Privacy Policy
Last updated: August 2026
NGWANGWA DIGITAL SYSTEMS LTD (RC 9791913) ("we", "us", or "our") operates Virtual Waitress. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and your rights in relation to it. We are committed to compliance with the Nigeria Data Protection Regulation (NDPR) and applicable data protection law.
1. Who This Policy Applies To
This policy applies to:
- Restaurant owners and staff — individuals who create and manage a Virtual Waitress account ("Account Holders").
- Customers — individuals who scan a restaurant's QR code and interact with the customer-facing menu.
2. Data We Collect
Account Holders
- Email address and password (hashed — we never store your password in plain text).
- Restaurant name, tagline, WhatsApp number, and accent colour settings.
- Menu items, categories, prices, and food photos you upload.
- Table configurations and staff account details.
- Subscription and billing status.
- Usage data — pages visited within the dashboard, feature interactions, timestamps.
Customers (QR code users)
- Orders placed — items, quantities, table number, and timestamp.
- Waiter call requests — table number and timestamp.
- We do not collect names, phone numbers, or any identifying information from customers unless they voluntarily provide it as part of an order note.
- We do not use tracking cookies or advertising pixels on the customer-facing menu.
3. How We Use Your Data
- To create and manage your account and provide the Service.
- To process and display orders between customers and your staff.
- To generate analytics — revenue, best sellers, staff performance — visible only to you.
- To send service-related notifications (order alerts, account emails).
- To respond to support requests.
- To improve the platform through aggregated, anonymised usage analysis.
- To comply with legal obligations.
We do not use your data for advertising. We do not sell your data or your customers' data to any third party.
4. Data Storage and Security
Data is stored using Supabase infrastructure, with servers located in the European Union. Supabase is SOC 2 Type II certified and employs industry-standard encryption in transit (TLS) and at rest.
Access to your account data is protected by email-and-password authentication. Passwords are hashed using bcrypt and never stored in recoverable form. We recommend enabling a strong, unique password for your account.
5. Data Sharing
We share data only in the following limited circumstances:
- Service providers — Supabase (database and authentication), Google (AI features via Gemini API — only menu item text you choose to send for AI copy generation). These providers are bound by data processing agreements.
- Legal requirements — if required by Nigerian law, court order, or lawful government request.
- Business transfer — if the business is acquired or merges, users will be notified and the new owner will be bound by this policy.
6. Data Retention
- Account data is retained while your account is active.
- On account deletion, data is purged within 30 days. You may request an export before deletion.
- Anonymised, aggregated analytics data (no personal identifiers) may be retained indefinitely to improve the platform.
7. Your Rights
Under the NDPR and applicable law, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — request correction of inaccurate data.
- Deletion — request deletion of your account and personal data.
- Portability — request your data in a structured, machine-readable format.
- Objection — object to processing where we rely on legitimate interests.
To exercise any of these rights, email us at support@virtualwaitress.com. We will respond within 30 days.
8. Cookies
The marketing website (virtualwaitress.com) uses only essential cookies — session management and navigation state. No advertising or analytics cookies are set on visitors. The dashboard uses authentication cookies required to maintain your logged-in session. The customer-facing menu sets no cookies of any kind.
9. Children's Privacy
The Service is intended for use by businesses and their adult staff. We do not knowingly collect personal data from individuals under 18. If you believe a minor has submitted data, contact us immediately and we will delete it.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated to Account Holders by email at least 7 days before they take effect. The "Last updated" date at the top of this page will always reflect the most recent version.
11. Contact Us
For any privacy-related questions, requests, or concerns:
- Email: support@virtualwaitress.com
- WhatsApp: +234 701 881 4381