Privacy Policy
What we collect, why we collect it, and what you can do about it.
Last updated: September 2026
Who this covers
This policy covers the Veltmo platform: the customer storefront, the restaurant dashboard, the point-of-sale terminal, and the three mobile apps listed below. The data controller is Almacq Holdings, contactable at privacy@almacq.com.
Restaurants using the platform are separate controllers of their own customer and staff records. Where a restaurant decides how your data is used, this policy describes what we do on their behalf.
What each app collects
Veltmo · Customers
- Account details you provide: name, phone number, and email address.
- Delivery addresses you save, including their map coordinates.
- Order and payment history. Card details are handled by our payment processor and are never stored on our servers.
- A push notification token, so we can tell you when your order changes status.
Veltmo Rider · Delivery riders
- Account and identity details, including the documents required to verify you as a rider (such as a licence).
- Precise location while you are on an active delivery, so the restaurant and the customer can see the order approaching. Location is not collected when you are off duty.
- Photographs you capture as proof of delivery.
- Earnings and withdrawal records.
- A push notification token, so we can offer you jobs.
Veltmo POS · Restaurant staff
- Your staff account details and the restaurant and branch you belong to.
- The orders, shifts, and till activity you record while signed in.
- A push notification token for kitchen and order alerts.
Location, camera, and notifications
These are the permissions a store listing asks us to justify, so we are specific about them.
- Precise location is requested only by the rider app, and only while a delivery is active. It is used to show the restaurant and the customer where their order is, and it stops when the delivery ends or the rider goes off duty.
- The camera and photo library are requested only by the rider app, to capture proof of delivery at the drop-off.
- Push notifications are used for order status, job offers, and kitchen alerts. You can turn them off in your device settings and keep using the app.
What we never collect
- Full card numbers. Card payments are processed by Paystack; we store only the result of the transaction and, if you choose to save a card, the masked reference our processor returns.
- Your contacts, your calendar, or your browsing outside our apps.
- Location from the customer or POS apps.
Who we share with
We do not sell personal data. We share only what a given task requires, with:
- The restaurant you ordered from, so it can prepare and deliver your order.
- The rider assigned to your delivery, who sees the delivery address and your first name and phone number for that delivery only.
- Paystack, our payment processor, to take payment and issue refunds.
- Infobip and Resend, to send the SMS and email you asked for, such as a verification code or a receipt.
- Amazon Web Services, which hosts the platform.
- A regulator or law enforcement, where we are legally required to.
If you run a restaurant on the platform
Onboarding a restaurant means giving us more than an account. To verify a business and to pay it out, we collect and store:
- Business registration and tax identification documents, and identification for the owner or director.
- Bank account details used for payouts, verified through our payment processor.
- The staff accounts you create, including each person’s name, contact details, role, and the hashed PIN they use at the till.
These documents are held privately. They are never served from a public URL, cannot be reached by guessing a filename, and are readable only through a short-lived signed link issued to someone authorised to see them.
Where your data is held
The platform runs on Amazon Web Services and a managed Postgres database, both located in the United States. If you are in Ghana, this means your personal data is processed outside the country.
We rely on our contracts with those providers to keep the data protected to the standard this policy describes, and we do not permit them to use it for their own purposes. If you would rather not have your data processed abroad, the platform is not able to offer that today, and you should not use it.
How we protect it
- Everything travels over HTTPS, and stored files and database contents are encrypted at rest.
- Passwords and staff PINs are stored only as one-way hashes. Nobody at Veltmo can read them, including us.
- Each restaurant’s data is scoped to that restaurant. Staff of one restaurant cannot read another restaurant’s orders, customers, or takings.
- Verification documents and delivery proofs are private, and are separated from the menu images that are meant to be public.
- Access to production systems is limited and logged, and the platform records an audit trail of significant actions taken in the dashboard.
No system is perfectly secure. If we discover a breach that puts you at risk, we will tell you and the Data Protection Commission as the law requires.
Cookies and on-device storage
We do not use cookies, and we do not run advertising or third-party analytics trackers.
When you sign in, the browser keeps your session token in its own local storage so you stay signed in between visits. Clearing your browser data signs you out. The mobile apps keep the equivalent token in the device’s secure storage.
How long we keep it
Account details are kept while your account is open. Order, payment, and payout records are kept for as long as tax and accounting rules require, even after an account closes, because we are obliged to be able to produce them. Rider location history is kept only as long as it is useful for resolving a delivery dispute, and then removed.
Your rights
Under the Ghanaian Data Protection Act, 2012 (Act 843), you have the right to be told what we hold about you, to have it corrected if it is wrong, to object to how we are using it, and to ask us to delete it.
- Ask for a copy of your data, and we will send it in a form you can read and take elsewhere.
- Ask us to correct anything inaccurate — most of it you can also edit yourself in the app.
- Ask us to delete your account: see the deletion page below, which sets out exactly what goes and what has to stay.
- Withdraw a permission you previously gave, such as location or notifications, from your device settings at any time.
Deletion has its own page with the process and the retained-records exceptions: Delete your account and data. For anything else, write to privacy@almacq.com. We answer within 30 days.
If you are not satisfied
Come to us first — most things are quicker to fix directly. If we cannot resolve it, you can complain to the Data Protection Commission of Ghana, the authority that supervises how personal data is handled under Act 843. You do not need our permission to do that, and you can do it at any point.
Children
The platform is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has given us information, write to privacy@almacq.com and we will remove it.
Changes
If this policy changes materially we will say so in the apps before the change takes effect. The date at the top always reflects the current version.
