Privacy Policy
Grubbian (K) Ltd — Effective Date: 01 October 2025
1. Introduction
Grubbian (K) Ltd ("Grubbian," "we," "our," "us") values your privacy. This Privacy Policy explains how we collect, use, share, and protect your personal data when you use the Grubbian app and related services ("Platform").
We comply with the Kenya Data Protection Act, 2019 and other applicable laws.
2. Data We Collect
We may collect the following categories of data:
- Account Data: name, phone number, email, password.
- Reservation Data: restaurant chosen, meals ordered, booking date and time, order status.
- Payment Data: transaction reference and status (processed securely by Paystack; we never store card details).
- Restaurant Partner Data: business name, contact details, menu, licenses.
- Usage Data: app activity, device type, IP address, log data.
- Location Data (if enabled): to suggest nearby restaurants or personalize services.
3. How We Use Your Data
- To create and manage your account.
- To process reservations and payments.
- To notify you of order status (pending, accepted, confirmed, fulfilled, cancelled).
- To communicate with you about updates, offers, or issues.
- To generate anonymized analytics to improve our services.
- To comply with legal obligations (tax, licensing, audits).
4. Sharing of Data
We may share your data with:
- Restaurant Partners – to enable reservations and service delivery.
- Service Providers – such as Google (hosting, cloud services) and Paystack (payment processing).
- Regulators or Authorities – if required by law.
- Business Transfers – if Grubbian undergoes a merger, acquisition, or sale.
We do not sell personal data to third parties.
5. Payments
Payments are processed by Paystack, a PCI DSS–compliant payment processor. Grubbian does not store or have access to your card details. Paystack handles all sensitive financial data in accordance with global standards.
6. Data Retention
Account data is retained as long as you have an active account. Reservation and transaction data is retained for 7 years to comply with tax and legal obligations. You may request deletion of your account and personal data, subject to legal retention requirements.
7. Security Measures
We implement appropriate technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission or storage is 100% secure.
8. Your Rights
Under the Data Protection Act, 2019, you have the right to:
- Access your personal data.
- Correct inaccuracies.
- Request deletion ("right to be forgotten").
- Withdraw consent for certain processing.
- Object to processing in some cases.
Requests can be made by contacting us at info@grubbian.com.
9. Children's Data
The Platform is not intended for children under 18. We do not knowingly collect personal data from minors.
10. International Data Transfers
Where data is transferred outside Kenya (e.g., to Google's servers), we ensure adequate protection measures are in place, consistent with the Data Protection Act, 2019.
11. Updates to this Policy
We may update this Privacy Policy from time to time. If we make significant changes, we will notify you via the app or email.
12. Contact Us
If you have questions or requests regarding this Privacy Policy, contact us at:
Grubbian (K) LtdEmail: info@grubbian.com
Phone: 0112 888 088
Website: grubbian.com
This Privacy Policy is aligned to the Kenya Data Protection Act, 2019.