1. Introduction
EatryCloud ("we", "our", "us") is a cloud-based restaurant management platform. This Privacy Policy explains how we collect, use, and protect your personal data when you use our services, including our website, point-of-sale system, kitchen display system, and WhatsApp ordering features.
We are committed to protecting your privacy in accordance with the Ghana Data Protection Act, 2012 (Act 843) and applicable data protection laws.
2. Data We Collect
We collect the following types of personal data:
- Account information: Name, email address, phone number, restaurant name, and business address
- Staff information: Names, phone numbers, roles, and PINs (stored securely as hashes)
- Order data: Order history, items ordered, delivery details, and table numbers
- Payment information: Mobile money phone numbers and transaction references (we do not store payment credentials)
- WhatsApp data: Phone numbers, message content, and ordering interactions sent via WhatsApp Business API
- Device information: Device type, app version, and last activity timestamps
3. How We Use Your Data
We use your personal data to:
- Provide and maintain our restaurant management services
- Process orders and facilitate payments
- Enable WhatsApp-based ordering for your customers
- Send order confirmations and payment notifications
- Generate business reports and analytics for restaurant owners
- Provide customer support
- Improve our platform and develop new features
4. Third-Party Services
We use the following third-party services to operate our platform:
- Meta (WhatsApp Business API): To enable WhatsApp ordering. Customer phone numbers and message content are processed through Meta's infrastructure. See WhatsApp's Privacy Policy.
- Paystack: To process mobile money and card payments. Payment data is handled by Paystack in accordance with PCI DSS standards. See Paystack's Privacy Policy.
- Railway: To host our platform infrastructure.
5. Data Retention
We retain your personal data for as long as your account is active or as needed to provide our services. Order and payment records are retained for a minimum of 6 years to comply with financial record-keeping requirements. You may request deletion of your account and personal data at any time (see our Data Deletion page).
6. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including encryption of data in transit (TLS), secure password and PIN hashing (bcrypt), and access controls based on user roles.
7. Your Rights
Under the Ghana Data Protection Act, 2012 (Act 843), you have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request deletion of your data
- Object to the processing of your data
- Withdraw consent at any time
8. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:
Email: privacy@eatrycloud.com