Last updated: July 20, 2026
Privacy Policy
This Privacy Policy explains how OKI collects, uses, stores, shares, and protects personal information when you use our digital menu platform, websites, checkout pages, advertising, and related services.
Company information
OKI is operated by the legal entities responsible for the relevant service or payment flow. For Paddle payments and international sales, the responsible entity is the Ukrainian legal entity of OKI: FOP PETROVA KATE, registered in Ukraine, registration number: 938457349857. Registered address: 65481, Ukraine, reg. Odeska, c. Pivdenne, st. Prymorska, bld. 11. Privacy contact email: [email protected].
Information we collect
We may collect account and business information, including name, email address, phone number, business name, restaurant details, billing information, subscription status, invoices, and any content you add to your digital menu, such as menu items, prices, images, links, promotions, and business information.
We collect technical and usage information, including IP address, approximate location, device type, browser, operating system, language, pages viewed, referral URLs, session events, cookie identifiers, local storage data, and interactions with our websites, checkout pages, ads, and emails.
If you contact us, we may collect the information you include in support messages, forms, emails, chat messages, and other communications.
If children under the age of 13 use parts of the service or submit information, we collect and process that information only as allowed by applicable law and, where required, with verifiable parental or guardian consent. Parents or guardians may contact us to access, correct, or delete a child's information.
Payments and billing providers
Users can pay for OKI products and services. We use Paddle as our third-party payment provider and Merchant of Record for all checkout and payment processing. Financial data, including full credit card numbers, bank details, tax information, fraud signals, and payment authentication data, is collected and processed directly by Paddle under Paddle's own Privacy Policy. We do not store full payment card details on our servers.
We receive limited payment-related information from Paddle, such as customer name, email address, country, subscription plan, transaction ID, payment status, invoice or receipt data, renewal and cancellation events, and fraud or chargeback status, so that we can provide access to the service, manage subscriptions, issue support, comply with tax and accounting duties, and prevent abuse.
How we use information
We use personal information to create and manage accounts, publish digital menus, provide access to paid features, process subscriptions, send transactional notices, provide technical support, respond to requests, prevent fraud and abuse, secure the service, improve performance, and comply with legal, tax, accounting, and regulatory obligations.
We may use contact and usage information to send service updates, onboarding messages, product announcements, promotional messages, and subscription-related communications. Where required by law, we ask for consent or provide an option to unsubscribe.
We may use aggregated, anonymized, or de-identified information to analyze trends and improve OKI without identifying a specific person or business.
Cookies, analytics, ads, and remarketing
OKI may use cookies, local storage, pixels, tags, and similar technologies to keep sessions active, remember preferences, measure traffic, detect abuse, show ads, personalize advertising, and understand how visitors use our pages.
We may use analytics and related tools, including Umami Analytics, Google Analytics, or similar services, to measure product usage, traffic sources, conversion events, and site performance.
We use remarketing and advertising services to advertise our business. These services may use cookies, pixels, device identifiers, IP addresses, page views, and interaction events to show or measure ads on OKI and third-party websites or platforms.
We use Cloudflare Turnstile or similar security tools to protect forms, signups, checkout flows, and other parts of the service from spam, bots, fraud, and abuse. These providers may process device, browser, IP address, and interaction data for security purposes.
You can control cookies through your browser settings and, where available, through consent tools. Disabling some cookies may affect login, checkout, security checks, analytics accuracy, or parts of the service.
Public menu and customer content
Restaurants are responsible for the menu content, prices, images, links, promotions, and business information they publish through OKI.
Public menu pages are designed to be visible to visitors who open the menu link or QR code. If a restaurant publishes personal information on a public menu page, that information may be visible to anyone with access to the link.
Sharing information
We do not sell personal information for money. We may share information with service providers that help us host the platform, process payments, provide checkout, manage subscriptions, deliver analytics, show ads, run remarketing campaigns, send communications, provide security checks, prevent fraud, store data, and provide customer support. We may share information with Paddle, hosting providers, cloud infrastructure providers, analytics providers, advertising and remarketing partners, email providers, customer support tools, fraud-prevention services, professional advisers, and legal or regulatory authorities where necessary.
International transfers
OKI, Paddle and our service providers may process and store information in countries other than the country where you or your business are located, including Ukraine, Argentina, the United States, the European Economic Area, the United Kingdom, and other countries where our providers operate.
Where required, we use appropriate safeguards for international transfers, such as contractual protections, data processing agreements, standard contractual clauses, adequacy decisions, and other lawful transfer mechanisms.
GDPR and European privacy rights
If the GDPR, UK GDPR, or similar European privacy laws apply, our legal bases for processing may include performance of a contract, legitimate interests, consent, compliance with legal obligations, and protection of rights and security.
You may have the right to access, correct, delete, restrict, object to, or request a portable copy of your personal information. You may also have the right to withdraw consent where processing is based on consent and to lodge a complaint with a supervisory authority.
For Paddle checkout, Paddle may act as Merchant of Record and independently process buyer data for payment processing, order fulfillment, fraud prevention, tax compliance, and buyer support under Paddle's own privacy documentation.
California privacy rights
If the CCPA, CPRA, CalOPPA, or other California privacy laws apply, California residents may have the right to know what personal information we collect, use, disclose, share, or sell; to request deletion; to request correction; to opt out of sale or sharing; to limit use of sensitive personal information where applicable; and to not be discriminated against for exercising privacy rights.
We do not sell personal information for money. Some advertising or remarketing activities may be considered sharing or targeted advertising under certain privacy laws. Where required, we provide ways to opt out or honor applicable browser-based opt-out signals.
Under CalOPPA, this policy describes the categories of information we collect, how we use and share it, how users can request changes, how we handle changes to this policy, and how we respond to applicable tracking choices.
Retention and security
We keep information for as long as needed to provide the service, maintain accounts and subscriptions, comply with legal, tax, accounting, and regulatory obligations, resolve disputes, prevent fraud, enforce agreements, and protect our rights.
We use reasonable technical and organizational measures to protect information, including access controls, provider security controls, and abuse-prevention measures, but no online service can guarantee absolute security.
Your choices and rights
Depending on your location, you may have rights to access, correct, delete, object to, restrict, withdraw consent, opt out of certain marketing or targeted advertising, or request a copy of personal information we hold about you.
You may request account or data changes by contacting us through the privacy contact listed in the Company information section. We may need to verify your identity before completing the request.
Some information may need to be retained where required for payment records, tax, accounting, fraud prevention, legal claims, security, or compliance obligations.
Changes and contact
We may update this Privacy Policy from time to time. The updated version will be posted on this page with a new last updated date. If changes are material, we may provide additional notice where required by law.
Questions about privacy, data requests, or children's data requests can be sent to the privacy contact email listed in the Company information section.