Privacy Policy
We believe privacy is a right, not a feature. This policy explains exactly what data NileOS collects, why we collect it, and what we do — and don't do — with it.
Last updated: July 5, 2026 · Operated by TOA Software Group
Information we collect
Account information
When you register for NileOS, we collect your name, email address, and authentication credentials managed through Clerk. Hotel owners additionally provide business name, business type (hotel, restaurant, café, or resort), and a unique subdomain slug.
Payment information
Subscription payments are processed through Chapa, a licensed Ethiopian payment gateway. NileOS does not store your card number or bank account details. We retain a transaction reference code, plan level, amount paid (in ETB), and payment timestamp for billing history and invoice purposes.
Operational data
As you use the platform, we collect data generated by your business: menu items, table configurations, staff accounts (name, role, Clerk ID), orders placed by customers via QR code, order status updates, and kitchen display events. This data belongs to your hotel account.
Customer ordering data
When guests scan your hotel's QR code and place an order through the customer interface, we collect their order items, table number, any note they attach to the order, and the timestamp. We do not collect guest names, phone numbers, or email addresses unless they voluntarily provide them.
Usage and technical data
We use Vercel Analytics to collect anonymized page-view and performance data. This includes browser type, device type, country-level location, and pages visited. No personally identifiable information is associated with these analytics records.
How we use your information
To deliver the service
We use your account and operational data solely to run NileOS for you — processing orders, routing them to the kitchen display, tracking staff activity, and powering your hotel dashboard.
Billing and subscriptions
Payment transaction records are used to manage your subscription, send billing confirmation emails via Resend, and display your billing history in the dashboard. We send a renewal reminder email before your 30-day subscription expires.
AI analytics (Level 3 plans only)
On the Premium plan, aggregated operational metrics (order volumes, peak hours, top menu items, revenue totals) are sent to Google Gemini to generate business insights. No personally identifiable information is included in these prompts. Insight results are displayed only to the hotel account owner.
Product improvement
Anonymized, aggregated usage patterns may inform decisions about which features to build or improve. We do not sell individual-level data for this purpose.
Communications
We send transactional emails only — subscription confirmations, renewal reminders, and staff invitation emails. We do not send marketing emails unless you have explicitly opted in.
Data sharing and third parties
We do not sell your data
NileOS does not sell, rent, or trade your personal data or your customers' data to any third party for marketing, advertising, or any other purpose.
Service providers
We share data with third-party services that are necessary to operate NileOS: Clerk (authentication and user management), Chapa (payment processing), Cloudinary (menu image storage), Resend (transactional email), Redis via Upstash (real-time messaging), and Google Gemini (AI analytics, Premium only). Each provider processes only the data necessary for their function and is bound by their own data protection terms.
Legal requirements
We may disclose data if required to do so by Ethiopian law, a court order, or a legitimate request from a government authority. We will notify affected users where legally permitted to do so.
Business transfers
If NileOS or TOA Software Group is acquired, merged, or its assets are sold, your data may transfer to the acquiring entity. We will notify you via email and prominent notice on the site at least 30 days before any such transfer.
Data retention
Active accounts
We retain your account data and operational data for as long as your NileOS account is active.
After cancellation
When you delete your hotel account, operational data (menus, tables, staff, orders) is soft-deleted immediately and permanently removed from our systems within 30 days. Payment transaction records are retained for 7 years as required by Ethiopian tax law.
Inactive accounts
Accounts with no activity and no active subscription for more than 12 consecutive months may be flagged for deletion. We will send an email warning at least 30 days before taking any action.
Your rights
Access and portability
You may request a copy of the personal data we hold about you at any time by emailing us. We will respond within 14 days.
Correction
You can update your name, email, and business information directly in the NileOS dashboard. For corrections to payment records, contact us.
Deletion
You can delete your hotel account from the Settings page in the dashboard. This removes all operational data. For deletion of your Clerk authentication account, follow the process in your account settings.
Objection to processing
If you believe we are processing your data in a way that is not consistent with this policy, contact us at the email below. We will investigate and respond within 14 days.
Security
What we do
NileOS uses HTTPS for all data in transit, HTTP security headers via Helmet, HTTP parameter pollution protection, Clerk-managed authentication with session tokens, and parameterized database queries to prevent SQL injection. Access to each hotel's data is enforced at the API layer by role — hotel owners, waiters, and kitchen staff each see only what their role permits.
What we cannot guarantee
No system is perfectly secure. While we take industry-standard precautions, we cannot guarantee that unauthorized third parties will never be able to defeat our security measures. If we become aware of a breach affecting your data, we will notify you within 72 hours.
Changes to this policy
We may update this Privacy Policy as the product evolves. When we make material changes, we will notify all registered hotel accounts by email and update the "Last updated" date at the top of this page. Continued use of NileOS after changes take effect constitutes acceptance of the updated policy.
Contact us
If you have questions about this Privacy Policy or how your data is handled, reach us at:
Company: TOA Software Group
Product: NileOS — https://nile-os.com
Email: anaf.coder@gmail.com
Telegram: @anafthecoder