Privacy Policy
Last updated: May 2026
1. Introduction
OKeep ("we", "our", or "us") operates the OKeep mobile application, the OKeep customer web ordering interface, the OKeep CRM dashboard for merchants, and the okeep.io website (collectively, the "Platform"). This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and your rights regarding that data.
By using any part of the Platform, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Platform.
2. Data Controller
The Platform is operated by Sushko Oleksandr, a sole proprietorship registered in Poland (Jednoosobowa Działalność Gospodarcza), operating under the brand name OKeep.
Data processing roles on the Platform follow a hybrid model:
- OKeep as independent controller: OKeep controls customer accounts, platform profiles, authentication, global notification settings, platform security, customer support, service analytics, and the overall multi-merchant platform experience. A customer uses one OKeep account across multiple merchants — OKeep determines how this account works.
- Merchants as independent controllers (limited scope): merchants make their own commercial decisions about orders, rewards, promotions, offers, customer communications, and fulfillment of goods or services within their own merchant context. Merchants do not control the OKeep customer account or global customer profile.
- OKeep as processor: where OKeep processes data strictly on a merchant's instructions (e.g., delivering a merchant's promotional campaign to that merchant's eligible customers), OKeep acts as a data processor for that specific activity.
Each merchant can access only the customer data related to their own orders, loyalty programs, rewards, promotions, and customer interactions. Merchants cannot see customer activity with other merchants.
For any privacy-related inquiries, you can contact us atprivacy@okeep.io.
3. Types of Users
The Platform serves three categories of users, each with different data collection needs:
- Customers (Mobile App) — individuals who download the OKeep app to browse menus, place orders, earn loyalty points, and redeem rewards.
- Customers (Web Ordering) — individuals who scan a QR code and place orders through a web browser without downloading the app. These users may be anonymous.
- Merchant Staff (CRM) — restaurant employees and managers who use the CRM dashboard to manage orders, menus, and customer communication.
4. Data We Collect
4.1 Data You Provide Directly
- Account information: username, phone number, and optionally profile picture, date of birth, and gender.
- Merchant staff accounts: name, email address, and profile picture (provided via your identity provider).
- Chat messages: text messages you send to merchants through the in-app chat feature.
- Order details: items selected, delivery mode, payment method, and any applied vouchers or promotions.
- Notification preferences: your choices regarding promotional, service, and push notifications on a per-merchant basis.
4.2 Data Collected Automatically
- Device identifier: a unique, randomly generated identifier stored securely on your device. This is not your hardware ID and cannot be used to identify your device outside the Platform.
- Push notification token: a token provided by your device's operating system that allows us to send you push notifications. This token is removed automatically if it becomes invalid.
- App usage events: interactions such as opening the app, viewing menus, placing orders, and redeeming rewards. These events are used for analytics and improving the Platform.
- Error and performance data: crash reports, error logs, and performance metrics to help us identify and fix technical issues.
- Location data: your GPS coordinates are collected only when you explicitly grant location permission and use features that require it (such as finding nearby restaurants). Location is not tracked continuously.
4.3 Anonymous Web Ordering
When you place an order via the web interface (by scanning a QR code), we create an anonymous account on your behalf. This account uses a randomly generated identifier (no name, email, or phone number required) and a secure token stored in your browser's local storage. The token is valid for 30 days — during this period, you can download the mobile app and link your anonymous orders and earned points to your app account. After the token expires, linking is no longer possible, but your order history remains associated with the anonymous account for merchant record-keeping purposes.
4.4 Payment Data
We do not store your credit card number, CVV, or full bank account details. All payment processing is handled by Stripe, a PCI DSS-compliant payment processor. We store only: the Stripe payment reference ID, the transaction amount and currency, the payment status, and a snapshot of what was ordered. Stripe may collect additional data as described in their own privacy policy.
4.5 Data We Do NOT Collect
For clarity, we do not collect:
- Photos or camera images — the camera is used only on your device to scan QR codes, and nothing it sees is captured, uploaded, or stored
- Biometric data (fingerprints, face scans)
- Government-issued identification numbers
- Health or medical information
- Browsing history outside the Platform
- Contacts from your phone
- Continuous background location tracking
- Browser fingerprints or cross-site tracking identifiers
5. How We Use Your Data
We use your data for the following purposes:
5.1 Providing the Service
- Facilitating and processing orders placed through the Platform (merchants remain responsible for order fulfillment)
- Managing your account, loyalty points, vouchers, and rewards
- Enabling real-time communication between you and merchants via chat
- Sending order status updates and service notifications
- Facilitating group ordering in shared lobbies
5.2 Improving the Platform
- Analyzing usage patterns to improve features and user experience
- Monitoring error rates and fixing bugs
- Understanding which features are most valuable to users
- Generating aggregated, anonymized statistics across the Platform (e.g., popular promotion types, average order sizes) — this data cannot identify individual users or merchants
5.3 Marketing (with your consent)
- Sending promotional notifications about deals and rewards from merchants you have interacted with through the Platform
- You can opt out of promotional notifications at any time in app settings or per-merchant
We do not use one merchant's customer data to market on behalf of another merchant. We do not build cross-merchant customer profiles for marketing purposes. We do not allow merchants to access customer activity with other merchants unless the customer explicitly interacts with that merchant.
5.4 Safety and Legal
- Preventing fraud and abuse of the loyalty system
- Complying with legal obligations
- Maintaining platform security
6. Legal Basis for Processing
Under the General Data Protection Regulation (GDPR), we process your data based on the following legal grounds:
- Contract performance: processing orders, managing your account, maintaining loyalty balances, and enabling chat communication.
- Legitimate interest: analytics to improve the Platform, error monitoring to maintain service quality, and fraud prevention.
- Consent: sending promotional notifications, collecting location data, and session replay for error investigation. You may withdraw consent at any time.
- Legal obligation: retaining transaction records as required by tax and financial regulations.
7. Third-Party Services
We use the following third-party services to operate the Platform. Each service receives only the minimum data necessary for its function:
| Service | Purpose | Data Shared |
|---|---|---|
| Stripe | Payment processing | Order amount, currency, payment method, order reference ID |
| PostHog | Product analytics | Anonymized user ID, app usage events (no personal details) |
| Sentry | Error monitoring | User ID (for error context), crash reports, optional session replay |
| Auth0 | Merchant staff authentication | Staff email, name, profile picture |
| Expo | Push notification delivery | Device push token, notification content |
| Cloudinary | Image hosting | Merchant-uploaded images (menu items, promotions). No personal user data. |
| Google Maps | Restaurant location display | Map tile requests. Your location is processed on-device. |
We do not sell your personal data to any third party. Data shared with these services is governed by their respective privacy policies.
8. Data Shared with Merchants
When you place an order or interact with a merchant through the Platform, the merchant receives:
- Your username (or "Anonymous" for web orders)
- Your order details (items, delivery mode, payment method)
- Chat messages you send to them
- Your loyalty point balance with that merchant
Merchants do not have access to your phone number, device ID, location, or activity with other merchants.
9. Local Storage and Cookies
The Platform uses local storage on your device to maintain your session and preferences:
- Mobile app: your authentication token is stored in AsyncStorage. Your device identifier is stored in the device's secure enclave (iOS Keychain / Android Keystore). Cart contents are stored locally per merchant.
- Web ordering: your anonymous session token and cart are stored in your browser's localStorage. This data expires after 30 days or when you clear your browser data.
- CRM dashboard: your authentication session is managed by Auth0 using standard browser cookies and localStorage.
The okeep.io marketing website uses only essential cookies for basic functionality. We do not use advertising cookies or cross-site tracking cookies.
10. Data Retention
We retain your data for as long as necessary to provide the service and comply with legal obligations:
- Account data: retained while your account is active. You may request deletion at any time via app settings or by contacting us.
- Anonymous web accounts: the linking token expires after 30 days. The anonymous account record and associated orders are retained for merchant record-keeping.
- Order and transaction history: retained for as long as required by applicable financial and tax regulations. After account deletion, order records are kept in anonymized form (not linked to your identity).
- Chat messages: retained while both the user account and the merchant account are active. Deleted when you delete your account.
- Push notification tokens: automatically removed when they become invalid (e.g., after app uninstall).
- Analytics data: retained for up to 12 months in PostHog and Sentry, unless longer retention is needed for security investigation.
- Authentication tokens: mobile app tokens expire after 1 year. CRM sessions follow Auth0's session policies.
11. Data Security
We implement the following measures to protect your data:
- All data transmitted between your device and our servers is encrypted using TLS (HTTPS).
- Sensitive tokens (anonymous user tokens, session tokens) are hashed using bcrypt before storage. Merchant staff authentication is handled by Auth0 — we do not store staff passwords.
- Payment data is processed by Stripe in a PCI DSS-compliant environment.
- Device identifiers are stored in your device's secure enclave (iOS Keychain / Android Keystore) when available.
- Database access is restricted and monitored.
No system is perfectly secure. If you discover a security vulnerability, please report it tosecurity@okeep.io.
12. Your Rights
Under the GDPR and applicable data protection laws, you have the following rights:
- Access: request a copy of the personal data we hold about you.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion of your personal data ("right to be forgotten"). Note that some data may be retained for legal compliance.
- Restriction: request that we limit how we process your data.
- Portability: request a copy of your data in a structured, machine-readable format.
- Objection: object to processing based on legitimate interest.
- Withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us atprivacy@okeep.io. We will respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.
13. Children's Privacy
The Platform is not intended for use by children under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at privacy@okeep.io and we will promptly delete the data.
14. International Data Transfers
Some of our third-party service providers (PostHog, Sentry, Stripe, Expo) may process data outside the European Economic Area (EEA). Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or adequacy decisions, to protect your data in accordance with GDPR requirements.
15. Early Access
The Platform is currently in early access. Features, data practices, and this Privacy Policy may evolve as the Platform develops. We will notify you of any material changes. Your continued use of the Platform after such changes constitutes acceptance of the updated policy.
16. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you through the Platform (via push notification or in-app notice) and update the "Last updated" date at the top of this page. We encourage you to review this policy periodically.
17. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
- Privacy inquiries: privacy@okeep.io
- Security issues: security@okeep.io
- General support: support@okeep.io