Privacy Policy

Last updated: 7 July 2026

QDOM Ltd (“QDOM”, “we”, “us”) operates the Quick Deals on Meals platform — this website, the QDOM diner app, and the QDOM restaurant app. We are the data controller for the personal data described below. QDOM Ltd is registered in England & Wales (Company No. 17065413). This policy explains what we collect, why, how long we keep it, and your rights under UK GDPR and the Data Protection Act 2018.

1. What we collect, and why

Diners (app users). Name, email address, phone number and password when you create an account (lawful basis: contract — we need these to run your account). Your device location while you use the app, so we can show deals near you (lawful basis: consent, via your device’s location permission — you can withdraw it in your device settings at any time). Your claims and redemptions (lawful basis: contract). Push notification tokens if you enable notifications (lawful basis: consent).

Restaurant owners and staff.Name, email, phone, password, and your venue’s business details, menu and photos (lawful basis: contract). Billing status for the flat monthly subscription (lawful basis: contract; see “Payments” below — we never see or store card numbers).

Website visitors. If you submit our contact or restaurant-interest forms, the details you provide (lawful basis: legitimate interest in responding to you). Analytics cookies as described in section 6.

We practise data minimisation: we do not collect anything not listed here, and we never sell personal data.

2. Location data

“Deals near me” is the heart of QDOM, so the diner app uses your device location while the app is in use. Location is used to run your nearby-deals query and is not used to build movement profiles, is not shared with restaurants beyond the fact that you claimed their deal, and is not sold or shared with advertisers. You can use search without location, with reduced functionality.

3. Payments

Restaurant subscription payments are processed by Stripe. Card details go directly to Stripe and never touch QDOM’s servers. Diners pay restaurants directly at the venue — QDOM takes no payment from diners and holds no diner payment details.

4. Who we share data with (processors)

We use a small number of service providers to run the platform:

  • Hetzner (Germany/EU) — hosting; all core data stays in the EU.
  • Stripe — subscription payments.
  • Amazon Web Services (SES) — transactional email (e.g. verification codes).
  • Google Firebase (FCM) — push notifications, if you enable them.
  • Cloudflare — content delivery and security; R2 for image storage.
  • Google — analytics on this website, and Google Places when a restaurant imports its business listing.
  • Meta — advertising measurement pixel on this website (see section 6).

Where a provider processes data outside the UK/EEA (for example AWS SES or Google FCM in the United States), the transfer is protected by the UK International Data Transfer Agreement/Addendum or equivalent safeguards in that provider’s data processing terms.

5. How long we keep data

  • Account data: while your account is active.
  • Deleted accounts: anonymised within 30 days of deletion — your name, email and phone are permanently overwritten.
  • Verification codes: expire after 10 minutes.
  • Deal claims: expire after 60 minutes if unredeemed; redemption records are kept as anonymous statistics.
  • Moderation audit logs: kept for platform safety and legal compliance.

6. Cookies and analytics

This website uses Google Analytics and a Meta pixel to understand how visitors find and use it. These load only on the marketing website — not inside the diner or restaurant apps. Your browser’s cookie controls and standard opt-out tools apply.

7. Your rights

Under UK GDPR you can ask us to:

  • access a copy of your data;
  • correct inaccurate data;
  • delete your data (you can also delete your account directly in the app — see section 5);
  • restrict or object to processing, including withdrawing location consent;
  • receive your data in a portable format.

Email privacy@quickdealsonmeals.com and we will respond within one month. You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk.

8. Security

All traffic is encrypted in transit (TLS). Passwords are stored hashed. Access to venue data is isolated per restaurant, admin actions are audit-logged, and we apply rate limiting, hardened file-upload validation and other technical controls throughout the platform.

9. Changes and contact

We will update this page when our practices change and revise the date at the top. Questions? Contact privacy@quickdealsonmeals.com or see our contact page.