DRAFT – requires legal review
Privacy Policy
Who is responsible
{{OPERATOR_LEGAL_NAME}}, {{OPERATOR_ADDRESS}}, is responsible for the personal data described here. Privacy officer: {{PRIVACY_OFFICER_NAME}}, {{PRIVACY_OFFICER_EMAIL}}.
What we collect
- Store owners and managers: name, email, password (stored as a hash), two-step sign-in secret, the consent you gave and when, and the address and device of each sign-in for security.
- Staff: display name and PIN (stored as a hash). Staff do not need an email.
- Guests: what you order and when, the order type, and, only if you give it, an email address for your receipt. Card details go to Stripe; we receive the payment result, never the card number. Your IP address is kept only as a keyed hash to limit abuse.
- Stores: business information such as the legal name, representative, registration numbers, address, phone and email, shown to Guests as the law requires.
Why we use it
- To provide ordering, payment, receipts and refund updates (to perform the contract).
- To keep accounts and payments secure and prevent abuse (legitimate interest).
- To bill Stores for their subscription (to perform the contract).
- To keep the records tax and commerce laws require (legal obligation).
- Marketing email only with your separate consent. You can withdraw it at any time in your account.
Who processes it for us
- Stripe — card payments and subscription billing (United States).
- Postmark — email delivery, including receipts (United States).
- Railway — hosting of the service and its databases (United States).
- Sentry — error reports, with personal data removed before sending (United States).
- OpenAI — reading menu files a Store uploads to import its menu; no Guest data (United States).
How long we keep it
- Receipt email addresses: deleted 90 days after the order.
- Sign-in sessions, sign-in links and invitations: deleted 30 days after they expire or are used.
- Payment provider event details: reduced to their identifiers after 90 days.
- Security and audit logs: 1 year.
- Orders, payments and refunds: as long as tax and commerce laws require (7 years in the United States, 5 years in Korea).
- When you delete your account, your name and email are removed; records of orders you handled keep only an anonymous reference.
Your rights
You can see, correct, export and delete your data, and withdraw consent. Most of this is in the owner app; for everything else write to the privacy officer. Guests can ask the Store, or us, about their order data. You can also complain to your data protection authority.
Cookies and browser storage
We use only what the service needs: a sign-in cookie for owners and staff, and, on a Guest’s phone, the order’s access key in browser storage for up to 30 days so the order status can be opened again. We use no advertising or tracking cookies.
Transfers abroad
Our processors store data in the United States. Where the law requires it, we rely on contracts with appropriate safeguards. For Korean users, the details of the transfer are listed in the Korean version of this policy.
Children
Kiswave accounts are for businesses and adults. Guests under 14 should order with a parent or guardian.
Changes
We publish every version of this policy with its date and tell account holders about material changes before they apply.