Oct 2, 2026 · @Kiff
This Privacy Policy explains how DeelaMart ("we", "us") collects, uses, shares and protects personal data when you use our websites, mobile apps and related services (the "Platform"). It applies to Customers, Merchants, Couriers and visitors.
DeelaMart acts as the data controller for personal data we collect for our own purposes. Where Merchants or Couriers receive your data to fulfil an Order, they handle it as independent controllers under their own legal duties. By using the Platform, you acknowledge this Policy. Where the law requires your consent, we will ask for it separately.
This Policy should be read with our Terms and Conditions. Capitalised terms not defined here have the meaning given there.
We collect the categories of information below, depending on how you use the Platform.
|
Category |
Examples |
Source |
|---|---|---|
|
Account and contact |
Name, email, phone number, password, profile photo |
You |
|
Order and transaction |
Items ordered, delivery address, order history, delivery notes, tips, promo codes |
You, Merchants, Couriers |
|
Payment |
Payment token, card type and last four digits, billing details, payout bank or wallet details |
You, payment processors |
|
Identity and verification |
Government ID, business registration, licences, vehicle documents, background-check results (Merchants and Couriers) |
You, verification providers |
|
Location |
Delivery address, device location, Courier real-time location and routes |
Your device, Courier app |
|
Device and usage |
IP address, device model, operating system, app version, pages viewed, crash logs, cookie identifiers |
Automatically |
|
Communications |
Support chats, calls, emails, ratings, reviews, photos you upload |
You, our support team |
|
Marketing and survey |
Preferences, campaign responses, survey answers |
You, automatically |
|
Safety and fraud |
Risk signals, account flags, incident reports |
Automatically, users, partners |
We do not intentionally collect sensitive data such as health, religion or biometric data. If you give us allergy or dietary information with an Order, we treat it with extra care and share it only with the relevant Merchant. Where we may use facial or document checks for identity verification, we do so only with your consent and as permitted by law.
We use personal data only where we have a lawful basis, which may be performance of a contract, our legitimate interests, compliance with legal obligations, or your consent.
Automated processing. We use automated tools to match Orders to Couriers, estimate delivery times, detect fraud and rank search results. Where an automated decision significantly affects you, such as an account restriction, you may ask for human review.
We do not sell your personal data for money. We share it only as described below.
We may share aggregated or de-identified data that cannot reasonably identify you.
We use cookies, SDKs, pixels and similar technologies for four purposes:
You can manage non-essential cookies through our cookie banner or settings, and through your browser or device controls. Blocking some cookies may affect how the Platform works. You can also reset or limit your device advertising identifier in your device settings.
We use location data to show nearby Merchants, calculate delivery fees and times, route Couriers, and help keep deliveries safe.
We retain precise location history only as long as needed for the purposes in section 8.
Payments are processed by third-party payment providers that are certified to industry security standards, including PCI DSS. DeelaMart does not store full card numbers; we hold a secure token, the card type and the last four digits.
Merchant and Courier bank or wallet details are collected to pay out earnings and are shared only with payout and banking partners. We may use payment and transaction data to detect fraud, resolve disputes and meet tax and accounting duties.
We keep personal data only as long as needed for the purposes in this Policy, to meet legal duties, or to resolve disputes. Typical periods are below; local law may require longer or shorter periods.
|
Data |
Retention |
|---|---|
|
Account and profile |
While your account is active, then up to 12 months after closure |
|
Order and transaction records |
6 to 7 years, for tax, accounting and dispute purposes |
|
Precise location data |
Up to 90 days after the delivery |
|
Support communications |
Up to 3 years after the issue is closed |
|
Identity and verification documents |
Duration of the relationship plus up to 5 years, or as required by law |
|
Marketing preferences |
Until you withdraw consent or ask us to stop |
|
Device and usage logs |
Up to 24 months |
When data is no longer needed, we delete or anonymise it.
We protect personal data with technical and organisational measures that include encryption in transit and at rest where appropriate, access controls based on role and need, staff confidentiality and training, regular security testing, and vendor due diligence. No system can be completely secure, so please use a strong, unique password and keep it private.
If a breach is likely to put your rights and freedoms at risk, we will notify you and the relevant regulator within the time limits set by Applicable Law.
We and our service providers may process personal data in countries other than where you live, including countries whose data protection laws differ from yours. Where we transfer data across borders, we use lawful safeguards such as standard contractual clauses, adequacy decisions, or other mechanisms recognised by Applicable Law, and require recipients to protect data to a comparable standard.
Depending on where you live, you may have the following rights:
How to exercise them. Use the privacy controls in the app or contact us using the details in section 14. We may need to verify your identity first. We aim to respond within 30 days, or the period required by law, and will explain any refusal.
Marketing choices. Use the unsubscribe link in any email, reply STOP to SMS, or change push notification settings on your device.
Complaints. You may complain to your local data protection authority at any time. We would welcome the chance to address your concern first.
The Platform is for adults aged 18 and over (or the age of majority where you live). We do not knowingly collect personal data from children. If we learn that we have collected data from someone under the minimum age, we will delete it and close the account. If you believe a child has given us data, contact us using the details in section 14.
Their data. We collect business, identity, vehicle, banking, performance and, for Couriers, location data to onboard, verify, pay and support them, and to maintain safety and quality. Background checks are run only where permitted by law and with consent, and we receive the results from the screening provider.
Customer data duties. Merchants and Couriers may use Customer data only to fulfil the relevant Order and as the law allows. They must not store it longer than needed, contact Customers for unrelated purposes, sell or disclose it, or add it to marketing lists without consent. Breach of these duties may lead to suspension and legal action.
Changes. We may update this Policy from time to time. We will post the new version with its effective date and, for material changes, notify you by email or in the app. Where the law requires consent for a change, we will ask for it.
Contact. For questions or to exercise your rights, contact DeelaMart's Data Protection Officer or privacy team: Deela Harvest Limited, 87 Idua Road, Eket, Akwa Ibom State, privacy-policy@deelamart.shop, 08160959418.