Yombana
Log InGet Started

Privacy Policy

What we collect, why we collect it, who we share it with, and how you can control your data across the Yombana POS, Vendor, Rider, and Customer apps.

This Privacy Policy explains how Yombana ("we," "us," or "our") collects, uses, discloses, and safeguards personal data when you use any of the following services (together, the "Services"):

  • Yombana POS — the web dashboard restaurants use to manage products, staff, sales, inventory, accounting, and reports.
  • Yombana Vendor app — the mobile app restaurant staff use to take orders, accept payments, and manage tables.
  • Yombana Rider app — the mobile app delivery riders use to accept, pick up, navigate to, and complete delivery orders.
  • Yombana Customer app — the mobile app diners use to browse menus, place orders, pay, gift meals, and track delivery.
  • The Yombana website at yombana.com and its sub-domains.

By creating an account or otherwise using the Services, you agree to this Privacy Policy. We will notify you of any material changes by updating the "Last Updated" date below and, where appropriate, by an in-app or email notice.

Last Updated: 15 July 2026
Effective: Upon publication
Data controller: Yombana, Sukuta Jabang Traffic Light, The Gambia

1. Information We Collect

We only collect what we need to deliver each Service. The exact data depends on which product you use and which features you enable.

A. Account & identity (all products)

  • Full name, username, phone number, and email address (when provided).
  • Authentication credentials — password and/or numeric PIN, stored only as a bcrypt hash. We never see your raw password or PIN.
  • Role (e.g. Owner, Manager, Cashier, Waiter, Rider, Customer) and branch / restaurant assignment.
  • Profile photo, if you choose to upload one.

B. Yombana Customer app (diners)

  • Delivery address — typed by you, or selected from your saved addresses.
  • Approximate location — used to show restaurants near you. Only collected while the app is in use and only if you grant permission.
  • Order history — items, quantities, prices, restaurant, payment method, delivery status.
  • Payment details — Wave wallet phone number is passed to Wave to authorise payment. We do not see or store your Wave PIN or card numbers; full payment-instrument data stays with the payment processor.
  • Gift orders — if you send a meal to someone, we store the recipient's phone number / name and your message so we can deliver and notify them.
  • Loyalty balance — points earned and redeemed per restaurant.
  • Push-notification token — used to send order-status alerts.

C. Yombana Rider app

  • Precise location (GPS) — collected while you are on an active delivery so we can show the restaurant and customer your ETA, navigate you to the drop-off, and confirm completion. We stop collecting location the moment a trip ends. We do not collect background location when you are off-shift.
  • Trip history — orders accepted, pickup/drop-off times, distance, and earnings.
  • Vehicle & document info — vehicle type, plate, and any documents (e.g. ID, licence) you submit to qualify as a rider.
  • Push-notification token — used to alert you of new delivery offers.

D. Yombana Vendor app & POS web (restaurants)

  • Business information — restaurant name, branch addresses, contact details, tax/registration info.
  • Approximate location — optional, and only if you grant permission, to set a branch's position on the map. Collected only at the moment you set it, not on an ongoing basis.
  • Staff records — names, role, PIN hash, shift & schedule data, permissions.
  • Menu & inventory — products, categories, prices, stock levels, ingredients, supplier info, photos you upload.
  • Sales & accounting — orders, transactions, payment method, GL postings, daily / monthly reports.
  • Customer records you create — names, phone numbers, loyalty data of walk-in customers entered by your staff.
  • Item-removal audit log — when an item is removed from an open order, we record who removed it, who approved it (manager / owner), the item, and the time. The cashier-facing UI no longer asks for a reason — the audit is silent and visible only to owners.
  • Camera / photo library access — used only if you take or upload a photo for a product, receipt, or profile.

E. Device & technical data (all products)

  • Device model, operating system, app version, IP address, language, time zone.
  • Crash logs, performance metrics, anonymised usage events used to fix bugs and improve features.
  • Standard server logs (e.g. request paths and response codes) for security and reliability.

2. How We Use Your Information

  • To deliver the Services — authenticate you, route orders, accept payments, track deliveries, run reports, generate receipts.
  • To communicate with you — order updates, delivery progress, account notices, security alerts. We send marketing messages only with your consent and you can opt out at any time.
  • To keep the platform safe — detect fraud, abuse, unauthorised access, and to enforce our Terms of Service.
  • To comply with the law — tax record keeping, regulatory reporting, and responding to lawful requests from authorities.
  • To improve our products — analyse aggregated, de-identified usage to fix bugs and design new features. We do not use your individual data to train models offered to third parties.

3. Device Permissions

Each Yombana mobile app only requests the permissions it needs. You can review and revoke any of them in your device's Settings at any time. If you revoke a permission, the dependent feature stops working but the rest of the app continues normally.

  • Location — required by the Rider app for active deliveries; optional in the Customer app to suggest nearby restaurants; optional in the Vendor app, used only to set a branch's position on the map when you choose to.
  • Push notifications — order status (Customer), new delivery offers (Rider), new incoming orders (Vendor).
  • Camera & photo library — only when you actively choose to take or upload a photo (e.g. menu item, profile picture, expense receipt).
  • Bluetooth — Vendor app only, used to talk to a thermal receipt printer if you choose to pair one.
  • Contacts — we do not read your contacts in any app.

4. How We Share Data

We do not sell personal data. We share it only with parties that help us deliver the Services, and only the minimum needed:

  • Payment providers — Wave (and any other authorised mobile-money / card processor) receive the information needed to authorise and confirm a payment. Their handling of your data is governed by their own privacy policies.
  • Push-notification providers — Firebase Cloud Messaging (Google) and Apple Push Notification Service receive an anonymised device token plus the message we want to deliver.
  • Cloud infrastructure — servers, databases, and object storage (including Cloudflare R2 for menu and receipt images) used to host the Services. These providers process data on our instructions only.
  • Restaurants you order from — when you place an order through the Customer app, we share your name, contact phone, and delivery address with the restaurant and the assigned rider so they can fulfil it.
  • Riders assigned to your order — the rider sees your name, phone, drop-off address, and the items so they can complete the delivery.
  • Legal & safety — when required by law, court order, or to protect rights, life, property, or safety.
  • Business transfers — if Yombana is acquired or merges with another entity, your data may transfer under the same protections this policy provides.

5. Data Security

  • All traffic between our apps, website, and servers is encrypted in transit using TLS.
  • Passwords and PINs are stored only as bcrypt hashes — they are never visible to us, our staff, or restaurants.
  • Role-based access controls and audit logging restrict who can view or change sensitive records.
  • Payment-card data is never stored on our servers; tokenisation is handled by the payment processor.
  • We monitor for suspicious activity and patch known vulnerabilities promptly.

No system can be guaranteed 100% secure. If we ever identify a breach that affects your personal data, we will notify you and the relevant authority without undue delay.

6. Data Retention

  • Account data — kept while your account is active and for up to 90 days after you delete it, to handle disputes and abuse appeals.
  • Order & transaction records — kept for up to 7 years to comply with tax and accounting obligations in The Gambia.
  • Location traces (Rider app) — kept for the duration of each trip plus 90 days for dispute resolution, then deleted or anonymised.
  • Diagnostic logs — kept for up to 90 days, then deleted.
  • Audit logs (e.g. item removals) — kept for the lifetime of the restaurant's account, since they are part of its accounting record.

7. Your Rights & Choices

You can, at any time:

  • Access the personal data we hold about you.
  • Correct information that is inaccurate or incomplete (most fields are editable directly in-app).
  • Delete your account and associated personal data — see Section 8 below for the exact steps.
  • Export a portable copy of your data in a structured machine-readable format.
  • Object or restrict certain processing.
  • Withdraw consent for any optional processing (e.g. push notifications, marketing).
  • Lodge a complaint with The Gambia's data-protection authority if you believe we are mishandling your data.

Email info@yombana.com from the address associated with your account and we will respond within 30 days.

8. How to Delete Your Account

Yombana Customer app: Open the app → Profile → Settings → Delete account. Confirm by entering your password.

Yombana Rider app: Open the app → Profile → Delete account. Confirm by entering your PIN. Any active deliveries must be completed or reassigned first.

Yombana Vendor app & POS web: Restaurant accounts are deleted by request — email info@yombana.com from the owner's registered address. We confirm the request before we act.

When we delete an account we remove your personal profile and any data we are not legally required to keep. Records we must retain for tax or accounting reasons (see Section 6) remain only for that purpose and are not used to identify you for anything else.

9. Children's Privacy

The Services are not intended for individuals under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

10. International Data Transfers

Yombana is based in The Gambia, but some of our infrastructure providers (e.g. Cloudflare, Google, Apple) operate globally. By using the Services you understand that your data may be processed in countries outside The Gambia. Where this happens we rely on the provider's standard contractual protections and choose providers that meet recognised data-protection standards.

11. Third-Party Services

The Services integrate with the following third parties. Each has its own privacy policy:

  • Wave Mobile Money — payment processing for customer and restaurant transactions.
  • Firebase / Google Cloud — push notifications, crash reporting.
  • Apple Push Notification Service — push notifications on iOS.
  • Cloudflare R2 — object storage for images and receipts.
  • OpenStreetMap / Google Maps — map tiles and routing in the Rider and Customer apps.

We share only the minimum data needed for each integration, and only when you use the relevant feature.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be highlighted in the apps or sent by email before they take effect. The latest version is always available at this URL.

13. Contact Us

If you have questions about this Privacy Policy or about our use of your data, please get in touch:

  • Email: info@yombana.com
  • Address: Sukuta Jabang Traffic Light, The Gambia
  • Phone: (220) 313 6343

We aim to respond to every privacy enquiry within 30 days.

Notes for Restaurant Owners

  • You are the data controller for customer records you create in your own POS (walk-in customer names, phone numbers, loyalty data). Yombana processes that data on your behalf.
  • Make sure you have the appropriate consent before collecting personal information from your customers or staff.
  • Review staff access permissions regularly — only give people the level of access they need.
  • Export your data regularly. We retain backups, but you remain responsible for your own business records.