Pekkish

Privacy policy

Last updated: 7 September 2026.

This policy explains what information Pekkish collects, how we use it, and the rights you have over it. It covers both operators (food businesses using Pekkish to take orders) and customers (people placing those orders).

1. Who we are

Pekkish is operated by One Tandem Limited, a company registered in England and Wales (company number 17229064), trading as Pekkish. For privacy queries, email [email protected].

For UK GDPR purposes, One Tandem Limited is the data controller for information about operators and customers using the platform itself. Operators are the data controllers for their own customer data once an order has been placed through their storefront.

One Tandem Limited is registered with the Information Commissioner's Office under registration number ZC156390.

2. What we collect

From operators

  • Account details (name, email, shop name, address, phone)
  • Stripe Connect identification details, processed by Stripe for verification
  • Order, menu, and pricing data you enter into the platform
  • Communications you send to support

From customers

  • Name, email, phone, and delivery addresses
  • Order history with the operators you've ordered from
  • Payment details, processed by Stripe — we never store full card numbers

Automatically, from everyone

  • IP address, browser type, and basic usage data needed to keep the service running and secure
  • Essential cookies for authentication and basket persistence (listed in the cookie policy)
  • If you set up a passkey: the public half of the key and a name for the device. The private half never leaves your device
  • If you allow notifications in the Pekkish app: a push token that identifies your device to Apple or Google
  • First-party analytics cookies that record which link, ad, or campaign brought you to a shop's storefront, so operators can see where their customers come from. These are first-party only — no third-party trackers and no cross-site advertising networks. On a shop storefront and on the Pekkish marketing site alike, we ask your consent before setting them, and set nothing until you accept. When you place an order, we store the acquisition source (e.g. a social link, ad, referral link, or voucher code) with that order.

3. How we use it

  • To run the platform — show you menus, accept orders, process payments, send notifications
  • To bill operators for their Pekkish subscription and platform fees
  • To respond to support requests
  • To detect fraud, abuse, and security issues
  • To meet legal obligations (tax, accounting, fraud reporting)

We do not sell personal data to third parties. We do not use your data to advertise to you.

4. Lawful basis

  • Contract — most of what we do is necessary to provide the service you've signed up for or ordered through
  • Legitimate interest — keeping the service secure, preventing fraud, improving the product
  • Legal obligation — keeping records for tax and accounting purposes

5. Who we share data with

This is every service that handles personal data on our behalf, and what each one sees.

  • Operators — when you place an order, the operator receives your name, contact details, and order. They become the data controller for that data.
  • Stripe — payment processing, operator onboarding and our own billing. Stripe sees the details you give it at checkout and, for operators, the identification details it needs to verify a business.
  • Brevo — sends every email we send: order notifications, password resets, account and billing emails. Brevo is based in the EU.
  • Scalingo — our hosting provider; application servers and the database are in France.
  • Cloudflare — three things: every request to a Pekkish site passes through Cloudflare's network, which sees your IP address and protects the site; Cloudflare R2 stores uploaded images (shop logos, product photos, menu files); and Cloudflare Turnstile, the bot check on the sign-up and contact forms, sees your IP address and browser signals. Cloudflare's commitments are at cloudflare.com/trust-hub.
  • Anthropic — when an operator uses "import a menu", the photo or PDF they upload is sent to Anthropic's API to be read into a menu. Only that file is sent; no customer data ever is. Anthropic does not train its models on data sent through its API.
  • PrintNode — for operators who print order sheets automatically: the order ticket, which includes the customer's name and order, is sent to PrintNode (a US company) to reach the shop's printer.
  • Star Micronics CloudPRNT — for operators with a label printer: the printer, on the shop's own premises, fetches label images (customer name and order) from our server.
  • Apple and Google — if you allow notifications in the Pekkish app, the notification text (an order reference and the shop's name) is delivered through Apple's and Google's push services.
  • Ideal Postcodes and postcodes.io — when you type a postcode, it is sent to Ideal Postcodes to find the address and to postcodes.io to place it on a map. The postcode alone is sent.
  • OpenStreetMap — map images on a shop's "find us" page come from OpenStreetMap's servers, which see your IP address like any image request.
  • GlitchTip — error reporting. When something breaks we receive the technical details; we have configured it not to send personal details.
  • Slack — our internal notifications. A new shop signing up, an order being placed, or a message through the contact form produces a short alert to our team naming the shop and, for a contact message, the sender's name and subject. Email addresses, customer names and full addresses are not sent to Slack.
  • Legal authorities — if we're required by law to disclose

Each of these is a processor bound by its own data protection terms.

5.1 Transfers outside the UK

Brevo and Scalingo are in the EU, which the UK recognises as adequate. Stripe, Cloudflare, Anthropic, PrintNode, Apple, Google, GlitchTip and Slack process some data in the United States or elsewhere. Where they do, the transfer is covered by the UK International Data Transfer Agreement or Addendum in their terms, or by a UK adequacy regulation, and we send them only what is described above.

6. How long we keep it

  • Active accounts — for as long as the account exists
  • Deleted accounts — you can delete your account yourself from Your account (the steps are on Delete your account). We stop all email straight away and erase your personal details 30 days later; sign in before then and the account is kept. After that your name, email address, phone number, saved addresses and sign-in details are gone and cannot be recovered
  • Orders you placed — kept by the shop that fulfilled them as its own business record, including for tax purposes (at least six years, as HMRC requires), with your name and contact details removed once your account is deleted
  • Email records — a log of each email we sent (recipient, subject, whether it was delivered; never the message itself) for 13 months
  • Printing records — which order was printed where, and whether it worked, for 12 months; the ticket and label images themselves for 7 days after printing
  • Push tokens — removed when Apple or Google tell us the device is no longer receiving, or when you delete your account
  • Marketing measurement — which link or campaign brought a visit: a random visitor identifier, the campaign and the landing page, with no name, email or IP address, for 13 months
  • Operator admin records — a trail of who changed what in a shop's settings, for two years
  • Menu files uploaded for import — deleted 90 days after the import is finished or fails
  • Sign-in records — one per signed-in device, removed when you sign out, reset your password, delete your account, or after 90 days without a visit from that device
  • Customer data on operator storefronts — controlled by the operator, who is responsible for retention

7. Your rights

Under UK GDPR you can:

  • Request a copy of the data we hold about you
  • Correct inaccurate data
  • Delete your account yourself, from Your account — no need to ask us. Records a shop must keep, such as the orders it fulfilled for tax purposes, are retained without your name or contact details
  • Object to processing or restrict how we use your data
  • Take your data elsewhere — ask us and we will send you your account and order data in a machine-readable form
  • Withdraw consent where we relied on it
  • Complain to the Information Commissioner's Office (ico.org.uk)

To exercise any of these, email [email protected]. We respond within a month, and usually within a few days.

8. Security

Data is encrypted in transit (HTTPS) and at rest. Authentication uses session cookies with secure flags. Payment card data never touches our servers — Stripe handles it directly.

9. Changes to this policy

We may update this policy from time to time. Significant changes will be notified by email to operators. The "last updated" date at the top reflects the current version.

10. Contact

Questions about this policy or your data: [email protected].