Privacy Policy
Last updated: [June 29, 2026]
1. Scope of This Policy
This Privacy Policy explains how Menyoo Innovations LTD ("Menyoo," "we," "us") collects, uses, discloses, and protects personal data in connection with the Menyoo hospitality ERP platform (the "Platform"). It applies to three groups of people, whose data we handle differently, as explained below:
- Merchants — businesses that register a Menyoo account, and the individuals who own or represent them;
- Staff — employees of a Merchant whose records (including HR and payroll data) are entered into the Platform by that Merchant;
- Customers — individuals who place an order with a Merchant through the Platform's ordering interface.
2. Our Role: Controller and Processor
Under the Nigeria Data Protection Act 2023 ("NDPA"), the entity that decides why and how personal data is processed is the "data controller," and an entity that processes data on a controller's instructions is a "data processor." Menyoo holds both roles, depending on whose data is involved:
Practical effect: if you are a Staff member or Customer of a Menyoo Merchant and want to exercise a data protection right (access, correction, deletion, and so on), your request should generally go to that Merchant first, since they control the purpose of the processing. If you contact us directly, we will assist and, where appropriate, forward your request to the relevant Merchant.
3. Data We Collect
Merchant Account Data
| Category | Examples |
|---|---|
| Business details | Business name, address, business type, subscription plan |
| Representative details | Name, email, phone number of the account owner/administrators |
| Billing data | Bank details for payouts, transaction history (payment card data itself is handled by our payment processor, not stored by Menyoo) |
Staff (Employee) Data — processed on the Merchant's behalf
| Category | Examples |
|---|---|
| Personal details | Full name, phone, email, date of birth, photo |
| Emergency contact | Name and phone number of an emergency contact |
| Employment details | Department, job title, start date, shift and attendance records, leave records |
| Banking & tax data | Bank account details and tax identification, used for payroll processing |
Banking, tax, and date-of-birth data are treated as sensitive and are only accessible within a Merchant account to Administrator/Owner-level roles, consistent with the access controls described in Section 9.
Customer (Order) Data — processed on the Merchant's behalf
| Category | Examples |
|---|---|
| Order details | Name, phone number, email, delivery address, order contents and history |
| Payment status | Whether an order was paid and by what method (card data itself is handled by our payment processor) |
Technical & Usage Data
We automatically collect limited technical data when the Platform is used, including IP address, browser/device type, and usage logs, for security, fraud prevention, and service improvement purposes.
4. Legal Basis for Processing
We process personal data under the following lawful bases recognized by the NDPA:
- Contract — to provide the Platform to a Merchant, or to enable an order between a Customer and a Merchant;
- Legal obligation — for example, tax and employment record-keeping requirements;
- Legitimate interest — for security, fraud prevention, and improving the Platform, balanced against individual rights;
- Consent — for optional communications, such as marketing messages, which can be withdrawn at any time.
5. How We Use Data
- To provide, maintain, and improve the Platform's features;
- To process orders, payroll runs, and purchasing transactions as instructed by Merchants;
- To send order notifications, account communications, and (where consented to) marketing messages;
- To detect and prevent fraud, abuse, and security incidents;
- To comply with legal and regulatory obligations.
6. Data Sharing & Third Parties
We share personal data with the following categories of third parties, only as necessary to provide the Platform:
- Payment processors (including Paystack) — to process card and bank payments;
- Communication providers — SMS and email delivery services used for order notifications and Merchant-initiated marketing campaigns;
- Hosting and infrastructure providers — who store and process data on our behalf under contractual confidentiality and security obligations;
- Regulators and law enforcement — where required by law.
We do not sell personal data to third parties.
7. Cross-Border Data Transfer
Our servers and database are hosted in the U.S. Where personal data is transferred outside Nigeria, we rely on the safeguards recognized under the NDPA (including adequacy decisions, standard contractual clauses, or other approved transfer mechanisms) to ensure the data remains protected to a standard consistent with Nigerian law.
8. Data Retention
We retain personal data for as long as a Merchant account is active, and for a reasonable period afterward to comply with legal obligations (including tax and employment record- keeping requirements, which can require retention of payroll records for 6 years or longer under applicable Nigerian law), resolve disputes, and enforce our agreements. Merchants can request export of their data before account closure as described in our Terms of Use.
9. Data Security
We apply technical and organizational measures appropriate to the sensitivity of the data we process, including:
- Encrypted connections (TLS) for data in transit;
- Role-based access controls, so sensitive data (banking, tax, payroll) is restricted to Administrator/Owner-level accounts;
- Session-based authentication and account activity logging;
- Ongoing review of security practices as the Platform evolves.
No system is completely secure, and we cannot guarantee absolute security, but we are committed to promptly investigating and addressing any suspected breach.
10. Your Rights
Subject to the controller/processor distinction in Section 2, and to the extent you are dealing directly with Menyoo as controller, you have the right to:
- Access the personal data we hold about you;
- Correct inaccurate or incomplete data;
- Request deletion of your data, subject to our legal retention obligations;
- Object to or restrict certain processing, including marketing;
- Request a copy of your data in a portable format;
- Withdraw consent at any time, where processing is based on consent;
- Lodge a complaint with the Nigeria Data Protection Commission (NDPC) if you believe your data protection rights have been violated.
To exercise any of these rights, contact us at hi@menyoo.ng. We will respond within the timeframe required under the NDPA.
11. Children's Data
The Platform is intended for business use and is not directed at children. We do not knowingly collect personal data from individuals under the age recognized under the Child Rights Act 2003 and the NDPA without appropriate parental/guardian consent. If you believe a child's data has been provided to us without appropriate consent, contact us so we can remove it.
12. Cookies
We use cookies and similar technologies to keep you logged in, remember preferences, and understand how the Platform is used. You can control cookies through your browser settings; disabling some cookies may affect Platform functionality.
13. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the NDPC and affected individuals as required under the NDPA and the General Application and Implementation Directive 2025, without undue delay.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified to Merchants by email or through the Platform at least 7 days before taking effect.
15. Contact
Questions about this Privacy Policy, or requests to exercise your data protection rights, can be sent to:
Menyoo Innovations LTD
Email: hi@menyoo.ng
WhatsApp: +44 7348 595040
You may also lodge a complaint directly with the Nigeria Data Protection Commission at ndpc.gov.ng.
Terms of Use →
