Lunch Room · Legal
Privacy Policy
Last updated October 1, 2026
Lunch Room is made by ZET Studios in British Columbia, Canada. It gives companies a live waitlist room on their own website. This policy covers two groups: the companies that run rooms, and the people who join a waitlist (“members”). For members, the company running the room decides why your information is collected; we store and process it on their behalf. For company accounts, we are responsible.
What we collect from members
- Your email address, and a display name if you give one.
- Your place in line, who referred you, and who you referred.
- What you do in the room: chat messages, poll votes, reports, and game scores. Scoreboards show a number (“Player 12”), never your name.
- Your approximate country, worked out from your IP address when you join, and your browser's time zone. We don't store your IP address itself; we keep a scrambled version to stop abuse.
- Whether you're in the room right now, so it can show how many people are here.
What we collect from companies
- Account email addresses, your organisation's name, and your team members.
- Everything you set up: room settings, posts, polls, links, and the AI agent's instructions.
- Billing details: your plan and Stripe customer and subscription IDs. Card details go straight to Stripe; we never see or store them.
- API keys and signing secrets you give us for the AI agent, encrypted before they're stored.
How we use it
- To run the room: show your place in line, chat, polls, games and updates.
- To send the emails you need: confirming your address and signing you in. Other emails, like updates from the company, only go out if you've opted in, and each one has a one-click unsubscribe.
- To keep rooms safe: moderating messages and preventing spam and abuse.
- To bill companies and provide support.
- To fix problems: when something breaks, we record the error and the page it happened on. These records don't include your name, email or IP address.
- To see how our own website is doing: we count visits to our homepage and sign-up pages. We use no cookies for this and don't store your IP address; each visit is recorded as a scrambled code that changes every day, along with the site that sent you to us.
We don't sell personal information, and we don't use it for advertising.
Who sees it and who we share it with
The company running a room can see its members' email addresses, names, place in line, country, messages and activity, and can download its waitlist. Other members see only what's shown in the room.
We use these service providers to run Lunch Room:
- Supabase — database and sign-in (United States)
- Fly.io — hosting (United States)
- Resend — sending email
- Cloudflare — domain name and email routing
- Stripe — payments. For some purchases, Stripe's Link acts as the seller, and its terms also apply.
- GitHub — storing encrypted database backups
If a company turns on an AI agent in its room, recent chat messages and display names from that room are sent to the AI service the company chose (for example Anthropic, OpenAI or Google) or to the company's own system, so the agent can reply. Email addresses are never sent. Replies are labelled “AI”.
We may disclose information if the law requires it.
Cookies
We use cookies and similar browser storage only to keep you signed in and to remember your settings, such as a minimised room window. There are no advertising cookies.
Where it's stored and for how long
Data is stored in the United States. We keep it for as long as the room or account exists. When something is deleted, it disappears from our backups within 30 days.
Your choices
- In any room, open your profile to leave the waitlist or delete your data.
- Use the unsubscribe link in any optional email.
- Ask the company running the room, or email us at hello@zetstudios.ca, to see, correct, export or delete your information. We'll reply within 30 days.
If you're in Canada and not satisfied with our answer, you can contact the Office of the Privacy Commissioner of Canada. If you're elsewhere, you may have similar rights under your local law.
Security
Connections are encrypted. API keys and secrets are encrypted before storage, IP addresses are only kept scrambled, and backups are encrypted with a key that isn't stored alongside them. No system is perfectly secure; if a breach affects you, we'll tell you.
Children
Lunch Room isn't meant for children under 13, and we don't knowingly collect their information.
Changes and contact
If we change this policy in a way that matters, we'll update the date above and tell companies by email. Questions: hello@zetstudios.ca.