |
| Complain | Raise a complaint with Sufra, the relevant Merchant or the competent privacy authority in Qatar. |
How to submit a request
- Use the available account or privacy settings, or email privacy@sufra.tech. State the right you wish to exercise and the account or Interaction concerned.
- Sufra may verify identity, usually through the registered contact channel, and may ask for enough information to locate the records. Do not send unnecessary identity documents.
- Sufra will respond within the period required by applicable law and binding guidance and aims to respond without undue delay. A complex or third-party request may require clarification.
- A request may be limited where necessary to protect another person’s rights, confidential information, security, a legal obligation or a valid claim. Sufra will explain the lawful reason where permitted.
- If the request concerns Merchant-controlled processing, contact that Merchant. Sufra may forward the request and provide technical assistance, but the Merchant remains responsible for its response.
Complaints
If you are not satisfied, first contact privacy@sufra.tech so Sufra can investigate. You may also complain to the National Cyber Security Agency, National Data Privacy Office, State of Qatar, using the current complaint channel published on its official website.
Official NCSA privacy guidance and complaint information: www.ncsa.gov.qa
Changes to this Policy
Sufra may amend this Policy from time to time to reflect changes in law, guidance, Services, providers, security or processing. The current version and effective date will be published in the app or on the Sufra website.
Where a change materially affects your privacy or an existing choice, Sufra will provide an appropriate notice before the change takes effect where reasonably practicable. If the change requires a new consent or regulatory permission, Sufra will obtain it before starting that processing. Silence or continued use will not be treated as a substitute for a consent that the law requires to be express.
A prior version may be requested from privacy@sufra.tech. A change to this Policy does not retrospectively authorise processing that was unlawful when it occurred.
Contact details
| Contact | Details |
|---|---|
| Controller | Sufra Technology W.L.L. — Commercial Registration No. 233626 |
| Registered address | Building 15, Street 2322, Zone 51, Floor 2, Qatar Science & Technology Park, Doha, State of Qatar |
| Privacy and rights | privacy@sufra.tech |
| General and security support | info@sufra.tech |
| Website | www.sufra.tech |
| Regulator | National Cyber Security Agency — National Data Privacy Office, State of Qatar |
Legal framework used for this Policy
This Policy is drafted against the following Qatar legal and regulatory framework. The law and binding regulatory requirements prevail if guidance or this summary is inconsistent with them.
| Source | Relevance |
|---|---|
| Law No. 13 of 2016 Concerning Personal Data Privacy Protection | Transparency, consent and lawful purpose, individual rights, controller and processor obligations, security, breaches, special nature data, direct marketing and cross-border processing. |
| NCSA Privacy Notice Guideline | Content, transparency and layered presentation of privacy information. |
| NCSA Controller and Processor Guideline | Role allocation and processing responsibilities. |
| NCSA Individuals’ Rights Guideline | Operational handling of access, correction, erasure, objection and withdrawal. |
| NCSA Special Nature Processing Guideline | Risk assessment, permitted conditions, explicit consent where applicable and regulatory permission. |
| NCSA Electronic Communications for Direct Marketing Guideline | Prior express opt-in, sender transparency, channel and purpose scope, and opt-out controls. |
| NCSA Personal Data Breach Notifications Guideline | Assessment, notification content and the applicable seventy-two-hour guidance period where serious harm may result. |
END OF PRIVACY POLICY • VERSION 1.1 • EFFECTIVE 14 SEPTEMBER 2026