Legal
Privacy Policy
Last updated: 6 August 2026
Quay is operated by Quay Ops Ltd, a company registered in Scotland. This policy explains what personal data Quay handles, why, and what rights people have in relation to it.
Who we are
Quay Ops Ltd
Clyde Offices
48 West George Street
Glasgow G2 1BP
United Kingdom
Company number: SC893787
Contact: hello@joinquay.com
What Quay does
Quay is a business-to-business order management platform for food and drink wholesale suppliers. Suppliers connect their existing business phone number, WhatsApp Business number and email address to Quay. Customer orders arriving on those channels are captured into a single review queue, where the supplier reviews and approves them. Approved orders produce delivery run lists and invoice records.
Our role and our customers' role
Quay's customers are the suppliers who use the platform. Where Quay processes personal data about a supplier's own customers, their staff, drivers, contractors and other business contacts, the supplier determines why and how that data is used, and Quay acts on their instructions under a written agreement. In data protection terms, the supplier is the controller and Quay is the processor for that data.
Quay is the controller for data relating to its own account holders, for its own account administration, security and service audit records, and for platform data obtained from Meta under Quay's WhatsApp Business Platform integration.
Controller and processor roles are recorded for each processing activity rather than applied as a single label across the whole service.
What data we handle
For supplier account holders: name, email address, phone number, business details, and account activity records.
For messages sent to a supplier's connected channels: the message content, the sender's phone number or email address, attachments where sent, voice recordings and their transcriptions where an order is placed by phone, and the time the message was received.
For orders derived from those messages: customer identity, products, quantities, delivery addresses, delivery dates, delivery confirmations and invoice records.
For drivers carrying out deliveries for a supplier: the driver's name and mobile number, the copy of those details recorded against each dispatch, the dispatch instructions and message content sent to them, the replies they send back, whether a delivery has been reported, the times, provider message identifiers and delivery-status information for those messages, and any operator notes recorded against that communication. These details are provided to Quay by the supplier rather than collected from the driver directly.
Why we handle it
Message content is processed to extract order details — products, quantities, delivery dates and delivery instructions — and present them to the supplier for review and approval. Sender phone numbers and email addresses are used to identify which of the supplier's customers placed an order, and to send order confirmations and delivery updates back to that customer. Order records are used to produce delivery run lists and invoice records for the supplier.
Driver names and mobile numbers are used to assign deliveries, to send dispatch instructions to the driver, and to receive and record delivery reports. The dispatch record and the messages exchanged with the driver are retained to resolve delivery disputes and delivery failures, to maintain an operational audit history of what was sent and when, and to support invoicing.
Quay does not use this data for advertising. Quay does not sell it. Quay does not use it for any purpose other than delivering the service to the supplier.
Legal basis
Where Quay acts as processor, the supplier is responsible for the legal basis on which their customers' data is processed. Where Quay acts as controller, processing is based on the performance of a contract with the account holder, and on Quay's legitimate interests in operating and securing the platform.
Service providers
Quay uses the following service providers, which process data on Quay's behalf solely to deliver the service:
- Twilio Inc. — telephone calls, call recordings and voicemail, SMS and WhatsApp messages, including telephone numbers, message content and delivery metadata
- Postmark — inbound and outbound email, including sender and recipient details, message content and delivery metadata
- Vercel Inc. — application hosting
- Supabase Inc. — database and file storage
- Anthropic, PBC — processing of order message text to extract structured order details
- Microsoft Corporation (Azure) — speech-to-text transcription of voice orders
Quay integrates with Xero where a supplier authorises it, to create invoice records in the supplier's own accounting system. That integration transfers the supplier's own commercial records; it does not transfer message content.
International transfers
Some service providers process data outside the United Kingdom, and not all data handled by Quay is held in the United Kingdom.
Calls, recordings, voicemail, SMS and WhatsApp messages are carried by Twilio, whose default processing region is the United States. Message content, call recordings and the related call and delivery metadata are processed there, including before Quay stores its own copy. Email is carried by Postmark, whose infrastructure and message data are in the United States, where message content and delivery metadata are retained for a limited period under Postmark's own retention settings.
Where personal data is transferred outside the United Kingdom, transfers are made under the safeguards required by UK data protection law, including standard contractual clauses and the UK International Data Transfer Addendum where applicable.
How long we keep it
Message and order records are retained for as long as the supplier's account is active, and afterwards for as long as the supplier requires them for their own business and accounting records. Data is deleted on request in line with the process set out at joinquay.com/data-deletion.
Security
Data is encrypted in transit and at rest. Access is restricted to authenticated users. Each supplier's data is isolated so that no supplier can access another supplier's records. Access to production systems is limited to authorised personnel.
Rights
Individuals have rights under UK data protection law, including the right to access their personal data, to have inaccurate data corrected, to have data erased in certain circumstances, to restrict or object to processing, and to data portability.
Where Quay acts as processor for a supplier, requests are normally directed to that supplier, and Quay will assist them in responding. Where Quay is the controller, requests can be made to hello@joinquay.com.
Complaints can be made to the Information Commissioner's Office at ico.org.uk.
Requests from public authorities
Quay will disclose personal data to a public authority only where legally required to do so.
Changes to this policy
This policy may be updated. The date at the top of the page shows when it was last changed.