Legal

Privacy Policy

Last updated: 13 May 2026

This Privacy Policy explains how Gyaale (the SaaS platform at gyaale.thekloudwiz.com and the operator dashboard at app.gyaale.thekloudwiz.com) collects, uses, and protects information about business users — owners, managers, and staff. Gyaale is operated by TheKloudWiz from Accra, Ghana.

If you're a customer ordering from a vendor on the Gyaale marketplace, the customer-facing notice at order.gyaale.thekloudwiz.com/privacy.html applies to you.

1. What we collect

When your business signs up and uses Gyaale, we collect:

  • Account & KYC — business name, owner name, owner phone and email, store type, physical address (if applicable).
  • Login data — usernames, hashed passwords (handled by Amazon Cognito), and group membership for each seat you create.
  • Operational data — your menu, prices, opening hours, settings, payment gateway keys (encrypted at rest with AWS KMS), and WhatsApp Business credentials if you connect that channel.
  • Transactional data — orders received through Gyaale, bookings, audit logs of actions taken in the dashboard, and billing history.
  • Device data — basic technical information your browser sends (IP, user agent) for security and abuse prevention.

2. How we use it

  • Provide the dashboard, kitchen display, POS, and marketplace storefront features included in your plan.
  • Process subscription payments and offline (bank transfer) confirmations.
  • Send transactional emails — welcome, password resets, billing receipts, trial-expiry notices.
  • Investigate incidents, prevent fraud, and meet legal obligations.

3. Your customers' data

When customers place orders through your storefront, you (the business) are the controller of their personal data — Gyaale is a processor acting on your behalf. We store and process that data only to operate your account. You're responsible for any direct marketing or follow-up to your customers using the data we surface in the dashboard.

4. Subprocessors

Gyaale runs on third-party infrastructure. Our current subprocessors:

  • Amazon Web Services (eu-central-1, Frankfurt) — hosting, database, storage, secrets, authentication (Cognito).
  • Paystack — subscription billing and customer payment processing.
  • Brevo (Sendinblue) — transactional email delivery.
  • Meta WhatsApp Business Platform — only if you enable WhatsApp ordering; messages and the customer's WhatsApp display name pass through Meta.
  • Google Maps Platform — address autocomplete and delivery zone lookups.

We don't sell business data and we don't share it with parties outside this list.

5. Data location and security

Primary data is stored in eu-central-1 (Frankfurt). Sensitive credentials (Paystack secret keys, WhatsApp access tokens, app secrets) are encrypted at rest with AWS KMS using a key dedicated to the platform. Communication with the dashboard is HTTPS-only with a Web Application Firewall in front of the API.

6. Data retention

Account, menu, and order records are retained while your subscription is active and for up to 90 days after termination, after which they are deleted (subject to any legal hold). You can request an earlier export and deletion at any time.

7. Your rights

  • Access — request a copy of the data we hold about your business and its users.
  • Correction — fix anything inaccurate directly in the dashboard or by emailing us.
  • Deletion — close your account and have your personal data erased.
  • Portability — request an export of your menu, orders, and customer list.

8. Cookies

See our Cookies notice.

9. Contact

Email hello@thekloudwiz.com for any privacy question, data request, or complaint.

10. Changes

We may update this notice as the platform evolves. The "Last updated" date reflects the most recent change; material changes will be flagged in the dashboard.