Back
queshot
Legal

Privacy Policy

Last updated [EFFECTIVE_DATE — to be completed]

1. Who we are

This Privacy Policy explains how Queshot Pty Ltd (ACN 699 051 744, ABN 12 699 051 744) ("Queshot", "we", "us") collects, holds, uses and discloses your personal information. We handle personal information in accordance with the *Privacy Act 1988* (Cth) and the Australian Privacy Principles (APPs), and we comply with the APPs whether or not the small-business exemption would otherwise apply to us. This policy covers both customers and café partners who use the Queshot app, café dashboard and website (the "Platform").

2. What personal information we collect and hold

digits) provided by our payment processor, Stripe. We do not collect or store your full card number.

have an active order or have enabled Kerbside or auto-order, to time your order and trigger auto-order; and, if you save a home or other place, the coordinates and address of those saved places. We retain this location information — your saved home/place coordinates and the origin, route, travel time and timing of your orders — linked to your account, and use it as described in clause 4. Access to identifiable location data is restricted to authorised Queshot staff and is logged. We do not** sell it.

on your device before the image is sent to us.** We store the picture, not where or when it was taken.

collected through analytics and error-monitoring tools (see clause 5).

the information needed to set up payouts through Stripe.

We collect sensitive information (such as allergy or dietary notes) only where you choose to provide it so an order can be prepared safely; we treat it as health information and only use it for that purpose.

3. How we collect it

We collect personal information: directly from you (when you create an account, place an order, or contact us); automatically as you use the Platform (through analytics, error-monitoring and device data); and from third parties where relevant — for example, order-status information from cafés, payment confirmations from Stripe, and address suggestions from Google when you use address search.

4. Why we collect, use and disclose it

We use your personal information for the primary purpose of providing the Platform and fulfilling your orders, and for related purposes you would reasonably expect, including:

obligations;

customers are located, to plan coverage and improve the service; access to identifiable location data is restricted to authorised Queshot staff and is logged;

using your order and journey history (origin, route, travel time and timing); and

We disclose your personal information to:

to protect your information consistently with the APPs:

We do not sell your personal information, and we never will.

5. Analytics, session replay and tracking

We use PostHog (product analytics and session replay) and Sentry (error monitoring) to understand how the Platform is used and to fix problems. Session replays mask sensitive fields, and we do not put personal identifiers such as your phone number into analytics events. These tools use device identifiers and similar technologies. You can ask us to opt you out of non-essential analytics by emailing support@queshot.com. See our How we use data notice for more.

6. Overseas disclosure

Some of our service providers store or process personal information overseas. The countries where your information is likely to be handled include the United States and member states of the European Union/EEA, and other countries where our sub-processors operate. Before disclosing information overseas we take reasonable steps to ensure the recipient handles it consistently with the APPs (including through data-processing agreements). Under the *Privacy Act*, in many cases we remain accountable for how those overseas recipients handle your information.

7. Direct marketing

We will only send you marketing communications where you have opted in. Every marketing message includes a simple way to unsubscribe, and we honour opt-outs promptly. You can also change your marketing preferences in settings. Service and transactional messages (order updates, security codes, receipts) are part of the service and are not marketing — you cannot opt out of them while you hold an active account or order. We do not use sensitive information for marketing.

8. How we keep your information secure

We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure — including encryption in transit, access controls and row-level security on our database, vendor due diligence, and staff access on a need-to-know basis. No system is completely secure, but we work to protect your information and to respond quickly if something goes wrong.

9. Data breaches

If we ever experience a data breach that is likely to result in serious harm, we will assess it promptly and, where the Notifiable Data Breaches scheme requires, notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable, including the steps you can take.

10. How long we keep your information

We keep your personal information while your account is active and for as long as needed for the purposes above or to meet our legal, tax and fraud-prevention obligations. When you delete your account, we delete or de-identify your personal information, retaining only the records the law requires us to keep (for example, transaction records for tax purposes).

11. Accessing and correcting your information

You can access and correct most of your information directly in settings. You can also ask us for access to, or correction of, your personal information by emailing support@queshot.com. We will respond within a reasonable time (generally 30 days). Access is free to request; if we refuse access or correction, we will give you written reasons and tell you how to complain, and you may ask us to attach a statement noting your disagreement.

12. Deleting your account and data

You can delete your account and personal information in the app (Settings → Account), or request deletion at any time by emailing support@queshot.com or via our deletion request page. When you delete your account we remove or de-identify your personal data, keeping only what the law requires.

13. Children

The Platform is intended for people aged 18 and over and is not directed at children. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

14. Automated decision-making

Some Platform features operate automatically — for example, auto-order places your saved order when you enter a café's area, and automated checks help us detect fraud and prevent misuse. Where we introduce automated decisions that could significantly affect your rights or interests, we will describe in this policy the kinds of information used and the kinds of decisions involved, consistent with our obligations under the *Privacy Act* (this obligation applies from 10 December 2026).

15. Cookies and our website

Our website uses essential cookies to function and may use analytics cookies to understand usage. You can control cookies through your browser. See our How we use data notice for details.

16. Complaints and contact

If you have a question, an access or correction request, or a privacy complaint, contact our Privacy Officer at support@queshot.com (or write to Queshot Pty Ltd, [REGISTERED_OFFICE_ADDRESS — to be completed]). We will acknowledge and respond to complaints within a reasonable time. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner: oaic.gov.au, 1300 363 992.

17. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version with a new "last updated" date and, for material changes, take reasonable steps to notify you. This policy is available free of charge, and we will provide a copy in another form on request.

Terms of ServiceHow we use dataCafé Partner Agreement