Privacy Policy

Version 2026-07-19 · Last updated: 19 July 2026

Operational draft aligned with Nigeria Data Protection Regulation (NDPR) principles. Have counsel review before relying on it for compliance.

1. Controller

Nabata ("we") operates www.nabataa.com. For privacy requests contact hello@nabata.app. We process personal data as a controller for account and billing data, and may act as a processor for guest order data on behalf of restaurants.

2. Data we collect

Account data (name, email, password hashes, consent timestamps), restaurant profile (name, logo, bank details for guest transfers), staff accounts, menu content, table sessions and orders, device/push subscription endpoints, billing metadata from Paystack, and technical logs needed for security.

3. Purposes & lawful bases (NDPR)

We process data to provide the Service (contract), improve reliability and prevent abuse (legitimate interest / security), comply with law, and — only with consent — send marketing emails. You may withdraw marketing consent anytime.

4. Processors & transfers

We use infrastructure and tools such as hosting (e.g. Vercel), databases, object storage, email (Resend), realtime (Pusher), and payments (Paystack). Data may be processed in jurisdictions outside Nigeria with appropriate safeguards as available from those providers.

5. Retention

Account and restaurant data are kept while your account is active. After closure we may retain limited records for legal, tax, or dispute purposes. Order history retention may follow plan limits (e.g. Free review caps) and operational needs.

6. Your rights

Subject to NDPR, you may request access, correction, deletion, or restriction of your personal data, and lodge a complaint with the relevant Nigerian authority. Email hello@nabata.app to exercise rights. We will respond within a reasonable period.

7. Cookies

We use essential cookies for authentication and security. We do not currently use non-essential advertising trackers. See the on-site cookie notice.

8. Children

Nabata is intended for business users. We do not knowingly collect data from children under 13 for marketing.

9. Security

We use industry-standard measures including hashed passwords, HTTPS, and access controls. No method of transmission is 100% secure.

10. Changes

We may update this Policy and post a new version date. Material changes will be highlighted where practicable. See also our Terms of Service.