Background Pattern
cloud Pattern
LEGAL · PRIVACY POLICY

Privacy Policy

What personal information Recommend collects, why, who we share it with, how long we keep it, and the rights you have over it under Nigerian law.

Last updated 8 October 2026Effective 8 October 2026Brand Collaborator Limited · Lagos, Nigeria
On this page12 sections
1

Introduction and Who We Are

This Privacy Policy describes how Brand Collaborator Limited (“Recommend”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects the personal information of users (“you” or “your”) who interact with our platform, including through WhatsApp, our website, and any related services (collectively, the “Service”).

We are committed to protecting your privacy and processing your personal data responsibly, lawfully, and transparently. This Policy is issued in compliance with:

  • The Nigeria Data Protection Regulation 2019 (NDPR) and its Implementation Framework;
  • The Nigeria Data Protection Act 2023 (NDPA);
  • Any other applicable data protection laws in force in Nigeria.

By using Recommend — including by messaging our WhatsApp line, placing an order, registering as a vendor, or visiting our website — you acknowledge that you have read and understood this Privacy Policy. If you do not agree, you must not use the Service.

This Policy applies to:

  • Buyers who place orders through our WhatsApp channel or website;
  • Vendors (restaurants, grocery stores, pharmacies, and other merchants) registered on our platform;
  • Riders and logistics agents who fulfil deliveries;
  • Visitors to our website or any Recommend-operated digital channel.

Governing Law

This Policy is governed by and construed in accordance with the laws of the Federal Republic of Nigeria. Any disputes shall be subject to the exclusive jurisdiction of the courts of Lagos State, Nigeria.

2

Information We Collect

We collect personal information in the following categories:

2.1 Information You Provide Directly

  • Identity data: full name, phone number, email address;
  • Delivery data: delivery address, landmark notes, geolocation (where provided);
  • Account data: login credentials, account preferences;
  • Order data: items ordered, vendor selected, special instructions;
  • Payment data: transaction references, payment method type (we do not store full card numbers; payment processing is handled by licensed third-party payment processors);
  • Vendor onboarding data: business name, CAC registration details, bank account details, menu information, operating hours;
  • Rider/logistics data: name, phone, vehicle details, National ID or driver’s licence number, bank account details.

2.2 Information Collected Automatically

  • Chat metadata: timestamps, message delivery status, WhatsApp phone number, chat session data generated through WhatsApp Business API;
  • Device and technical data: IP address, device type, operating system, browser type, referring URL;
  • Usage data: pages visited, features used, click patterns, session duration;
  • Location data: approximate or precise location, where enabled by you on your device.

2.3 Information from Third Parties

  • Data from payment processors confirming transaction status;
  • Data from logistics partners (Whoosh NG and others) confirming delivery status;
  • Data from WhatsApp / Meta Platforms Inc. relating to message delivery and business account metrics;
  • Publicly available business information used for vendor verification.

2.4 Special Categories of Data

We do not intentionally collect special categories of personal data (such as health, biometric, religious, or political data). If such data is incidentally shared with us, it will be deleted as soon as it is identified, unless we are required by law to retain it.

2.5 Sensitive Financial Data

All payment card data is processed directly by PCI-DSS-compliant third-party payment processors. We store only payment transaction references and status confirmations — never full card numbers, CVV codes, or bank PINs.

3

How We Use Your Information

We process personal data only for lawful purposes and on one or more of the following legal bases under the NDPR and NDPA:

PurposeLegal Basis
Processing and fulfilling your ordersPerformance of a contract
Verifying vendor and rider identityLegal obligation; Legitimate interest
Processing paymentsPerformance of a contract
Sending transactional notifications (order confirmed, rider dispatched, delivered)Performance of a contract
Communicating service updates and changes to this PolicyLegitimate interest
Sending promotional messages (where opted in)Consent
Fraud detection, security, and abuse preventionLegitimate interest; Legal obligation
Complying with a court order, regulatory request, or law enforcement demandLegal obligation
Improving and developing the Service through analyticsLegitimate interest
Resolving disputes and enforcing our Terms of ServiceLegitimate interest; Legal obligation

3.1 Marketing Communications

We will only send you marketing or promotional messages via WhatsApp, email, or SMS if you have given us explicit consent or opted in. You may withdraw consent at any time by replying STOP to any WhatsApp marketing message or by contacting us at legal@getrecommend.co. Withdrawal of consent does not affect the lawfulness of processing before withdrawal.

3.2 Automated Decision-Making

We may use automated processes to match your order request to nearby vendors, calculate delivery fees, and detect potentially fraudulent activity. These automated processes do not produce legal or similarly significant effects on you. Where a decision may significantly affect you (for example, suspension of a vendor or rider account), a human review will be conducted upon request.

4

Sharing and Disclosure

We do not sell your personal data. We share your personal data only in the following limited circumstances:

4.1 Vendors

When you place an order, we share your name, phone number, delivery address, and order details with the relevant vendor to enable fulfilment. Vendors are contractually prohibited from using your data for any purpose other than fulfilling your order.

4.2 Logistics and Delivery Partners

We share your name, phone number, and delivery address with our logistics partner (currently Whoosh NG and any successor or additional logistics providers) solely to enable delivery. Logistics partners are not permitted to use your data for marketing or any secondary purpose.

4.3 Payment Processors

Payment data is processed by third-party payment service providers licensed by the Central Bank of Nigeria (CBN). These providers process payment data under their own privacy policies and applicable PCI-DSS standards. We share only what is necessary to complete the transaction.

4.4 Service Providers and Sub-Processors

We may engage trusted third-party service providers (“sub-processors”) to operate parts of the Service, including cloud hosting, SMS/email delivery, analytics, and customer support tools. All sub-processors are bound by data processing agreements that prohibit them from using your data for purposes beyond the services they provide to us.

4.5 Legal and Regulatory Disclosure

We may disclose personal data if required to do so by law, court order, or a valid request from a government authority, law enforcement agency, or regulatory body in Nigeria. We will, where legally permitted, notify you of such a request before disclosing.

4.6 Business Transfers

In the event of a merger, acquisition, restructuring, or sale of all or part of our assets, your personal data may be transferred to the successor entity. We will notify you of any such transfer via WhatsApp or email and will ensure the successor entity is bound by terms at least as protective as this Policy.

4.7 Aggregated and Anonymised Data

We may share aggregated, de-identified, or anonymised data (which cannot reasonably be used to identify you) with partners, investors, or for public reporting. This is not subject to this Policy.

4.8 No Cross-Border Transfers Without Safeguards

If we ever transfer personal data outside Nigeria, we will only do so in compliance with the NDPA requirements, including ensuring the receiving country provides adequate protection or that appropriate contractual safeguards are in place.

5

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, as required by law, or as needed to resolve disputes and enforce our agreements. The following general periods apply:

Category of DataRetention PeriodReason
Order history and transaction records7 years from date of transactionNigerian tax and commercial law obligations
Customer account dataDuration of account + 2 years after deletionDispute resolution; fraud prevention
Payment transaction references7 yearsCBN and FIRS compliance
Vendor and rider identity documentsDuration of engagement + 3 yearsRegulatory compliance; potential claims
Marketing consent recordsUntil consent withdrawn + 1 yearProof of lawful processing
WhatsApp chat logs12 months from last interactionService improvement; dispute resolution
Device and usage/analytics data12 monthsAnalytics; service improvement
Data subject rights requests and responses5 yearsRegulatory audit trail

Upon expiry of the applicable retention period, personal data will be securely deleted or anonymised such that it can no longer be associated with you. We will not retain data solely on the basis that it may conceivably become useful in the future.

You may request earlier deletion of your data in accordance with Section 6 of this Policy, subject to our legal retention obligations.

6

Your Rights Under the NDPR

Under the Nigeria Data Protection Regulation 2019 and the Nigeria Data Protection Act 2023, you have the following rights regarding your personal data:

6.1 Right of Access

You may request a copy of the personal data we hold about you and information about how we process it.

6.2 Right to Rectification

You may request that we correct inaccurate or incomplete personal data about you without undue delay.

6.3 Right to Erasure (“Right to be Forgotten”)

You may request deletion of your personal data where: (a) the data is no longer necessary for the purpose it was collected; (b) you withdraw consent and there is no other lawful basis; (c) the data has been unlawfully processed; or (d) deletion is required to comply with a legal obligation. We will honour erasure requests unless we are required or entitled by law to retain the data.

6.4 Right to Restriction of Processing

You may request that we restrict processing of your personal data in certain circumstances, for example while the accuracy of the data is contested.

6.5 Right to Data Portability

Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.

6.6 Right to Object

You may object at any time to processing of your personal data that is based on our legitimate interests, including profiling. We will cease such processing unless we can demonstrate compelling legitimate grounds that override your interests.

6.7 Right to Withdraw Consent

Where we rely on your consent as the lawful basis for processing, you may withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing before the withdrawal.

6.8 How to Exercise Your Rights

Submit a written request to legal@getrecommend.co

We will respond within 30 days of receiving a verifiable request. We may request identity verification before processing your request. There is no fee for exercising your rights unless a request is manifestly unfounded or excessive.

6.9 Right to Lodge a Complaint

If you believe we have violated your data protection rights, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC):

You may also seek civil redress through the courts of Nigeria.

7

Children’s Privacy

Our Service is not directed at children under the age of 18. We do not knowingly collect or process personal data from individuals under 18 years of age.

If you are a parent or legal guardian and you believe your child has provided us with personal data without your consent, please contact us immediately at legal@getrecommend.co. We will take prompt steps to delete such data from our systems.

If we discover that we have inadvertently collected personal data from a child under 18, we will delete it without delay unless we are required by law to retain it.

Vendors and riders must be aged 18 or over to register on the platform. By registering, you confirm that you are 18 years of age or older.

8

WhatsApp and Third-Party Platforms

Recommend operates through WhatsApp Business, a platform owned and operated by Meta Platforms, Inc. By communicating with us through WhatsApp, you acknowledge and agree that:

8.1 Meta Data Processing

WhatsApp and Meta collect and process data about your messages and interactions in accordance with Meta’s own Privacy Policy and WhatsApp’s Privacy Policy. We have no control over and accept no responsibility for the data processing practices of Meta or WhatsApp. You are encouraged to review WhatsApp’s Privacy Policy at www.whatsapp.com/legal/privacy-policy.

8.2 Message Content

Messages you send through WhatsApp to Recommend are received and stored by us for the purpose of processing your orders and responding to your enquiries. We cannot guarantee the security of data in transit over WhatsApp’s infrastructure.

8.3 WhatsApp Business API

We use the WhatsApp Business API, provided by Meta or an authorised Business Solution Provider (BSP). Our BSP is bound by Meta’s partner terms and applicable data protection obligations.

8.4 Other Third-Party Links

Our Service may contain links to third-party websites, applications, or services. We are not responsible for the privacy practices of those third parties. We strongly encourage you to read the privacy policy of every third-party site or service you visit.

8.5 Payment Platforms

Payments are processed through third-party payment platforms. Their data practices are governed by their own privacy policies and are subject to CBN regulation. We are not responsible for data breaches or misuse by payment processors, provided we have taken reasonable steps to engage reputable, licensed processors.

9

Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or disclosure. These measures include:

  • Encryption of data in transit (TLS/SSL) and at rest where technically feasible;
  • Access controls ensuring that only authorised personnel can access personal data, limited to what is necessary for their role;
  • Regular review of our data handling practices and security procedures;
  • Contractual obligations imposed on all data processors and sub-processors;
  • Employee training on data protection obligations.

9.1 Limitations

No method of electronic transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the Nigeria Data Protection Commission (NDPC) within 72 hours of becoming aware of the breach, and will notify affected individuals without undue delay in accordance with the NDPA.

9.2 Your Responsibility

You are responsible for keeping your WhatsApp account and any access credentials secure. Do not share your order confirmation codes, one-time passwords (OTPs), or any account credentials with anyone, including persons claiming to represent Recommend.

We will never ask for these

We will never ask you for your password, OTP, or full card details via WhatsApp or any other channel.

10

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, applicable law, or the Service. When we make material changes, we will:

  • Update the “Last Updated” date at the top of this Policy;
  • Notify registered users via WhatsApp message or email at least 14 days before the changes take effect;
  • Where required by law, obtain your consent before applying changes that materially affect how we process your personal data.

Your continued use of the Service after the effective date of any revised Policy constitutes your acceptance of the changes. If you do not agree with a revised Policy, you must stop using the Service and may request deletion of your account.

All previous versions of this Policy are archived and available upon request by contacting legal@getrecommend.co.

11

Contact and Complaints

11.1 Contact Us

For any questions, requests, or concerns regarding this Privacy Policy or our data practices, please contact our designated Data Protection Officer (DPO) or Privacy Contact:

We will acknowledge your request within 5 business days and endeavour to resolve it within 30 days.

11.2 Complaints to the NDPC

If you are not satisfied with our response to a data protection concern, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC):

11.3 Mandatory Data Protection Compliance Notice

In accordance with the NDPR, Brand Collaborator Limited has conducted a Data Protection Impact Assessment (DPIA) for high-risk processing activities and has filed the required Annual Data Protection Audit with a licensed Data Protection Compliance Organisation (DPCO) as mandated by the NDPA 2023.

12

Limitation of Liability

12.1 Liability Cap

To the maximum extent permitted by applicable Nigerian law, the total aggregate liability of Brand Collaborator Limited, its directors, officers, employees, agents, and assigns arising out of or in connection with this Privacy Policy or the processing of your personal data shall not exceed the greater of:

  • The value of the single transaction or order to which the claim relates; or
  • Ten Thousand Naira (NGN 10,000)

whichever is lower.

12.2 Exclusion of Consequential Loss

Brand Collaborator Limited shall not be liable — whether in contract, tort (including negligence), breach of statutory duty, or otherwise — for any:

  • Loss of profit, revenue, or anticipated savings;
  • Loss of business, contracts, or goodwill;
  • Loss of data or corruption of data (beyond the obligations set out in Section 9);
  • Indirect, incidental, special, punitive, or consequential loss or damage;

arising out of or in connection with this Privacy Policy or the use of the Service, even if we have been advised of the possibility of such losses.

12.3 Third-Party Platforms

We are not liable for the data practices, security incidents, outages, or privacy failures of:

  • Meta Platforms Inc. (WhatsApp, Instagram, Facebook);
  • Payment processors (Paystack, Flutterwave, or any other payment gateway);
  • Logistics and dispatch partners (including but not limited to Whoosh NG and Legbegbe);
  • Any other third-party service, API, or platform integrated with or accessible through the Service.

Your use of those platforms is governed by their own terms and privacy policies. We disclaim all liability arising from your interactions with such platforms.

12.4 User Indemnification

You agree to indemnify, defend, and hold harmless Brand Collaborator Limited and its directors, officers, employees, and agents from and against any claims, liabilities, damages, losses, costs, and expenses (including reasonable legal fees) arising out of or in connection with:

  • Your breach of this Privacy Policy or our Terms of Service;
  • Your misuse of the Service or submission of false, inaccurate, or misleading information;
  • Any violation by you of applicable law, including the NDPR and NDPA 2023;
  • Any claim by a third party arising from data you shared through the Service about another person without their consent.

12.5 Force Majeure

We shall not be in breach of this Privacy Policy nor liable for any failure or delay in our obligations under this Policy where such failure or delay results from any cause beyond our reasonable control, including but not limited to: acts of God, telecommunications failures, internet outages, cyberattacks by third parties, government action, regulatory directives, civil unrest, or national emergencies. In such circumstances, our obligations are suspended for the duration of the event, and we will use reasonable endeavours to resume normal operations as soon as practicable.

12.6 No Waiver

No failure or delay by us in exercising any right or remedy under this Policy shall constitute a waiver of that right or remedy. A waiver of any breach of this Policy shall not constitute a waiver of any subsequent breach.

12.7 Severability

If any provision of this Privacy Policy is found by a court or regulatory authority of competent jurisdiction to be invalid, unlawful, or unenforceable, that provision shall be deemed severed from the Policy. The remaining provisions shall continue in full force and effect to the maximum extent permitted by law.

12.8 Entire Agreement

This Privacy Policy, together with our Terms of Service and any other policies published on our website or communicated through the Service, constitutes the entire agreement between you and Brand Collaborator Limited regarding the collection, use, and protection of your personal data, and supersedes all prior representations, understandings, or agreements on that subject.

Last updated 8 October 2026.

Back to top