Privacy Policy

Privacy Policy · version 2.0.0 · in effect from 11 August 2026

In short.

We collect what we need to take your order, cook-and-carry it to the right place, take payment, and keep the service safe. We share your name, number and location with the vendor and rider handling your order — nothing more than that. We do not sell your data. You can ask us for a copy of it, or ask us to delete it, at any time.

1. Who this policy is about

This policy explains how ìlúEats ("we") collects, uses, shares and protects your personal information when you use our website, apps and services, and the rights you have over it.

We are the data controller for the information described here. That means we decide what is collected and why, and we are accountable for it under the Nigeria Data Protection Act 2023 (NDPA) and the regulations made under it.

Questions, or a request about your data: privacy@ilueats.com.

2. What we collect

Information you give us. Your name, email address, phone number, password, and — if you choose to add them — your date of birth, delivery addresses, saved landmarks and delivery notes.

Order information. What you ordered, from which vendor, when, the price, the delivery mode and destination, your order notes, and any rating, complaint or food safety report you file.

Payment information. The method used, the amount, and the reference returned by our payment processor. Card numbers are entered directly with the licensed processor — we never receive or store your full card details.

Location information. The delivery coordinates you select or confirm, and — only with your device permission and only while you are using the app — your approximate location, so we can show nearby vendors and calculate delivery distance.

Device and usage information. IP address, device and browser type, operating system, app version, pages and screens viewed, and diagnostic logs.

Communications. Messages you send our support team, and records of order-related calls or messages between you and a rider.

Consent records. Which version of these documents you accepted, when, and the IP address and device it came from. We keep this so that both of us can rely on what was actually agreed.

3. Why we use it, and our lawful basis

Under the NDPA we must have a lawful basis for each use. Ours are:

  • Performance of our contract with you — creating and securing your account, taking and fulfilling orders, passing your details to the vendor and rider, processing payment, running your wallet, issuing refunds, and providing support.
  • Compliance with a legal obligation — keeping financial and transaction records, responding to lawful requests from regulators, tax authorities, the police or a court, and handling food safety incidents where a health authority must be informed.
  • Our legitimate interests — preventing fraud and abuse, securing the Platform, investigating complaints, monitoring vendor quality and food safety patterns, understanding which parts of the service are used, and defending legal claims. We balance these against your rights and use the least intrusive option that works.
  • Your consent — marketing messages, precise device location, optional cookies, and your date of birth for birthday offers. You can withdraw consent at any time without affecting the processing already done on it.
  • Protection of vital interests — in the rare case that information must be shared urgently to protect someone's life or health, such as a serious food safety incident.

We do not use your data for automated decisions that have a legal or similarly significant effect on you. Fraud checks may flag an account for review, but a person makes the decision to suspend it.

4. Who we share it with

We do not sell or rent your personal information. We share it only as follows:

  • The vendor preparing your order — your first name, order contents and notes, so they can make it correctly.
  • The rider delivering your order — your name, phone number, delivery address or landmark and directions, for the duration of that delivery.
  • Service providers acting on our instructions — payment processing, hosting and databases, email and SMS delivery, mapping and geocoding, image hosting, and error monitoring. They may only use the data to provide that service to us.
  • Regulators, law enforcement and our professional advisers — where we are legally required to disclose, or where it is necessary to establish, exercise or defend a legal claim, including a food safety investigation.
  • A buyer or successor — if the business is reorganised, merged or sold, under the same protections set out here.

Vendors and riders are independent businesses and become responsible in their own right for what they do with the details we pass them for your order. We require them to use those details only to fulfil it.

5. Where your data is held

Our infrastructure providers may store or process data outside Nigeria. Where personal data is transferred abroad we do so only where the NDPA allows it — because the destination provides adequate protection, because the transfer is covered by contractual safeguards binding the recipient to equivalent standards, or because it is necessary to perform our contract with you.

6. How long we keep it

We keep personal data only as long as we need it for the purpose it was collected, and then delete or anonymise it.

  • Account details — while your account is open, then up to 12 months after closure in case you return or a dispute arises.
  • Order, payment and wallet records — 7 years, which is the period Nigerian tax and financial record-keeping rules require.
  • Food safety reports and consent records — 7 years, since these are the records that establish what was agreed and what was reported if a claim is brought later.
  • Support conversations — 24 months.
  • Diagnostic and security logs — up to 12 months.

We may keep information longer where an investigation, dispute or legal claim is live, and only for as long as that lasts.

7. Your rights under the NDPA

You have the right to:

  • be told what we hold about you and get a copy of it;
  • have inaccurate or incomplete information corrected;
  • have your data deleted where we no longer need it or where you withdraw the consent it rested on;
  • restrict or object to processing we carry out on the basis of our legitimate interests;
  • receive the data you gave us in a portable, machine-readable format;
  • withdraw consent at any time; and
  • complain to the Nigeria Data Protection Commission (NDPC) if you think we have handled your data wrongly.

To exercise any of these, email privacy@ilueats.com or use Help & support. We will ask you to verify your identity, and we will respond within 30 days. These requests are free; we may charge a reasonable fee only where a request is manifestly repetitive or excessive.

Some rights have limits — for example, we cannot delete order and payment records we are legally required to keep, and deleting your account does not erase the transaction history behind an order the vendor and the tax authority both have a record of.

8. How we protect it

Passwords are stored only as salted hashes, never in a readable form. Traffic between your device and our servers is encrypted in transit. Access to production data is limited to the staff who need it, sessions are token-based and expire, and sensitive endpoints are rate-limited.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the NDPC within 72 hours as the NDPA requires, and tell you directly where the risk to you is high.

You play a part too: use a strong, unique password, do not share your login, and tell us immediately if you think your account has been accessed by someone else.

9. Cookies and similar technologies

We use strictly necessary cookies and local storage to keep you signed in, remember your cart, addresses and favourites, and keep the service secure. These are required for the site to work and cannot be turned off from within it.

Any analytics or preference storage beyond that is used only with your consent, and you can clear it through your browser or device settings at any time. We do not use advertising or cross-site tracking cookies.

10. Children

ìlúEats is not intended for children under 18, and we do not knowingly collect their personal data. If you believe a child has given us information, contact privacy@ilueats.com and we will delete it.

11. Marketing

We send order and account messages — confirmations, rider updates, receipts, security notices — because they are part of the service, and you cannot opt out of those while you hold an account.

Promotional messages are sent only with your consent, and every one carries a way to stop them. You can also turn them off in your account settings.

12. Changes to this policy

We review this policy at least once a year and whenever the way we handle data changes. The version and effective date at the top of this page always identify the current wording; where a change is material we will tell you and, where the NDPA requires it, ask for your consent again.

13. Contact and complaints

Data protection queries and requests: privacy@ilueats.com. Other legal matters: legal@ilueats.com. Anything else: Help & support.

If you are not satisfied with our response, you may complain to the Nigeria Data Protection Commission.