Guide
Is QR code ordering safe? What restaurant owners should check
QR code ordering is safe when the system checks every order on its server. The real risks are fake QR stickers, edited links, tampered prices and orders from people who aren't at the table, and each one can be guarded against.
Risk: a fake QR sticker over yours
The most common QR trick has nothing to do with your ordering system. Someone sticks their own code over yours, and guests who scan it land on a lookalike page that takes their money. It works best where codes are loose stickers that nobody checks.
Check every table’s code at the start of each service, and train staff to notice a code that looks different or sits on top of another. Use tamper-evident holders or table tents, where a sticker on top is easy to spot, and print your restaurant’s name next to each code. Tell guests what they should see after scanning: your restaurant’s name and logo. If a guest says a payment page looked wrong, check that table’s code straight away.
How KioSync helps: your logo and welcome line appear on the ordering page, so a guest who lands on a different page has a reason to stop and ask.
Risk: someone edits the link
A QR code is only a link. If that link carries a plain table number, for example one ending in “table=5”, anyone can change the number and place orders that show up for another table, or even another restaurant on the same system. The fix is a table code the server can verify, so it can tell when a link has been changed.
How KioSync helps: each table’s QR carries an encrypted, tamper-proof table code, and the server rejects a link edited to point at another table or restaurant. The security page explains how KioSync checks each order.
Risk: changed prices
If an ordering system trusts the prices that the guest’s phone sends, someone who knows how could edit the cart and pay less than the menu price. The same goes for taxes, sizes and add-ons. The safe approach is for the server to ignore prices from the phone and work out every bill from its own menu. It is also worth asking what happens when you change a price while a guest already has that dish in their cart: the bill should use the current menu price, not the one the phone remembers.
How KioSync helps: prices, GST, sizes and add-ons are recalculated on KioSync’s server for every order, so a tampered cart can’t change the bill, and sold-out or hidden dishes are refused at checkout even if a guest’s screen is out of date.
Risk: orders from outside the restaurant
A photo of a QR code works anywhere. Unless the system checks something more than the code, someone who has photographed it, or shared it in a group chat, could send an order from outside while you’re open. Most restaurants rely on one of two checks: staff open a table before it can order, or the kitchen only cooks orders that are already paid. Whichever you use, ask staff to check any order for a table that nobody is sitting at before the kitchen starts on it.
How KioSync helps: KioSync’s printed QR codes don’t expire and there is no location check, so in standard mode someone with a photo of a table’s code can place an order while you’re open. Optional table sessions, switched on for your restaurant on request, make a table’s QR accept orders only after staff open the table, and one tap switches every table off. With cash turned off, orders reach the kitchen only once paid, and staff can cancel an unwanted order.
Risk: duplicate orders
A double tap, a slow connection or a guest pressing “Order” again can send the same order twice, and the kitchen cooks both. A good system gives each checkout its own reference, so the server recognises a repeat and returns the original order instead of creating a new one. Duplicates waste food and staff time, and in a rush they are easy to miss until two identical plates reach the same table.
How KioSync helps: double taps and network retries never create duplicate orders.
Risk: payment safety
Card and UPI details should never pass through the restaurant’s own ordering screens. They belong on a payment gateway’s checkout page, which is built to handle them. Check where the money settles, too: it should go to your bank account rather than sit with the ordering provider, and your gateway’s secret keys should be stored securely.
How KioSync helps: online payments go through your own Razorpay, PayU or PhonePe account, so money settles directly to your bank, and the gateway’s checkout handles card and UPI details; KioSync doesn’t store card numbers. Gateway secret keys are encrypted at rest and never shown again after saving. More on payments.
Questions to ask any QR ordering provider
Whichever system you choose, these questions show how seriously it treats safety:
- Does the server recalculate prices and tax for every order, or trust the phone?
- Is the table code in the link protected, so an edited link is rejected?
- Can you limit orders to tables that staff have opened, or to orders that are already paid?
- Do printed codes expire, and what does it take to replace one?
- How does the system stop duplicate orders?
- Where do guests enter card and UPI details, and where does the money settle?
- How are your payment gateway keys stored, and who can see them?
- Is each restaurant’s data kept separate from every other restaurant’s?
How KioSync helps: the security page answers these for KioSync, including what it doesn’t do yet.
Frequently asked questions
Can QR codes be hacked?
A QR code is just a printed link, so there is little in the code itself to hack. The real risks are a fake sticker placed over your code and a link that someone edits, which is why the ordering system should check every order on its server.
Is it safe for guests to pay through a QR menu?
Paying through a QR menu is safe when the payment happens on a known payment gateway’s checkout page. With KioSync, online payments go through your own Razorpay, PayU or PhonePe account, and KioSync doesn’t store card numbers.
Should restaurant QR codes expire?
Expiring codes stop old photos of a code from working, but they mean replacing printed codes or adding steps for guests. KioSync’s printed QR codes don’t expire today; optional table sessions, switched on for your restaurant on request, control when each table can order instead.
How do I stop prank orders?
To stop prank orders, let the kitchen act only on orders you can trust: orders from tables that staff have opened, or orders that are already paid. In KioSync, optional table sessions, switched on for your restaurant on request, do the first, turning cash off does the second, and staff can cancel an unwanted order.
What should guests check before paying?
Before paying, guests should check that the ordering page shows the restaurant’s name and logo and that the payment page belongs to a known payment gateway. If anything looks wrong, they should ask a member of staff first.