TablaOne

Legal

Privacy Policy

What we collect, why, who else touches it, how long we keep it, and how to ask for a copy or for deletion.

Draft: needs legal review before launch.

Last updated: 5 October 2026

1. Who this covers

This policy covers TablaOne, the table ordering service for restaurants in Nigeria, and everyone whose data passes through it: restaurant owners and staff, and guests who order at a table. It is written with the Nigeria Data Protection Act 2023 in mind. It does not claim that TablaOne has been audited or certified under that Act or any other standard.

Payments are processed by vyyBe Bank, which has its own privacy terms for its accounts and wallets.

2. What we collect

Restaurant owners and staff

  • Name, email address and phone number.
  • A hash of the password. We never store the password itself.
  • The restaurant's CAC number and each branch's address.
  • KYC documents for verification: the CAC certificate, a director's ID and a proof of address for the branch. They are kept in private storage, not on the public web, and are described to vyyBe Bank for verification.
  • The role each person holds (owner, manager or kitchen) and, if turned on, a two-factor secret and backup codes.

Guests

  • An anonymous session cookie, t1_guest, that lasts 30 days. It does not contain a name or a phone number.
  • What was ordered, the note to the kitchen, and the table number.
  • An email address or phone number only if the guest asks for a receipt.
  • A rating only if the guest leaves one.
  • Card details never reach TablaOne. They go to the licensed payment processor. For wallet payments, vyyBe Bank gives TablaOne a payer id, which is used only to award Ascend points.

Operational records

  • An audit log of staff actions: who accepted, declined, refunded, paused, or changed the menu, and when.
  • A delivery log of the emails and SMS messages we send: to whom, when, and whether they arrived.
  • Webhook events from vyyBe Bank about payments, settlements, refunds and verification.

3. Cookies and browser storage

  • t1_session: sign-in for owners and staff. 14 days, or 30 days on a kitchen tablet.
  • t1_guest: the anonymous guest session. 30 days.
  • Browser storage on the guest's phone holds the cart and recent orders; on a kitchen tablet it holds console preferences such as sound. It never leaves the device.
  • There are no analytics or advertising cookies, so there is no cookie banner.

4. Who else processes it

  • vyyBe Bank processes payments, settlements and refunds, and verifies restaurants. It receives the order amount, the payment method and, for verification, the descriptions of the KYC documents.
  • An email provider and an SMS provider deliver receipts, notifications and acknowledgements. They receive the address or number and the message.
  • We do not sell data and do not share it with advertisers.

5. How long we keep it

These periods are the current settings and are flagged for legal review.

  • Guest sessions: 90 days.
  • Orders and settlements: 7 years, as financial records.
  • KYC documents: 5 years after the restaurant stops being live.
  • Email and SMS delivery logs: 90 days.
  • Audit log: 7 years.

6. Your rights

You can ask for a copy of the data we hold about you, or ask us to delete it. Use the form below. We reply to the email address you give. Records we must keep as financial records, such as paid orders and settlements, are kept for their retention period even after a deletion request, and we tell you which.

The address we hold for you: your sign-in email, or the receipt email you gave as a guest.

7. Changes

We may change this policy. The date at the top says when it last changed.

8. Contact

Anything else about privacy goes through the contact page.