NourishGo logonourishgo

Last updated: 1 October 2026

Privacy Policy

How NourishGo collects, uses and protects your personal data, in line with Kenya's Data Protection Act, 2019.

1. Who controls your data

NourishGo is the data controller for the personal data described here. You can reach our data protection contact at hello@nourishgo.co.ke.

2. What we collect

We never store your full card details or M-Pesa PIN. Payments are handled by our payment provider.

  • Account details: name, email address, phone number and a securely hashed password.
  • Vendor details: business name, type, address, contact number and licence or food-handler reference.
  • Transaction data: reservations, pickup codes, payment references, amounts and status.
  • Content you provide: listing text and photographs, and reports you submit about listings.
  • Technical data: IP address and basic request information used for security and rate limiting.

3. Why we use it, and our lawful basis

We do not sell your personal data, and we do not send marketing email without your consent.

  • To provide the service — performance of our contract with you: accounts, reservations, pickups and payouts.
  • To keep people safe — legitimate interest and legal obligation: vendor verification, moderation, fraud prevention and audit records.
  • To communicate — performance of contract: reservation confirmations, pickup receipts and account emails.
  • To improve the service — legitimate interest: anonymous, aggregated usage and impact statistics.

4. Who we share it with

  • Vendors: your name and order details, so they can prepare and hand over your food.
  • Paystack: to process payments securely.
  • Cloudinary: to host listing images uploaded by vendors.
  • Our email provider: to deliver transactional messages.
  • Authorities: where we are legally required to disclose information.

5. How long we keep it

Account data is kept while your account is open. Transaction and audit records are kept for seven years to meet tax, accounting and food-safety obligations. Password reset tokens expire within the hour and are deleted afterwards.

6. Your rights

To exercise any of these, email hello@nourishgo.co.ke. We respond within the statutory timeframe.

  • Ask for a copy of the personal data we hold about you.
  • Ask us to correct data that is wrong or incomplete.
  • Ask us to delete data we no longer need to keep.
  • Object to, or ask us to restrict, certain processing.
  • Complain to the Office of the Data Protection Commissioner (ODPC) in Kenya.

7. Security

Passwords are hashed with bcrypt and never stored in readable form. Sessions use signed, http-only cookies. Access to production data is limited to staff who need it, and privileged actions are written to an audit log.

Questions about this document? Email hello@nourishgo.co.ke and we'll respond within five working days.

Questions about this policy? Contact us at hello@nourishgo.co.ke.

This document is provided for transparency and is not legal advice. NourishGo should have it reviewed by a qualified Kenyan advocate before commercial launch.