Last updated: September 2026

This Privacy Policy explains how Munchspace ("we", "our", "us") collects, uses, stores, shares, and protects personal data when you use the Munchspace mobile applications, vendor and administrative dashboards, websites, and related services (together, the "Service").
Munchspace operates a food ordering and delivery marketplace. That means we handle personal data belonging to several different kinds of people — customers who place orders, vendors and their staff who run businesses on the platform, riders who complete deliveries, and our own administrators. This Policy covers all of them, and Section 5 sets out separately what we collect for each.
Data controller:
Munch Space Limited
RC 9051132
1 Ayo Adeleye Drive Ilassan ,ikate Lagos state
Email: privacy@munchspace.io
Data Protection Officer: the Data Protection Officer, reachable at dpo@munchspace.io.
We are committed to handling personal data transparently, lawfully, and securely, in line with the Nigeria Data Protection Act 2023 ("NDPA") and, where it applies to you, the EU/UK General Data Protection Regulation ("GDPR").
This Policy applies to the Service. It does not apply to:
For most processing described here we are a data controller — we decide why and how personal data is used.
In one respect we act as a data processor on a vendor's behalf: where a vendor uses the Service to manage their own menu, orders, staff accounts, and customer interactions, the vendor is the controller of that business's own operational records and we process them under our agreement with that vendor. Where a vendor and Munchspace are joint controllers of the same order data, each of us is responsible for the obligations set out in this Policy for the part we control.
| Term | Meaning |
|---|---|
| Account | A unique account created to access the Service, in any role. |
| Admin | A Munchspace staff member with access to administrative tools. |
| Application | The Munchspace mobile or web applications. |
| Business | A vendor's storefront on the platform, with its own menu, hours and location. |
| Customer | A person who browses or places orders through the Service. |
| Device | Any device capable of accessing the Service. |
| Personal Data | Any information relating to an identified or identifiable individual. |
| Processing | Any operation performed on personal data, including collection, storage, use, disclosure and deletion. |
| Rider | A delivery partner who accepts and completes deliveries through the Service. |
| Service Provider | A third party that processes personal data on our behalf and on our instructions. |
| Usage Data | Data collected automatically through your use of the Service. |
| Vendor | A business owner or operator who sells through the Service, including their authorised staff users. |
| You | The individual or legal entity using the Service. |
We process personal data only where we have a lawful basis to do so. Under the NDPA and the GDPR, our bases are:
| Basis | When we rely on it |
|---|---|
| Contract | Creating and operating your account; taking, routing, and fulfilling orders; processing payments and payouts; providing support. |
| Legal obligation | Tax and financial record-keeping; identity and business verification (KYC); anti-fraud and anti-money-laundering duties; responding to lawful requests from authorities. |
| Legitimate interests | Securing the platform; preventing fraud and abuse; debugging and improving the Service; analytics on aggregate usage; recovering debts; defending legal claims. Where we rely on legitimate interests we have assessed that they are not overridden by your rights, and you may object (Section 15). |
| Consent | Precise device location; marketing communications; access to your camera or media library; optional profile details. Consent can be withdrawn at any time, without affecting processing already carried out. |
| Vital interests | Rare cases involving a threat to someone's life or safety, such as a serious incident during a delivery. |
We collect personal data:
For every order we record the items, quantities, prices, discounts, taxes and fees; the business it was placed with; the delivery or pickup address; the assigned rider; timestamps for each stage; and any messages exchanged about it. This record necessarily links a customer, a vendor and a rider together.
We do not collect or store full card numbers. Card details are entered with, and held by, our payment providers, who are certified to the relevant security standards. We receive and store:
We log search queries, the number of results returned, and which result was clicked or ordered, associated either with your account or with a temporary guest identifier. Signed-in users also have a personal search history, which you can clear.
With your consent, the Application may request access to:
You can withdraw any of these permissions in your device settings. Parts of the Service will stop working when you do: a rider cannot receive job assignments without location access, for example.
Location is the most sensitive category of data we handle, and it works differently for each role.
With your permission, we collect your device's location to suggest nearby businesses, estimate delivery times, and prefill delivery addresses. You may decline, and enter an address manually instead. We also store the coordinates of addresses you save.
While you are online and available for work, the Application records your location continuously. Each ping stores latitude, longitude, and — where the device reports them — accuracy, heading and speed, with a timestamp, and is linked to the delivery you are on if you are on one.
We use this to:
We do not track a rider's location while offline. Going offline in the Application stops the collection.
How long we keep it. Location trails are deleted automatically on a schedule, and the two windows differ because the reasons for keeping them differ:
Deletion runs nightly and is permanent.
Because this is precise, continuous location data about an identifiable person, we treat it as sensitive: access is restricted to staff who need it for the purposes above, and it is disclosed outside Munchspace only as described in Section 9.
We store the geographic coordinates of a business's premises, which the vendor sets when creating or editing the business. This is business location data, not personal tracking.
Vendors and riders must provide documents so we can verify who they are and that they are entitled to operate. Depending on role these may include government-issued identity documents, driver's licences, vehicle registration and insurance, proof of address, and corporate registration documents such as a CAC certificate.
We record the document type, the file itself, any reference number, its issue and expiry dates, its review status, and — where a document is rejected — the reason.
These documents are held to a stricter standard than other files:
We keep them for as long as the account is active and for the period afterwards required by law (Section 13).
| Purpose | Legal basis |
|---|---|
| Create, authenticate and manage your account | Contract |
| Display businesses, menus and prices | Contract |
| Take, route, fulfil and track orders | Contract |
| Assign deliveries to riders and calculate distance, fees and earnings | Contract; legitimate interests |
| Process payments, refunds, settlements and payouts | Contract; legal obligation |
| Verify vendor and rider identity and eligibility | Legal obligation |
| Send transactional messages — order status, receipts, security alerts | Contract |
| Send marketing messages | Consent |
| Provide customer and vendor support | Contract; legitimate interests |
| Detect, investigate and prevent fraud, abuse and security incidents | Legitimate interests; legal obligation |
| Flag, suspend or block accounts that breach our terms | Legitimate interests; contract |
| Monitor, debug and improve the Service | Legitimate interests |
| Produce aggregate analytics and business reporting | Legitimate interests |
| Comply with tax, accounting and regulatory obligations | Legal obligation |
| Establish, exercise or defend legal claims | Legitimate interests; legal obligation |
We do not use your personal data to train machine learning models that are made available outside Munchspace.
We do not sell your personal data.
We share personal data only as set out below.
Completing an order requires it:
We share the minimum needed to complete the order. Contact details shared for one order may not be used for any other purpose, and doing so breaches our terms.
We use the following categories of provider, who process data on our instructions under written terms:
| Category | Providers currently used | What they receive |
|---|---|---|
| Payment processing | Paystack, Flutterwave | Payment and card data entered by you; transaction metadata |
| Payouts and settlements | Paystack | Bank account details of vendors and riders; payout amounts |
| Cloud hosting and storage | Cloudflare R2; our hosting provider | All data stored by the Service |
| Email delivery | Amazon Web Services (SES) | Recipient email address and message content |
| Push notifications | Google Firebase Cloud Messaging | Device tokens and notification content |
| Mapping, routing and geocoding | Google Maps Platform | Coordinates and addresses used to calculate routes and distances |
This list reflects our providers as at the date of this Policy and may change; we will update it when it does.
Our administrators can access account and order records to provide support, investigate fraud and disputes, and meet compliance obligations. Access is limited by role-based permissions and is recorded in an activity log that captures who acted, what they did, and the IP address and user agent used.
Vendor account impersonation. To diagnose a problem a vendor reports, an authorised administrator can open the vendor dashboard as that vendor. This is:
An impersonating administrator sees what the vendor sees. They cannot see the vendor's password, which we do not hold in readable form.
We use automated logic to:
Fraud flags and suspensions that materially affect you are reviewed by a person before they take permanent effect, and you may contest a decision under Section 15. We do not carry out solely automated decision-making producing legal or similarly significant effects without human involvement.
Munchspace operates primarily in Nigeria, but several of our service providers process data outside Nigeria, including in the United States and the European Union.
Where we transfer personal data out of Nigeria, we do so under the NDPA's provisions for cross-border transfer — relying on an adequacy determination by the Nigeria Data Protection Commission where one exists, and otherwise on contractual safeguards with the recipient, on your explicit consent, or on the necessity of the transfer for performing our contract with you.
Where the GDPR applies, we rely on adequacy decisions or Standard Contractual Clauses, together with supplementary measures where required.
You may request details of the safeguards applied to a specific transfer at the contact address in Section 22.
We retain personal data for as long as it is needed for the purpose it was collected, and then delete or irreversibly anonymise it.
| Data | Retention |
|---|---|
| Account profile data | For the life of the account; removed on deletion, subject to the exceptions below |
| Order and transaction records | Seven years from the transaction, for tax and accounting compliance |
| Payment, payout and ledger records | Seven years from the transaction |
| Identity and compliance (KYC) documents | For the life of the account, afterwards as required by anti-money-laundering rules |
| Rider location pings — recorded during a delivery | 90 days from the ping, then deleted automatically |
| Rider location pings — recorded between deliveries | 7 days from the ping, then deleted automatically |
| Authentication and activity logs | 12 months |
| Support tickets | 24 months after resolution |
| Marketing consents and preferences | Until withdrawn, plus a record of the withdrawal |
| Backups | Deleted data persists in encrypted backups for up to 6 months before being overwritten |
Where data must be kept after account deletion for legal reasons, it is restricted to that purpose and not used to contact or profile you.
We apply administrative, technical and physical safeguards to protect personal data, including:
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Nigeria Data Protection Commission and, where the risk is high, you directly, within the timeframes the NDPA requires.
Please help us by using a strong, unique password, keeping your credentials confidential, and telling us promptly at the address in Section 22 if you believe your account has been compromised.
Subject to the conditions and exemptions in applicable law, you have the right to:
Write to us at the address in Section 22, or use the in-app controls where they are available. We will:
If we cannot act on your request, we will tell you the reason and how to challenge it.
You may delete your Munchspace account at any time.
Once confirmed, your account is scheduled for permanent deletion.
If you cannot access your account, request deletion by writing to support@munchspace.io from the email address registered to the account, or by contacting us at the address in Section 22.
Deletion cannot be reversed once it completes. Please note:
We retain certain information where the law requires it or where we have an overriding legitimate reason, including:
Retained data is stored securely, restricted to those purposes, and deleted at the end of the periods in Section 13.
The Service is not directed at children. You must be at least eighteen (18) years old to hold a vendor or rider account, and at least thirteen (13) years old to hold a customer account. Where local law sets a higher minimum age for consent to data processing, that higher age applies.
We do not knowingly collect personal data from a child below these ages. If you believe a child has provided us with personal data, contact us at the address in Section 22 and we will delete it promptly.
Our web applications use cookies and browser storage to:
Strictly necessary storage cannot be disabled without breaking the Service. You can clear or block other cookies in your browser settings; some features may then stop working.
Our mobile applications use the device's local storage for the equivalent purposes.
We send transactional messages — order updates, receipts, security alerts and service notices — as part of providing the Service. These are not marketing and you cannot opt out of them while you hold an account.
Marketing messages are sent only with your consent. You can withdraw it at any time using the unsubscribe link in any marketing email, through your notification preferences in the Application, or by contacting us. Withdrawing consent does not affect messages already sent.
The Service may link to third-party websites and services we do not control, including payment provider pages. This Policy does not apply to them. We encourage you to read the privacy policy of any third party before providing them with personal data.
We may update this Policy from time to time. When we do, we will change the "Last updated" date above and post the revised Policy within the Service.
Where a change materially affects how we use your personal data, we will give you notice — by email or an in-app notice — before it takes effect, and where the law requires it we will ask for your consent.
Previous versions are available on request.
For any question about this Policy, or to exercise your rights:
Email: privacy@munchspace.io
Support: support@munchspace.io
Data Protection Officer: dpo@munchspace.io
Postal address: 1 Ayo Adeleye Drive Ilassan ,ikate Lagos state
If you are not satisfied with our response, you may complain to a supervisory authority.
In Nigeria, that is the Nigeria Data Protection Commission (NDPC):
Nigeria Data Protection Commission
Website: https://ndpc.gov.ng
Email: info@ndpc.gov.ng
In the EU or UK, you may complain to the supervisory authority in your country of residence, place of work, or where the alleged infringement occurred.
We would appreciate the chance to address your concern before you approach a regulator, so please consider contacting us first.