Feature
How KioSync keeps QR orders safe
KioSync protects QR orders on the server, not just in the app: each table’s QR carries an encrypted, tamper-proof code, and every price, tax and sold-out check is redone on our server. Optional table sessions and pay-first mode help keep unwanted orders out of your kitchen.
Tamper-proof table codes
Each table’s QR link carries a code encrypted and authenticated with AES-256-GCM. The code holds your restaurant and the table number, and only KioSync’s server can read it.
When a guest places an order, the server decrypts the code and checks that its restaurant and table match the order. Changing the table or restaurant in the link is rejected, and so is a code that has been edited or made up, because it fails the authentication check. For dine-in orders, the table number also has to exist in your restaurant: an order for a table number you haven’t set up is refused.
The phone can’t change the bill
Whatever prices a guest’s phone shows or sends, KioSync works out every bill again from your menu on the server: prices, GST, sizes and add-ons are recalculated for every order, so a cart edited on the phone can’t lower the bill. Counter and captain orders go through the same checks.
On the Basic and Pro plans, loyalty redemptions are checked on the server too: KioSync applies your redemption cap, minimum order and cooldown, and points held by an unpaid order can’t be spent again.
Sold-out and hidden dishes are refused
When you mark a dish sold out or hide it from the menu, KioSync refuses it at checkout, even if a guest’s screen is out of date. The check runs on the server for QR, counter and captain orders alike, so one switch covers every way an order comes in.
Guests’ menus also refresh on their own, and carts saved on their phones are checked against the live menu, so sold-out dishes drop out of them.
No duplicate orders
Every checkout carries a one-time key. If a guest double-taps the order button, or a weak network makes the phone send the order twice, the server recognises the key and returns the original order instead of creating a second one. The key survives a page refresh, so retrying after a refresh doesn’t create a duplicate either.
Limiting orders from outside the restaurant
Printed QR codes don’t expire, so in standard mode anyone with the link or a photo of it can order while you are open. Two optional switches reduce the risk: table sessions, switched on for your restaurant on request, reject orders for tables staff haven’t opened, and pay-first mode (cash turned off) keeps unpaid orders away from the kitchen and printer. An open table can still receive an order from someone with its QR, but staff see every order and can cancel one while it is still queued, and a table can’t close with unpaid orders. In the optional captain mode, “close all” also turns every table’s QR off at once, for example during a Wi-Fi outage. For the wider risks, such as fake QR stickers, see the QR ordering safety guide.
Your data and keys
Each restaurant’s data is isolated: staff logins reach only their own restaurant, and the ordering pages accept only table codes issued for the restaurant they belong to.
Payment gateway keys are encrypted at rest and never shown again after saving, and KioSync doesn’t store your guests’ card numbers or banking details. Five roles (owner, manager, counter, captain and kitchen) control who can change what: managers can’t see sales or staff data, and kitchen logins can’t open or close tables. The activity log records who changed menus, prices, payments and settings, and logging out ends that login’s sessions.
Frequently asked questions
Can someone change the table number in the QR link?
No. Each KioSync table QR carries a tamper-proof code, and the server rejects a link that has been edited to another table or restaurant.
Can a guest change prices in their cart?
No. KioSync recalculates prices, GST, sizes and add-ons on the server for every order, so a guest can’t change the bill from their cart.
Can someone order using a photo of our QR code?
In standard mode, yes: someone with a photo of your QR code can order while you are open. Optional table sessions, switched on for your restaurant on request, reject orders for tables that staff haven’t opened, and pay-first mode (cash turned off) keeps unpaid orders out of the kitchen.
Do KioSync QR codes expire?
Not today. Printed codes keep working, so there’s no routine reprinting; optional table sessions, switched on for your restaurant on request, control when each table can order.
How are payment keys stored?
KioSync stores payment gateway keys encrypted at rest and never shows them again after saving.
Can other restaurants see my data?
No. Each restaurant’s data in KioSync is isolated, and staff logins only reach their own restaurant’s orders, settings and reports.
Try KioSync free for 15 days
No card needed. We set up your trial with you: QR ordering, kitchen display and admin.