KitchenQueue
FeaturesPricingHow it works
Add app to Shopify
Legal

Privacy Policy

This policy explains what personal data the KitchenQueue app processes when it is installed on a Shopify store, how and why we process it, how long we keep it, and how it is deleted.

Last updated: 2026-09-11 · Applies to the KitchenQueue Shopify app and the pages under this domain.

1. Who we are

KitchenQueue is operated by DiLight Entertainment UG (haftungsbeschränkt) ("KitchenQueue", "we", "us"). For questions about this policy or about the data we process, contact us at privacy@dilight.website.

When KitchenQueue is installed on a merchant's Shopify store, the merchant is the data controller for their customers' personal data, and KitchenQueue acts as a data processor on the merchant's behalf, processing store data only to provide the app's features. For our own account and billing records, we act as the controller.

2. Data we process

To turn paid orders into a live kitchen queue, KitchenQueue reads and stores the minimum data needed:

  • Store & account data — your .myshopify.com domain, the OAuth access token issued at install (stored securely and never shown to us in plain text in the UI), your plan and billing status, and app settings (stations, displays, number-reset schedule, board privacy options).
  • Order data — for each paid order we process the order ID and number, line items, timestamps and fulfilment status. Each order is assigned a pickup number and tracked as a ticket through the queue (queued → preparing → ready → served).
  • Customer data — the only customer field KitchenQueue ever reads or stores is the order email address, and only while the merchant has the optional “email the customer when ready” notification switched on. It is used for that one message and nothing else. KitchenQueue does not read, store or display customer names, phone numbers or addresses, and the public pickup board and QR status page show the pickup number only (plus a table number, if the merchant writes one onto the order themselves).

We do not process payment card details, we never use customer data for marketing, profiling or advertising, and we do not sell or share it with third parties. Access to store data is limited to the Shopify scopes granted at install (read_orders, read_products, write_products, read_inventory, read_locations, and write_merchant_managed_fulfillment_orders when the merchant turns on marking items fulfilled in Shopify).

2a. Protected customer data

Shopify classifies some order fields as protected customer data. This is exactly what KitchenQueue requests and why:

FieldRequested?Why / how it is used
Email Yes — optional Sending the single “your order is ready for pickup” message, when the merchant enables that notification. Stored on the ticket only, cleared when the ticket is deleted (90 days by default), and erased on a customers/redact request. Never used for anything else.
Name No Not requested and not used. Orders are identified to kitchen staff and to customers by their pickup number, which is why the app does not need to know who placed them.
Phone No Not requested and not used. KitchenQueue sends no SMS.
Address No Not requested and not used. KitchenQueue is a pickup-queue app; it never ships anything.

Order-level, non-customer data (order id and number, line items, timestamps, financial and fulfilment status) is processed for every order — that is what the queue ticket is built from.

3. How we use data

  • Assign pickup numbers and maintain the live queue, kitchen display and customer pickup board.
  • Route tickets to the correct station and across multiple locations.
  • Send optional "order ready" notifications and serve QR order-status pages.
  • Produce aggregate prep-time and volume insights for the merchant.
  • Operate billing, enforce plan limits, and provide support.

4. Legal basis (GDPR)

Where the GDPR applies, we process data on the basis of performance of a contract (Art. 6(1)(b)) with the merchant and our legitimate interest (Art. 6(1)(f)) in providing and securing the service. For customer personal data, the merchant's own privacy policy and legal basis govern the underlying processing; we act only on the merchant's documented instructions.

5. Sharing & sub-processors

We do not sell personal data. We share data only with the providers needed to run the service:

  • Shopify — the platform the app is installed on and the source of order/store data.
  • Our hosting/infrastructure provider — to host the application and its database.
  • Notification channels you enable (e.g. the signed webhook channel used for ready-pings).

6. Data retention

Completed (terminal) tickets and their call records are automatically deleted after 90 days by default (configurable by the merchant); open tickets are never auto-deleted. Aggregated, non-identifying statistics may be kept longer. When the app is uninstalled, or on a Shopify shop/redact request, we purge the store's data as described below.

7. GDPR / data-deletion requests

KitchenQueue implements Shopify's mandatory compliance webhooks:

  • customers/data_request — we acknowledge the request; KitchenQueue does not retain a customer data profile beyond the transient order/ticket data described above.
  • customers/redact — we clear the stored order email from every ticket belonging to the identified customer. That address is the only customer-linked field we hold.
  • shop/redact — we purge all of the store's data (tickets, counters, settings, billing and queued records). This runs after the store uninstalls the app.

Store customers should direct data-subject requests to the merchant (the controller). Merchants can reach us at privacy@dilight.website for assistance.

8. Security

The app uses Shopify's OAuth for install, verifies inbound webhooks with HMAC signatures, stores access tokens securely, and serves all traffic over TLS. Access to store data is scoped to the permissions granted at install.

9. Cookies

The embedded admin relies on Shopify App Bridge session tokens rather than tracking cookies. These marketing pages may set a small preference cookie to remember your chosen language. We do not use advertising cookies.

10. Changes to this policy

We may update this policy as the app evolves. Material changes will be reflected on this page with a new "Last updated" date.

11. Contact

DiLight Entertainment UG (haftungsbeschränkt) · privacy@dilight.website · dilight.website

← Back to KitchenQueue

KitchenQueue
FeaturesPricingHow it worksPrivacy
Native Shopify app
© 2026 KitchenQueue by DiLight Entertainment UG (haftungsbeschränkt). Order queues & pickup numbers for Shopify.
KitchenQueue is not affiliated with or endorsed by Shopify Inc. “Shopify” is a trademark of Shopify Inc.