Jari — Privacy Policy
Jari (자리; package io.pinekey.jari) is a store waitlist service: scan a
store's QR code to join its queue and watch your place in line. Store owners use the app
to manage their queue. Jari is designed to collect as little personal data as possible.
TL;DR
- You join a store's queue by scanning a QR code — no sign-up required. You're identified by an anonymous device ID (guest).
- We collect your party size and a nickname for the queue, plus a push token to notify you when it's your turn.
- The camera is used only to scan QR codes, on your device — no photo is taken, stored, or uploaded.
- We show no ads and do not track you across apps.
- Your data is stored on our own server in South Korea (Seoul).
01 Who we are
Jari is built and operated by Pinekey, an independent mobile app studio, and is the data controller for the information described here. For any privacy question or request, contact pinekey.dev@gmail.com.
02 Information we collect
- Anonymous guest identity. A device identifier (Android ID on Android, identifierForVendor on iOS) is sent to create an anonymous "guest" account. On our server it is stored only as a one-way hashed value — no name, email, or phone number is required to join a queue.
- Queue information. When you join a queue, your party size and a nickname are collected. The nickname and party size are shown to the store and to other waiting customers in that queue.
- Notifications. A push token (Firebase Cloud Messaging) so we can alert you when your turn is near.
- Optional account. If you choose to create an account with email or Google/Apple sign-in, we collect your email and a nickname. (The apps use anonymous guest mode by default.)
- Store owners. A login ID, a password (stored hashed), and the store name (business information).
What we do not collect
Jari does not collect your location/GPS, contacts, photos, or microphone. The camera is used solely to decode QR codes on your device; camera images are never stored or uploaded.
03 How your data is stored
- Your queue and account data are stored in our PostgreSQL database on a server we operate on Amazon Web Services (AWS) in South Korea (Seoul region). Device identifiers are stored only as one-way hashes; passwords as hashes.
- Data is transmitted over encrypted HTTPS (jari-api.pinekey.io).
- On your device, your session tokens are stored locally.
Retention and deletion
Because the app uses an anonymous guest identity, uninstalling the app removes your local identity from your device. To delete your server-side queue history or account data, email pinekey.dev@gmail.com and we will remove it.
04 Third parties
Jari relies on the following third-party services. There are no advertising networks, and we do not sell your data.
| Service | Purpose | Data involved |
|---|---|---|
| Firebase Cloud Messaging | "Your turn" push notifications (Android app) | FCM device token |
| Firebase Analytics / Crashlytics | Usage analytics and crash diagnostics (Android app) | App events, crash logs, device info |
| Google ML Kit (on-device) | QR-code decoding | None — processed on your device |
| Google / Apple Sign-In | Optional login | Email (only if you sign up) |
| Google Play / App Store Billing | In-app purchases (not yet active) | Purchase receipts, when enabled |
| Amazon Web Services | Hosting — our server (Seoul) | All queue and account data |
These services process data under their own privacy policies (for example, Google's and Apple's).
05 Children's privacy
Jari is a general-audience utility for joining store queues and is not directed to children. We do not collect a birth date and do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
06 Changes to this policy
Jari is a new service, and this policy may change as the app is launched and evolves. Updates will be reflected on this page with a new "Last updated" date.
07 Contact
Questions or requests, including data deletion: pinekey.dev@gmail.com.