Home / Help / Privacy & data

Privacy & data

What is stored, what is purged, what customers can ask for, and what we never do.

Read the walkthrough script for this guide
  1. Two minutes on data, because your customers trust YOU with theirs, and you are the one they will ask.
  2. What an order stores: name, WhatsApp number, building and unit or the table, the map pin if they shared one, any note, the items and the money. What it never stores: card numbers — there are no online payments anywhere in this system, so there is no card form and nothing to steal.
  3. Your OWN card, if you pay us by card, is a different thing entirely: it is held by Stripe on their own page, and the number never reaches our servers either.
  4. Autofill: a returning customer's details are remembered by THEIR OWN phone's browser, per restaurant, not looked up from our database. There is deliberately no way to type a phone number and retrieve a person — that would let anyone look up anyone.
  5. Retention: content with no long-term business need is blanked on a hundred-and-twenty-day schedule — message bodies, delivery pins, customer notes, and the identifying parts of visit measurement. Who ordered and what they paid, the accounting truth, is kept.
  6. One thing is deleted outright rather than blanked: a cart somebody filled in and never ordered. Three days, the whole row — and immediately if that number does place an order. It is the shortest retention on the platform, because it is the one place holding somebody who never bought anything.
  7. Erasure: a customer can ask to be forgotten. We anonymise rather than delete — the money history your accounting needs survives with its invoice numbers, and the person disappears from it, including from the message archive.
  8. Analytics: first-party only. No third-party ad trackers, no cross-site profiles, nothing follows anyone anywhere, nothing is sold.
  9. Two records exist for your protection as much as ours. The change log names who changed a WhatsApp group, who downloaded a month of your figures, who cancelled a delivered order. And Reports, Sent email shows every email we sent you.
  10. If somebody else set your restaurant up before you claimed it, know exactly what that meant: everything in the dashboard while it was unclaimed, nothing after — and never your password, which no screen of theirs could set.
  11. And isolation: every row of data is tagged to one restaurant and every query is fenced to it at the database layer. Your customer list is yours.

Common questions

What customer data does an order store?

Name, WhatsApp number, delivery building/unit (or table for dine-in), the GPS pin link if shared, any note, the items and the money. No payment credentials exist anywhere — payment happens physically at the door or table.

Are card details ever handled?

Never. There are no online payments in the system: customers pay cash or by card machine on delivery. No card form exists, so there is nothing to steal.

How does checkout autofill work — is it a database lookup?

No. A returning customer's details are stored by their own browser on their own phone, per restaurant, and offered back to them there. The platform deliberately provides no way to type a phone number and retrieve a person — that would let anyone look up anyone.

What gets deleted automatically?

Content with no long-term business need is blanked on a 120-day schedule: WhatsApp message bodies, delivery pins, customer notes — and visit analytics lose their IP addresses, full referrer addresses and page-by-page history on the same clock, keeping only anonymous totals. What who ordered and what they paid — the accounting truth — is retained. The privacy policy states this in plain language.

Can a customer ask to be erased?

Yes — via the support contacts. Erasure anonymises the person across their orders and message history: financial records stay (they must, legally), but the name and number are gone from them. It covers the message archive too, not just the customer record.

Can other restaurants see my customers?

No. Every row of data is tagged to one restaurant and every query is fenced to that restaurant at the database layer — isolation is structural, verified repeatedly by security review, not a setting someone could forget.

Who on my team sees customer data?

Owners and managers see order data in the panel, and your WhatsApp groups receive tickets containing it — keep those groups staff-only. Rider links carry only their one order and die after use or expiry.

Do wallet loyalty cards expose customer data?

No — the pass carries stamps and branding, not the customer's name or number, and the pass-update path is engineered so wallet infrastructure never receives your customer list.

What analytics do customers experience on my page?

First-party only — no third-party ad trackers, no cross-site profiles, nothing follows anyone to other websites, nothing is sold. The platform records its own visit measurement: pages viewed (page address only, never the codes a link may carry), the referring address the visitor arrived from, the landing page, the country, IP address, browser, operating system and device type, and a visit count via a random first-party cookie. The country is the one our hosting reports on the request itself — no lookup service is involved and no third party is asked. Nothing here identifies a person by name: a visitor becomes a named customer only by placing an order. The identifying parts are erased automatically after 120 days, and the privacy policy states all of it in plain language.

Can I see who is visiting my page before they order?

Visit measurement exists platform-wide (pages viewed, where visitors came from, which country, browser and device, visit counts) and is read by the platform operator today; a visitor is linked to a customer record only when they actually place an order. There is no restaurant-facing analytics screen yet — when there is, it will appear in your panel and in these docs.

Does the visit tracking slow my page down or affect ordering?

No. The measurement is a background signal sent after a page has already loaded — nothing in the ordering flow waits for it, and if it fails for any reason the page and the checkout carry on exactly as normal, by construction.

Where is the data hosted?

On managed cloud infrastructure with the application served from a Middle-East region for speed in the UAE. Access to production data is limited to the platform operator with audited access.

What is in the audit log?

Sensitive actions: who changed WhatsApp group IDs, who exported customer data, operator support access, status overrides — the who/what/when of anything that matters in a dispute. It exists to protect you as much as the platform.

How are passwords stored?

Hashed by the authentication provider — never in plain text, never visible to anyone including the platform team. Login attempts are throttled; captcha guards the doors.

Can I export my data?

From your own panel you can export monthly statements (PDF and Excel) and per-order invoices — every statement download is audit-logged because it is a month of your trading leaving the system. A customer-list export exists only as an operator action, also audit-logged; ask support if you genuinely need one.

What happens to data when a trial is deleted?

When an expired trial's grace window passes, the account and its data are removed as documented in the trial terms — staff logins first, then the restaurant record. A subscribed restaurant's data is never auto-deleted.

Something looks like a security issue — where do I report it?

Straight to the support email, marked security. It reaches the operator directly; the platform runs recurring internal security reviews and treats external reports with priority.

What happens to a cart somebody filled but never ordered?

Deleted outright after three days — the whole row, not just its contents — and deleted immediately if that phone number does place an order. It is the shortest retention on the platform and the only place where purging means deletion rather than blanking, because it is the one table that can hold the identity of somebody who never bought anything.

What exactly does an erasure request remove?

It anonymises rather than deletes: orders survive with their money and invoice numbers intact while the name, phone, unit, map link and notes are stripped; the customer record is deleted; message bodies and recipients are blanked; queued marketing loses its content and recipient; and a group order's per-person breakdown keeps the amounts but loses the names.

Can I erase a customer myself from my dashboard?

No — erasure is run by the platform operator; email support with the mobile number the person ordered with. It is scoped to ONE restaurant on purpose (the same number at a different restaurant is a different relationship), and the audit record proves it happened without re-recording what was erased — a masked number and counts only.

Is it recorded when someone downloads a month of my figures?

Yes — a statement puts a whole month of your trading in one file, so every download records who took it, which month, which format and when. The same rule applies to customer exports on the operator's side.

What happens to the record of a group order over time?

The per-person breakdown — who ordered which items and what each share was — is removed after 120 days; the mode and pot total stay, because those are the money-shaped facts. The order's own subtotal and total are never touched.