← Back to Daqiq

Privacy Policy

Last updated 20 September 2026

Daqiq is built on one idea: your data is yours. We do not browse it, mine it, sell it, or use it to train anything. This page describes exactly what we hold, where it sits, and who can reach it — in plain terms rather than boilerplate.

Who we are

Daqiq is an analytics platform for restaurants and cafés, operated from the United Arab Emirates. You can reach us at privacy@daqiq.me for any question about this policy, or to ask for a copy or deletion of your data.

What we collect

Account information

Business data you connect

This is the data you deliberately bring in — a CSV you upload, or the columns you map from a Google Sheet. It is whatever you choose to connect and nothing else. We keep a version history of it so you can ask what a figure looked like on a past date.

Usage analytics

Our public marketing site uses PostHog to count visits and understand which pages are read. Product analytics are not linked to the contents of your business data.

Google account data

If you connect Google Sheets, Daqiq requests a single OAuth scope: drive.file.

This scope is deliberately the narrowest one that does the job. It grants access only to the specific files you pick in Google's own file picker. Daqiq cannot list, search, open, or even detect the existence of any other file in your Drive. Choosing a file in the picker is the act of granting access; nothing is shared before that, and nothing beyond it.

From a file you have picked, we read:

We store the resulting values in your organisation's own database schema, along with an OAuth token so scheduled syncs can run without you signing in again. Tokens are encrypted at rest. You can revoke access at any time by disconnecting the sheet in Daqiq, or from your Google account permissions page; disconnecting deletes the stored token.

Limited Use. Daqiq's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use Google user data for advertising, we do not sell it, and we do not use it to train generalised AI or machine-learning models.

How your data is isolated

Every organisation's business data lives in its own separate database schema rather than in shared tables with a customer column. Queries are executed under a database role that can read only that organisation's schema and cannot write anything. This is enforced by the database itself, not by application code that could be talked around.

Stored credentials are held back from that role at the column level, so the query layer — including anything the AI generates — cannot read them even in encrypted form.

The AI, specifically

Daqiq lets you ask questions in plain language through an AI assistant, which writes read-only SQL against your schema to build a dashboard. Three things are worth being explicit about:

Where your data is held

Application data is stored with Supabase (PostgreSQL) in the ap-south-1 region, and the service runs on Railway. Being candid about this: although Daqiq is operated from the UAE, the database itself is currently hosted in India. If your organisation has a data-residency requirement, please talk to us before connecting anything.

Who we share data with

We do not sell data. We use these providers to run the service:

ProviderPurpose
SupabaseDatabase hosting
RailwayApplication hosting
AnthropicThe AI that builds dashboards on request
GoogleSheets access, only for files you pick
PostHogMarketing-site analytics

We will also disclose data where we are legally required to. If that ever happens and we are permitted to tell you, we will.

Support access

We think you should know this rather than discover it. Daqiq currently has an internal administrator capability that can reach customer data for support and debugging. We are moving this behind an explicit, per-customer grant with an audit trail you can inspect. Until that ships, access is restricted to the people who operate the service and is used only to investigate a problem you have reported.

How long we keep things

Your rights

You can ask us to give you a copy of your data, correct it, or delete it. Email privacy@daqiq.me and we will respond within 30 days. You can disconnect any data source yourself at any time from the Connectors page, without asking us.

Security

No system is perfectly secure. If you believe you have found a vulnerability in Daqiq, please write to security@daqiq.me — we would much rather hear it from you.

Children

Daqiq is a business tool and is not directed at anyone under 18.

Changes to this policy

If we change this policy in a way that affects how your data is handled, we will update the date at the top and tell account holders by email before it takes effect.