Privacy Policy
Effective date: March 31, 2026
1. Introduction
This Privacy Policy explains how Wymzy Industries LLC ("Company," "we," "us," or "our") collects, uses, and protects your information when you use Katydid ("the Service"), a local delivery ordering platform operated at katydid.app. By using the Service, you agree to the collection and use of information as described in this policy.
2. Information We Collect
From Operators (Business Owners):
- Email address and password (for account authentication)
- Business name, type, address, and phone number
- Logo and banner images
- Bank account information (collected by Stripe Connect, not stored by us)
- Menu items, pricing, and delivery schedules
From Customers (People Who Order):
- Name and phone number
- Email address (optional)
- Delivery address
- Order details and delivery notes
- Payment information (collected by Stripe, not stored by us)
Automatically Collected:
- Device type, browser, and operating system (via standard HTTP headers)
- Page views and interaction events (via PostHog and Vercel Analytics, when enabled)
- IP addresses (for rate limiting and abuse prevention)
3. How We Use Your Information
- To operate, maintain, and improve the Service
- To process orders and facilitate delivery
- To send transactional notifications (order confirmations, delivery updates) via SMS
- To enable Operators to manage their ordering pages and routes
- To process subscription billing
- To detect and prevent fraud, abuse, and security threats
- To comply with legal obligations
4. Third-Party Services
We use the following third-party services to operate Katydid:
- Stripe — Payment processing for both Operator subscriptions and Customer orders. Stripe collects and stores payment information directly; we never see or store full card numbers.
- Twilio — SMS notifications for order confirmations and delivery updates. Customer phone numbers are sent to Twilio to deliver messages.
- Google Maps — Address autocomplete, geocoding, and delivery route optimization. Addresses are sent to Google to validate delivery zones and plan routes.
- Cloudflare R2 — Image storage for menu item photos, logos, and banners.
- Vercel — Hosting and deployment. Vercel Analytics and Speed Insights may collect anonymized performance data.
- PostHog — Product analytics (when enabled via environment variable). Collects anonymized usage events.
- Sentry — Error tracking (when enabled via environment variable). May collect technical error data including device/browser information.
Each third-party service is governed by its own privacy policy. We encourage you to review them.
5. Customer Data Isolation
Customer data is strictly isolated per Operator. Each Operator can only access data from customers who have ordered through their specific ordering page. No Operator can access, view, or export another Operator's customer data. We do not aggregate customer data across Operators for any purpose.
6. Image Handling & EXIF Data
When Operators upload menu item photos, logos, or banners, we strip EXIF metadata (including GPS coordinates, camera information, and timestamps) from images before storing them. This prevents inadvertent disclosure of location or personal information embedded in photos.
7. Data Retention
Operator account data and associated customer data are retained for the lifetime of the active subscription. After cancellation, data is retained for 90 days to allow for reactivation, after which it may be permanently deleted.
Customer order data (names, addresses, order history) is retained as part of the Operator's account and subject to the same retention policy. SMS message logs are retained for 30 days for delivery verification purposes.
8. Cookies & Local Storage
The Service uses essential cookies for Operator authentication (session management via NextAuth). We do not use advertising or tracking cookies. Customer ordering pages may use localStorage to remember returning customer information (name, phone, address) for convenience. This data is stored only on the customer's device and is not transmitted to our servers unless they place an order.
9. Your Rights
You may request access to, correction of, or deletion of your personal information at any time by contacting us at info@wymzy.ai.
Operators may delete their account through the Service settings or by contacting us. Account deletion will remove all associated data, including customer data, after the 90-day retention period. Customers may contact us to request deletion of their order data from a specific Operator's records.
10. Children's Privacy
The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will take steps to delete that information promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Effective date" at the top of this page. Your continued use of the Service after any changes constitutes your acceptance of the updated policy.
12. Contact
If you have any questions about this Privacy Policy, please contact us:
Wymzy Industries LLC
El Dorado, Arkansas
info@wymzy.ai