Privacy Policy

Kiosk Wizard runs no analytics, sets no advertising cookies, and stores no shopper records of its own. This page explains, in order, exactly what we do hold.

Effective
July 25, 2026
Applies to
www.kioskwizard.com

1. Who we are

Kiosk Wizard is operated by Web Wiz LLC, a company formed in California, United States(“we”, “us”). For the personal data described in this policy we are the data controller, except where section 3 says otherwise.

Postal address: 2108 N ST STE N, Sacramento, CA 95816, United States.
Privacy contact: support@kioskwizard.com.

We are not required to appoint a Data Protection Officer under GDPR Article 37, and have not appointed one. Privacy questions go to the address above and reach a person, not a queue.

2. Two very different sets of data

Kiosk Wizard sits between two groups of people, and the distinction governs everything below:

  • Merchants — the shop owners who hold an account with us, connect a WooCommerce store, and pay a subscription. We are the controller of their data.
  • Shoppers— the people who walk up to a kiosk screen in a merchant’s shop and place an order. We are only a processor of their data; the merchant is the controller. See section 3.

3. If you used a kiosk in a shop

When you place an order on a Kiosk Wizard screen you enter a first name, a last name, an email address, and optionally an order note. That information is passed straight throughto the WooCommerce store of the shop you are standing in, where it becomes an ordinary order in that shop’s own records. Kiosk Wizard does not copy it, does not store it in our database, and does not use it for anything else. Our servers hold it only for the seconds it takes to forward the order.

The shop is the data controller for that order. To ask what a shop holds about you, to correct it, or to have it deleted, contact the shop directly — they hold the record and they answer the request. We act on that shop’s written instructions under the terms in our Data Processing Addendum.

The kiosk also sets one cookie in the browser on the screen so your cart survives between taps. It contains a random cart identifier issued by the shop’s own WooCommerce store — no name, no email. It is cleared when the order is placed, when the screen sits idle for fifteen minutes, and in any case within 24 hours. Details are in the Cookie Policy.

4. What we collect from merchants

Everything below is either given to us directly by the account holder or generated by the act of using the service. We do not buy personal data, and we do not enrich it from third-party sources.

Account
Email address and a password, held by our authentication provider. Passwords are stored only as a salted hash — we never see or store the password itself.
Kiosk configuration
Kiosk name, the URL of your WooCommerce store, your chosen kiosk address, and the shop’s pickup address. The pickup address is a business address, read from your store during setup.
Store credentials
The WooCommerce REST API key and secret issued to us when you approve the connection in your own wp-admin. These are encrypted with AES-256-GCM before they are written to the database, and are only decrypted in memory to make a request to your store. You can revoke them from WooCommerce at any time, without our involvement.
Billing
Handled by Stripe. Stripe collects your card details directly — they never touch our servers. We receive and store your Stripe customer identifier, billing email, subscription status, and renewal dates.
Contact form
The name, email address, optional store address, and message you type into the form on our home page. This is emailed to our support inbox and is not written to any database — the email is the only record.
Technical data
Standard web server logs kept by our hosting provider: IP address, user agent, requested URL, timestamp, and response status. We also hold your IP in memory for up to one minute to rate-limit the contact form; that copy is never written to disk.

5. What we deliberately do not collect

  • No analytics. There is no Google Analytics, no product analytics SDK, no session recording, and no heatmapping anywhere in the product or on this website.
  • No advertising or tracking cookies, and no cross-site tracking of any kind. We do not participate in ad networks.
  • No third-party fonts or scripts loaded at runtime. Our typeface is compiled into the site at build time and served from our own domain, so visiting a page does not disclose your IP address to a font CDN.
  • No shopper database. As described in section 3, we hold no record of anyone who orders from a kiosk.
  • No selling or sharing. We have never sold or shared personal information for money or for cross-context behavioural advertising, as those terms are defined under California law, and we do not intend to.
  • No special category data. We do not ask for, and have no use for, data revealing health, biometrics, race, religion, political opinion, or sexual orientation.

6. Why we use it, and our legal basis

For anyone in the UK or the European Economic Area, GDPR Article 6 requires us to name a lawful basis for each purpose. Ours are:

Running your kiosks
Authenticating you, reading your catalogue, and creating orders in your store. Basis: performance of a contract (Art. 6(1)(b)) — this is the service you signed up for.
Billing and collections
Charging the subscription, issuing receipts, and handling failed payments. Basis: performance of a contract, and legal obligation (Art. 6(1)(c)) for the tax and accounting records we are required to retain.
Support and correspondence
Answering the contact form and support email. Basis: legitimate interests (Art. 6(1)(f)) — replying to somebody who wrote to us. You can object at any time by asking us to delete the thread.
Security and abuse prevention
Server logs, rate limiting, and investigating suspected fraud or attack. Basis: legitimate interests— keeping the service available and merchants’ stores safe.
Service notices
Emailing account holders about outages, security issues, price changes, or changes to these terms. Basis: performance of a contract. These are not marketing and cannot be unsubscribed from while you hold an account.

We do not send marketing email. If that ever changes it will be opt-in, with a working unsubscribe link in every message.

7. Who else sees it

We use a small number of vendors to run the service. Each one processes data only on our documented instructions, under a written data processing agreement, and none of them may use it for their own purposes. The current list — who they are, what they hold, and where — is maintained at Sub-processors.

Beyond those vendors, we disclose personal data only:

  • to your own WooCommerce store, which is the entire point of the product and happens under your control;
  • when compelled by valid legal process, and then only the minimum required — we will notify you first unless we are legally barred from doing so;
  • to professional advisers, or to an acquirer in a merger or sale of the business, in which case this policy continues to apply until you are given notice of any change.

8. International transfers

We and all of our vendors are located in the United States. If you are in the UK or the EEA, using Kiosk Wizardnecessarily transfers your personal data there. Those transfers rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable), which are incorporated into our agreements with each vendor listed on the sub-processor page. You may request a copy of the relevant clauses from support@kioskwizard.com.

9. How long we keep it

Account and kiosk data
For as long as your account exists. When you delete your account it is removed from our live database immediately, and from encrypted backups within 30 days as those backups age out.
WooCommerce credentials
Deleted with the kiosk they belong to. Deleting your account destroys them; revoking the key in wp-admin renders any copy useless immediately.
Billing records
Retained by Stripe and by us for seven years after the final transaction, because tax and accounting law requires it. This survives account deletion — it is the one category we cannot erase on request.
Support email
Kept for two years from the last message in the thread, then deleted.
Server logs
Retained by our hosting provider for up to 30 days.
Shopper order data
Not retained at all. See section 3.

10. How it is protected

  • All traffic is served over TLS. The application is only reachable over HTTPS.
  • WooCommerce API credentials are encrypted at rest with AES-256-GCM using a key held only in the server environment, separate from the database.
  • The database enforces row-level security, and application queries run through narrowly scoped functions rather than direct table access, so one account cannot read another’s rows.
  • Card details never reach our servers; Stripe collects them directly and we hold only an identifier.
  • Administrative access is limited to personnel who need it, protected by multi-factor authentication.

No system is perfectly secure. If a breach affects your personal data we will notify the relevant supervisory authority within 72 hours where GDPR Article 33 requires it, and notify you directly without undue delay where the risk to you is high.

11. Your rights

If you are in the UK or the EEA, the GDPR gives you the right to:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — have inaccurate data corrected.
  • Erasure — have your data deleted, subject to the billing records in section 9.
  • Restriction — have us pause processing while a dispute is resolved.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests.
  • Complaint— lodge a complaint with your national supervisory authority, or with the Information Commissioner’s Office in the UK. We would rather you came to us first, but you do not have to.

If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what we collect, to delete it, to correct it, to opt out of sale or sharing (we do neither), and not to be discriminated against for exercising any of them. Residents of Colorado, Connecticut, Virginia, and other states with comparable laws have equivalent rights, and we honour them for every user rather than checking your address first.

Exercising them

Deletion is self-service. Sign in and go to your account page, where Delete account cancels your subscriptions, destroys your stored WooCommerce credentials, removes your kiosks, and deletes your login. It takes effect immediately and cannot be undone.

For anything else — access, portability, correction, restriction, or objection — email support@kioskwizard.com from the address on your account. We respond within 30 days, and will tell you if we need the one-off extension the GDPR allows for complex requests. There is no charge unless a request is manifestly unfounded or repetitive. We may need to verify your identity before acting, and we will not ask for more information than that verification requires.

12. Children

Kiosk Wizard is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, write to support@kioskwizard.com and we will delete it.

13. Changes to this policy

When this policy changes we update the effective date at the top. If a change materially reduces your rights or expands what we collect, we will email every account holder at least 30 days before it takes effect. Continuing to use Kiosk Wizard after that date means you accept the revised policy.

14. Contact

Privacy and data-subject requests: support@kioskwizard.com
Everything else: support@kioskwizard.com
Post: Web Wiz LLC, 2108 N ST STE N, Sacramento, CA 95816, United States