This policy describes how Orgent Co. Ltd (“Hangout”, “we”) handles personal data when you use this website. It is written to be read, not skimmed past — if anything here is unclear, ask us at privacy@hangout.ng and we will explain it in plain terms.
We are the data controller for the information described below. We process it under the Nigeria Data Protection Act 2023 (NDPA) and the regulations made under it by the Nigeria Data Protection Commission (NDPC).
1. What we collect
Only what the service actually needs:
- When you create an account: your name, email address, and phone number if you choose to give one. Phone is optional and the account works without it.
- Your password: stored only as a bcrypt hash. We cannot read it, and neither can anyone who obtains a copy of the database. If you forget it, we can only reset it — we can never tell you what it was.
- When you book: the venue, the date, how many guests, the budget you entered, the items in your order and their prices at the time, and any note you add for the venue.
- If you list a venue:your business name, address, contact details, and your menu and prices. Bear in mind that a venue's public page is exactly that — public.
- Technical data: your IP address is used briefly, in memory, to rate-limit sign-in and sign-up attempts so that nobody can grind through passwords or create accounts in bulk. It is not written to our database and not used to build a profile of you.
We do not collect your card details. We never see them — see “Payments” below.
2. Why we process it, and on what legal basis
- To perform our contract with you — creating your account, building your order, sending your booking to the venue, telling you when they accept it, and keeping a record of what was agreed and at what price.
- Because we have a legitimate interest in keeping the service working and safe: rate-limiting sign-ins, investigating abuse, and fixing faults.
- Because the law requires it — transaction records may need to be retained for tax and accounting purposes.
We do not sell your personal data. We do not share it with advertisers. We do not run advertising or analytics trackers on this site.
3. Cookies
This site sets one cookie. It holds your sign-in session, it is markedhttpOnlyso page scripts cannot read it, it is sent only to this site, it is transmitted over HTTPS only in production, and it lasts 30 days or until you sign out.
There are no advertising cookies, no analytics cookies and no third-party trackers. That is why you are not being shown a cookie banner: there is nothing to consent to beyond the cookie that signing in strictly requires. If that ever changes, this page changes first and you will be asked.
4. Who else sees your data
Three kinds of recipient, and nothing beyond them:
- The venue you book. They receive your name, your party size, your booking reference, the items you ordered and any note you wrote. They need this to hold your table. They do not receive your email address or phone number through the platform.
- Flutterwave, our payment processor, when you pay. They receive your email address, the amount, and the booking reference. Your card details go from your browser straight to Flutterwave and never touch our servers. Flutterwave is a Nigerian company and processes your data under its own privacy policy.
- Anthropic, whose Claude model can help compose your order when that feature is switched on. It receives the venue's name, the occasion you picked, the number of guests, your budget figure, and the venue's menu. It does not receive your name, email, phone number, account identifier or booking history. This transfer is outside Nigeria, and where it happens we rely on the cross-border transfer safeguards the NDPA provides for. If the feature is off, nothing leaves us at all for this purpose.
We also rely on ordinary infrastructure providers — hosting and database services — who process data only to run the service on our instructions.
5. How long we keep it
Account details are kept while your account exists. Booking records are kept for as long as we may need them for accounting, tax and dispute-resolution purposes. Sign-in sessions expire after 30 days, and are deleted immediately when you sign out.
We would rather be straight with you than impressive: we do not yet run an automated deletion schedule. If you ask us to erase your data we will do it by hand, and we will confirm when it is done.
6. Your rights
Under the NDPA you can ask us to:
- tell you what we hold about you, and give you a copy;
- correct anything that is wrong;
- delete your data, where we are not required to keep it;
- restrict or object to how we use it;
- give you your data in a portable form.
Write to privacy@hangout.ng and we will respond within 30 days. You will not be charged for asking. If you think we have handled your data badly and we have not put it right, you can complain to the Nigeria Data Protection Commission.
7. Keeping it safe
Passwords are hashed with bcrypt. Sessions are random 256-bit tokens stored server-side, not guessable identifiers. Traffic is served over HTTPS. Access to a venue's own bookings and menu is checked on every single request, not assumed from the page you came from.
No system is perfectly secure. If a breach ever affects your personal data, we will notify the NDPC and, where the risk to you is high, tell you directly.
8. Children
This service is not intended for anyone under 18, and several venues on it serve alcohol. We do not knowingly collect data from children. If you believe a child has created an account, tell us and we will remove it.
9. Changes, and how to reach us
If this policy changes materially we will update the date at the top and, where the change affects you, tell you in the app. Questions, requests and complaints all go to privacy@hangout.ng — or use the contact page.
