Privacy Policy

Last updated 4 October 2026

Who operates the service

Qliovio is the online service at qliovio.com. A local business can apply for a store, publish a product catalog, and take delivery or pickup orders.

Qliovio operates the service. This page does not name a registered company or a registered office, because the product does not publish those details. Questions about personal data go to the address at the end of this page.

Platform data and store data

Qliovio decides how it handles store applications and merchant accounts. That information is for the platform itself.

When a customer orders on a merchant's storefront, Qliovio processes the order so that merchant can receive and fulfill it. The merchant chooses the products, prices, descriptions, and whether the order is delivered or picked up. The merchant is responsible for that sale. Qliovio provides the software and is not the seller of the goods.

Store applications

An application asks for a contact name, email, phone, store name, business location, and an optional note.

Before an application is stored, Qliovio emails a one-time code to that address. The code expires after 10 minutes. Qliovio stores a hash of the code, not the code itself. The pending check, including the form and the IP address used to request the email, is removed about a day after it is created.

Qliovio does not accept an application when the phone, address, or network location is in Russia, Belarus and Iran, when the email cannot receive mail, or when that email already belongs to a merchant account or an open application.

Merchant accounts

A merchant signs in with an email and a password. The password is stored only as a hash and cannot be read back.

Access to a store is a membership for that store. The same email can be a member of more than one store.

Customer orders

A customer does not create a Qliovio account. Checkout asks for a name and a phone number. Email is optional. A delivery order asks for an address. The customer may leave a comment.

The order keeps the items, quantities, and prices from that store's catalog, the delivery or pickup choice, and the payment method the store has turned on.

Qliovio does not store payment card numbers. Online card payment is handled by the provider that merchant configured: LiqPay or plata by mono.

The phone number is how a customer is recognized inside one store. The same phone in another store is a different customer.

Technical and security data

A store application stores the IP address, browser type, language, referrer, and campaign parameters so Qliovio staff can review abuse. Merchants and the public confirmation page do not see those fields. A country inferred from a phone number or an IP address is not treated as a person's nationality.

That application review data is deleted after 12 months. The application itself remains.

Checkout can store the IP address and browser type, encrypted, to limit abusive orders. The merchant's order page does not show those raw values.

The browser receives a random identifier in a signed cookie named qliovio_visitor. It is not a device fingerprint. It is used to count checkout attempts.

If a checkout looks abusive, the page can ask Cloudflare Turnstile to check that a person is using it. A normal checkout does not show that check.

Text a merchant writes for a menu, category, or product may be sent to Google so it can be translated. Customer names, phones, and addresses are not sent for translation.

Why the data is used

Qliovio uses this data to review applications, open and run stores, show catalogs, take and track orders, send service email, limit abuse, and protect the service.

How long data is kept

Merchant accounts and orders are kept while the store is in use and for as long as needed to finish an order, handle a dispute, or meet a legal duty. This page does not set a fixed number of years.

The one-time email code expires after 10 minutes. The pending verification record is removed after about a day.

Application data kept only for abuse review is deleted after 12 months.

Service providers

The application runs on an OVHcloud server. Cloudflare proxies DNS and HTTPS. When a checkout check is shown, Cloudflare Turnstile performs that check.

Uploaded images are stored in a private Amazon S3 bucket.

Service email is sent through the mail server configured for qliovio.com. This page does not name a separate email company.

An address or map coordinates may be sent to Google to show a map, suggest an address, or check a delivery zone.

If the merchant turns on online card payment, that payment is processed by LiqPay or plata by mono on the merchant's account. Qliovio stores that store's provider secrets encrypted.

Security

Emails and phone numbers that identify a person, and payment-provider secrets, are encrypted in the database. Passwords are hashed. The database is not open to the public internet. The site is served over HTTPS.

These steps reduce risk. They are not a promise that access by the wrong person is impossible, and Qliovio does not claim a security certification.

Your requests

You can email Qliovio to ask what personal data it holds, to correct it, or to ask for deletion. Qliovio may need enough detail to find the record, and it may keep a copy when a legal duty or an open order requires that.

The merchant may also keep order details needed to deliver the goods. A question about one store's sale can be sent to that store as well.

Other countries

Hosting, email, file storage, maps, translation, the Cloudflare check, and payment providers may process data in countries other than the merchant's or customer's country. Qliovio does not keep a separate public list of each transfer.

Cookies

A session cookie keeps a merchant signed in and keeps a checkout cart.

A signed cookie remembers the language, Ukrainian or English.

The qliovio_visitor cookie is a random identifier used to limit abusive checkouts. It is HTTP-only. It is not used for advertising.

Cloudflare may set its own cookies when Turnstile is shown.

Qliovio does not use advertising cookies, and the product does not show a cookie-consent banner.

Changes

Qliovio updates this page when the service changes. The date above is the latest update.

Contact

Privacy questions and requests about personal data go to this address.

[email protected]