Legal
Privacy Policy for Restaurants
Last updated: August 8, 2026
This policy covers the information Zikiti Ltd. holds about partner restaurants and the people who run them — applicants, owners, managers, and floor staff. Diners' privacy is covered by the policy on zikiti.com. The same principles apply on both sides: we collect what the partnership needs, we protect it seriously, and we don't sell it.
Who is responsible
Zikiti Ltd. (Toronto, Ontario, Canada). Privacy Officer: support@zikiti.com, marked “Privacy”.
What we collect
- Application details — what you submit on the apply form: restaurant name, contact name, email, phone, location, cuisine, and what you tell us about your room.
- Verification documents — business licence, insurance, and banking confirmation, collected during onboarding.
- People’s accounts — names and emails of owners and managers; names and employee numbers of floor staff. Staff PINs are stored only as cryptographic hashes — never in a readable form, not even to us.
- Operations — your listing content, discount schedules, bookings served, settlement records, and per-employee tip attribution.
- Payments identity — Stripe collects its own verification (identity, banking) directly from you during Connect onboarding, under Stripe’s own privacy policy. Zikiti sees your account’s status, not those underlying documents.
What we use it for
Evaluating applications, verifying the business, running the portal and staff terminal, paying you out, attributing tips to the right person, supporting you, preventing fraud, and meeting legal record-keeping obligations. Commercial updates about your own partnership are part of running it; anything beyond that is opt-in.
How documents are protected
Verification documents live in a private, encrypted vault with no public access path. Viewing one requires an authorized admin, generates a link that expires in minutes, and writes an audit record of who opened what, when. There is no permanent URL to any document you upload.
Who we share it with
The same infrastructure providers as the diner side — Stripe (payments and payouts), Supabase (database and authentication), Vercel (hosting), Sentry (error monitoring) — each receiving only what its role requires, plus authorities where the law genuinely requires it. Your public listing (name, photos, menu, hours, savings) is, by design, public. We do not sell your information.
Diner information in your portal
The diner details you see in the portal are shared with you for one purpose: running the bookings and services in front of you. Using them for your own marketing, or passing them on, requires the diner’s own consent and makes you independently responsible under privacy law. This is also a term of the platform.
Your people's rights
Owners, managers, and staff can access and correct personal information we hold about them, and can complain to the Office of the Privacy Commissioner of Canada. Restaurants add their own staff to the roster — it’s the restaurant’s job to tell staff their name and employee number are processed by Zikiti for sign-in and tip attribution.
Storage, retention, and safeguards
Information may be processed in Canada and/or the United States, encrypted in transit and at rest, with row-level database access controls, mandatory two-factor authentication on every administrative account, and audit logging on sensitive access. Business and transaction records are retained as financial and tax law requires; documents and accounts for partnerships that end are removed once no longer legally required.