Chính sách bảo mật
Nourishubs: Website, Mobile Application, and Platform
Last updated: 26/09/2026
At Nourishubs, the owner and operator of www.nourishubs.com and our mobile application “Nourishubs” (the “App”), and the associated platform connecting schools, early learning centres, workplaces, parents, vendors, and other users (together with the App, the “Services”) (hereinafter referred to as “Company,” “we,” “our,” or “us”), we are committed to safeguarding the privacy of our users (parents, schools, early learning centres, workplaces, vendors, and children) across the countries in which we operate. This Privacy Policy outlines how we collect, use, store, disclose, and protect your personal information when you use the Services to connect with food vendors, manage school and workplace meal ordering, make payments, or manage orders.
Nourishubs currently operates in South Africa, Australia, and Mauritius, and is actively expanding into further markets. This Policy is designed to apply generally across all countries in which we operate, with country-specific provisions included wherever local law requires something different. As we expand into new countries, this Policy will be updated to reflect the additional jurisdiction, without changing the overall structure of how we handle your information.
By using our services, you agree to the practices described in this Privacy Policy and our Terms of Service. If you do not agree, please do not use our services.
Scope
This Privacy Policy applies to personal information collected through:
- Our website: www.nourishubs.com
- Our mobile application (the “App”), available on the Apple App Store and Google Play
- Our social media pages
- Other applications, software, digital media, or functionality related to the Nourishubs brand and services
Where local law requires it, country-specific sections within this Policy supplement the general provisions to meet additional legal obligations.
Definition of Personal Information
“Personal information” means any data relating to an identified or identifiable individual, including:
- Name, surname, address, phone number, email address
- Payment and bank account details (for Vendors, this includes banking details for order payouts)
- Location data
- Purchase and transaction history
- IP address, device IDs, browsing behaviour, and other online identifiers
- Dietary requirements and allergen information
- Any other data that identifies or could reasonably identify you
How We Collect Information
We collect personal information lawfully, fairly, and transparently, only to the extent necessary for the purposes outlined below. The Services are used through four account types, each linked to an “Institutional User”: an early learning centre (ELC), school, workplace, or other organisation using the Services. References in this Policy to a “Minor” mean an individual under the age of 18 whose information is provided to us by a Guardian or Institutional User, and who does not hold or operate an account of their own.
Admin Accounts
- Name, email address, and phone number (optional); the Institutional User's organisation name and address.
Guardian Accounts (referred to within the App as ‘Parent’)
- The Guardian's name, email address, and phone number (optional); the Institutional User's organisation name and address; and, in relation to each Minor linked to the account, the Minor's name, age, grade, class, and allergens and dietary requirements.
Staff User Accounts
- The Staff User's name, email address, phone number (optional), the Institutional User's details, and the Staff User's own allergens and dietary requirements.
Vendor Accounts
- Business name and address, trading hours, bank account details for order payouts, and business registration number or licence.
Automatically Collected Information
- Device type, operating system, unique device identifiers, IP address, app usage and interaction data, crash and diagnostic data, and approximate location (if enabled in your device settings).
Information from Third Parties
- From social media platforms when you interact with our pages; from others providing information about you (e.g., an Institutional User providing information about a Minor or Staff User), with that party responsible for obtaining any consent required to do so.
We will inform you of the purposes of collection at the time of gathering your data and, where required, obtain your consent.
Lawful Basis for Processing
We process your personal information based on one or more of the following grounds, depending on applicable law: consent, performance of a contract, compliance with a legal obligation, and our legitimate interests in operating and improving the Services. Where required, we will specify the applicable basis at the time of collection.
- South Africa: processed in reliance on the lawful processing conditions under the Protection of Personal Information Act 4 of 2013 (“POPIA”).
- Australia: handled in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth), including obtaining consent for sensitive information such as allergy and dietary data.
- Mauritius: processed on the bases permitted under the Data Protection Act 2017 (“DPA”).
Purposes of Processing
We use your personal information only for specific, legitimate purposes, including:
- Verifying your identity and account
- Providing and delivering the Services, including connecting Guardians, Staff Users, and Institutional Users with food Vendors
- Processing transactions, payments, and Vendor payouts
- Sending service-related communications (e.g., order confirmations)
- Sharing dietary and allergy information with the relevant Vendor to safely prepare and supply meals
- Sending a Guardian a cross-contamination notice, described further below, where an allergy has been disclosed
- Improving our website, App, and services
- Sending marketing communications (with consent where required)
- Complying with legal obligations and enforcing our policies
- Protecting against fraud or unauthorised activity
We will not use your data for unrelated purposes without your consent or another lawful basis.
Children's Data
Our services involve collecting information about children, primarily through Guardians and Institutional Users (ELCs, schools, and workplaces). Minors do not register for or hold their own account; all information relating to a Minor is provided to us by their Guardian, who is responsible for ensuring they have the legal authority to do so.
We minimise data collection from children and use it only for the purpose of safely and effectively providing the Services in relation to that child, in particular the safe preparation and supply of meals. We do not use a child's information for marketing, advertising, or profiling directed at them, and do not sell such information to third parties.
Registration of a Minor is submitted to the relevant Institutional User for approval in the ordinary course. Where a Guardian discloses that a Minor has an allergy, that disclosure is not routed to the Institutional User as part of the standard approval process, and is instead submitted directly to us. We use that disclosure to send the Guardian a written notice confirming that cross-contamination in Vendor kitchens is unavoidable, and that we do not operate, and cannot guarantee, an allergen-free or cross-contamination-free environment, before the Guardian is able to proceed with an order for that Minor. The relevant Institutional User may not be separately notified of a disclosed allergy through the Services, and it remains the Guardian's responsibility to inform the Institutional User directly if they wish the Institutional User to be aware of it.
We require verifiable Guardian consent for the collection of a child's information, in accordance with the requirements applicable in each country in which we operate:
- South Africa: in accordance with section 35 of POPIA.
- Australia: consistent with APP 3 and the best interests of the child, and the approach being developed under Australia's forthcoming Privacy (Children's Online Privacy) Code.
- Mauritius: in accordance with Section 30 of the Data Protection Act 2017, which requires parental or guardian consent for the personal data of a child below the age of 16, and makes non-compliance a criminal offence.
Guardians and Staff Users can contact us at any time to review, correct, or delete their own information or their child's information (see “Contact” section).
Cookies and Similar Technologies
We use cookies and similar technologies to enhance your experience, analyse usage, and provide personalised content.
- Essential cookies: necessary for our services to function
- Analytics cookies: help us understand how users interact with our platform
- Marketing cookies: deliver personalised advertising, with your consent
Where legally required, we will obtain your consent before using non-essential cookies. You can manage preferences through our cookie consent tool or your browser or device settings. We do not use these technologies to track children for advertising purposes, and we do not use personal information to track Users across other companies' apps or websites (accordingly, we do not request Apple's App Tracking Transparency permission).
Disclosure of Personal Information
We may share your personal information with:
- Vendors, for the purpose of fulfilling meal orders, including relevant dietary and allergy information
- Institutional Users, in relation to Minors and Staff Users associated with them
- Payment processors (such as Paystack, or other providers depending on your country), for processing payments and Vendor payouts
- Service providers who support our technology infrastructure, bound by confidentiality and security obligations
- Other Nourishubs group entities, as necessary to operate the Services across the countries in which we operate
- Regulators, courts, or other authorities, where required by law
- A successor entity in the event of a merger, acquisition, or sale of business assets, bound by materially equivalent privacy protections
We limit sharing to what is necessary and do not sell your personal information to third parties for their own marketing purposes.
International Data Transfers
As a company operating across multiple countries, your data may be transferred to and stored in a country other than your own; in particular, our core technology infrastructure is maintained in Mauritius. We take steps appropriate to each jurisdiction to protect your information when this happens:
- South Africa: transfers are made in accordance with section 72 of POPIA, including by ensuring the recipient is subject to adequate protection or by obtaining consent.
- Australia: in accordance with APP 8, we take reasonable steps to ensure an overseas recipient does not breach the Australian Privacy Principles.
- Mauritius: transfers are made in accordance with the cross-border transfer requirements of the DPA.
As we expand into new countries, we will apply the equivalent safeguards required under that country's law. Contact us for more detail on the safeguards that apply to you.
Data Retention
We keep your personal information only as long as needed for the purposes outlined here, legal compliance, dispute resolution, or agreement enforcement. For example:
- Account information: kept while your account is active, plus a reasonable period after closure
- Transaction data: retained in line with applicable tax recordkeeping laws (generally a minimum of five years)
- A child's information: retained only for as long as necessary while they remain associated with an active Institutional User account
- Marketing consent records: kept until you withdraw consent
When no longer needed, we securely delete or anonymise your data in accordance with applicable law.
Security Measures
We use technical and organisational measures to protect your data, including encryption in transit, secure servers with access controls, restricted access to sensitive information (including children's, Staff Users', and Vendors' banking information), regular security reviews, and staff training on data protection. Our third-party providers must meet similar standards.
Payment Security
Payments are processed via PCI DSS-compliant providers; we do not store full payment card details.
Data Breaches
If a breach risks your rights, we will notify you and the relevant authority as required by law, namely the Information Regulator (South Africa), the Office of the Australian Information Commissioner (Australia), or the Data Protection Office (Mauritius), within the timeframe required in your country.
App Store Disclosures and Account Deletion
In accordance with Apple App Store and Google Play requirements, we maintain accurate “App Privacy” (Apple) and “Data Safety” (Google Play) disclosures reflecting the information described in this Policy. Where your account was created via the App downloaded from the Apple App Store, you may delete your account directly within the App. Where your account was created via the App downloaded from Google Play, you may delete your account within the App, or via [WEB ACCOUNT DELETION URL], which remains available even after the App has been uninstalled.
Your Data Subject Rights
Depending on where you are located, you generally have the right to:
- Access: request the personal information we hold about you
- Rectification: correct inaccurate data
- Erasure: request deletion of your data, subject to certain conditions
- Restriction: limit our processing in specific cases
- Objection: oppose processing carried out on the basis of legitimate interests, or for marketing
- Withdraw consent: where processing is based on consent
To exercise these rights, email support@nourishubs.com. We will respond within 30 days, or within the timeframe required by law in your country. You may also update your account directly. If unsatisfied with our response, you may contact the regulator applicable to your country; see “Complaints” below.
Marketing Communications
We may send marketing messages about our services where you have consented, or where we rely on another lawful basis permitted in your country. You can opt out at any time by clicking “unsubscribe” in emails, adjusting your account settings, or emailing support@nourishubs.com. Service-related messages (e.g., order updates) are necessary while you use our services and are not part of marketing communications.
Jurisdiction-Specific Information
Nourishubs currently operates in the following countries. As we expand, this section will be updated to include each new jurisdiction.
- South Africa: Protection of Personal Information Act 4 of 2013 (POPIA)
- Australia: Privacy Act 1988 (Cth) and the Australian Privacy Principles
- Mauritius: Data Protection Act 2017
Contact us for further detail on how this Policy applies in your specific country.
Updates to This Privacy Policy
We may update this Policy to reflect changes in our practices, the countries in which we operate, or applicable law. Updates will be posted on this page, and we will notify you directly (for example, by email) of any significant change affecting your rights, where possible. Please check this page periodically.
Contact
Email: support@nourishubs.com
For questions or to exercise your rights, use the details above.
Complaints
If you are concerned about our privacy practices, email support@nourishubs.com. We will respond within 30 days. If unresolved, you may contact the regulator applicable to your country: the Information Regulator (South Africa), the Office of the Australian Information Commissioner (Australia), or the Data Protection Office (Mauritius).
Acknowledgment
By using our services, you confirm that you have read and understood this Privacy Policy and consent to our handling of your personal information as described, subject to applicable law. You also acknowledge your rights and our obligations as set out above.