Legal
Privacy Policy
Last updated 15 September 2026
1. Who we are
This Privacy Policy explains how Queshot Pty Ltd (ACN 699 051 744, ABN 12 699 051 744) ("Queshot", "we", "us") collects, holds, uses and discloses your personal information. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and we comply with the APPs whether or not the small-business exemption would otherwise apply to us. This policy covers both customers and venue partners who use the Queshot app, venue dashboard and website (the "Platform").
2. What personal information we collect and hold
- Account information - your name, email address, phone number and the suburb you give us.
- Order information - your orders, items, preferences (your "usual"), order history and loyalty activity.
- Payment information - payment tokens and limited card details (such as the card type and last four digits) provided by our payment processor, Stripe. We do not collect or store your full card number.
- Location information - your approximate device location, only with your permission and only while you have an active order or have enabled Kerbside or auto-order, to time your order and trigger auto-order; and, if you save a home or other place, the coordinates and address of those saved places. We retain this location information - your saved home/place coordinates and the origin, route, travel time and timing of your orders - linked to your account, and use it as described in clause 4. Access to identifiable location data is restricted to authorised Queshot staff and is logged. We do not sell it. When you tell us you're on your way to collect an order ("I'm on my way"), we collect your precise location for the duration of that pickup trip only. This location is sent to Google Maps Platform solely to calculate your arrival estimate - we do not store a trail of where you have been; only the resulting estimate and the time it was last refreshed are kept against your order. Sharing stops automatically when you arrive, when the order is collected or cancelled, if you tap Stop, or after a two-hour cap, whichever comes first. While an on-my-way trip is active, iOS shows the system location indicator and Android shows a persistent notification, so it is always visible to you that sharing is under way.
- Images you upload - such as a venue logo. Embedded metadata, including EXIF GPS location, is stripped on your device before the image is sent to us. We store the picture, not where or when it was taken.
- Device and usage information - device and push identifiers, app interactions, and diagnostic/crash data, collected through analytics and error-monitoring tools (see clause 5).
- Venue partner information - for venue accounts, business and contact details, menu and pricing data, and the information needed to set up payouts through Stripe.
- Venue dashboard activity - for venue and staff accounts, records of actions taken in the venue dashboard, including a history of changes to venue settings (the setting changed, its previous and new values, when, and which signed-in account made the change - a venue staff account, or Queshot support acting on the venue's account) and staff-facing records such as rosters, timesheets and task completions.
- Security and account-protection information - to protect accounts and prevent fraud and abuse, we keep records of failed or suspicious sign-in and account-security events across our sign-in and account systems. These records include the email address entered (which may not belong to a Queshot account), the IP address, browser/device information, and the time, outcome and reason. We do not record the password entered. We use this information only to detect, investigate and prevent unauthorised access, fraud and abuse.
We collect sensitive information (such as allergy or dietary notes) only where you choose to provide it so an order can be prepared safely; we treat it as health information and only use it for that purpose.
Separately, when you open an item's allergen or nutrition information panel in the app or on a venue's ordering page, we record which item, and whether it covered allergens, nutrition, or both - never what the panel said and never anything about you - as an analytics event (see clause 5).
3. How we collect it
We collect personal information: directly from you (when you create an account, place an order, or contact us); automatically as you use the Platform (through analytics, error-monitoring and device data); and from third parties where relevant - for example, order-status information from venues, payment confirmations from Stripe, and address suggestions from Google when you use address search.
4. Why we collect, use and disclose it
We use your personal information for the primary purpose of providing the Platform and fulfilling your orders, and for related purposes you would reasonably expect, including:
- creating and managing your account;
- processing orders and payments, and operating Kerbside and auto-order;
- powering loyalty, receipts and order history;
- sending you service communications (order updates, security codes, receipts);
- preventing, detecting and investigating fraud, abuse and unauthorised access - including keeping security logs of failed or suspicious sign-in and account-security events (see clauses 2 and 10), and keeping records needed to investigate and pursue fraudulent transactions - and meeting legal, tax and record-keeping obligations;
- improving and securing the Platform;
- operating internal analytics and operational tools - including a staff view of venue demand and where our customers are located, to plan coverage and improve the service; access to identifiable location data is restricted to authorised Queshot staff and is logged;
- building and improving forecasting and optimisation models that make the Platform work better - for example helping venues decide when to start preparing your order so it is fresh when you arrive (using your order and journey history - origin, route, travel time and timing), predicting demand, and improving preparation timing and scheduling; clause 10 explains how this data is kept; and
- sending marketing only where you have opted in (see clause 9).
We disclose your personal information to:
- the venue you order from - your name and order details, so it can prepare and fulfil your order;
- a venue you switch on offers from - once you turn on "Let venues I order from email me offers" in the app (asked once, after your first collected order, off by default), each venue you have ordered from receives your name and email address; you can turn it off for everyone at any time in the app, or for one venue while the switch is on; the venue must stop within 5 business days;
- service providers who help us run the Platform, each bound by a data-processing agreement and required to protect your information consistently with the APPs:
- Stripe - payment processing;
- Supabase - database, authentication and image storage;
- Resend - transactional email;
- ClickSend - SMS one-time codes;
- Google - Maps (address search and arrival timing) and Firebase Cloud Messaging (push delivery);
- PostHog - product analytics, autocapture, heatmaps and session replay (with all typed input masked);
- Sentry - error and crash monitoring;
- Meta Platforms and Google - advertising measurement, only while our advertising campaigns are active (see clause 5);
- authorities or others where required or authorised by law, or to protect our rights, users or the public.
We do not sell your personal information, and we never will.
5. Analytics, session replay and tracking
We use PostHog (product analytics, session replay and heatmaps) and Sentry (error and crash monitoring) to understand how the Platform is used, find and fix problems, and improve the experience for you and for venues.
- Autocapture and heatmaps. PostHog automatically records interactions such as taps, clicks, screens viewed and navigation paths, and, on our website, may show us heatmaps of where visitors tap or click.
- Session replay. We record a masked replay of app and website sessions so we can see how the Platform actually behaves. Everything you type is masked in these recordings - we never capture passwords, card details, messages, search terms or any other text you enter.
- Device and technical data. We collect device and app information (device type, operating system, app version and similar technical data) and diagnostic/crash data through these tools, so we can reproduce and fix problems.
- Approximate location and IP addresses. Analytics events may include a coarse, city-level location worked out from your IP address at the moment of the event. Where we retain an IP address, we keep it for security and fraud-prevention purposes (see clause 10).
- Identifiers, not names. Analytics events and recordings are keyed to an internal account identifier, or, if you are not signed in, an anonymous device identifier - never directly to your name, email address or phone number, and we do not put personal identifiers into analytics events.
- Menu information panels. When you open an item's allergen or nutrition information panel, the analytics event records which item, and whether it covered allergens, nutrition, or both. It does not record any allergen, dietary or nutrition value, and nothing about you - only that the panel for that item was opened, and from which screen. These events are part of the curated subset of analytics events we keep to build and improve our models (see Retention below and clause 10).
- Advertising measurement. On our website, and only while our advertising campaigns are active, we may use the Meta Pixel and Google Ads/Analytics (gtag) to measure whether our ads work - for example whether someone who clicked an ad went on to join our waitlist. These tools can set cookies or similar identifiers in your browser and share limited technical data (such as the page you visited and an advertising click identifier) with Meta Platforms and Google. We never send them your name, email address or phone number for this purpose. We use your browser's reported time zone to avoid enabling them for visitors who appear to be browsing from the EU/EEA, UK or Switzerland. See our How we use data notice for the specific cookies involved.
- Your choices. You can turn analytics, session replay and the advertising pixels above off at any time in Settings → Privacy or from the privacy control at the bottom of our website and dashboards. This choice roams with your account while you are signed in to the app or your venue/admin dashboard; on our public web pages it applies per browser. You can also email [email protected], or use Meta's (facebook.com/adpreferences) and Google's (adssettings.google.com) own ad-preference controls directly. Turning analytics off stops new analytics events, session recordings and advertising-measurement events; it does not affect service communications or how the Platform works for you.
- Retention. We keep analytics data for as long as reasonably needed for the purposes above. Session recordings are automatically deleted after a fixed period following capture, regardless of whether your account stays active. We also keep a curated subset of analytics events in our own systems, on an ongoing basis with no fixed end date, to build and improve the forecasting and optimisation models described in clause 4. When you close your account we replace your account identifier in those records with an internal reference that does not identify you directly, rather than deleting them - see clause 10.
See our How we use data notice for more, including which of our service providers process this information and where.
6. Overseas disclosure
Some of our service providers store or process personal information overseas. The countries where your information is likely to be handled include the United States and member states of the European Union/EEA, and other countries where our sub-processors operate - including, where our advertising campaigns are active, Meta Platforms (which processes advertising-measurement data in Ireland and the United States) and Google LLC (United States). Before disclosing information overseas we take reasonable steps to ensure the recipient handles it consistently with the APPs (including through data-processing agreements). Under the Privacy Act, in many cases we remain accountable for how those overseas recipients handle your information.
7. Direct marketing
We will only send you marketing communications where you have opted in. Every marketing message includes a simple way to unsubscribe, and we honour opt-outs promptly. You can also change your marketing preferences in settings. Service and transactional messages (order updates, security codes, receipts) are part of the service and are not marketing - you cannot opt out of them while you hold an active account or order. We do not use sensitive information for marketing.
Queshot's marketing versus venue offers. This clause covers marketing Queshot sends about Queshot. Once you turn on "Let venues I order from email me offers" in the app - asked once after your first collected order, off by default - each venue you have ordered from receives your name and email address so it can send its own offers directly, under its own consent, separately from anything Queshot sends; you can turn it off for everyone at any time in the app, or for one venue while the switch is on, and the venue must stop within 5 business days. Turning it off for one venue does not affect any other venue or your Queshot marketing preferences.
8. How we keep your information secure
We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure - including encryption in transit, access controls and row-level security on our database, vendor due diligence, and staff access on a need-to-know basis. No system is completely secure, but we work to protect your information and to respond quickly if something goes wrong.
9. Data breaches
If we ever experience a data breach that is likely to result in serious harm, we will assess it promptly and, where the Notifiable Data Breaches scheme requires, notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable, including the steps you can take.
10. How long we keep your information
We keep your personal information while your account is active and for as long as needed for the purposes above or to meet our legal, tax and fraud-prevention obligations. When you delete your account, we delete or de-identify your personal information, except that we may retain certain information - including the email address and IP address associated with security or fraud-prevention records - where we need it for security, fraud-prevention or legal purposes (for example, transaction records the law requires us to keep for tax purposes). We keep that retained information only for those purposes, for as long as they require. Session recordings are retained as described in clause 5.
Security and fraud-prevention records. Records of failed or suspicious sign-in and account-security events (clause 2), and other records we need to investigate and prevent fraud and abuse, are kept for as long as necessary for those security, fraud-prevention and legal purposes. They are held in a restricted, staff-only store and are not sold or disclosed for third-party advertising.
Analytics records after you close your account. We do not delete the curated analytics events described in clause 5. Instead we replace your account identifier in them with an internal reference that does not identify you directly, and keep them on an ongoing basis with no fixed end date to build and improve the forecasting and optimisation models described in clause 4. These records contain no name, email address, phone number or other contact detail, and nothing you typed. Because we retain the ability to connect that internal reference back to your former account, we continue to treat these records as personal information under the Privacy Act and to apply this policy to them - we do not claim they are anonymous. If you would prefer these records to be deleted outright rather than kept in this form, email [email protected] (please include an order number so we can locate them) and we will delete them.
Some analytics records are created before you sign in - while you are browsing as a guest - and are held against a device identifier rather than your account. We cannot reliably connect those to you, which also means we cannot single them out to change or delete them on request; they are retained as they are. If that matters to you, turning analytics off in Settings → Privacy stops new ones being created. This includes the menu information-panel events described in clause 5 that are created while you browse a venue's ordering page as a guest: because they are held against a device identifier, we cannot connect them to you and cannot delete them individually on request.
De-identified data for forecasting models. Separately from the analytics records described immediately above, when you delete your account, when a venue's agreement ends, or when we no longer need records that contain personal information, we delete or de-identify them in line with the Australian Privacy Principles. We may retain de-identified data - with names, contact details, account identifiers and other identifying details removed, so it no longer identifies you (or, for venue records, the venue) - and any de-identified data we retain this way is used solely to build and improve Queshot's own forecasting and optimisation models described in clause 4. We do not sell this de-identified forecasting data, and do not disclose it for third-party advertising. (Our separate, narrower use of advertising-measurement pixels - while our ad campaigns are active, and never using this de-identified forecasting dataset - is described in clause 5.)
Careers expressions of interest. If you register your interest through our Careers page before we are hiring, we keep the name, email address and any message you give us while the relevant roles are under consideration, so we can get back in touch when hiring opens. You can ask us to delete these details at any time by emailing [email protected].
11. Accessing and correcting your information
You can access and correct most of your information directly in settings. You can also ask us for access to, or correction of, your personal information by emailing [email protected]. We will respond within a reasonable time (generally 30 days). Access is free to request; if we refuse access or correction, we will give you written reasons and tell you how to complain, and you may ask us to attach a statement noting your disagreement.
12. Deleting your account and data
You can delete your account and personal information in the app (Profile → Settings → Delete account), or, without needing the app installed, self-service at queshot.com/delete-account - enter your account email, confirm the 6-digit code we send you, and your account is deleted immediately. You can also request deletion at any time by emailing [email protected] (for example, for a venue, admin, or suspended account, which the self-service page does not cover). When you delete your account we remove or de-identify your personal data, keeping only what the law requires, any de-identified data described in clause 10 (which no longer identifies you), and certain information we may retain - including the email address and IP address associated with security or fraud-prevention records - where we need it for security, fraud-prevention or legal purposes (see clause 10). We keep that retained information only for those purposes, for as long as they require.
13. Children
The Platform is intended for people aged 18 and over and is not directed at children. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
14. Automated decision-making
Some Platform features operate automatically - for example, auto-order places your saved order when you enter a venue's area, and automated checks help us detect fraud and prevent misuse. Where we introduce automated decisions that could significantly affect your rights or interests, we will describe in this policy the kinds of information used and the kinds of decisions involved, consistent with our obligations under the Privacy Act (this obligation applies from 10 December 2026).
15. Cookies and our website
Our website uses essential cookies to function, may use analytics cookies to understand usage, and - only while our advertising campaigns are active - may use advertising cookies (set by the Meta Pixel and Google Ads/Analytics) to measure ad performance. You can control cookies through your browser, and can turn the advertising cookies off using the on-site privacy control described in clause 5. See our How we use data notice for details, including the specific cookies involved.
16. Complaints and contact
If you have a question, an access or correction request, or a privacy complaint, contact our Privacy Officer at [email protected]. We will acknowledge and respond to complaints within a reasonable time. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner: oaic.gov.au, 1300 363 992.
17. Venue staff data
Venues (café, restaurant, food truck and other hospitality partners) can enter details about their own team in their venue dashboard, to help manage staffing.
- What venues enter. A venue can add each staff member's name, contact details, position/role, employment type and pay rate.
- Our role. We process this staff information as a service provider to the venue - the venue decides what is entered and who it's about. We handle it with the same care as the other personal information we process, under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
- Who can see what. Pay rates are visible only to the venue owner. Staff names and contact emails are visible to the venue's managers.
- No Tax File Numbers. We never collect or store Tax File Numbers, and the Platform has no field to enter one. Tax and payroll declarations are a matter for the venue's own payroll or accounting provider.
- Linked logins. If a staff profile is linked to a Queshot account, that account's email address is copied into the staff profile when the link is set up. If the account's email later changes, the copy held in the staff profile can become out of date.
- Staff activity records. Where a venue uses staff-facing features - rostering and shift swaps, timesheets, task completion (including any photo evidence or temperature entries submitted), worker documents and training records the venue keeps, and the venue's settings-change history - the Platform keeps records of those actions linked to the relevant staff profile or signed-in account. Venues use these records to run their business; we process them as a service provider to the venue and use them to operate, secure and improve the Platform as described in this policy. Some of these records must be kept for legally required periods (for example, time-and-wages records under Fair Work record-keeping rules, and food-safety task records); photo evidence attached to a completed task is automatically deleted after the venue's chosen retention period, while the completion record itself is kept.
- Notice to staff. The venue, as the employer, is responsible for telling its staff which features it uses and what records they create, and for meeting any workplace-surveillance notice, consultation or policy requirements that apply where its staff work. If you are a staff member with a question about records held about you, start with your venue; you can also contact us at [email protected].
- Archiving and deletion. Removing a staff member in the venue dashboard archives their record rather than erasing it. A venue can request permanent deletion of its staff records at any time by emailing [email protected]. When a staff member's linked Queshot account is deleted, the account itself is de-identified and the venue's settings-change history no longer identifies them as the person who made a change. The venue's own employment records - the staff profile, rosters, timesheets, task completions and documents - remain with the venue as the employer's records (some must be kept for legally required periods); staff can direct access or deletion requests about those records to their venue.
18. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version with a new "last updated" date and, for material changes, take reasonable steps to notify you. This policy is available free of charge, and we will provide a copy in another form on request.