Legal
Privacy Policy
Last updated: August 8, 2026
This policy explains what personal information Zikiti Ltd. collects from diners, why we collect it, who we share it with, and the rights you have over it under Canadian privacy law (PIPEDA). The short version: we collect what's needed to run your bookings and payments, we don't sell your information, and we don't run advertising trackers.
Who is responsible
Zikiti Ltd. (Toronto, Ontario, Canada) is responsible for the personal information it holds. Our Privacy Officer can be reached at support@zikiti.com — mark your message “Privacy”.
What we collect
- Account details — name, email address, phone number, and, only if you choose to add them, your date of birth and anniversary.
- Dining activity — bookings, cancellations, restaurants you favourite, reviews you write, and the bills you settle through Zikiti (amounts, savings, tip, fee).
- Payment details — handled by Stripe. We never receive or store your card number; we see only what’s needed to show you your own cards (brand, last four digits, expiry).
- Technical and security data — sign-in events and error reports, and limited connection data used to prevent abuse. Where we count requests for rate limiting, we store a salted cryptographic hash of your IP address, not the address itself.
- From Google — if you sign in with Google, we receive your name and email address from Google. Never your password.
Location is the exception, and it is deliberate. If you choose to sort restaurants by distance, your browser asks your permission and gives your coordinates to the page you are on. They are used there, in your browser, to order a list we have already sent you. They are never transmitted to Zikiti, never written to our database, and never logged. We keep them in your browser’s session storage so you are asked once per visit rather than on every page, and your browser discards them when you close the tab. You can decline, and everything else on the site works exactly as before.
What we use it for
To run your account, bookings, and payments; to send you one-time sign-in codes and transactional messages about your bookings; to attribute verified reviews; to prevent fraud and abuse; and to meet legal obligations such as tax and financial record-keeping.
Marketing is opt-in only. We send marketing messages only if you expressly said yes (the box is unchecked by default), and you can withdraw that consent at any time from your profile. This is how Canada’s anti-spam law (CASL) requires it, and how we built it.
Who we share it with
- The restaurant you book — sees what it needs to serve you: your name, party size, booking time, special request, and your bill and tip at settlement. It never sees your payment method.
- Service providers — Stripe (payments), Supabase (database and authentication), Vercel (hosting), Google (only if you sign in with Google), and Sentry (error monitoring). Each receives only what its role requires.
- Authorities — where the law genuinely requires it.
We do not sell personal information, and there are no advertising or data-broker relationships.
Where your information lives
Our service providers may store and process information in Canada and/or the United States. While information is outside Canada, it is subject to the laws of that jurisdiction, and authorities there may have lawful access to it.
How long we keep it
Account information is kept while your account is active. Transaction records are kept as long as tax and financial law requires, even after an account closes. When you request deletion, your identity information is removed from use immediately and your account can’t be signed into again; the transactional records the law requires us to keep are retained without being used for anything else.
Your rights
You can ask to see the personal information we hold about you, correct it, withdraw consents you’ve given, or have your account deleted — write to support@zikiti.com. If you’re not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada.
How we protect it
Information is encrypted in transit and at rest. Access inside the database is restricted row-by-row so accounts can only ever read their own data. Every administrative account requires two-factor authentication, and access to sensitive records is logged. Card numbers never touch our systems at all.
Cookies
Zikiti uses only essential cookies — the ones that keep you signed in. There are no advertising cookies and no third-party tracking.
Children
Zikiti is not directed at minors, and you must be at least 18 (or the age of majority in your province) to hold an account.
Changes
If this policy changes materially, we’ll post the updated version here with a new date before it takes effect.