PrioEat
Legal

Privacy Policy

We are committed to protecting your personal information and your right to privacy. This policy explains exactly what we collect, why, and how we protect it.

πŸ“… Effective: April 6, 2026 πŸ“… Last Updated: April 6, 2026 🌍 Governing Law: Federal Republic of Nigeria

Who we are: PrioEat ("PrioEat", "we", "us", "our") is a technology platform operated by PrioEat Technologies Limited, a company registered under the laws of the Federal Republic of Nigeria. We operate a restaurant pre-ordering and table reservation platform accessible via our mobile application and website at prioeatng.com.

This Privacy Policy applies to: all users of the PrioEat mobile application (iOS and Android), the PrioEat website, and any related services. By using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree, please discontinue use of our Services immediately.

Table of Contents
  1. Information We Collect
  2. How We Use Your Information
  3. Legal Basis for Processing
  4. Information Sharing & Disclosure
  5. Third-Party Service Providers
  6. Payment Processing & Financial Data
  7. Push Notifications
  8. Data Retention
  9. Data Security
  10. Your Rights & Choices
  11. Cookies & Tracking Technologies
  12. Children's Privacy
  13. International Data Transfers
  14. Changes to This Policy
  15. Governing Law & Dispute Resolution
  16. Contact & Data Protection Officer
Section 01

Information We Collect

We collect information you provide directly, information generated automatically when you use our Services, and information obtained from third-party partners. The categories of personal data we collect are described below.

1.1 Information You Provide Directly

Data CategorySpecific Data PointsWhen Collected
Account InformationFull name, email address, phone number, password (hashed)At account registration
Order InformationSelected menu items, quantities, special instructions, table preference, dining timeWhen placing an order
Reservation InformationDate, time, party size, special requests, occasion notesWhen making a reservation
Payment InformationPayment method type, last 4 digits of card (tokenised), billing detailsAt checkout. Full card numbers are never stored by PrioEat.
CommunicationsMessages sent to our support team, feedback, reviewsWhen you contact us
Restaurant Partner DataBusiness name, address, banking details (for restaurant managers), menu and pricing informationDuring partner onboarding

1.2 Information Collected Automatically

Data CategorySpecific Data PointsPurpose
Device InformationDevice model, operating system version, unique device identifiers (IDFV), app versionSecurity, troubleshooting, compatibility
Usage DataScreens viewed, features used, time spent in-app, tap interactions, order flow completionProduct improvement, analytics
Location InformationApproximate or precise device location, only after you grant device-level permissionShowing nearby restaurants, distance estimates, directions, and arrival support
Network InformationIP address, network type (Wi-Fi/mobile data), approximate city-level location derived from IPFraud detection, service delivery
Push Notification TokenFirebase Cloud Messaging (FCM) device tokenDelivering order status notifications
Transaction MetadataPaystack payment reference, transaction timestamps, payment statusOrder fulfilment, dispute resolution

What we do NOT collect: We do not collect contacts, microphone recordings, biometric data, social media credentials, or any data not described above. We do not collect full payment card numbers β€” this data is handled exclusively by Paystack under PCI-DSS Level 1 compliance.

Section 02

How We Use Your Information

We use your personal data only for the purposes described below. We do not sell your personal data to third parties for marketing purposes.

2.1 Service Delivery (Core Purpose)

2.2 Safety & Fraud Prevention

2.3 Communications

2.4 Platform Improvement

2.5 Legal & Regulatory Compliance

Section 03

Legal Basis for Processing

Under the Nigeria Data Protection Regulation (NDPR) 2019 and the Nigeria Data Protection Act (NDPA) 2023, we are required to identify a valid legal basis for each category of personal data processing. Our legal bases are as follows:

Processing ActivityLegal BasisApplicable Provision
Account creation and authenticationContractual necessity β€” required to provide the service you requestedNDPA 2023, s. 25(1)(b)
Processing and fulfilling ordersContractual necessityNDPA 2023, s. 25(1)(b)
Payment processingContractual necessity and legal obligation (CBN regulations)NDPA 2023, s. 25(1)(b)(c)
Push notifications for order updatesContractual necessity and consent (device-level permission)NDPA 2023, s. 25(1)(a)(b)
Fraud detection and securityLegitimate interests β€” protecting users and the platform from harmNDPA 2023, s. 25(1)(f)
Marketing communicationsConsent β€” you must actively opt inNDPA 2023, s. 25(1)(a)
Analytics and product improvementLegitimate interests β€” improving our services for all usersNDPA 2023, s. 25(1)(f)
Legal compliance and regulatory reportingLegal obligationNDPA 2023, s. 25(1)(c)

Where we rely on legitimate interests: We have conducted a Legitimate Interests Assessment (LIA) for each processing activity relying on this basis. We have determined that our interests are not overridden by your rights and interests, taking into account the nature of the data processed and the reasonable expectations of users of a restaurant pre-ordering platform. You may request a copy of our LIAs by contacting us at the details in Section 16.

Section 04

Information Sharing & Disclosure

We do not sell, rent, or trade your personal data to third parties for their marketing or commercial purposes. Period.

We share personal data only in the following limited circumstances:

4.1 With Restaurant Partners

When you place an order or make a reservation, we share the following information with the relevant restaurant partner to fulfil your request:

Restaurant partners are bound by our Partner Data Processing Agreement and are prohibited from using your data for any purpose other than fulfilling your order or reservation.

4.2 With Technology Service Providers

We engage third-party technology providers who process data on our behalf as data processors under binding data processing agreements. See Section 5 for the complete list.

4.3 For Legal and Regulatory Compliance

We may disclose your personal data without prior notice where required by:

4.4 Business Transfers

In the event of a merger, acquisition, restructuring, or sale of all or substantially all of our assets, your personal data may be transferred to the acquiring entity. We will notify you by email and/or prominent in-app notice at least 30 days before your data becomes subject to a materially different privacy policy, and you will have the right to delete your account during this period.

4.5 With Your Consent

We may share your data with third parties where you have given us explicit, specific, informed, and unambiguous consent to do so.

Section 05

Third-Party Service Providers

We use the following sub-processors to operate our platform. Each is bound by a data processing agreement and is required to apply technical and organisational security measures equivalent to or exceeding our own standards.

ProviderServiceData SharedData LocationPrivacy Policy
Supabase, Inc. Database, authentication, real-time data infrastructure All account, order, and reservation data United States (AWS us-east-1) supabase.com/privacy
Paystack Payments Limited Payment processing, subaccount disbursement Payment card data (tokenised), transaction amounts, customer name and email Nigeria / Ireland paystack.com/privacy
Google LLC (Firebase) Push notification delivery (Firebase Cloud Messaging) Device push token, notification payload (order status text) United States policies.google.com/privacy
Vercel, Inc. Web hosting and content delivery IP address, HTTP request metadata (logs retained for 30 days) United States vercel.com/legal/privacy-policy

International transfers: Some of our service providers are located outside Nigeria. Where personal data is transferred outside Nigeria, we ensure that such transfers comply with the NDPA 2023 and the NDPC's Transfer of Personal Data Across Borders regulations, including through the use of Standard Contractual Clauses (SCCs) or adequacy decisions where applicable.

Section 06

Payment Processing & Financial Data

All payment transactions on PrioEat are processed by Paystack Payments Limited, a CBN-licensed payment service provider and a subsidiary of Stripe, Inc. Paystack operates at PCI-DSS Level 1 β€” the highest level of payment security certification in the industry.

What PrioEat Does NOT Store

What PrioEat Stores

Payment Model β€” 100% Online Settlement

PrioEat charges the full order amount (food subtotal plus PrioEat's platform fee) in-app at the time of ordering. Nothing is collected on arrival at the restaurant. Paystack splits the payment at the gateway between the restaurant's registered Paystack subaccount (food revenue, minus Paystack's processing fee) and PrioEat's main account (platform fee). For restaurants whose Paystack subaccount has not yet been provisioned, the food portion is held temporarily by PrioEat and disbursed to the restaurant on settlement day.

No Separate VAT Line

Menu prices are inclusive of any applicable tax the restaurant chooses to embed. PrioEat does not compute, display, or charge VAT as a separate line item. Restaurants remain responsible for their own tax obligations to Nigerian tax authorities.

Platform Fee

PrioEat charges a single platform fee per order: a ₦1,000 base plus 2.5% of the order value above ₦20,000 (subject to a configurable floor and ceiling). Member-tier customers (Bronze / Silver / Gold / Platinum) receive a percentage discount on this fee, applied automatically at checkout. The final fee β€” including any tier discount β€” is always shown before payment.

Cancellations & Refund Policy

If you cancel a paid order, or if a restaurant cancels your confirmed order, the full charged amount (food plus platform fee) is issued to you as PrioEat Credit β€” a balance held in your in-app Wallet, redeemable on a future order at the same restaurant. Credit issued by a restaurant that is later suspended automatically converts to platform-wide credit, usable at any active restaurant. PrioEat Credit does not expire. PrioEat does not process cash refunds or Paystack reversals to original payment methods; every refund is issued as PrioEat Credit only.

Section 07

Push Notifications

PrioEat sends push notifications to keep you informed about your orders and reservations. These notifications are powered by Google Firebase Cloud Messaging (FCM).

Types of Notifications We Send

Managing Notifications

You may manage push notification permissions at any time through your device's system settings (iOS: Settings β†’ PrioEat β†’ Notifications; Android: Settings β†’ Apps β†’ PrioEat β†’ Notifications). Disabling notifications will not affect your ability to use the app, but you will not receive real-time order updates until notifications are re-enabled.

Section 08

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, or as required by applicable law. Our retention schedules are as follows:

Data CategoryRetention PeriodRationale
Account data (name, email, phone)Duration of account + 3 years post-deletionDispute resolution, legal claims
Order records7 years from order dateNigerian tax and accounting regulations (FIRS)
Payment transaction records7 years from transaction dateCBN record-keeping requirements, AML compliance
Reservation records2 years from reservation dateDispute resolution, analytics
Push notification tokensUntil account deletion or token refreshNotification delivery
Support communications3 years from last interactionQuality assurance, dispute resolution
Web server logs (IP addresses)30 daysSecurity monitoring
Abandoned/ghost orders (pending payment, no completion)Automatically deleted after 30 minutesData minimisation; these represent incomplete transactions

Upon account deletion, we will anonymise or securely delete your personal data within 30 days, except where retention is required by law (as noted above). Anonymised, aggregated data that cannot be used to identify you may be retained indefinitely for statistical purposes.

Section 09

Data Security

We implement industry-standard technical and organisational security measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. Our security programme includes:

Technical Measures

Organisational Measures

No system is 100% secure. While we take your data security extremely seriously, we cannot guarantee absolute security. In the event of a data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the Nigeria Data Protection Commission (NDPC) within 72 hours of becoming aware of the breach, as required by the NDPA 2023.

Section 10

Your Rights & Choices

Under the Nigeria Data Protection Act (NDPA) 2023, you have the following rights with respect to your personal data. We will respond to all valid requests within 30 days of receipt (extendable to 60 days for complex requests, with notice to you).

πŸ“‹
Right of Access
Request a copy of all personal data we hold about you, including the purposes for which it is processed and the recipients with whom it has been shared.
✏️
Right to Rectification
Request correction of inaccurate or incomplete personal data. You may update most information directly in your account profile.
πŸ—‘οΈ
Right to Erasure
Request deletion of your personal data ("right to be forgotten"), subject to our legal retention obligations under Nigerian tax and financial regulations.
🚫
Right to Object
Object to processing based on legitimate interests (including profiling) or for direct marketing purposes. We will cease such processing upon valid objection.
⏸️
Right to Restriction
Request that we restrict processing of your data while you contest its accuracy or pending resolution of an objection you have raised.
πŸ“¦
Right to Portability
Receive your personal data in a structured, commonly used, machine-readable format (JSON or CSV), and transmit it to another controller where technically feasible.
↩️
Right to Withdraw Consent
Where processing is based on consent (e.g., marketing emails), withdraw consent at any time without affecting the lawfulness of prior processing.
βš–οΈ
Right to Lodge a Complaint
Lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng if you believe your rights have been violated.

To exercise any of the above rights, please contact our Data Protection Officer at privacy@prioeat.com with the subject line "Data Rights Request β€” [Your Full Name]". We may require identity verification before processing your request.

Section 11

Cookies & Tracking Technologies

Our mobile application does not use cookies. Our website (prioeatng.com) uses a limited set of cookies as described below.

Cookie TypeName / SourcePurposeDuration
Strictly Necessarysupabase-auth-tokenMaintains your authenticated sessionSession / 7 days
Strictly Necessarysb-ecpg-auth-tokenSupabase authentication refresh tokenUp to 1 year
PerformanceVercel analytics (anonymous)Aggregated page load metrics, no personal identifiersSession

We do not use advertising cookies, third-party tracking pixels, or any cross-site tracking technologies. You may clear cookies at any time through your browser settings; however, this will log you out of active sessions.

Section 12

Children's Privacy

PrioEat is not directed at, and does not knowingly collect personal data from, children under the age of 13 years (or under 16 years where a higher age applies under local law). Our Services are intended for use by persons aged 13 and above; persons under 18 should use the platform only with parental or guardian supervision.

If we become aware that we have inadvertently collected personal data from a child under 13, we will take immediate steps to delete that information from our systems. If you believe we may have collected data from a child under 13, please contact us immediately at privacy@prioeat.com.

Our mobile application is rated 4+ on the Apple App Store and Everyone on Google Play. This rating reflects the absence of objectionable content, violence, or adult themes in our application.

Section 13

International Data Transfers

PrioEat is based in Nigeria, and our primary operations are conducted within Nigeria. However, some of our technology service providers (notably Supabase, Firebase, and Vercel) are headquartered in or operate infrastructure in the United States.

When we transfer personal data outside Nigeria, we ensure that adequate safeguards are in place in accordance with the NDPA 2023 and the NDPC Transfer of Personal Data Across Borders Regulations 2023. Safeguards used include:

You may obtain a copy of the specific safeguards applicable to any international transfer by contacting our Data Protection Officer.

Section 14

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will:

Your continued use of our Services after the effective date of any updated Privacy Policy constitutes your acceptance of the updated terms. If you do not agree with the updated policy, you must discontinue use of our Services and may request deletion of your account.

All previous versions of this Privacy Policy are archived and available upon request.

Section 15

Governing Law & Dispute Resolution

This Privacy Policy is governed by and construed in accordance with the laws of the Federal Republic of Nigeria, including the Nigeria Data Protection Act (NDPA) 2023, the Nigeria Data Protection Regulation (NDPR) 2019, and all applicable regulations issued by the Nigeria Data Protection Commission (NDPC).

Any dispute arising from this Privacy Policy or our data processing practices shall be subject to the exclusive jurisdiction of the courts of the Federal Capital Territory, Abuja, Nigeria, without prejudice to your right to lodge a complaint with the NDPC.

Regulatory Oversight

PrioEat Technologies Limited operates under the regulatory oversight of the Nigeria Data Protection Commission (NDPC). Our Data Protection Compliance Organisation (DPCO) registration and our annual Data Protection Audit reports are available upon request.

Apple App Store: If you downloaded PrioEat from the Apple App Store, Apple Inc. may have access to transaction and download data as described in Apple's Privacy Policy (apple.com/legal/privacy). Apple is an independent data controller for that data, and PrioEat has no control over Apple's data practices.

Section 16

Contact & Data Protection Officer

If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us through any of the channels below. We take all privacy enquiries seriously and will respond within 5 business days.

PrioEat Technologies Limited β€” Privacy Team

Registered in the Federal Republic of Nigeria

Data Protection Officer
General Support
Registered Address
Abuja, Federal Capital Territory, Nigeria
Regulator (NDPC)