PENNY · LEGAL
Privacy Policy
Effective Date: September 27, 2026
This Privacy Policy explains how Penny collects, uses, discloses, and protects personal information when businesses use Penny and when individuals interact with Penny-powered phone, SMS, reservation, ordering, or customer-service experiences.
This Privacy Policy (the “Policy”) applies to Penny websites, software, dashboards, voice agents, messaging features, integrations, and related services (collectively, the “Services”). Penny is operated by Incyte Works LLC. In this Policy, “Penny,” “we,” “us,” and “our” refer to Incyte Works LLC and the Penny Services it operates. “Business Customer” means a restaurant, food business, or other organization that uses Penny. “End User” means a caller, texter, diner, customer, or other individual who interacts with a Business Customer through the Services.
This Policy does not replace the privacy policy of a Business Customer. When Penny processes End User information on behalf of a Business Customer, the Business Customer may be responsible for providing additional privacy notices and honoring privacy rights under applicable law.
1. Information We Collect
The information we collect depends on how the Services are used and which features are enabled by a Business Customer.
A. Information from Business Customers
- Account and contact information, such as name, business name, business address, email address, phone number, role, and login credentials or authentication information.
- Business configuration information, such as locations, hours, menus, products, pricing, reservation rules, pickup instructions, staff routing preferences, FAQs, and agent settings.
- Integration information, including identifiers, access credentials, API tokens, permissions, or configuration data needed to connect approved point-of-sale, reservation, messaging, telephony, analytics, or other business systems. Where feasible, sensitive credentials are stored or handled using security controls appropriate to their purpose.
- Billing and transaction information related to the Business Customer relationship. Payment card information may be processed directly by a third-party payment processor rather than stored by Penny.
- Support and communications data, including messages, feedback, troubleshooting information, and other content a Business Customer provides to us.
B. Information from End Users
- Contact and identity information, such as caller ID, phone number, name, and other information voluntarily provided during a call or message exchange.
- Conversation content, including call metadata, transcripts, SMS or other message content, and information contained in those interactions, if the relevant feature is enabled. Voice audio may be processed in real time by telephony or speech-processing providers. Penny currently stores text transcripts of calls and does not store call audio recordings.
- Order and reservation information, such as items requested, pickup details, party size, reservation date and time, special instructions, dietary preferences or allergen-related requests, and order or reservation status.
- Customer-service information, including questions, complaints, requests, preferences, or other information submitted during an interaction.
- Payment-related status or limited transaction information received from an integrated payment, POS, or ordering provider. Penny should not be used to collect sensitive payment authentication data unless an authorized payment flow specifically supports it.
C. Information Collected Automatically
- Device and usage information, such as IP address, browser type, device type, operating system, referring page, pages or features used, dates and times of access, and diagnostic logs.
- Telephony and messaging metadata, such as call duration, routing information, delivery status, timestamps, and technical identifiers associated with communications.
- Cookies and similar technologies used for essential functionality, security, analytics, and service performance, where applicable.
D. Information from Third-Party Integrations
If a Business Customer connects Penny to a third-party service, Penny may receive information from that service as authorized by the Business Customer and subject to the third party's terms and privacy practices. Examples may include point-of-sale systems, reservation platforms, telephony providers, messaging providers, payment processors, business-management systems, and analytics tools.
2. How We Use Information
We use personal information for purposes that include:
- Providing, operating, maintaining, and improving the Services.
- Answering calls and messages, routing communications, and supporting customer-service interactions.
- Creating, updating, or transmitting orders, reservations, pickup requests, and related service information.
- Personalizing responses based on the Business Customer's approved business information and the context of an End User interaction.
- Connecting the Services to approved third-party platforms and synchronizing information between systems.
- Authenticating users, protecting accounts, preventing abuse, detecting fraud, and maintaining the security and reliability of the Services.
- Monitoring performance, debugging issues, conducting analytics, and understanding how the Services are used.
- Communicating with Business Customers about the Services, including operational notices, support, product updates, and billing or administrative matters.
- Complying with legal obligations, responding to lawful requests, enforcing agreements, and protecting the rights, safety, and property of Penny, Business Customers, End Users, and others.
3. AI-Powered Interactions and Automated Processing
Penny uses artificial intelligence and automated systems to interpret voice or text, identify intent, retrieve approved business information, generate responses, and complete supported actions such as creating an order or reservation request. AI-generated responses may be incorrect, incomplete, or misunderstood. Business Customers should configure appropriate escalation, confirmation, and human-review processes for higher-risk or sensitive interactions.
To provide AI functionality, conversation content and related context may be processed by cloud infrastructure, speech-processing providers, model providers, or other service providers acting on Penny's behalf. Penny seeks to limit the information shared with providers to what is reasonably necessary to deliver the relevant feature and to use providers under contractual or technical restrictions appropriate to their role.
Penny does not use End User call, SMS, order, or reservation content for unrelated cross-context behavioral advertising. If Penny materially changes how such content is used, this Policy will be updated as required by applicable law.
4. Call Recording, Transcription, and Messaging
Penny currently stores a text transcript of each voice call and does not store an audio recording of the call. Call audio may transit or be processed by telephony and speech-processing providers as necessary to provide the Service. If Penny introduces stored call recording as a feature, this Policy will be updated to describe that practice and the applicable retention terms.
Recording, transcription, notice, consent, telecommunications, and messaging requirements vary by jurisdiction. Business Customers are responsible for configuring and using the Services in a manner consistent with applicable law, and Penny may provide technical features or notices to support those obligations.
5. SMS, 2FA, and Mobile Information
For Business Customer administrative users, Penny may use SMS as an alternate or supplementary channel to deliver a six-digit sign-in code to a phone number registered on the user's Account. By registering a phone number for this purpose, the administrative user consents to receive these transactional authentication messages.
End Customer SMS or WhatsApp messaging may be enabled for certain Business Customers in the future. Before such messaging is enabled, Penny and the Business Customer will use consent and opt-out flows appropriate to the message type and applicable law. Transactional consent and marketing consent will be handled separately where required.
Where SMS is enabled, message and data rates may apply. We may retain delivery status and related metadata. We do not sell personal information for monetary consideration, and we do not use End User call, SMS, order, or reservation data for third-party cross-context behavioral advertising.
SMS opt-in data, mobile numbers, and SMS consent information are not sold or shared with third parties or affiliates for their marketing or promotional purposes. We may disclose mobile information to telecommunications providers, messaging aggregators, and other service providers solely as necessary to deliver, secure, support, or operate the messaging service, or as required by law.
6. How We Disclose Information
We may disclose personal information in the following circumstances:
- To Business Customers. End User information may be made available to the Business Customer with whom the End User is interacting, including staff members and systems authorized by that Business Customer.
- To service providers. We may use vendors that provide hosting, telecommunications, messaging, AI or speech processing, analytics, authentication, payment processing, monitoring, customer support, and other services. These providers may process information for us subject to contractual or legal restrictions.
- To integrated third parties. At a Business Customer's direction, we may transmit information to or receive information from connected point-of-sale, reservation, ordering, payment, CRM, or other systems.
- For legal and safety reasons. We may disclose information if we reasonably believe disclosure is required by law, legal process, regulation, or a valid government request, or is necessary to protect rights, prevent fraud or abuse, investigate security incidents, or protect personal safety.
- In a business transaction. Information may be transferred as part of a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar corporate transaction, subject to applicable legal requirements.
- With consent or direction. We may disclose information when a Business Customer or End User directs us to do so or provides valid consent.
Penny does not sell personal information for monetary consideration. Penny also does not use End User call, SMS, order, or reservation data for third-party cross-context behavioral advertising.
7. Penny's Role When Processing Data for Business Customers
For information Penny processes on behalf of a Business Customer, the Business Customer generally determines why and how the information is used, while Penny processes the information to provide the Services and follow the Business Customer's documented instructions, subject to applicable law and Penny's agreements. Depending on the jurisdiction, the Business Customer may be the controller, business, or similar regulated entity, and Penny may be a processor, service provider, contractor, or similar service provider.
If an End User wants to exercise a privacy right relating to information collected through a specific restaurant or Business Customer, the End User may need to contact that Business Customer directly. Penny may assist Business Customers in responding to verified requests where required or appropriate.
8. Data Retention
We retain personal information for as long as reasonably necessary to provide the Services, maintain business and security records, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods may vary based on the type of information, Business Customer settings, contractual requirements, legal requirements, security needs, and whether the information is stored in an integrated third-party system.
Business Customers may have configurable retention options for certain types of data. Deleting information from Penny does not necessarily delete copies maintained by a Business Customer or by an independent third-party service integrated with the Services.
9. Data Security
We use administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure. These measures may include access controls, authentication, encryption in transit, logging, monitoring, credential-management practices, and vendor-security controls, as appropriate to the nature of the data and the Services.
No method of transmission or storage is completely secure. We therefore cannot guarantee absolute security. Business Customers are also responsible for protecting their accounts, devices, integration credentials, and administrative access.
10. Privacy Rights and Choices
Depending on where an individual lives and which privacy law applies, an individual may have rights such as the right to request access to personal information, obtain a copy, correct inaccurate information, request deletion, restrict or object to certain processing, or opt out of certain forms of sale, sharing, targeted advertising, or profiling. Some rights are subject to exceptions and verification requirements.
Penny does not sell personal information for monetary consideration and does not use End User call, SMS, order, or reservation data for third-party cross-context behavioral advertising. Where applicable law requires recognition of browser-based opt-out preference signals, such as Global Privacy Control, Penny will process supported signals as required for the relevant website or service context.
A Business Customer account holder may contact Penny using the information in Section 17. An End User whose request relates to a specific Business Customer should generally contact that Business Customer first. Penny may direct or forward the request to the appropriate Business Customer when Penny is acting on that customer's behalf.
11. California and Other U.S. State Privacy Disclosures
Certain U.S. state privacy laws require additional disclosures regarding categories of personal information. Depending on how the Services are used, Penny may collect identifiers; customer records information; commercial information; internet or electronic network activity; audio, electronic, or similar information; approximate location inferred from technical data; professional or employment-related information for Business Customer contacts; and inferences generated from interaction context. Penny uses and discloses these categories for the purposes described in this Policy.
Penny does not knowingly use or disclose sensitive personal information for purposes that require a right to limit under applicable U.S. state privacy laws, except as necessary to provide the requested Services, maintain security, comply with law, or as otherwise permitted by applicable law. End Users should avoid providing highly sensitive information that is not necessary for an order, reservation, or customer-service request.
12. Cookies and Analytics
Penny websites and dashboards may use cookies, local storage, pixels, logs, or similar technologies for authentication, security, preferences, performance, and analytics. Some technologies are necessary for the Services to function. Where required by law, Penny will provide choices regarding non-essential cookies or similar technologies.
Third-party sites or services reached through links or integrations may use their own cookies and tracking technologies. Their practices are governed by their own privacy policies.
13. Children's Privacy
The Services are designed for businesses and general restaurant customer-service interactions and are not directed to children under 13. Penny does not knowingly collect personal information directly from children under 13 for the purpose of creating a Penny account. If we learn that personal information has been collected from a child in a manner prohibited by applicable law, we will take reasonable steps to delete or otherwise address the information.
14. International Data Transfers
Penny and its service providers may process information in the United States and other countries where they operate. Those countries may have data-protection laws that differ from the laws where an individual lives. Where required, Penny will use appropriate safeguards for cross-border transfers of personal information.
15. Third-Party Services
The Services may link to or integrate with third-party platforms. Penny does not control the independent privacy practices of third parties when they determine their own purposes and means of processing. Business Customers and End Users should review the privacy policies of applicable third-party services, including point-of-sale, reservation, ordering, payment, telephony, messaging, and other providers.
16. Changes to This Privacy Policy
We may update this Policy from time to time to reflect changes in the Services, technology, legal requirements, or our privacy practices. When we make changes, we will update the effective date above and provide additional notice when required by applicable law. Continued use of the Services after an updated Policy becomes effective is subject to the updated Policy, to the extent permitted by law.
17. Contact Us
Questions, privacy requests, or concerns regarding this Policy may be submitted to Incyte Works LLC at or through the contact information made available on the Penny website at pennyspeaking.com.
If your request concerns information collected through a particular restaurant or other Business Customer, please identify that business so the request can be routed appropriately. Incyte Works LLC, through Penny, may need to verify your identity or authority before completing certain requests.