Why Waitery?
No app downloads Cancel anytime Built for Canada EN / FR bilingual 1-yr hardware warranty
Legal

Privacy Policy

How Waitery handles personal information across this website, the Waitery KDS and Cashier staff apps, and the guest-facing ordering services restaurants offer through Waitery.

Last updated: July 19, 2026

1. Introduction

Waitery (“we,” “us,” or “our”) provides restaurant point-of-sale software and related services in Canada. This policy explains what personal information we collect, why we collect it, how we use and share it, and the choices and rights you have. It is written with Canadian privacy law in mind, including the federal Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec’s Act respecting the protection of personal information in the private sector(often called Law 25), and Canada’s Anti-Spam Legislation (CASL).

This policy covers three things:

  1. This marketing website (sections 2–14);
  2. The Waitery staff applications — Waitery KDS and Waitery Cashier— installed by restaurant businesses on their own or their staff’s devices (the dedicated Waitery Staff Applications section below); and
  3. Guest-facing ordering services that restaurants offer to their customers through Waitery (QR self-ordering, reservations, waitlists, and receipts), described in the Guest Data section below.

Where a restaurant’s own agreement with us addresses the same subject, the agreement governs the restaurant’s use of its operational data; this policy governs Waitery’s collection and handling.

2. What we collect (this website)

When you fill out our demo or contact form, we collect the information you choose to provide, which may include:

  • Business name
  • Email address
  • Number of locations
  • Your current POS system
  • Province
  • Restaurant type
  • Any message or details you add

With your consent, we also collect limited analytics about how you use this site — for example pages viewed, approximate region, device and browser type, and referring links. Analytics are only loaded after you accept them through our consent banner. If you decline, we do not load non-essential analytics.

3. Why we collect it

We use the personal information above to:

  • Respond to your demo requests and questions
  • Prepare a relevant demo and pricing for your business
  • Communicate with you about Waitery, where you have consented to hear from us
  • Understand and improve how our website performs (with consent)
  • Keep our site and systems secure and prevent abuse

5. Cookies and analytics

We use a small number of strictly necessary cookies to make the site work. Any non-essential cookies and analytics — such as usage measurement — are consent-gated: they only run after you accept them in our consent banner, and you can change your choice at any time. Declining non-essential cookies does not stop you from using the site.

6. How we share information

We do not sell your personal information. We share it only with trusted service providers who help us run our business — for example our customer-relationship (CRM) and email tools, form and hosting providers, and analytics services we have enabled. These providers process information on our behalf, are bound by contract to use it only for the services they provide to us, and are listed by category in the service providers table below (Amazon Web Services, Sentry, Pushy, Google Firebase, Twilio, SendGrid, and Clover/Fiserv for payment processing). We may also disclose information where required by law or to protect our rights and the safety of others.

7. Data retention

We keep personal information only as long as needed for the purposes described here — for example to follow up on your inquiry, to maintain a business relationship, or to meet legal and accounting obligations. Restaurant operational and financial records are retained as described in §A5 (including retention required by the Income Tax Act and Excise Tax Act). Application logs are retained for a limited period (up to 90 days) for security and diagnostics. When information is no longer needed, we take reasonable steps to delete or de-identify it.

8. Your rights

Subject to applicable law, you have the right to:

  • Access the personal information we hold about you
  • Correct information that is inaccurate or out of date
  • Withdraw consent and request deletion of your information
  • Unsubscribe from marketing emails at any time

To exercise any of these rights, contact us at hello@waitery.ca. We will respond within the timeframes required by applicable Canadian law — for deletion requests, no later than 30 days, including removal from our payment processor’s token vault where applicable.

9. Quebec residents — Law 25

If you are in Quebec, additional rights under Law 25 may apply, including the right to request deletion of your personal information and the right to information about how it is handled. We have designated a person responsible for the protection of personal information.

The person responsible for the protection of personal information at Waitery is Mohamed Bakoush, Privacy Officer, reachable at hello@waitery.ca.

10. International transfers

Our primary hosting is in Canada (Amazon Web Services, Canada Central region). Some of our service providers store or process personal information outside your province or outside Canada — in particular Sentry (crash and performance reports, stripped of personal identifiers before upload), Pushy and Google Firebase Cloud Messaging (push-registration tokens only), Twilio (guest SMS notifications), SendGrid (transactional email), and Clover/Fiserv (payment processing) — which process data in the United States or other jurisdictions. Where information is transferred outside Quebec or Canada, it may be subject to the laws of those jurisdictions. Before using such providers, we assess that they offer a comparable level of protection for your information, as required by Law 25, and we bind them contractually to process it only on our behalf.

11. Security

We use reasonable administrative, technical, and physical safeguards to protect personal information against loss, theft, and unauthorized access, use, or disclosure — including encryption in transit (HTTPS/TLS), scoping every record to the business it belongs to, and time-limited, revocable access credentials. No method of transmission or storage is completely secure, but we work to protect your information appropriately to its sensitivity.

12. Children

This website and our services are intended for businesses and are not directed at children. We do not knowingly collect personal information from children.

13. Changes to this policy

We may update this policy from time to time. When we do, we will revise the “Last updated” date above. Material changes will be communicated as required by law.

14. Contact us

Questions about this policy or your personal information? Get in touch:

Waitery Inc.

Canada

hello@waitery.ca

Looking for pricing or a walkthrough instead? Book a demo.

Part two

Waitery Staff Applications (KDS, Cashier)

This section describes the personal information handled by the Waitery staff applications — Waitery KDS and Waitery Cashier(the “Staff Apps”) — which restaurant businesses (“Restaurants”) install on their own or their staff’s mobile devices (tablets and phones) to operate their kitchen and front of house. It supplements the policy above and the agreements between Waitery and each Restaurant.

Waitery designed the Staff Apps to handle only the operational data a restaurant needs to run. The Staff Apps contain no advertising, no third-party marketing or analytics SDKs, and no location tracking of any kind.

A1. Whose information, and our role

  • Restaurant staff use the Staff Apps under accounts their employer creates and administers in the Waitery Restaurant Panel. Staff cannot create accounts in the apps themselves. Waitery processes staff information to provide the service to the Restaurant; the Restaurant is responsible for informing its staff and, where consent is the applicable basis under PIPEDA and Law 25, for obtaining it.
  • Restaurant guestsmay have limited information (a name, and optionally a phone number) entered by staff to manage reservations and waitlists. The Restaurant determines what guest information to record; Waitery processes it on the Restaurant’s behalf.

A2. Information the Staff Apps collect

CategoryDetails
Staff account dataName and work email address associated with the staff account, delivered to the device at sign-in and attached to the operational records that staff member creates (orders, kitchen tickets, time-clock entries).
Staff sign-in credentialA personal PIN, transmitted securely at each sign-in to authenticate the staff member; staff account identifiers and session tokens.
Device identifiers (pairing)A device serial number or, on devices without managed provisioning, a platform system identifier — the Android system identifier (ANDROID_ID) on Android, or Apple's identifierForVendor on iOS, which resets if the app is reinstalled, at which point the device simply re-pairs — used to pair the device to the Restaurant's location, to route print jobs, and to let the Restaurant revoke a lost or retired device. Both apps also collect a Firebase Cloud Messaging registration token to wake the printing service (registered at sign-in, removed at sign-out); Waitery Cashier additionally registers a Pushy push token. Device model and app version accompany diagnostics.
Crash and performance reportsIf the app crashes or performs poorly, a technical report (stack trace, device model, OS version, app version) is sent to our error-monitoring provider. These reports are configured not to include personal information: the reporting SDK's “send personal data” option is disabled and an automated redaction step strips sensitive fields before anything leaves the device. Performance timings are sampled (10% in production).
Guest reservation and waitlist details (Cashier only)Guest name and optional phone number, entered by staff, used to manage seating and to send the guest a “table ready” text message.
Operational activityThe restaurant-operations actions performed in the apps (orders placed, tickets completed, payments recorded, shifts clocked) — this is the Restaurant's business record, associated with the staff member who performed each action.

The Staff Apps do notcollect: location data; contacts, photos, audio, or files; browsing data; payment card numbers (card payments are captured on the Restaurant’s Clover payment hardware and never pass through the Staff Apps); or any information for advertising purposes.

A3. Purposes and limiting collection

We collect the information above only to: (a) operate the service — real-time kitchen display, order and payment workflows, reservations and waitlists, ticket and receipt printing, including maintaining an always-on connection so kitchen tickets keep printing between staff shifts; (b) secure it — authenticating staff, scoping every record to the Restaurant it belongs to, and letting Restaurants revoke devices; and (c) maintain quality — diagnosing crashes and performance problems. We do not sell personal information, and we do not use it for advertising or profiling.

A4. Service providers

Waitery uses a small number of service providers that process data on our behalf under contract, with primary hosting in Canada (AWS, Canada Central region):

ProviderWhat they processWhy
Amazon Web Services (ca-central-1)All service dataHosting
Sentry (Functional Software, Inc.)Crash/performance reports (redacted, no personal data by configuration)Error monitoring
Pushy Ltd. and Google (Firebase Cloud Messaging)Push registration tokens; wake-up signals that contain no personal or order dataWaking the printing service
TwilioGuest phone numbers and “table ready” notification content, when a Restaurant uses waitlist/reservation textingGuest SMS notifications
SendGridTransactional email content and recipient addresses (receipts, order and account notifications)Transactional email delivery
Clover / FiservPayment card and transaction data, captured on the Restaurant's Clover hardware and services — never inside the Staff AppsPayment processing

A5. Retention and deletion

  • Operational records (orders, payments, and the staff/guest details embedded in them) are financial records of the Restaurant and are retained to meet Canada Revenue Agency requirements (minimum 7 years, Income Tax Act s.230 / Excise Tax Act s.286), consistent with PIPEDA s.7(2)(a), which permits retention required by law. Where an individual exercises a deletion right, we anonymize the personal information while retaining the anonymized financial record.
  • Staff account data is retained while the account exists; Restaurants deactivate staff accounts in the Restaurant Panel.
  • Device identifiers are retained while the device is paired/registered; Restaurants can deactivate a device, which severs its access.
  • Crash reportsare retained per our error-monitoring provider’s rolling retention window.

A6. Safeguards

All data in transit between the Staff Apps and Waitery is encrypted (HTTPS/TLS and secure WebSockets); release builds refuse to run against a non-configured endpoint. Every record is scoped to its Restaurant; staff sessions and device credentials are time-limited and revocable per device. Crash reporting is PII-disabled at the SDK level with an additional redaction pass.

A7. Access, correction, and questions

Staff members should direct access/correction requests to their employer (the account administrator), or to Waitery at hello@waitery.ca. Guests who received a waitlist/reservation text can ask the Restaurant, or Waitery at the same address, to access or delete their details, subject to the legal retention described in §A5. Complaints follow the challenging-compliance process described in the main policy; individuals may also contact the Office of the Privacy Commissioner of Canada.

Part three

Guest Data (QR Ordering, Reservations, Waitlists, Receipts)

This section describes personal information handled when a restaurant’s customer (a “Guest”) interacts with Waitery’s guest-facing services — QR self-ordering on the web, reservation and waitlist bookings, order-status and “table ready” notifications, and electronic receipts.

G1. What is collected

  • Contact details a Guest or staff member provides: name, and optionally a phone number or email address (for notifications, receipts, reservations, and waitlists).
  • Order history and preferences: items ordered, dietary notes or allergy flags a Guest chooses to share, and visit history at the Restaurant.
  • Payment information: card payments are processed by Clover/Fiserv on the Restaurant’s payment hardware or hosted payment pages. Waitery stores only a payment token and transaction metadata (never full card numbers) so refunds and receipts can be processed.

G2. Roles and rights

The Restaurant is the business that decides what to record about its Guests; Waitery processes Guest information on the Restaurant’s behalf. A Guest may request access, correction, or deletion of their personal information through the Restaurant or directly from Waitery at hello@waitery.ca. Deletion requests are completed within 30 days, including removal from our payment processor’s token vault, subject to the financial-record retention required by law (§A5) — in which case personal identifiers are anonymized while the legally required record is kept.

G3. Messaging

Order confirmations, receipts, order-ready alerts, and “table ready” texts are transactional messages needed to provide the service (sent via Twilio for SMS and SendGrid for email) and do not require marketing consent. Marketing messages are sent only with explicit opt-in consent, recorded with a timestamp, and every marketing message includes an unsubscribe mechanism honored within 10 business days, as CASL requires.