The adoption of Quick-Service Restaurant (QSR) apps in Indonesia tripled from 2020 to the following three years. However, technical privacy audits of local apps remain very limited, and no research has systematically evaluated QSR apps in Indonesia using technical methods. To address this gap as the study's objective, the privacy compliance of QSR applications was systematically evaluated. Methodologically, the PbD-MASVS-MobSF evaluation framework was implemented, wherein Privacy by Design (PbD) principles, OWASP MASVS privacy controls, and Mobile Security Framework (MobSF) processes were integrated. As a sample, seven QSR apps were analysed, and their privacy findings were compared to the provisions of Law No. 27 of 2022 on Personal Data Protection (UU PDP). Regarding the key results, it was found that the apps were at a MEDIUM to HIGH risk level, with MobSF scores of 39-54 out of 100. The compliance analysis found that the apps consistently failed to meet six of the ten MobSF subprocesses. Meanwhile, strong compliance was only identified in the absence of API access for device identification. These findings indicate that privacy risks in the Indonesian QSR sector are structural and sectoral. Crucially, because only static analysis was utilised in this assessment, the findings are considered indicative rather than conclusive, and legal non-compliance with the PDP Law cannot be independently established. As a primary contribution, an operational framework that connects static analysis results, privacy design principles, and national regulatory requirements is provided as a reference for application developers, privacy auditors, and regulators.