Overview
This Privacy Policy describes how Quilo Technologies LTD("Waitr", "we", "us", or "our") collects, uses, stores, and shares information when you use the Waitr Vendor App (available on Google Play) and our web platform at waitr.ng(collectively, the "Service").
By downloading the app, creating an account, or using the Service, you agree to the practices described in this policy. If you do not agree, please do not use the Service.
This policy complies with the Nigeria Data Protection Act 2023 (NDPA) and applicable international privacy standards.
Who this policy covers
This policy applies to restaurant owners, managers, and staff ("Partners" or "Vendors") who use the Waitr Vendor App to manage their restaurant orders and menus. If you are a customer (diner) placing an order via a QR code, the Waitr Customer Privacy Policy applies to you.
Data We Collect
We collect only the information necessary to provide, maintain, and improve the Service. Here is a complete breakdown:
- Full name and email address
- Business name and branch details
- Account password (stored as a secure hash)
- Profile photo (optional)
- Menu items, descriptions, and prices
- Table layout and QR code assignments
- Order history and transaction records
- Opening hours and availability settings
- Device type, OS version, and model
- Push notification token (FCM)
- App version and crash reports
- IP address and approximate location (city-level)
- Features used and screens visited
- Session duration and frequency
- In-app actions (order accepted, menu updated)
- Error logs and performance diagnostics
We do not collect: Payment card numbers, bank account details, biometric data, precise GPS location, contacts, photos, files, microphone input, or any data unrelated to operating the Service.
How We Use Your Data
We use your data only for the purposes listed below. We do not sell your personal data to third parties for advertising or marketing.
Providing the Service
Creating and managing your account, displaying your menu to customers via QR code, routing orders to your vendor dashboard in real time, and enabling payment settlement.
Push Notifications
Sending alerts for new orders, order status changes, and critical account activity. You can manage notification preferences in the app settings at any time.
Performance & Reliability
Diagnosing crashes, monitoring uptime, and improving app stability. Crash reports are anonymised before analysis.
Customer Support
Responding to your support requests, troubleshooting issues, and communicating service updates or important account notices.
Security & Fraud Prevention
Detecting suspicious activity, preventing unauthorised access, and complying with legal obligations.
Product Improvement
Understanding how features are used in aggregate to guide product decisions. This analysis uses anonymised, aggregated data only.
Third-Party Services
The Service integrates with the following third-party platforms. Each operates under its own privacy policy, which we link below.
Paystack
Payment processing — handles card and bank transfer payments from customers
Pusher
Real-time order updates — pushes order events to your vendor dashboard instantly
Firebase (Google)
Cloud hosting, database, and authentication infrastructure
Google Play Services
App distribution, in-app updates, and Firebase Cloud Messaging (FCM) for push notifications
We review our third-party partners regularly and update this list when integrations change. Where possible, we choose providers with data centres in regions that offer equivalent data protection to Nigeria.
Data Retention
We retain your data only for as long as necessary to fulfil the purposes described in this policy or as required by law.
| Data Type | Retention Period |
|---|---|
| Account information | Duration of account + 30 days after deletion request |
| Order history | 7 years (required for financial records under Nigerian law) |
| Push notification tokens | Until app is uninstalled or token refreshed |
| Crash & diagnostic logs | 90 days, then automatically purged |
| Anonymised usage analytics | Up to 3 years in aggregated form |
| Support correspondence | 3 years from last interaction |
When data is no longer needed, we securely delete or anonymise it. You may request early deletion of your account data at any time (see Your Rights).
Security
We apply industry-standard technical and organisational measures to protect your data against unauthorised access, alteration, disclosure, or destruction.
Encryption in transit
All data between your app and our servers is encrypted via TLS 1.2+.
Encryption at rest
Sensitive database fields and backups are encrypted at rest using AES-256.
Access controls
Production data access is restricted to authorised personnel with audit logging.
Password hashing
Passwords are never stored in plain text — we use bcrypt with a strong work factor.
Regular audits
We conduct periodic security reviews and promptly address vulnerabilities.
Breach notification
In the event of a data breach, we will notify affected users and relevant authorities within 72 hours as required by law.
No method of transmission over the internet is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee its absolute security. You are responsible for keeping your account credentials confidential.
Your Rights
Under the Nigeria Data Protection Act 2023 and applicable law, you have the following rights regarding your personal data:
Right of Access
You may request a copy of the personal data we hold about you, including what it is, how we use it, and who we share it with.
Right to Rectification
If any data we hold about you is inaccurate or incomplete, you can update it directly in the app or ask us to correct it.
Right to Erasure
You may request deletion of your account and associated personal data. We will comply within 30 days, subject to legal retention obligations (e.g., financial records).
Right to Restrict Processing
You can ask us to pause processing your data in certain circumstances, such as while a dispute is pending.
Right to Data Portability
You may request an export of your data in a structured, machine-readable format (JSON or CSV).
Right to Object
You may object to processing based on legitimate interests or for direct marketing at any time.
To exercise any of these rights, email us at support@waitr.ng with the subject line "Data Request". We will respond within 30 days. We may need to verify your identity before processing the request.
Push Notifications
The Waitr Vendor App uses push notifications to alert you to new orders, order status updates, and other time-sensitive events critical to running your restaurant.
How it works
- On first launch, the app requests your permission to send notifications.
- If granted, a device token is generated by Firebase Cloud Messaging (FCM) and sent to our servers.
- This token is used only to deliver order alerts and Waitr service messages — never for advertising.
- You can revoke notification permission at any time in your device Settings → Apps → Waitr.
- Revoking permission stops notifications but does not affect your account or data.
Notification tokens are stored securely and deleted automatically when the app is uninstalled or when a new token is issued by the device.
Payment Data
Waitr does not process, store, or have access to your customers' payment card numbers, bank account details, or any sensitive financial credentials.
All customer payments are handled directly by Paystack, a PCI DSS-compliant payment processor licensed by the Central Bank of Nigeria. When a customer pays, they interact with Paystack's secure payment interface — Waitr only receives a transaction reference and confirmation status.
Settlement information
To facilitate settlement of funds to your account, we may collect and store your bank account details (account number, bank name, account name) for payout purposes. This data is encrypted at rest and is never shared with third parties except as required to process the settlement.
Children's Privacy
The Waitr Vendor App is a business management tool intended solely for use by adults (18 years and older) operating food or hospitality businesses.
We do not knowingly collect personal information from anyone under the age of 18. If you believe a minor has provided us with personal information, please contact us immediately at support@waitr.ng and we will delete that information promptly.
Policy Changes
We may update this Privacy Policy from time to time to reflect changes in the Service, applicable law, or our data practices.
When we make a material change, we will:
- Update the "Last updated" date at the top of this page
- Send a notification via the app or to your registered email address
- Give you at least 14 days' notice before the change takes effect
Your continued use of the Service after any changes take effect constitutes your acceptance of the updated policy. If you do not agree with the changes, you should stop using the Service and request deletion of your account.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Response time
We aim to respond to all privacy-related requests within 5 business days. For data deletion or access requests, the maximum response time is 30 days as required by the NDPA 2023.