Order data is sensitive. We treat it that way.
Running your kitchen through Heipung means trusting us with your orders and your customers' details. Here is what we store, how long we keep it, who can reach it, and what we connect to on your behalf - stated plainly, with no claims we cannot stand behind.
What we store
Order contents, timing and status, the menu and recipe data you configure, and the account details of your team. We hold what the belt needs to run - not more.
Retention
Operational order data is kept while it is useful for your reporting and forecasting, then aged out on a defined schedule. You can request deletion of your data when you leave.
Access scope
Access inside your account is role-based, so a line cook sees the belt and an owner sees the estate. On our side, access to production data is limited and logged.
Platform connections
When you connect a delivery platform, we request only the scope needed to pull orders and update their status - nothing broader - and you can disconnect any platform at any time.
Encryption
Traffic between your kitchen and Heipung is encrypted in transit, and stored data is encrypted at rest. Credentials and platform tokens are held separately from operational data.
Honest posture
We do not claim certifications we have not earned. As our compliance position advances, we will state the current status here in plain terms rather than aspirational ones.
Customer data from delivery platforms
Delivery orders arrive with the details needed to prepare and dispatch them - items, notes, and the delivery information the platform passes through. We use that data to run the queue, coordinate the handoff, and report back to you. We do not sell it, and we do not use one kitchen's data to train a model that benefits a competitor.
How the forecast uses your history
Demand forecasting is built from your own order history. Your patterns inform your predictions. We treat that history as yours, kept within your account's scope, and used to serve your kitchen rather than pooled indiscriminately.
Connecting and disconnecting platforms
You authorise each platform connection, and you can revoke it. When a connection is removed, we stop pulling new orders from it. We request the narrowest scope that still lets the belt do its job - reading incoming orders and reflecting their status back.
Reporting a concern
If you believe you have found a security issue or have a question about how your data is handled, reach us through the Talk to us page and flag it as a security matter. We would rather hear about a concern early than late.
Have a security question before you commit?
Send it over and we will answer honestly about where we are today, not just where we intend to be. No overclaiming.
