1. Scope and who this applies to
Ordara is a software-as-a-service platform used by restaurants, cafés, hotels, and other food-and-beverage businesses ("Customers", "you") to manage orders, inventory, staff, payments, and customer-facing ordering. This policy covers:
- Customers: the businesses that sign up for and administer an Ordara account.
- Authorized users: staff, managers, and owners a Customer invites into their Ordara account.
- End customers: the diners and guests who place orders, make reservations, or make payments through a Customer's Ordara-powered ordering site, QR menu, or point of sale.
- Site visitors: anyone browsing getordara.com, including prospects filling out our contact form.
This policy is written to meet the expectations of major privacy laws worldwide, including the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA, Nigeria's Data Protection Act 2023 (NDPA) and NDPR, Canada's PIPEDA, and Brazil's LGPD. Where local law gives you stronger or different rights than described here, local law controls.
2. Two roles: controller and processor
Because Ordara is B2B software that businesses use to run their own operations, we act in two different capacities, and it matters which one applies to your data:
- As a data controller: for account and billing data about our Customers, marketing data about site visitors and prospects, and data about our own employees and vendors. Here, we decide why and how the data is processed, and this policy is our primary privacy notice to you.
- As a data processor (or "service provider"): for the data a Customer's End customers hand over when they order food, book a table, or pay through that Customer's Ordara-powered ordering site or POS. Here, the restaurant is the controller. We process that data only on the restaurant's instructions and under a data processing agreement, to provide the service. If you are an end customer of a restaurant using Ordara and have a privacy question about your order, please contact that restaurant directly. We can point you to them if you contact us.
3. Data we collect
Account and business data (from Customers, as controller): name, business name, email, phone number, business address, tax/VAT identifiers, staff accounts and role permissions, and communications with our sales or support team.
Billing data: billing contact details and subscription history. Card and bank details are collected and stored by our payment processors (such as Paystack and Flutterwave), not by Ordara directly. See Section 6.
Operational data (processed on a Customer's behalf, as processor): menu items and pricing, table layouts, inventory levels, order and kitchen ticket records, sales and tax reports, and staff shift records that a Customer enters or that flow through their point of sale.
End customer data (processed on a Customer's behalf, as processor): names, phone numbers, delivery addresses, order history, loyalty information, and payment confirmations submitted when placing an order, booking a table, or paying through a Customer's ordering site, QR menu, or point of sale.
Usage and device data: log data, IP address, browser and device type, pages viewed, and approximate location inferred from IP, collected automatically when you use our website, dashboard, or apps.
Cookies and similar technologies: as described in Section 10.
Enquiry data: information you submit through our website contact form (name, email, subject, and message), used to respond to your enquiry.
4. How we use data
- To provide, maintain, and secure the Ordara platform, including order processing, inventory sync, payment reconciliation, and reporting.
- To create and administer Customer accounts, and to authenticate staff logins.
- To process payments and prevent fraud, in conjunction with our payment processors.
- To provide customer support and respond to enquiries.
- To send service communications (billing notices, security alerts, product updates) and, where you've opted in, marketing communications.
- To monitor, debug, and improve platform performance and reliability.
- To comply with legal, tax, and regulatory obligations.
- To detect, investigate, and prevent fraud, abuse, and security incidents.
We do not use End customer data collected on a Customer's behalf for our own advertising purposes, and we do not sell personal data.
5. Our legal bases for processing
Where GDPR or a similar framework applies, we rely on one or more of the following legal bases:
- Contract: processing needed to provide the Ordara service you or your business signed up for.
- Legitimate interests: for security, fraud prevention, service improvement, and direct marketing to existing business customers, balanced against your rights.
- Consent: for optional cookies, marketing to prospects, and any other case where we ask for it. You can withdraw consent at any time.
- Legal obligation: for tax records, financial reporting, and responding to lawful requests from authorities.
7. International data transfers
Ordara serves restaurants across multiple countries, and our infrastructure and sub-processors may be located outside your country of residence, including outside the EU/EEA, UK, or Nigeria. Where we transfer personal data internationally, we use recognized safeguards such as Standard Contractual Clauses, adequacy decisions, or equivalent mechanisms required by applicable law, and we require recipients to protect data to a standard consistent with this policy.
8. Data retention
We retain personal data for as long as needed to provide the service and for legitimate business purposes, such as maintaining financial and tax records, resolving disputes, and enforcing our agreements. Retention periods vary by data type and are influenced by local statutory requirements (for example, tax and accounting laws typically require order and payment records to be kept for several years). When data is no longer needed, we delete or anonymize it, or securely archive it where deletion is not immediately possible.
If a Customer closes their Ordara account, we retain their business and End customer data for a limited transition period to allow data export, then delete it in line with our standard retention schedule, unless a longer period is required by law.
9. Security
We use administrative, technical, and physical safeguards designed to protect personal data, including encryption of data in transit, access controls and role-based permissions, regular security reviews, and staff training. No system is completely secure, and we encourage Customers to use strong, unique passwords and to manage staff access carefully within their account.
11. Your rights, by region
Depending on where you live, you generally have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, contact us using the details in Section 15; we will verify your request and respond within the timeframe required by applicable law.
European Economic Area, UK, and Switzerland (GDPR / UK GDPR): you have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your local data protection authority.
Nigeria (NDPA 2023 / NDPR): you have the right to access, correct, and request deletion of your personal data, to object to processing, and to lodge a complaint with the Nigeria Data Protection Commission (NDPC).
California, USA (CCPA/CPRA): California residents have the right to know what personal information is collected, to request deletion or correction, to opt out of the sale or sharing of personal information (Ordara does not sell personal information), and to non-discrimination for exercising these rights.
Other US states with comprehensive privacy laws (including but not limited to Virginia, Colorado, Connecticut, and Utah): you have similar rights to access, correct, delete, and opt out of targeted advertising or profiling, which we will honor on request.
Canada (PIPEDA): you have the right to access your personal information, challenge its accuracy, and withdraw consent, subject to legal and contractual restrictions.
Brazil (LGPD): you have the right to confirmation of processing, access, correction, anonymization, portability, deletion, and information about entities we share data with.
If you are an End customer of a restaurant that uses Ordara, some of these rights are best exercised directly with that restaurant, since they control your order and account data; we will assist them, and you, on request.
12. Children's privacy
Ordara is intended for business use and is not directed at children. We do not knowingly collect personal data from children under 16 (or the minimum age required by local law) for our own controller purposes. If you believe a child has provided us with personal data, contact us and we will take appropriate steps to delete it.
13. Breach notification
If we become aware of a security incident affecting personal data, we will investigate and, where required by applicable law, notify affected Customers and relevant regulators without undue delay, along with information to help affected individuals protect themselves.
14. Changes to this policy
We may update this policy as our service, legal obligations, or industry practices evolve. We will update the "Last updated" date above and, for material changes, provide additional notice, such as an email to account administrators or a notice within the Ordara dashboard, before the change takes effect.
15. Contact us
For privacy questions, requests, or complaints, contact us at:
Ordara Labs
300 Adeola Odeku St, Victoria Island,
Lagos 101241, Nigeria
Email: hello@getordara.com
Phone: 08107275865
You can also reach us through our contact page.