Pekkish

Privacy policy

Last updated: 19 May 2026.

This policy explains what information Pekkish collects, how we use it, and the rights you have over it. It covers both operators (food businesses using Pekkish to take orders) and customers (people placing those orders).

1. Who we are

Pekkish is operated by One Tandem Limited, a company registered in England and Wales, trading as Pekkish. For privacy queries, email [email protected].

For UK GDPR purposes, One Tandem Limited is the data controller for information about operators and customers using the platform itself. Operators are the data controllers for their own customer data once an order has been placed through their storefront.

One Tandem Limited is registered with the Information Commissioner's Office under registration number ZC156390.

2. What we collect

From operators

  • Account details (name, email, shop name, address, phone)
  • Stripe Connect identification details, processed by Stripe for verification
  • Order, menu, and pricing data you enter into the platform
  • Communications you send to support

From customers

  • Name, email, phone, and delivery addresses
  • Order history with the operators you've ordered from
  • Payment details, processed by Stripe — we never store full card numbers

Automatically, from everyone

  • IP address, browser type, and basic usage data needed to keep the service running and secure
  • Essential cookies for authentication and basket persistence
  • First-party analytics cookies that record which link, ad, or campaign brought you to a shop's storefront, so operators can see where their customers come from. These are first-party only — no third-party trackers and no cross-site advertising networks. On a shop storefront we ask your consent before setting them; on the Pekkish marketing site we use them to attribute operator sign-ups under legitimate interest. When you place an order, we store the acquisition source (e.g. a social link, ad, referral link, or voucher code) with that order.

3. How we use it

  • To run the platform — show you menus, accept orders, process payments, send notifications
  • To bill operators for their Pekkish subscription and platform fees
  • To respond to support requests
  • To detect fraud, abuse, and security issues
  • To meet legal obligations (tax, accounting, fraud reporting)

We do not sell personal data to third parties. We do not use your data to advertise to you.

4. Lawful basis

  • Contract — most of what we do is necessary to provide the service you've signed up for or ordered through
  • Legitimate interest — keeping the service secure, preventing fraud, improving the product
  • Legal obligation — keeping records for tax and accounting purposes

5. Who we share data with

  • Operators — when you place an order, the operator receives your name, contact details, and order. They become the data controller for that data.
  • Stripe — for payment processing and operator onboarding
  • Brevo (formerly Sendinblue) — for sending transactional emails such as order notifications, password resets, and account emails. Brevo is based in the EU.
  • Scalingo — our hosting provider; application servers and primary database are in the EU
  • Cloudflare R2 — object storage for uploaded images (shop logos, product photos, background images). Cloudflare's privacy commitments and sub-processor list are at cloudflare.com/trust-hub.
  • Legal authorities — if we're required by law to disclose

Each of these is a sub-processor bound by their own data protection terms.

6. How long we keep it

  • Active accounts — for as long as the account exists
  • Deleted accounts — you can delete your account yourself from Your account. We stop all email straight away and erase your personal details 30 days later; sign in before then and the account is kept. After that your name, email address, phone number, saved addresses and sign-in details are gone and cannot be recovered
  • Orders you placed — kept by the shop that fulfilled them as its own business record, including for tax purposes (7 years), with your name and contact details removed once your account is deleted
  • Customer data on operator storefronts — controlled by the operator, who is responsible for retention

7. Your rights

Under UK GDPR you can:

  • Request a copy of the data we hold about you
  • Correct inaccurate data
  • Delete your account yourself, from Your account — no need to ask us. Records a shop must keep, such as the orders it fulfilled for tax purposes, are retained without your name or contact details
  • Object to processing or restrict how we use your data
  • Take your data elsewhere (data portability)
  • Withdraw consent where we relied on it
  • Complain to the Information Commissioner's Office (ico.org.uk)

To exercise any of these, email [email protected]. We aim to respond within a working week.

8. Security

Data is encrypted in transit (HTTPS) and at rest. Authentication uses session cookies with secure flags. Payment card data never touches our servers — Stripe handles it directly.

9. Changes to this policy

We may update this policy from time to time. Significant changes will be notified by email to operators. The "last updated" date at the top reflects the current version.

10. Contact

Questions about this policy or your data: [email protected].