Privacy Policy
Effective: 18 June 2026 · Last updated: 18 June 2026
Template — pending legal review. This document is a starting point tailored to OrderEase's stack and South African law (POPIA, ECTA, CPA). Replace every [PLACEHOLDER] and have it reviewed by a qualified legal practitioner before publishing.
1. Introduction
This Privacy Policy explains how [LEGAL ENTITY NAME] ("OrderEase", "we", "us", "our") collects, uses, shares, and protects personal information when you use the OrderEase platform, websites, dashboards, storefronts, embeddable widget, and the OrderEase Kitchen application (together, the "Service").
We are committed to processing personal information lawfully and transparently in accordance with the Protection of Personal Information Act, 2013 (POPIA) and other applicable South African law.
By using the Service, you acknowledge that you have read and understood this Policy.
2. Who we are (Responsible Party & Information Officer)
The responsible party for personal information processed through the Service is:
- Entity: [LEGAL ENTITY NAME]
- Registration number: [COMPANY REGISTRATION NUMBER]
- Registered address: [REGISTERED ADDRESS]
- Information Officer: [INFORMATION OFFICER NAME]
- Privacy contact: [PRIVACY EMAIL]
3. Our two roles
OrderEase processes personal information in two distinct capacities:
- As a Responsible Party — for information about our direct users: business owners, managers, and kitchen staff who create and use OrderEase accounts.
- As an Operator (processor) — for information about a merchant's own customers that flows through the Service when those customers place orders on a merchant's storefront. In that case the merchant is the responsible party and determines how that information is used; we process it on the merchant's behalf and under our agreement with them.
If you are a customer of a business that uses OrderEase, please also refer to that business's own privacy notice.
4. Information we collect
Account information — name, email address, phone number, business name, role, and password (stored hashed) for the people who run a business on OrderEase.
Business & store information — store details, menus, products, add-ons, pricing, promotions, and operating hours.
Order & customer information — when a customer places an order, we process their name, contact details, delivery address, order contents, and order history so that the order can be fulfilled by the merchant and delivery partner.
Payment information — card and EFT payments are processed by Paystack. We do not store full card numbers. We receive limited transaction metadata (e.g. reference, amount, status) needed to reconcile orders.
Location information — approximate or precise delivery addresses and map/geolocation data processed via Google Maps for address selection and delivery, and geospatial data for serviceable areas.
Device & notification information — when you use the Kitchen app or enable web notifications, we process device identifiers and push tokens via OneSignal to deliver order alerts.
Usage & technical information — log data, IP address, browser/device type, pages viewed, and similar analytics collected via Vercel Analytics, and diagnostic/error data via Sentry, to operate, secure, and improve the Service.
5. Why we process it, and our lawful basis
We process personal information to:
- create and administer accounts and authenticate users;
- operate storefronts and process and fulfil orders;
- take payment and reconcile transactions;
- dispatch and track deliveries;
- send transactional and operational notifications;
- provide support, secure the Service, prevent fraud, and meet legal obligations;
- understand usage and improve the Service.
Our lawful bases under POPIA include: performance of a contract with you; your consent (which you may withdraw); compliance with a legal obligation; and our legitimate interests (and those of the merchants we serve) in operating and securing the Service, balanced against your rights.
6. Who we share information with
We share personal information only as needed to provide the Service, with the following categories of recipients (operators/sub-processors):
| Recipient | Purpose |
|---|---|
| Paystack | Payment processing |
| Uber Direct | On-demand delivery dispatch and tracking |
| Amazon Web Services (S3) / CloudFront | Media storage and content delivery |
| Google Maps Platform | Address selection, mapping, geolocation |
| OneSignal | Push and web notifications |
| Sentry | Error monitoring and diagnostics |
| Vercel | Application hosting and analytics |
| Merchants | Order and customer details necessary to fulfil that customer's order |
We may also disclose information where required by law, to enforce our terms, or to protect the rights, safety, and property of any person. We do not sell personal information.
7. Cross-border transfers
Some of the service providers above process information outside South Africa. Where we transfer personal information across borders, we do so in accordance with section 72 of POPIA — for example, where the recipient is subject to laws or binding agreements that provide an adequate level of protection, or where the transfer is necessary to perform our contract with you.
8. Retention
We retain personal information only for as long as necessary for the purposes set out in this Policy, to comply with legal, accounting, or reporting obligations, and to resolve disputes. Retention periods vary by data type — see [RETENTION SCHEDULE / CONTACT US] for details. Where we act as an operator, retention of a merchant's customer data is governed by our agreement with that merchant.
9. How we protect information
We apply appropriate technical and organisational measures to safeguard personal information, including encryption in transit, hashed credentials, access controls, and monitoring. No method of transmission or storage is completely secure, but we work to protect your information and to notify you and the Information Regulator of any compromise as required by POPIA.
10. Your rights under POPIA
Subject to the conditions in POPIA, you have the right to:
- access the personal information we hold about you;
- request correction or deletion of personal information that is inaccurate, irrelevant, excessive, or out of date;
- object to processing in certain circumstances;
- withdraw consent where processing is based on consent;
- complain to the Information Regulator.
To exercise any of these rights, contact our Information Officer at [PRIVACY EMAIL]. If you are a customer of a merchant, please direct requests about your order data to that merchant.
Information Regulator (South Africa) JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001 Email: enquiries@inforegulator.org.za · complaints: POPIAComplaints@inforegulator.org.za
11. Cookies and similar technologies
We use cookies and similar technologies for authentication, to remember your preferences (for example cart and store selection), and to measure usage. You can control cookies through your browser settings; disabling some cookies may affect how the Service works.
12. Children
The Service is intended for businesses and their adult customers. We do not knowingly collect personal information from children without appropriate consent. If you believe a child's information has been provided to us, contact us so we can address it.
13. Changes to this Policy
We may update this Policy from time to time. We will post the updated version here and revise the "Updated" date above. Material changes will be communicated where appropriate.
14. Contact us
Questions or requests about this Policy or your personal information:
- Information Officer: [INFORMATION OFFICER NAME]
- Email: [PRIVACY EMAIL]
- Address: [REGISTERED ADDRESS]