Legal
Privacy Policy
QSRTasks LLC
Effective August 1, 2026 · Last updated August 1, 2026
This policy explains what personal information we handle on behalf of the restaurant operators who use QSRTasks, what we do with it, and how to exercise your rights.
1. Who We Are and What This Policy Covers
QSRTasks LLC (“QSRTasks,” “we,” “us,” or “our”) provides a business-to-business software platform that helps quick-service-restaurant operators manage employees, scheduling, timekeeping, inventory, financial reporting, training, and applicant onboarding (the “Service”). This Privacy Policy describes how we collect, use, disclose, and protect personal information in connection with the Service and our website at qsrtasks.com (the “Site”). It applies to restaurant employees and job applicants whose information is processed through the Service, to the client personnel who administer and use the Service, and to visitors to our Site.
2. Our Role: Service Provider and Processor
Most of the personal information we handle is provided to us by, or at the direction of, our clients — the restaurant operator organizations that subscribe to the Service (each, a “Client”). For that information, the Client decides why and how the data is used, and we process it only on the Client’s behalf and instructions. In privacy-law terms, the Client is the “controller” (or “business”) and QSRTasks is the “processor” (or “service provider”). If you are an employee or job applicant of one of our Clients, your employer (or prospective employer) is responsible for the decisions about your data, and requests about your data are best directed to them, as described in § 8. For information about visitors to our Site and our own business contacts, we act as the controller.
3. Information We Collect
We collect the following categories of information.
3.1 Information provided by Clients and their authorized data feeds
Our Clients and their authorized restaurant-technology providers transmit information to the Service, including through data feeds such as DataPass (QSRSoft), QSRSoft reporting services, Paradox, McHire, McDonald’s corporate data feeds, Checkr, and FullSchedule. Each feed operates only with the Client’s authorization. The categories include:
| Category | Examples | Notes |
|---|---|---|
| Employee identity & contact | Name, address, phone, and email | Personal information |
| Date of birth | DOB | Encrypted at rest |
| Payroll & timekeeping | Pay rates, hours, time punches | Employee financial information |
| Store financial / cash | Cash sheets, deposits, sales totals | Business data, generally not personal information |
| Applicant data | Job-applicant records received from hiring platforms | Encrypted personal information |
3.2 Information collected directly
When Client personnel create accounts, contact support, or communicate with us, we collect the information they provide, such as name, work contact information, role, and message content.
3.3 Information collected automatically
When you use the Service or Site, we collect log and device information such as IP address, browser type, pages viewed, and timestamps, using cookies and similar technologies. You can control cookies through your browser settings; the Service may not function properly without essential cookies.
3.4 Information we deliberately do not collect
The Service is designed not to ingest, store, or display Social Security numbers, bank account or routing numbers, payment card numbers, or employee direct-deposit details. Sales and payment figures in the Service are aggregate store totals, not individual payment credentials.
4. How We Use Information
We use personal information to provide, maintain, secure, and improve the Service; to perform our contracts with Clients and follow their documented instructions; to authenticate users and enforce role-based access; to send transactional and service communications (including via email, SMS, and mobile push notifications, with consent where required); to comply with legal obligations; and to detect, investigate, and prevent security incidents and misuse. We do not use personal information processed on behalf of Clients to build advertising profiles, and we do not sell personal information or share it for cross-context behavioral advertising.
5. How We Disclose Information
We disclose personal information only as follows:
- To subprocessors and service providers that support the Service under written contracts limiting their use of the data, currently including providers of cloud hosting and storage (DigitalOcean; Amazon Web Services), deployment orchestration (Hatchbox), transactional email (Mailgun), SMS delivery (Twilio), and mobile push notifications (Apple and Google).
- To the relevant Client — your employer or prospective employer — whose authorized managers access their organization’s data through the Service. Each Client organization’s data is isolated from every other Client’s.
- For legal reasons, when we believe disclosure is required by law, subpoena, or court order, or is necessary to protect the rights, safety, or property of QSRTasks, our Clients, or others.
- In a business transfer, in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy’s commitments.
6. Security
We maintain administrative, technical, and physical safeguards designed to protect personal information at a level at least consistent with industry standards for comparable services, including encryption of personal information at rest, tenant isolation between Client organizations, role-based access controls, transport-layer encryption, rate limiting, and exclusion of personal information from application logs. No system is perfectly secure, and we encourage users to protect their credentials. Our procedures for responding to security incidents, including legally required notifications, are described in our Data Incident Response and Breach Notification Procedure.
7. Retention
We retain personal information processed on behalf of a Client for as long as the Client’s subscription is active and thereafter as the Client instructs or as our agreement with the Client provides, after which it is deleted or de-identified within 60 days. We retain Site and business-contact information for as long as needed for the purposes described above, and as required by law.
8. Your Privacy Rights — How to Make a Request
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to object to or restrict certain processing. Because most of the information we hold is processed on behalf of your employer or prospective employer as controller, the law generally directs those requests to the Client, and we support our Clients in honoring them. If you submit a request directly to us for Client-controlled data, we will refer it to the relevant Client and assist. For information for which QSRTasks is the controller (for example, Site visitor data), contact us as set out in § 13 and we will respond within the time required by applicable law. We will not discriminate or retaliate against anyone for exercising privacy rights.
9. Texas Residents
The Texas Data Privacy and Security Act (Tex. Bus. & Com. Code ch. 541) (“TDPSA”) grants Texas residents rights over personal data collected about them as consumers acting in an individual or household context. Data processed in an employment context is generally outside the TDPSA’s scope; QSRTasks nevertheless applies the safeguards in § 6 to all personal information it processes. QSRTasks also maintains reasonable procedures to protect sensitive personal information as required by the Texas Identity Theft Enforcement and Protection Act (Tex. Bus. & Com. Code ch. 521) and provides breach notifications as required by § 521.053. Where the TDPSA applies to data for which QSRTasks is the controller, Texas residents may exercise the rights of access, correction, deletion, portability, and opt-out described in the statute by contacting us under § 13, and may appeal a refusal by email at admin@qsrtasks.com.
10. California Residents
This section applies if and to the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), applies to QSRTasks’ processing of your personal information. California residents — including employees and job applicants of California employers — have the right to: know the categories and specific pieces of personal information collected about them, the sources, the purposes, and the categories of third parties to whom it is disclosed; delete personal information, subject to statutory exceptions; correct inaccurate personal information; limit the use of sensitive personal information to purposes permitted by regulation; opt out of the sale or sharing of personal information; and be free from retaliation for exercising these rights.
In the preceding 12 months, we have collected the categories of personal information described in § 3 (identifiers; professional or employment-related information; and characteristics of protected classifications, such as veteran and disability status, where a Client’s onboarding process collects them). We collect them from the sources described in § 3, use them for the purposes in § 4, and disclose them for business purposes to the categories of recipients in § 5. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We do not knowingly collect personal information of consumers under 16 years of age for sale or sharing. Where QSRTasks processes California personal information on behalf of a Client, it does so as a “service provider” and the Client is the “business” responsible for responding to consumer requests; we assist Clients as required by our contracts. To exercise rights against QSRTasks directly, or through an authorized agent, use the contact methods in § 13; we will verify your identity before responding.
11. European Economic Area and United Kingdom
This section applies if and to the extent the EU General Data Protection Regulation or the UK GDPR (together, “GDPR”) applies to our processing. QSRTasks processes Client-provided personal data as a processor under art. 28 GDPR, pursuant to a data processing agreement with the relevant Client, and processes controller data (such as Site visitor data) on the legal bases of contract performance (art. 6(1)(b)), legitimate interests in operating and securing the Service (art. 6(1)(f)), consent where required (art. 6(1)(a)), and legal obligation (art. 6(1)(c)). Data subjects have the rights of access, rectification, erasure, restriction, portability, and objection under arts. 15–21 GDPR, exercisable against the controller; where QSRTasks is the processor, we will refer your request to the relevant Client and assist. If personal data is transferred from the EEA or UK to the United States, we will implement an approved transfer mechanism, such as the European Commission’s Standard Contractual Clauses or the UK International Data Transfer Addendum. You have the right to lodge a complaint with your supervisory authority. Our EU/UK representative, when appointed, will be listed here.
12. Children and Minors; COPPA
The Service and Site are business tools intended for use by adults, are not directed to children, and we do not knowingly collect personal information from children under 13 within the meaning of the Children’s Online Privacy Protection Act (“COPPA”). The Service is not designed for, and must not be used for, online interaction with children under 13. Because quick-service restaurants lawfully employ workers who are minors (for example, 14- and 15-year-olds where permitted by wage-and-hour law), the Service may process employment records of minors supplied by their employer; we treat those records as employee personal information subject to the safeguards in § 6, and Clients are responsible for complying with laws applicable to the employment records of minors. If you believe a child under 13 has provided personal information to us directly, contact us under § 13 and we will delete it.
13. Contact Us
Questions, requests, and complaints may be directed to: QSRTasks LLC, Attn: Privacy, 956 Stirrup Drive, Spring Branch, TX 78070, or by email to admin@qsrtasks.com. If you are an employee or applicant of a Client, please also consider contacting your employer’s management or human-resources contact, who controls your data.
14. Communications Preferences
Transactional messages (such as schedule notifications) are part of the Service. Where we send SMS or mobile push notifications, we do so with the consent and recordkeeping required by applicable law, and recipients may opt out at any time — for SMS, by replying STOP; for push notifications, through device settings; for marketing email, if any, through the unsubscribe link in each message.
15. Changes to This Policy
We may update this Policy from time to time. We will post the updated version with a revised “Last Updated” date and, for material changes, will provide notice through the Service or by email before the changes take effect.
Questions about your privacy?
Reach out through our contact page or email admin@qsrtasks.com. If you are an employee or applicant of one of our Clients, your employer controls your data — see § 8.