Privacy Policy
Last updated: 27 April 2026
1. Who we are
OrderBridge ("we", "us") provides a mobile-first order-management platform for merchants. This policy explains what data we collect and how we use it.
2. Data we collect
- Account data: business name, email, phone number, password (hashed).
- Order data: orders, customers, products, and notes you create or import.
- Payment data: billing reference and subscription status (full card data is handled by Paystack and never stored on our servers).
- Usage data: log files, IP address, device, and browser information for security and debugging.
3. How we use it
- To provide, secure, and improve the Service
- To process payments and manage subscriptions
- To send essential service emails (receipts, security alerts)
- To comply with legal obligations
We do not sell your data, and we do not use it for advertising.
4. Sub-processors
We share data only with the providers required to run the Service:
- Supabase — database, authentication, file storage (EU/US regions).
- Paystack — payment processing (Nigeria).
- Cloudflare — content delivery and DDoS protection.
5. Your customers' data
You are the data controller for the customer information you store in OrderBridge. We act as the data processor under your instructions. You must obtain any required consents from your customers.
6. Security
We use TLS in transit, encryption at rest, row-level access control, and regular backups. No system is perfectly secure; you use the Service at your own risk.
7. Retention & deletion
We retain your data for as long as your account is active. You can delete your account at any time from Settings → Danger Zone; this permanently removes your data within 30 days, except where we are legally required to retain certain records (e.g. payment records for tax purposes).
8. Your rights (NDPA 2023 / GDPR)
You have the right to access, correct, export, or delete your personal data.
Email privacy@getorderbridge.com to exercise these rights.
9. Children
The Service is not directed to anyone under 18. We do not knowingly collect data from children.
10. International transfers
Your data may be processed outside Nigeria by our sub-processors. We require them to apply safeguards equivalent to NDPA standards.
11. Changes
We will notify you of material changes by email or in-app notice at least 14 days before they take effect.
12. Contact
Privacy questions? Email privacy@getorderbridge.com.
See also our Terms of Service.