1. Introduction
Food & Delight (“we,” “us”) is the controller of the personal information described in this policy. We’re based in Accra, Ghana, with operations in Lagos, Nigeria, and we’re responsible for how your information is handled within the Service. Our wallet-service partners (Paystack in Ghana, Monnify in Nigeria) act as joint controllers for payment data they process directly.
This policy is written to comply with Ghana’s Data Protection Act 2012 (Act 843), Nigeria’s Nigeria Data Protection Act 2023, and equivalent standards in markets we expand into. Where local law gives you stronger rights, those rights apply.
2. Who this covers
This policy applies to:
- Customers who scan a QR, browse a menu, place an order, or top up a wallet;
- Restaurant operators and staff who manage menus, tables, orders, and finance from the dashboard;
- Riders who accept and complete deliveries;
- Visitors to our marketing site and anyone who contacts us for support or sales;
- Platform administrators with elevated access to operational tools.
3. Data we collect
The information we collect depends on which part of the Service you use. Below is the complete list across roles.
Identity & contact
- Name, phone number, email address, and, where you choose to set one, a nickname and avatar image.
- A short public identifier we generate for friend-discovery features.
Restaurant & rider details
- Business name, slug, country, address, logo, cuisine type, and operating hours.
- Staff invitations (the email or phone of the person being invited) and their role on the team.
- For Riders: vehicle type, licence number, and any KYC documents you upload during verification.
Order & payment
- Items ordered, modifier choices, special instructions, tip amount, takeout / delivery selection, table or seat reference, and any promo applied.
- Payment method type (wallet, MoMo, card, bank transfer), the last four digits of saved cards, the card brand, and a token issued by our payment partner. We do not store full card numbers, CVV codes, or expiry dates.
- Wallet ledger entries, balances, deposit / withdrawal / transfer history, and the reference codes our payment partners assign to each transaction.
Location
- For dine-in: the restaurant, table, and seat you scanned — derived from the QR code, not GPS.
- For deliveries: the delivery address you enter, and approximate real-time location for Riders while they have an active delivery (used for dispatch, tracking, and rider safety).
Device & usage
- Device type, operating system, browser, IP address, language preference, and timezone.
- App version, feature flags assigned to your account, and high-level interaction events (which screens you opened, which buttons you tapped) used for product analytics.
- Crash and error reports, with personal identifiers stripped where possible.
Communications
- Messages you send to support, contact-form submissions, and the content of any SMS or email receipts we send you.
- Push-notification device tokens you provide so we can send real-time order, delivery, and wallet notifications.
4. How we collect it
We collect information in three ways:
- You provide it. When you register, place an order, top up a wallet, set up a restaurant, accept a delivery, or contact us.
- Automatically. When you use the Service, we collect device, usage, and error data via cookies and similar technologies on the web, and via SDKs in our PWAs.
- From third parties. Our payment partners (Paystack, Monnify) confirm transaction outcomes back to us via webhooks. Google OAuth (when you sign in with Google) shares your name and email with us. SMS and email providers (Termii, Resend) confirm delivery of one-time codes and notifications.
5. How we use it
We use personal information to:
- Operate the Service — accept orders, take payments, route deliveries, run kitchens, settle payouts, display menus, and surface promotions.
- Communicate — send order receipts, delivery updates, wallet alerts, one-time login codes, and important account notices.
- Personalise — show your favourites, remember recently visited restaurants, suggest the right currency at checkout.
- Prevent fraud and abuse — detect unusual account activity, block suspicious payments, enforce transaction limits, and protect Restaurants and Riders from chargebacks.
- Improve the Service — debug crashes, prioritise features based on real-world usage, and measure performance.
- Meet legal obligations — keep tax, accounting, and anti-money laundering records as required by Ghanaian, Nigerian, and other applicable law.
We don’t sell your personal information, and we don’t use it for advertising on third-party platforms.
6. Legal bases
Where required by law, we rely on one of these bases for each use of your information:
- Contract — to provide the Service you signed up for (order placement, wallet funding, delivery dispatch).
- Legitimate interests — to keep the platform safe, prevent fraud, debug errors, and improve features. We balance our interests against your rights before relying on this basis.
- Consent — for optional things like marketing emails or push notifications. You can withdraw consent at any time without affecting the lawfulness of prior processing.
- Legal obligation — to keep records that financial-services and tax laws require us to maintain.
8. International transfers
We’re based in Ghana and Nigeria, but some of the infrastructure we rely on (cloud storage, email delivery, analytics) is hosted outside West Africa. When personal information is transferred internationally, we rely on contractual safeguards with the recipient and, where required, on country-level adequacy mechanisms recognised by our regulator. You can ask us for a list of the countries involved and the safeguards in place.
9. How long we keep it
We keep personal information only as long as needed for the purposes it was collected for:
- Account information for as long as the account is active, then up to 7 years after closure to meet tax and accounting requirements.
- Order and wallet records for at least 7 years, because they’re financial records under Ghanaian and Nigerian law.
- Marketing preferences until you change them or close your account.
- Support messages for up to 3 years after the conversation closes.
- Device, crash, and usage logs for up to 12 months, then aggregated or deleted.
When we no longer need information, we delete it or irreversibly anonymise it.
10. Your rights
Subject to local law, you have the right to:
- Access a copy of the personal information we hold about you.
- Rectify inaccurate or incomplete information (most of which you can edit directly in your profile).
- Erase your information, subject to our legal obligation to retain financial records for the periods above.
- Restrict certain processing while a dispute is being resolved.
- Object to processing based on our legitimate interests.
- Withdraw consent for any optional processing without affecting prior lawfulness.
- Port a copy of the data you provided to us, in a portable machine-readable format.
- Complain to your local data-protection regulator — the Data Protection Commission in Ghana, the Nigeria Data Protection Commission in Nigeria.
To exercise these rights, email privacy@fooddelight.tech. We’ll respond within 30 days and may need to verify your identity before acting on the request.
11. Security
We protect your information with industry-standard controls: TLS 1.3 for data in transit, encryption at rest for sensitive fields, hashed passwords and wallet PINs, HttpOnly cookies for refresh tokens, role-based access controls, audit logging on financial and administrative actions, and progressive lockouts against PIN-guessing.
No system is perfectly secure. If we discover a personal-data breach that’s likely to affect you, we’ll notify you and the relevant regulator without undue delay, as required by law.
13. Marketing & messages
Transactional messages — order receipts, delivery updates, wallet alerts, one-time codes — are part of the Service and can’t be disabled while your account is active. You can choose how you receive them (SMS, email, push) in your notification preferences.
Marketing messages (new features, restaurant offers, newsletters) are opt-in only. Every marketing email includes an unsubscribe link, and every SMS can be stopped by replying STOP.
14. Children
The Service isn’t designed for children. You must be at least 18 to place an order, register a restaurant, or act as a rider. We don’t knowingly collect information from anyone under 18. If you think a child has provided us with information, contact us and we’ll delete it.
15. Changes to this policy
We may update this policy from time to time as the Service evolves. When we make material changes, we’ll post a notice and update the effective date at the top. For meaningful changes we’ll also email account holders directly.
16. Contact us
For privacy questions, data-rights requests, or to reach our Data Protection Officer, email privacy@fooddelight.tech or write to us via the contact page.