Back to Home

Privacy Policy

Last updated: June 17, 2026

1. Age and Eligibility

Kyoskgo is intended for users who are 18 years or older. The product is built for business, vendor, order, booking, and account-management workflows rather than for children or general-audience use.

2. Information We Collect

We collect information you provide when you create an account or use Kyoskgo, including your name, email address, password, phone number, country, currency, timezone, and consent preferences. If you sign in with Google, we also receive your verified email address and profile name from that provider.

When you operate a business on Kyoskgo, we also collect business profile data such as the business name, description, categories, contact details, location fields, services or items, booking settings, orders, customer records, QR codes, media uploads, reviews, and analytics data tied to that business.

We automatically collect technical information such as IP addresses, browser user agent strings, timestamps, session data, QR scan events, and security logs. Cookie preferences and analytics consent are stored in browser storage so the site can remember your choice.

3. How We Use Your Information

  • To provide and maintain the platform
  • To power customer and vendor accounts, orders, bookings, support, and discovery
  • To send account, verification, and service notifications
  • To store consent records, audit logs, and security events
  • To run analytics and improve the product where consent or legitimate interests apply
  • To detect fraud, abuse, and unauthorized access

4. Sharing and Processors

We share personal data only with service providers that help us operate Kyoskgo or where we are required to do so by law. Kyoskgo is hosted on self-managed VPS infrastructure provided by Hetzner, using Docker and self-hosted Coolify for deployment management. Based on the current service, this includes Google OAuth for sign-in, UploadThing for file uploads, MSG91 for phone verification and OTP delivery, PostHog for analytics when enabled, Sentry for error monitoring, SMTP/email infrastructure, and Mapbox or other mapping services when those features are enabled in the deployment environment.

5. Cookies and Browser Storage

Kyoskgo uses essential cookies for sign-in, session continuity, and CSRF protection. Analytics cookies or similar technologies are only used when analytics consent is enabled. We also use localStorage and sessionStorage to remember cookie preferences and related UI state.

Logged-in users can update analytics consent in Settings. See our Cookie Policy for more detail.

6. Your Choices and Rights

You can review and change your profile information, consent settings, API keys, and password from Settings. You can also export your data in JSON format or delete your account from the same area.

  • Account deletion anonymizes profile details, unpublishes owned businesses, revokes sessions and API keys, and soft-deletes the user record.
  • Audit logs are retained for 2 years before the cleanup job removes them.
  • QR scan telemetry is retained for 90 days, then removed by the retention job.
  • Verification tokens are removed after they expire, plus a 1-day grace period.
  • Order lookup attempts are retained for 30 days; order lookup tokens are retained for 7 days; idempotency keys are retained for 2 days.
  • Failed jobs are retained for 7 days.
  • Payment proof screenshots, where used, are retained based on status: approved proofs for 90 days, rejected proofs for 30 days, and dispute-closed proofs for 180 days.
  • Daily metrics are retained for 2 years. Archive handling is present in the current service, but a full historical archive is not yet exposed.

7. Security

We protect the platform with password hashing, CSRF protection, session cookies, CSP controls, tenant-scoped ownership checks, hashed IP/user-agent storage where applicable, and audit logging for security-relevant actions.

8. Public Business Profiles

Kyoskgo lets business owners choose which public fields to expose. The current service supports hiding exact location, full address, direct phone number, WhatsApp, social links, and payment instructions from public catalog pages. These privacy flags are respected by the public search, map, and business detail views.

9. Data Export, Access, and Deletion

You can request a JSON export of your account data from Settings. You can also delete your account from the Danger Zone section in Settings. When deletion is requested, Kyoskgo anonymizes personal details, revokes access where appropriate, and keeps only the records needed for legal, security, or fraud-prevention reasons.

10. Contact

For privacy questions, email [email protected]. For access, export, or deletion requests, use Settings. Enterprise customers who need a data processing reference can review the Data Processing Information.