Legal

Privacy policy

Effective 28 June 2026

We take privacy seriously. This policy explains what personal information Food & Delight collects, why we collect it, who we share it with, and the choices you have. It applies to all parts of the Service — our marketing site, customer PWA, restaurant dashboard, kitchen and server views, rider app, platform admin, and related APIs.

1. Introduction

Food & Delight (“we,” “us”) is the controller of the personal information described in this policy. We’re based in Accra, Ghana, with operations in Lagos, Nigeria, and we’re responsible for how your information is handled within the Service. Our wallet-service partners (Paystack in Ghana, Monnify in Nigeria) act as joint controllers for payment data they process directly.

This policy is written to comply with Ghana’s Data Protection Act 2012 (Act 843), Nigeria’s Nigeria Data Protection Act 2023, and equivalent standards in markets we expand into. Where local law gives you stronger rights, those rights apply.

2. Who this covers

This policy applies to:

  • Customers who scan a QR, browse a menu, place an order, or top up a wallet;
  • Restaurant operators and staff who manage menus, tables, orders, and finance from the dashboard;
  • Riders who accept and complete deliveries;
  • Visitors to our marketing site and anyone who contacts us for support or sales;
  • Platform administrators with elevated access to operational tools.

3. Data we collect

The information we collect depends on which part of the Service you use. Below is the complete list across roles.

Identity & contact

  • Name, phone number, email address, and, where you choose to set one, a nickname and avatar image.
  • A short public identifier we generate for friend-discovery features.

Restaurant & rider details

  • Business name, slug, country, address, logo, cuisine type, and operating hours.
  • Staff invitations (the email or phone of the person being invited) and their role on the team.
  • For Riders: vehicle type, licence number, and any KYC documents you upload during verification.

Order & payment

  • Items ordered, modifier choices, special instructions, tip amount, takeout / delivery selection, table or seat reference, and any promo applied.
  • Payment method type (wallet, MoMo, card, bank transfer), the last four digits of saved cards, the card brand, and a token issued by our payment partner. We do not store full card numbers, CVV codes, or expiry dates.
  • Wallet ledger entries, balances, deposit / withdrawal / transfer history, and the reference codes our payment partners assign to each transaction.

Location

  • For dine-in: the restaurant, table, and seat you scanned — derived from the QR code, not GPS.
  • For deliveries: the delivery address you enter, and approximate real-time location for Riders while they have an active delivery (used for dispatch, tracking, and rider safety).

Device & usage

  • Device type, operating system, browser, IP address, language preference, and timezone.
  • App version, feature flags assigned to your account, and high-level interaction events (which screens you opened, which buttons you tapped) used for product analytics.
  • Crash and error reports, with personal identifiers stripped where possible.

Communications

  • Messages you send to support, contact-form submissions, and the content of any SMS or email receipts we send you.
  • Push-notification device tokens you provide so we can send real-time order, delivery, and wallet notifications.

4. How we collect it

We collect information in three ways:

  • You provide it. When you register, place an order, top up a wallet, set up a restaurant, accept a delivery, or contact us.
  • Automatically. When you use the Service, we collect device, usage, and error data via cookies and similar technologies on the web, and via SDKs in our PWAs.
  • From third parties. Our payment partners (Paystack, Monnify) confirm transaction outcomes back to us via webhooks. Google OAuth (when you sign in with Google) shares your name and email with us. SMS and email providers (Termii, Resend) confirm delivery of one-time codes and notifications.

5. How we use it

We use personal information to:

  • Operate the Service — accept orders, take payments, route deliveries, run kitchens, settle payouts, display menus, and surface promotions.
  • Communicate — send order receipts, delivery updates, wallet alerts, one-time login codes, and important account notices.
  • Personalise — show your favourites, remember recently visited restaurants, suggest the right currency at checkout.
  • Prevent fraud and abuse — detect unusual account activity, block suspicious payments, enforce transaction limits, and protect Restaurants and Riders from chargebacks.
  • Improve the Service — debug crashes, prioritise features based on real-world usage, and measure performance.
  • Meet legal obligations — keep tax, accounting, and anti-money laundering records as required by Ghanaian, Nigerian, and other applicable law.

We don’t sell your personal information, and we don’t use it for advertising on third-party platforms.

6. Legal bases

Where required by law, we rely on one of these bases for each use of your information:

  • Contract — to provide the Service you signed up for (order placement, wallet funding, delivery dispatch).
  • Legitimate interests — to keep the platform safe, prevent fraud, debug errors, and improve features. We balance our interests against your rights before relying on this basis.
  • Consent — for optional things like marketing emails or push notifications. You can withdraw consent at any time without affecting the lawfulness of prior processing.
  • Legal obligation — to keep records that financial-services and tax laws require us to maintain.

7. Who we share with

We share personal information only as needed to run the Service or comply with the law. Specifically:

  • Restaurants see the order details and contact information needed to fulfil what you ordered (your name, the items, allergens, table or delivery address).
  • Riders see the pickup restaurant, the customer’s first name, the delivery address, and a masked phone number for the duration of the delivery.
  • Customers see the Restaurant’s public menu, hours, location, and assigned Rider’s first name and location for an active delivery.
  • Payment partners (Paystack, Monnify) receive the data they need to process transactions and meet anti-money-laundering rules.
  • Infrastructure providers (Google Cloud for storage, Termii for SMS, Resend for email, similar) process data on our behalf under written agreements that restrict them to instructions from us.
  • Authorities when we’re legally required to disclose, such as in response to a valid court order or to comply with tax or AML laws.
  • Acquirers in the event of a corporate reorganisation, merger, or sale, with notice to you as required by law.

8. International transfers

We’re based in Ghana and Nigeria, but some of the infrastructure we rely on (cloud storage, email delivery, analytics) is hosted outside West Africa. When personal information is transferred internationally, we rely on contractual safeguards with the recipient and, where required, on country-level adequacy mechanisms recognised by our regulator. You can ask us for a list of the countries involved and the safeguards in place.

9. How long we keep it

We keep personal information only as long as needed for the purposes it was collected for:

  • Account information for as long as the account is active, then up to 7 years after closure to meet tax and accounting requirements.
  • Order and wallet records for at least 7 years, because they’re financial records under Ghanaian and Nigerian law.
  • Marketing preferences until you change them or close your account.
  • Support messages for up to 3 years after the conversation closes.
  • Device, crash, and usage logs for up to 12 months, then aggregated or deleted.

When we no longer need information, we delete it or irreversibly anonymise it.

10. Your rights

Subject to local law, you have the right to:

  • Access a copy of the personal information we hold about you.
  • Rectify inaccurate or incomplete information (most of which you can edit directly in your profile).
  • Erase your information, subject to our legal obligation to retain financial records for the periods above.
  • Restrict certain processing while a dispute is being resolved.
  • Object to processing based on our legitimate interests.
  • Withdraw consent for any optional processing without affecting prior lawfulness.
  • Port a copy of the data you provided to us, in a portable machine-readable format.
  • Complain to your local data-protection regulator — the Data Protection Commission in Ghana, the Nigeria Data Protection Commission in Nigeria.

To exercise these rights, email privacy@fooddelight.tech. We’ll respond within 30 days and may need to verify your identity before acting on the request.

11. Security

We protect your information with industry-standard controls: TLS 1.3 for data in transit, encryption at rest for sensitive fields, hashed passwords and wallet PINs, HttpOnly cookies for refresh tokens, role-based access controls, audit logging on financial and administrative actions, and progressive lockouts against PIN-guessing.

No system is perfectly secure. If we discover a personal-data breach that’s likely to affect you, we’ll notify you and the relevant regulator without undue delay, as required by law.

12. Cookies & device IDs

We use a small set of cookies and similar technologies:

  • Strictly necessary — to authenticate you, keep you signed in, and remember your cart. These don’t require consent.
  • Preferences — to remember theme choice, language, and recent restaurants. These improve the experience but aren’t required.
  • Analytics — to understand which features are used and where the Service slows down. We use first-party analytics with IP truncation; we don’t share device-level data with third-party ad networks.

You can clear cookies in your browser at any time. Some functionality (staying signed in, keeping a cart) depends on them.

13. Marketing & messages

Transactional messages — order receipts, delivery updates, wallet alerts, one-time codes — are part of the Service and can’t be disabled while your account is active. You can choose how you receive them (SMS, email, push) in your notification preferences.

Marketing messages (new features, restaurant offers, newsletters) are opt-in only. Every marketing email includes an unsubscribe link, and every SMS can be stopped by replying STOP.

14. Children

The Service isn’t designed for children. You must be at least 18 to place an order, register a restaurant, or act as a rider. We don’t knowingly collect information from anyone under 18. If you think a child has provided us with information, contact us and we’ll delete it.

15. Changes to this policy

We may update this policy from time to time as the Service evolves. When we make material changes, we’ll post a notice and update the effective date at the top. For meaningful changes we’ll also email account holders directly.

16. Contact us

For privacy questions, data-rights requests, or to reach our Data Protection Officer, email privacy@fooddelight.tech or write to us via the contact page.