Derin's Pot
How it worksToday’s marketMarket indexFor diasporaStoriesFAQ
MARKET LIVE · MILE 12
Sign inOrder on WhatsApp

Legal

Privacy Policy

Last updated: 14 May 2026 · Effective immediately · NDPR 2019 + GDPR-equivalent rights

The short version

We collect only what we need to shop for you, deliver to you, and stay in touch about your order. We never sell your data. You can delete it at any time via our Data Deletion page.

On this page

  1. Who we are
  2. What data we collect
  3. How we use your data
  4. Legal basis for processing
  5. Who we share it with
  6. WhatsApp & Meta
  7. Where we store it
  8. How long we keep it
  9. Your rights under NDPR
  10. Cookies & web tracking
  11. Children
  12. Security & breach notification
  13. Changes to this policy
  14. Contact our Data Protection Officer

1. Who we are

Derin’s Pot(“we”, “us”) is the data controller for the personal data described in this policy. We operate from Lagos, Nigeria.

  • Email: privacy@derinspot.com
  • WhatsApp: +234 806 708 8035

2. What data we collect

We only collect what we need to provide the service.

You give us directly

  • Phone number — your primary identifier on our system
  • Name (or the name shown on your WhatsApp profile)
  • Preferred name (optional, e.g. “Aunty Bisi”)
  • Alternate phone + label (e.g. “Husband”, “PA”) — optional
  • Email — optional, used for receipts
  • Delivery addresses — including landmarks and delivery notes
  • Location pins sent via WhatsApp — used once to suggest your address, then discarded if you decline
  • Messages you send the bot — text, voice notes, photos, lists

Generated as you use the service

  • Order history — items, prices, dates, totals
  • Delivery records — driver name, delivery time, photo confirmation if taken
  • Ratings you give us after an order
  • Conversation logs — full WhatsApp threads with the bot and human agents
  • Operator notes — staff may add internal notes to your profile (e.g. “prefers ripe plantain”). Some notes can be marked private

From third parties

  • Payment metadata from Paystack — transaction reference, last 4 digits of card, channel. We do not store full card numbers
  • Delivery webhooks from third-party logistics for diaspora freight

3. How we use your data

  • To take, shop, pack, and deliver your order
  • To send you order updates via WhatsApp (basket photos, ETAs, delivery confirmation, ratings request)
  • To process your payment via Paystack and our banking partners
  • To resolve disputes — refunds, returns, missing items
  • To send you occasional marketing (new in season, bundles) — you can opt out anytime
  • To improve the service — e.g. analysing which products customers ask for to plan stocking
  • To meet legal obligations — tax records, regulatory requests, fraud prevention

4. Legal basis for processing

Under NDPR, we process your data on the following legal bases:

  • Performance of a contract — to fulfil your order
  • Consent — for marketing messages; you can withdraw at any time
  • Legitimate interest — for fraud prevention, internal analytics, service improvement
  • Legal obligation — for tax and regulatory record-keeping

5. Who we share data with

We never sell your data. We share it only with these partners, and only what they need:

  • Meta Platforms, Inc. — WhatsApp Cloud API and Commerce Catalog. Your messages and phone go through Meta to reach our bot.
  • Paystack Payments Ltd. — to charge your card and verify the payment.
  • Cloudflare Inc. — image storage (R2) for product photos and proof-of-delivery snapshots.
  • Our delivery drivers — your name, phone, and delivery address.
  • Diaspora freight partners — when shipping abroad, the consignee’s name and destination address.
  • Our hosting provider — server and database hosting in a managed environment.
  • Tax and regulatory authorities — when legally required.

6. WhatsApp & Meta

When you message us on WhatsApp, your message goes through Meta’s servers before reaching ours. Meta’s own privacy policies apply to that leg of the journey. Meta provides us with:

  • Your WhatsApp phone number
  • Your WhatsApp profile name (the name you set in WhatsApp)
  • The content of the messages you send our business number
  • Delivery status of messages we send you (sent, delivered, read)

We do not see your other WhatsApp chats, contacts, or media you haven’t sent us. WhatsApp messages between you and us are end-to-end encrypted on the way in; once they reach our business server they are decrypted so we can act on them.

7. Where we store it

Your data is stored on managed PostgreSQL databases hosted in Frankfurt (DigitalOcean) and product images on Cloudflare R2. Both providers are SOC 2 / ISO 27001 certified. Some processing happens in jurisdictions outside Nigeria, but we ensure equivalent protections via standard contractual clauses with our processors.

8. How long we keep it

  • Active customer data (profile, addresses) — for as long as you have an account with us
  • Order history — 7 years from the date of the order, for tax and accounting reasons
  • WhatsApp message logs — 2 years from the last interaction, then automatically archived
  • Payment records — 7 years, per regulatory requirement
  • Marketing consent — until you withdraw it

When you request deletion (see /data-deletion), we delete or anonymise everything we’re not legally required to keep, within 30 days. Records we must retain for tax reasons are kept in pseudonymised form (your name removed, transaction ID kept).

9. Your rights under NDPR

You have the right to:

  • Access — see what data we hold about you
  • Rectify — correct anything inaccurate
  • Erase — request deletion (see the link below)
  • Restrict processing — pause certain uses (e.g. marketing) without deleting
  • Object — to processing based on legitimate interest, including profiling
  • Data portability — receive your data in a machine-readable format
  • Withdraw consent — for anything we do under consent (mostly marketing)
  • Complain — to the Nigerian Data Protection Commission (NDPC) at ndpc.gov.ng

To exercise any of these rights, email privacy@derinspot.com or use our Data Deletion request form.

10. Cookies & web tracking

Our website uses minimal cookies — essential ones for the admin login session, and no third-party analytics or advertising trackers at this time. If we add analytics in the future (e.g. Plausible), this policy will be updated to reflect what’s collected.

11. Children

Our service is intended for adults (18+). We don’t knowingly collect data from children under 13. If you believe a child has sent us their data, message privacy@derinspot.comand we’ll delete it.

12. Security & breach notification

We use industry-standard security (TLS in transit, encryption at rest, access controls, audit logging). No system is 100% secure. If a breach affects your data, we will:

  • Notify the NDPC within 72 hours of becoming aware
  • Notify affected customers without undue delay, via WhatsApp and email
  • Tell you what happened, what data was affected, and what we’re doing about it

13. Changes to this policy

We’ll update this page when our practices change. Material changes will be announced via WhatsApp and email, and on the homepage. The “Last updated” date reflects the most recent revision.

14. Contact our Data Protection Officer

Our DPO handles privacy questions and data-rights requests.

  • Email: privacy@derinspot.com
  • WhatsApp: +234 806 708 8035 (mark your message “PRIVACY”)

For an immediate data-deletion request, use the Data Deletion form — most are processed within 24 hours.

Derin's Pot

Fresh from the Lagos market. At your door — anywhere on earth. Choose Freshness for Tastier Meals.

About
Our storyWhere we shopPressCareers
Order
How it worksToday’s marketFor diasporaFAQMy account →
Contact
@derinspotmarketplace+234 806 708 8035orders@derinspot.comStaff portal →
© 2026 DERIN’S POT · NATURAL FOODS · LOCALLY SOURCED
TermsPrivacyData deletion