Legal
Privacy policy
How we handle personal data across the islands we serve, and the stricter rule we apply where local laws differ.
Version 2026-09-01 · baseline policy, applies wherever a market has not published its own
What we collect
- Account details: name, email, phone number, preferred language and island.
- Order details: what you ordered, where it was delivered, how you paid (never full card numbers), receipts and any refund history.
- Location: the delivery point you confirm, and — only while you have an order in progress and only if you allow it — your approximate device location to improve ETAs. Couriers share live location while online so orders can be tracked.
- Device and usage: device type, app version, crash reports and how you use the app, to keep it working and to spot fraud.
- Support: messages you send us and masked call metadata (time and duration, not content).
Why we use it
- To take, prepare, deliver and pay for orders.
- To show you live tracking and send status updates by push, SMS or email.
- To keep the marketplace safe: verifying couriers, detecting fraud, resolving disputes.
- To comply with tax, payment and consumer laws in your market.
- To improve the Service. We do not sell your personal data and we do not share it with advertisers.
Who sees it
- The merchant sees your first name, your order and any note you wrote for them.
- The courier sees your first name, the delivery point, your directions and a masked phone number that stops working after the order.
- Payment providers licensed in your market process payments under their own privacy terms.
- Service providers such as SMS, email, mapping and cloud hosting act on our instructions under contract.
- Authorities, where the law requires it.
How long we keep it
Order and payment records are kept as long as tax and payment rules in your market require, typically several years. Precise location history is reduced to the drop-off point after the dispute window. Support messages are kept for two years. Accounts inactive for three years are anonymised.
Your rights
Depending on your market you can ask for a copy of your data, correct it, delete it, object to certain uses or withdraw consent. Ask from the Help centre using the email on your account. We answer within 30 days and never charge for a reasonable request.
Staff access
Only named roles can see unmasked contact details or location history. They must use two-step sign-in and every access is logged and reviewed. Support agents act on your account only through an explicit, audited support mode.
Security
Data is encrypted in transit and at rest. Card details never reach our servers. We test the Service for vulnerabilities and fix them promptly. No system is perfect; if a breach affects you we will tell you and the relevant regulator as the law of your market requires.
Children
The Service is not for anyone under 18. If we learn we hold data about a child we will delete it.
Changes and contact
We will tell you about material changes in the app or by email. The version that applies is shown on this page. Questions and requests go to the Help centre; the data-protection contact for your market is listed on the Trust & Safety page.