Privacy

Privacy Policy

This Policy explains how PeckQ handles personal information belonging to restaurant users and waitlist guests.

1. Who operates PeckQ

PeckQ is a product and brand operated by IMPI TECH (PTY) LTD, registration number 2016/356031/07, a private company registered in South Africa. Our registered and service address is 244 Boshoff Street, Muckleneuk, Pretoria, 0181, South Africa. Contact contact@peckq.com for privacy questions or bernhard@peckq.com for the Information Officer, Bernhard Heesen.

2. Our roles

For guest waitlist information, the restaurant ordinarily decides why and how that information is used. The restaurant is therefore generally the responsible party or controller, and IMPI TECH operates PeckQ as its operator or processor. The restaurant remains responsible for its own privacy notices, lawful basis, staff use, and responses to guest requests. Our Data Processing Addendum describes this relationship.

IMPI TECH is separately the responsible party or controller for restaurant-account, authentication, security, support, billing, legal-compliance, and direct website-contact information.

3. Information we process

Restaurant users

  • account identifiers, email address, and basic profile information;
  • restaurant name, settings, staff roles, and account activity;
  • support correspondence and security/diagnostic records; and
  • subscription, invoice, and transaction references when billing is enabled.

Waitlist guests

  • first name and party size;
  • normalized phone number and privacy-preserving messaging identity;
  • restaurant/location joined, queue state, timestamps, and final outcome;
  • messages exchanged through the active or recent waitlist conversation; and
  • minimal provider, delivery, abuse-prevention, and reliability metadata.

A seated outcome means only that the guest was seated after a recorded waitlist entry. PeckQ does not know or claim the guest's total visits to a restaurant.

4. Why we process it

We process information to:

  • create accounts, authenticate users, and provide the PeckQ service;
  • route a guest to the correct restaurant waitlist and deliver WhatsApp messages;
  • show and preserve accurate waitlist and conversation history;
  • secure, troubleshoot, support, and improve service reliability;
  • administer subscriptions, payments, refunds, and business records; and
  • meet legal obligations and establish or defend legal claims.

Depending on the context and applicable law, processing is based on performing a contract, taking requested pre-contract steps, the restaurant's instructions and lawful basis, legitimate interests in operating and securing the service, consent where required, or compliance with law.

5. WhatsApp and free-text messages

WhatsApp is the guest communication channel. Messages pass through Meta/WhatsApp and are also governed by their terms and privacy information. PeckQ stores queue-related messages so authorized restaurant staff can view and reply to them. Free text is communication data only and does not automatically change a queue state.

6. Google authentication

If a restaurant user chooses Google sign-in, PeckQ requests only openid, email, and profile. We use the resulting verified email and basic profile fields only to identify and restore the user's account. Email/password authentication is handled through Amazon Cognito and remains separate from guest waitlist data.

7. Service providers and international processing

We use carefully selected providers to operate PeckQ, including Amazon Web Services for hosting, databases, security, and authentication; Meta/WhatsApp for guest messaging; Google when a user selects Google sign-in; and PayFast when payment checkout is enabled. Providers receive only the information needed for their role and may process it in other countries under their own legal safeguards and our contractual arrangements.

PeckQ's primary application infrastructure is in AWS's Frankfurt region. Cross-border processing may still occur through messaging, authentication, support, security, or payment providers. We use reasonable contractual and organizational safeguards where applicable law requires them.

8. Retention

  • Draft messaging and incomplete guest records: generally up to seven days.
  • Established customer profiles and waitlist history: generally up to 12 months after the latest waitlist entry.
  • Account, billing, security, support, and legal records: only as long as reasonably needed for the service, legal obligations, disputes, and legitimate business records.

DynamoDB time-to-live cleanup is eventual, so technical deletion may follow an application expiry. Backups may retain protected copies until their normal expiry.

9. Sharing

We do not sell personal information. Guest waitlist data is not used for marketing by default, and PeckQ does not use advertising trackers. We disclose information to the relevant restaurant, authorized providers, professional advisers, authorities when legally required, or a successor in a legitimate business transaction subject to appropriate protection.

10. Security

We use reasonable technical and organizational safeguards, including tenant-scoped access, encryption in transit and at rest, restricted cloud permissions, authenticated staff access, controlled secrets, audit records, and privacy-aware logging. No system is completely secure; please report a suspected issue to contact@peckq.com without including passwords or sensitive guest content.

11. Your rights and choices

Subject to applicable law, you may ask to access, correct, delete, restrict, or object to processing of personal information, request portability where applicable, or withdraw consent without affecting earlier lawful processing. We may need to verify identity and determine whether the restaurant or IMPI TECH is responsible for the request.

Guests should normally contact the restaurant first about its waitlist records, but may also email contact@peckq.com. Complaints may be raised with South Africa's Information Regulator or, where applicable, a local European data-protection authority. We ask that you contact us first so we can try to resolve the issue.

12. Children

Restaurant accounts are for adults acting for a business. PeckQ is not directed to children, and restaurants should not use the service to collect unnecessary information about children.

13. PAIA, cookies, and changes

Our PAIA Manual explains how to request access to records. See our Cookie and Browser Storage Notice. We may update this Policy when the service or law changes. We will publish the new effective date and give reasonable notice of material changes where appropriate.