Who is responsible
The legal name of the company that runs Ferculon, its registered address and business registration number ("we") is responsible for the details in this notice: those of account holders, of the people on restaurants' teams, and of the platform's own records.
Each restaurant is responsible for its own guests' details (bookings, orders, the waitlist, the guest list). We keep them on the restaurant's behalf and use them for nothing else. Guests find the restaurant's own privacy notice on its page.
What we keep
About the account holder
- Name and email address, and the version of the terms accepted and when.
- Sign-ins to the back office: when, the kind of browser or device, and the internet address it came from.
- The one-time codes we email. We keep only a scrambled form of each code, for 10 minutes.
About people on a restaurant's team
- Name, roles, the PIN the restaurant sets for them, and their email if they use the back office.
- Their time clock entries and, if the restaurant sets one, their hourly rate.
- What they do in Ferculon: the orders they take, payments, voids and discounts, recorded in the restaurant's audit log.
- For a delivery rider while on a delivery shift: the phone's position, so the restaurant and the guest can follow the delivery.
About tablets and phones
- The name the restaurant gives each device, when it was paired and last used, who last unlocked it, and a notification address if notifications are allowed.
Why
- To run Ferculon for the restaurant, and to keep accounts secure.
- To keep the records a restaurant needs: invoices, till counts and a tamper-evident audit log.
- To answer requests about these details.
We do not sell these details, use them for advertising, or pass them to anyone for their own use.
Who else handles them
Service providers that run parts of Ferculon for us, each only for that purpose:
- Amazon Web Services: the servers, the storage of photos, and the emails we send.
- Twilio and WhatsApp: messages and one-time codes to guests, when the restaurant uses them.
- Expo, Apple and Google: notifications to the app.
- Google Fonts: the web pages load their typeface from Google, which sees the browser's internet address.
- OpenStreetMap: the map on a delivery's tracking page.
Where the servers are, and the safeguards for keeping details outside Mauritius under the Data Protection Act 2017.
How long
- While the account is open.
- Sign-ins are kept for as long as the sign-in lasts (7 days at most). Codes last 10 minutes.
- When someone leaves a team and the restaurant removes them, their name, email, PIN and pay rate are deleted at once. Past orders then show "Former staff". The audit log keeps their name against what they did, because it is the restaurant's tamper-evident record for the tax office.
- When the account holder deletes the account, everything is deleted at the end of the grace period (7 days at present): the account, its restaurants, their orders, invoices, guests, team, devices, photos, audit logs and sign-ins. Paired devices sign out at once.
- After a deletion we keep only a record that an account was deleted and when, with a one-way fingerprint of the email. It holds no name, no email and nothing about the restaurant.
- How long backups are kept before deleted data leaves them.
Your rights
Under the Data Protection Act 2017 you can ask to see the details kept about you, to correct them, or to have them deleted.
- The account holder can download everything and delete the account from Account in the back office, from the app (More, Delete account), or from the deletion page.
- A person on a team can ask the restaurant's owner to remove them (People, Remove). In the app, More has a way to ask.
- A guest asks the restaurant, which has the tools to export and erase their details.
- Anything else: contact email.
If you are not happy with an answer, you can complain to the Data Protection Office of Mauritius.
Security
Sign-ins use one-time codes sent by email instead of passwords, and every connection is encrypted. Each person on a team has their own PIN and their own access, and the audit log shows who did what.
Changes
If this notice changes in a way that matters, we tell account holders by email before it takes effect.