This policy explains what personal data the KitchenQueue app processes when it is installed on a Shopify store, how and why we process it, how long we keep it, and how it is deleted.
KitchenQueue is operated by DiLight Entertainment UG (haftungsbeschränkt) ("KitchenQueue", "we", "us"). For questions about this policy or about the data we process, contact us at privacy@dilight.website.
When KitchenQueue is installed on a merchant's Shopify store, the merchant is the data controller for their customers' personal data, and KitchenQueue acts as a data processor on the merchant's behalf, processing store data only to provide the app's features. For our own account and billing records, we act as the controller.
To turn paid orders into a live kitchen queue, KitchenQueue reads and stores the minimum data needed:
.myshopify.com domain, the OAuth access token
issued at install (stored securely and never shown to us in plain text in the UI), your plan and billing status,
and app settings (stations, displays, number-reset schedule, board privacy options).We do not process payment card details, we never use customer data for marketing, profiling or advertising, and
we do not sell or share it with third parties. Access to store data is limited to the Shopify scopes granted at
install (read_orders, read_products, write_products,
read_inventory, read_locations, and
write_merchant_managed_fulfillment_orders when the merchant turns on marking items fulfilled in
Shopify).
Shopify classifies some order fields as protected customer data. This is exactly what KitchenQueue requests and why:
| Field | Requested? | Why / how it is used |
|---|---|---|
| Yes — optional | Sending the single “your order is ready for pickup” message, when the merchant enables that
notification. Stored on the ticket only, cleared when the ticket is deleted (90 days by default), and
erased on a customers/redact request. Never used for anything else. |
|
| Name | No | Not requested and not used. Orders are identified to kitchen staff and to customers by their pickup number, which is why the app does not need to know who placed them. |
| Phone | No | Not requested and not used. KitchenQueue sends no SMS. |
| Address | No | Not requested and not used. KitchenQueue is a pickup-queue app; it never ships anything. |
Order-level, non-customer data (order id and number, line items, timestamps, financial and fulfilment status) is processed for every order — that is what the queue ticket is built from.
Where the GDPR applies, we process data on the basis of performance of a contract (Art. 6(1)(b)) with the merchant and our legitimate interest (Art. 6(1)(f)) in providing and securing the service. For customer personal data, the merchant's own privacy policy and legal basis govern the underlying processing; we act only on the merchant's documented instructions.
We do not sell personal data. We share data only with the providers needed to run the service:
Completed (terminal) tickets and their call records are automatically deleted after
90 days by default (configurable by the merchant); open tickets are never auto-deleted.
Aggregated, non-identifying statistics may be kept longer. When the app is uninstalled, or on a Shopify
shop/redact request, we purge the store's data as described below.
KitchenQueue implements Shopify's mandatory compliance webhooks:
customers/data_request — we acknowledge the request; KitchenQueue does not retain a customer
data profile beyond the transient order/ticket data described above.customers/redact — we clear the stored order email from every ticket belonging to the
identified customer. That address is the only customer-linked field we hold.shop/redact — we purge all of the store's data (tickets, counters, settings, billing and queued
records). This runs after the store uninstalls the app.Store customers should direct data-subject requests to the merchant (the controller). Merchants can reach us at privacy@dilight.website for assistance.
The app uses Shopify's OAuth for install, verifies inbound webhooks with HMAC signatures, stores access tokens securely, and serves all traffic over TLS. Access to store data is scoped to the permissions granted at install.
The embedded admin relies on Shopify App Bridge session tokens rather than tracking cookies. These marketing pages may set a small preference cookie to remember your chosen language. We do not use advertising cookies.
We may update this policy as the app evolves. Material changes will be reflected on this page with a new "Last updated" date.
DiLight Entertainment UG (haftungsbeschränkt) · privacy@dilight.website · dilight.website