This policy explains what personal data Qweko collects, why, and what you can ask us to do with it. Qweko is operated by Kontextt, a software company established and lawfully operating in Algeria, which is responsible for the data described here. It applies to restaurant owners and their staff who use Qweko, and to the guests who order through a restaurant's menu.
1. Who is responsible for what
For the account data of restaurant owners and their staff, we decide how and why the data is used, and we are responsible for it.
For the data of a restaurant's own guests — an order, and where the order type requires it a name, a telephone number and a delivery address — the restaurant decides what it collects and why. We hold and process that data on the restaurant's behalf and under its instructions. If you are a guest and want your data corrected or removed, ask the restaurant you ordered from; we will support them in acting on your request.
2. What we collect from restaurants
When you register and use an account we collect:
- your restaurant's name, address, telephone number and logo;
- the name and email address of each owner or staff member with an account;
- your password, which is stored only as a cryptographic hash and is never readable by us;
- the menu, prices and photographs you publish;
- the orders recorded through the service, and which staff member handled them;
- your subscription history and the proof-of-payment documents you submit;
- the messages and attachments you send us through support or the contact form.
We also record when you accepted these terms and which version you accepted, because consent that cannot be attributed to a version is worthless.
3. What is collected about guests
A guest who scans a QR code does not create an account and does not give us a name, an email address or a password. Their session is temporary and identified only by a random code that carries no personal information.
What a guest provides depends on how they order. For an order placed at a table, nothing identifying is collected — only the items ordered and any note they add. For delivery or collection orders, the guest must give a name and a telephone number, and for delivery also an address, because the order cannot be fulfilled without them. That information is stored with the order and is visible to the restaurant.
4. Why we use it
We use the data described above to provide the service: to show your menu, record and route orders, run your dashboard, manage your subscription, verify payments, answer support requests, and send the service messages described below.
We also use aggregate, non-identifying information to understand how the service is used and to improve it. We do not use your data, or your guests' data, to build advertising profiles.
5. Messages we send
We send messages that are necessary to operate the service: account activation, invitations to join a dashboard, password reset codes, subscription reminders and expiry notices, payment confirmations and rejections, support replies, and occasional operational announcements about maintenance or changes.
These are service messages, not marketing. We do not run a newsletter, and we do not send you promotional email about other products.
6. We do not sell your data
We do not sell, rent or trade your data or your guests' data, and we do not share it with third parties for their own marketing or any other purpose of their own. There are no advertising or data-broker services in the platform.
We share data only with the service providers we need in order to run Qweko — such as hosting, storage and email delivery — and only to the extent required to provide that service to us. We also disclose data where the law requires it, or where it is necessary to establish or defend a legal claim.
7. Where your data is held
Qweko runs on infrastructure operated by specialist providers, and that infrastructure may be located outside Algeria. By using the service you understand that your data, and the data you hold about your guests, may be stored and processed outside Algeria.
Wherever it is held, the same policy applies to it, and we require our providers to protect it appropriately.
8. Access by our team
Our staff can access the data stored in the platform where it is necessary to operate it — to activate and support accounts, verify payments, investigate a fault or a report of abuse, and meet a legal obligation. Access is limited to what the task requires.
We do not read your data out of curiosity and we do not use it for any purpose unrelated to running the service.
9. Security
Traffic between your browser and the service is protected in transit by TLS encryption. Passwords are stored only as cryptographic hashes and are never stored in a readable form. Sessions use opaque tokens that we can revoke at any time, and access to data within the platform is restricted by role.
Files such as photographs and documents you upload are stored with addresses that are not published and cannot reasonably be guessed. You should not upload a document containing information you would not want a holder of its address to see.
No online service can promise perfect security. We work to protect your data but cannot guarantee it against every possible attack.
10. How long we keep it
We keep account and order data for as long as your account is active, and afterwards for as long as we need it to meet legal, accounting and tax obligations or to resolve a dispute.
Guest sessions are short-lived and expire automatically. Order records are kept as part of your restaurant's history.
Where a record shows which staff member handled an order, that name stays with the order even after the staff account is removed. Order history would otherwise become inaccurate, and it is a record of your business rather than a profile of that person.
11. Your rights and how to use them
You may ask us for a copy of the data held about your account, ask us to correct anything inaccurate, or ask us to delete your account and the data in it. You own your data and these requests are yours to make.
Send the request from the support section of your dashboard, or through the contact page if you can no longer sign in. We will verify that the request comes from the account holder and then act on it, normally within thirty (30) days.
Deletion is permanent and cannot be undone. We may need to keep a limited record — for example of payments — where the law requires it, and we will tell you when that applies.
If you have a concern about how we handle your data, contact us first and we will try to resolve it.