01What this policy covers
This Privacy Policy explains what personal information Orderly collects, why we collect it, who we share it with, and the controls you have. It applies to everyone who interacts with Orderly — vendors who run a store on the platform, customers who buy from those stores, marketers who refer vendors to us, and visitors to our marketing site.
Two roles to keep in mind throughout this policy: when you sign up as a vendor, Orderly is the data controller for your account information. When your customers shop on a storefront you operate, you are the data controller for their information and Orderly is your data processor — we hold and process customer data on your behalf so we can run your store.
02What we collect
The information we hold falls into a few buckets:
- Account information you give us when you sign up: name, email, phone number, country, password (hashed — we never see the plain text), and the role you signed up under (vendor, marketer, staff member).
- Store information you upload while operating your store: business name, logo, products, prices, working hours, delivery zones, payout bank account, custom domain.
- Customer informationcreated when someone buys from your store: name, phone, email, delivery address, order details. This is your customers' data — we hold it on your behalf.
- Payment informationwhen a payment is made on the platform: amount, status, the masked reference returned by our payment switch, the gateway's authorisation token (for saved-card flows on the customer side, where you've offered them). We do not store full card numbers, CVVs, or bank login credentials — those go directly to the payment switch and are never visible to us.
- Usage and device information automatically collected when you use Orderly: IP address, browser/device type, pages and actions, timestamps. We use this to keep the service running, detect abuse, and improve the product.
- Communications you send us: support emails, in-app messages, feedback. We keep these so we can follow up and improve.
03How we use it
We use the information above for:
- Running the service — authenticating you, rendering your dashboard and storefront, processing orders, sending payouts to your bank, fulfilling staff invitations.
- Communicating with you — order notifications, receipts, password resets, subscription expiry reminders, security alerts. Marketing emails are opt-in only and you can unsubscribe at any time.
- Keeping the platform safe — detecting fraud, blocking abuse, investigating chargebacks, enforcing our Terms of Service.
- Improving Orderly — understanding which features are used, where vendors get stuck, where customers drop off in checkout. Where possible we look at this in aggregate, not per-user.
- Legal and compliance obligations — keeping financial records, responding to lawful requests from authorities, defending claims.
05Your customers' data
When someone buys from your store, the personal information they enter (name, phone, address, email) belongs to them. You decide what to do with it within the limits of the law that applies to you. Orderly stores it on your behalf and exposes it back to you through your dashboard.
You agree to handle that information lawfully — only collecting what you need to fulfil orders, only contacting customers about their orders unless they've agreed to wider marketing, and honouring any access, correction, or deletion request they make. If a customer asks Orderly directly to access or delete their data, we'll route that request to you and help you action it.
07How long we keep it
We keep your information for as long as your account is active, and for a reasonable period after you close it so we can complete pending obligations and meet legal record-keeping duties. Concretely:
- Account data is kept while the account exists and for up to 90 days after deletion (in case you change your mind), then permanently removed.
- Order, payment, and payout records are kept for at least 7 years to meet financial record-keeping requirements in Nigeria.
- Anonymised usage logs may be kept indefinitely for product analytics — these can't be tied back to you.
08Your rights
You have the right to:
- Access the personal information we hold about you.
- Correctanything that's wrong (most of this you can do yourself in your account settings).
- Export your orders, customers, and catalog to CSV at any time, from the dashboard.
- Delete your account and the personal data tied to it. Deletion is permanent.
- Object to specific uses (e.g., opt out of marketing email) without giving up the rest of the service.
- Lodge a complaintwith the Nigeria Data Protection Commission (NDPC) if you believe we've mishandled your data.
To exercise any of these rights, email privacy@orderlystores.com. We respond within 30 days.
09How we protect your data
We protect your information with industry-standard technical and organisational measures: TLS in transit, encryption at rest for sensitive fields, hashed passwords, narrow access controls inside Orderly, and audit logging on admin actions. Card details are never stored on our servers — they go directly to our payment switch.
No system is perfect. If we ever detect a breach that materially affects your data, we'll notify you and the relevant authority within the timeframes the law requires.
10Children
Orderly is not intended for use by anyone under 18. We do not knowingly collect personal information from children. If you believe a child has given us their information, contact us and we'll remove it.
11International transfers
Some of our service providers (cloud hosting, email, image CDN, analytics) operate outside Nigeria. When your data crosses borders we rely on the data-protection commitments those providers make to us, and on the legal bases permitted under Nigerian data-protection law.
12Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced via email and the dashboard at least 14 days before they take effect. The "Last updated" date at the top of the page tells you the most recent revision.
13Contact
Questions about this policy or how we handle your data? Email privacy@orderlystores.com.
