The protection of your information is a top priority for EVODOO SARL, the company behind the Drayk platform. This Merchant Privacy & Cookie Policy (the "Policy") explains, in clear and complete terms, what data we collect from merchants and their staff who use the Drayk Store application, why we collect it, how we protect it, and what rights you have over it.
Please read this Policy carefully. By signing a partnership agreement with EVODOO, creating a Drayk Store account, or using the Drayk Store application — on Android, iOS, or any similar device — you acknowledge that you have read and understood this Policy. This Policy forms an integral part of the Drayk Store Merchant Terms & Conditions.
1. Commitment & Scope
Drayk Store is a business-to-business service: it is used by restaurant and shop owners, managers, and staff members who prepare and hand over customer orders. Even in this professional context, the application necessarily processes personal data of natural persons — owners, legal representatives, and staff users — and we protect it with the same rigor as customer data, guided by the following principles:
- Data Minimization: We collect only the personal and business information strictly necessary to onboard your store, publish your catalog, route orders to you, compute commissions, and pay your settlements.
- Purpose Limitation: Your data is processed exclusively for specific, legitimate purposes and never used incompatibly with them.
- Transparency: We tell you plainly what we collect, why, how long we keep it, and with whom we share it.
- Data Security: We implement robust administrative, technical, and physical safeguards, including encryption in transit and at rest, hashed credentials, signed short-lived tokens, masked bank details, and need-to-know access controls.
- Your Rights: We respect and facilitate your rights of access, rectification, opposition, and erasure at any time.
- Legal Compliance: All processing complies with Moroccan Law No. 09-08 on the protection of individuals with regard to personal data processing, under the oversight of the National Commission for the Control of Personal Data Protection (CNDP), and follows Apple App Store and Google Play data-handling requirements.
This Policy applies to owners, legal representatives, managers, and staff users of the Drayk Store mobile application (each a "Merchant User") in Morocco. It does not apply to end customers of the Drayk consumer app (governed by our customer Privacy & Cookie Policy) or to delivery drivers (governed by our Driver Privacy & Cookie Policy) — except where expressly stated.
The data controller for all personal data processed through the Drayk Store app is EVODOO SARL, a limited liability company organized under the laws of the Kingdom of Morocco, registered at DOUAR FASK, Guelmim, Morocco, 81003, under Registre du Commerce No. 5719 and I.C.E. No. 003904593000051. Contact: [email protected], +212 605-698143.
Merchant accounts are provisioned by EVODOO following a commercial agreement, business verification, and approval. Additional staff seats are created by your store administrator inside the app. Unknown or unverified businesses cannot self-register.
2. Data We Collect
To verify your business, publish your store, route orders to you, compute commissions, pay your settlements, and meet our legal obligations, we collect the following categories of information:
2.1 Business Identity & Representative
- Legal identity: business legal name, legal form, Registre du Commerce (RC) number, Identifiant Commun de l'Entreprise (ICE), patente and tax identifiers where applicable;
- Representative: full name of the owner or legal representative, and the contact email address and phone number used for the account, verification, and operational contact;
- Address: registered business address and store location used for listing, zoning, and delivery-radius configuration.
2.2 Bank Details (RIB)
- Bank name, account holder name, and RIB (relevé d'identité bancaire), used solely to pay your settlements and verify payout destinations;
- RIBs are stored with masked display — only the last digits are visible in the app and back-office views — and are verified before the first settlement is released.
2.3 Store Profile & Catalog
- Store profile: public store name, logo and cover photos, address and geocoded pickup point, opening hours, average preparation minutes, delivery radius, minimum order amount, categories or cuisines, and availability status (open, closed, busy);
- Catalog: products, categories, options and variants, prices, availability flags, promotions and discounts, and product photos you upload.
2.4 Orders, Settlements & Finance
- Orders & fulfillment events: incoming orders, acceptance, rejection and cancellation events with timestamps, preparation progress, readiness confirmation, and handover to the driver;
- Settlements & payout records: per-order commission computation, order financial snapshots, settlement periods, payout amounts with bank references and failure reasons, statements, and invoices;
- All monetary values are processed in minor currency units (centimes) in Moroccan Dirhams (MAD).
2.5 Support Communications
When you contact support — including via WhatsApp — we collect the conversation thread, the related store or order, your contact details, and any attachments you send, used to assist you, verify your identity, and resolve disputes.
2.6 Device, Diagnostics & Security Events
- Device identifiers: installation ID, device ID bound to your login session, and Firebase installation ID;
- Platform (Android or iOS), device model, OS version, app version and build number;
- Push registration data: notification token, locale, and timezone;
- Network data: IP address (hashed for rate-limiting and fraud prevention) and network type;
- Diagnostics: crash reports, error logs, and performance data collected via Firebase Crashlytics — the app's only remote crash reporter, enabled in production builds only — used solely to fix technical issues;
- Real-time session data: server-sent events (SSE) session identifiers used to push new orders and status updates to the app;
- Authentication security events: login attempts, password changes, session families, device revocation records, and audit-trail entries. Passwords and refresh tokens are stored only as hashes — never in plaintext.
2.7 Web Deletion & Support Requests
When you submit a deletion or support request through the website or by email, we collect your identifying details, the request content, and our correspondence, used to verify your identity and process the request.
3. Legal Basis for Processing
In accordance with Moroccan Law No. 09-08, we process your personal data on the following legal grounds:
- Performance of a Contract: processing necessary to execute the Merchant Terms — business onboarding and verification, store listing, order routing, commission and payout computation, statements, and support.
- Legal Obligation: tax and accounting records, commercial books, retention of financial documents, and responses to lawful requests from Moroccan judicial or administrative authorities.
- Legitimate Interests: platform safety, fraud prevention (including anomaly detection and rate limiting), service quality monitoring, and aggregated analytics — balanced against your fundamental rights.
- Consent (where required): marketing communications, promotional push messages, and any processing going beyond what the contract strictly requires. You may withdraw consent at any time.
CNDP formalities: EVODOO completes the declaration and, where required, prior authorization duties with the CNDP before operating the corresponding processing — in particular for sensitive identification data, geolocation-based operations, and transfers to countries without adequate protection.
4. How We Use Your Data
- Onboarding & Verification: reviewing your application, verifying business identity, RC/ICE records, representative details, and bank RIB, and deciding on approval.
- Listing: publishing and maintaining your store profile, hours, zones, catalog, prices, and promotions in the consumer app.
- Order Routing: sending you incoming orders in real time, tracking acceptance, preparation, readiness, and handover.
- Commission & Payout Computation: calculating commissions, building settlement periods, generating statements, and executing bank payouts.
- Statements: providing order histories, financial snapshots, and invoices for your accounting.
- Support: responding to your requests, investigating incidents and disputes, and verifying your identity.
- Safety & Fraud: detecting abnormal activity, preventing abuse, enforcing platform rules, and protecting customers, drivers, and merchants.
- Product Improvement: aggregated analytics, crash fixing, and service development.
- Legal Compliance: tax records, commercial books, CNDP formalities, and lawful authority requests.
5. Processors & Third-Party Services
The Drayk Store app and platform rely on the following processors and third-party services, each processing certain data under its own privacy policy and under contract with EVODOO. We vet providers contractually and limit their access to what is strictly necessary for a defined purpose:
- Google Maps Platform & Routes API (Google LLC): store geocoding, delivery-zone geometry, distances, and durations, per Google's Privacy Policy.
- Firebase Cloud Messaging, App Installations & Crashlytics (Google LLC): push delivery for new orders and settlement notices, installation identifiers, and crash diagnostics, per Firebase Privacy & Security and Google's policy above.
- Meta WhatsApp Business API (Meta Platforms, Inc., United States): operational and support messaging with your store, per WhatsApp's Privacy Policy.
- Payment & bank rails: banking partners that execute settlement payouts to your verified RIB under their own regulatory frameworks.
- Media hosting provider: storage of store logos, cover images, and catalog photos under encryption and access controls.
- Cloudflare, Inc.: content delivery, caching, DNS, and protection against malicious traffic for our APIs and website.
All processors act solely on EVODOO's documented instructions, under confidentiality and purpose-limitation obligations. We never authorize them to use your data for their own advertising purposes.
6. What Customers & Drivers See
We apply strict data minimization to what each party can see:
- Customers see only: your public store name, logo and cover photos, menu with prices, opening hours, preparation-time estimates, delivery conditions, and promotions. They never see your RIB, tax identifiers, RC/ICE numbers, internal notes, or staff details.
- Drivers see only: your store name, pickup address and access instructions, and the handover information of the specific order they are collecting — and only while that job is active.
Conversely, the app may show you limited third-party personal data needed for an order — such as a customer first name, special preparation notes, or a driver identifier for handover. When handling this data you must use it exclusively to prepare and hand over the assigned order, never copy, store, or disclose it, and never contact customers or drivers outside the assigned job. Any misuse is a serious breach of the Merchant Terms and may be referred to the competent Moroccan authorities.
7. No Sale of Data & No Cross-App Tracking
- No sale: EVODOO does not sell your personal data — or your staff's — to any third party, for any purpose.
- No cross-app advertising tracking: the Drayk Store app contains no third-party advertising SDKs and does not track you across other companies' apps or websites. In Apple App Tracking Transparency (ATT) terms: we do not track, we do not use the IDFA for advertising, and we do not share data with data brokers.
- No advertising profiles: your business and transaction data is never used to build advertising profiles or shared with advertisers.
8. International Data Transfers
Your data is primarily stored and processed in Morocco. However, some providers operate servers outside Morocco — notably Meta (WhatsApp, United States) for messaging, Google (Firebase Cloud Messaging, Crashlytics) on global infrastructure, Google (Maps) on global infrastructure, and Cloudflare on its global edge network.
Under Articles 43–44 of Law No. 09-08, a transfer of personal data to a foreign country is permitted only where that country ensures an adequate level of protection or where the CNDP has granted an authorization. Accordingly, transfers outside Morocco are included in our CNDP filings, prior CNDP authorization is sought wherever the law requires it — in particular for transfers to countries not recognized as providing adequate protection — and we apply safeguards including data-processing agreements imposing protections equivalent to Law No. 09-08 and strict minimization (for example, only the data strictly needed for the outsourced function leaves Morocco). For transfer questions, contact [email protected].
9. Information Security
- Encryption in Transit: all app-to-server traffic uses TLS — never plain HTTP.
- Encryption at Rest: databases and backups are encrypted; secrets are held in managed secrets storage.
- Credential Security: passwords are hashed with bcrypt (cost factor 12); OTP codes and refresh tokens are stored only as HMAC-SHA256 hashes; plaintext secrets are never persisted.
- Token Architecture: 15-minute signed JWT (HS256) access tokens; 256-bit opaque refresh tokens rotated on every use within token families, with reuse treated as a breach signal; device-bound sessions with remote revocation.
- RIB Masking: bank account numbers are masked in the app and back-office interfaces; full values are accessible only to strictly authorized finance operations.
- Least-Privilege Access: need-to-know access only — onboarding reviewers see business documents, finance sees payouts, support sees only the store or order at hand.
- Audit Trail: authentication events, permission changes, catalog and payout operations are logged for security review.
- Infrastructure: firewalls, intrusion detection, monitored error logging without user-data exposure, and rate limiting against brute force and abuse.
No digital system is 100% secure. Protect your devices with lock screens, use strong unique passwords, never share credentials or verification codes between staff, revoke access of departed staff immediately, and notify us at once of any suspected unauthorized access.
10. Data Retention Periods
We keep your data only as long as necessary for the purposes in this Policy:
- Active Account Data: retained while your merchant account is active and during the 15-day cancellable deletion grace period.
- Orders, Financial Snapshots & Settlement Ledger: minimum 5 years after the transaction, per Moroccan commercial and tax obligations.
- Business Registration & KYC Documents: retained for the duration of the commercial relationship plus 5 years thereafter for legal, tax, and dispute purposes, in access-restricted storage.
- Audit & Security Events: retained for 2 years for fraud investigation and platform safety.
- Support & WhatsApp Threads: up to 2 years after resolution of the request or dispute.
- Crash Reports: retained by Firebase Crashlytics for a rolling 90-day period for debugging.
- Push Tokens & SSE Sessions: push tokens are kept until you revoke them or after 45 days of app inactivity; SSE session identifiers are ephemeral and expire when the session ends.
- Deletion Requests & Correspondence: retained for 2 years as proof of compliance.
- Anonymized Analytics: may be kept indefinitely in de-identified, aggregated form.
After the applicable period, data is securely deleted or permanently anonymized.
11. Deletion & Your Requests
The Drayk Store app offers no self-serve account deletion. Because closing a merchant account affects catalog publication, pending orders, and regulated financial records, deletion is handled through verified support:
- Via the app: open Settings → Contact support, which opens WhatsApp with a prefilled deletion-request message identifying your store. Send it to start the process.
- By Email / Web: send a request to [email protected] from your registered business email or phone number with the subject "Merchant Account Deletion Request". This same address serves as our public web deletion contact for store compliance.
Upon your verified request, we confirm your identity as the account owner or authorized representative, settle any outstanding orders and payouts, and close ordering for your store. A 15-day grace period then begins during which you may contact us to cancel the deletion; afterwards your profile, catalog access, and session data are permanently deleted or anonymized. Data the law requires us to keep (orders, financial snapshots, settlement ledger, and tax records) is retained in de-identified, access-restricted form for the statutory 5-year periods above, and active legal disputes pause deletion of related records until resolved. Once processing completes, deletion is irreversible.
12. Staff & Multi-User Duties
Your store administrator may create seats for managers and staff inside the app. In this respect:
- You act as data controller for the personal data of your staff that you enter or manage in the app (names, phone numbers, roles). You must inform your staff of this processing and ensure you have a lawful basis to share their data with EVODOO for account operation.
- Access hygiene: grant each user only the permissions they need, use one personal account per user (never shared logins), and revoke access immediately when a staff member leaves.
- Device discipline: staff devices showing order and customer information must be locked, kept in staff-only areas where possible, and signed out at the end of shifts on shared terminals.
- EVODOO processes staff-user data as described in this Policy and provides the administrator with the means to review and remove staff seats.
13. Push Notifications & Sounds
Push notifications — with optional audible order alerts — are operationally essential for merchants and include:
- New Orders: incoming order alerts with preparation timers; these are required to trade — receiving orders requires an active push registration.
- Incidents: customer-unavailable notices, driver-arrival updates, cancellation and dispute alerts.
- Deposits & Payouts: settlement confirmations, payout notices, and bank-transfer failure alerts.
- Weekly Digest (optional): sales summaries and platform news. You may opt out of non-essential messages anytime.
Notification preferences (order sounds, incident alerts, digest) can be adjusted in the app's notification settings; system-level control remains available in your device settings. To deliver notifications we store your device push token, Firebase installation ID, locale, and timezone. Logging out revokes the push registration on that device.
14. Cookies, Storage & Webview
Website Cookies
When you visit drayk.ma (for example, the merchant onboarding or support pages), we may use strictly necessary cookies (session, language, consent choice), functional cookies (preferences), and — only with your prior consent — audience-measurement, advertising, or social-network cookies. In line with the CNDP cookie decision D-939-2025, consent-based cookies expire after a maximum of 6 months, and you may withdraw consent at any time in your browser settings; disabling some cookies may affect the site.
Mobile App Secure Storage
The Drayk Store app stores data on your device via the OS secure keystore (Keychain on iOS, Keystore on Android), app-private storage, and a local SQLite cache for offline resilience:
- Encrypted authentication tokens and session identifiers;
- Preferences: language, theme, notification and sound settings, onboarding flags;
- Cached operational data (store profile, recent orders) for offline resilience.
The app embeds no third-party advertising SDKs, and any in-app webview uses first-party local storage only. Logging out wipes session keys; uninstalling the app or clearing app data removes remaining local data. Server-side data is governed by Sections 10–11 above.
15. Apple App Store & Google Play Disclosures
For full transparency towards store review and towards you, we summarize here how this Policy maps to store requirements for Drayk Store:
- Apple Privacy Nutrition Labels (Drayk Store): Contact Info (business email, phone number, representative name); Identifiers (account and device identifiers); Financial Info (masked RIB destination, settlements); Usage & Diagnostics (crash data, SSE session activity); Photos (store and catalog images you choose to upload). Data is linked to the business account and used for app functionality, analytics, and fraud prevention; it is not sold, not used for third-party advertising, and not used for cross-app tracking.
- Google Play Data Safety (Drayk Store): personal info, financial info, photos, and app activity collected as described; data encrypted in transit; account deletion available via in-app WhatsApp support and via [email protected].
- No Tracking (Apple ATT): the app does not track you across other companies' apps or websites and does not use the IDFA for advertising.
- Required Links: this Policy URL is the app's store privacy-policy link; Section 11 provides the account-deletion path and contact required by both stores.
16. Children's Privacy
Drayk Store is an exclusively business-to-business service. Account holders must be persons aged 18 or older with full legal capacity to bind the business. We do not knowingly collect data from minors. Accounts found to be held by under-18 persons are immediately suspended and closed. If you believe a minor has submitted data, contact [email protected] for prompt removal.
17. Your Rights & the CNDP
Under Moroccan Law No. 09-08, you hold the following rights over your personal data:
- Access: obtain a copy of the personal data we hold about you and how it is processed and shared.
- Rectification: correct inaccurate, incomplete, or outdated data (many store and profile fields are editable in-app; business documents are renewed by resubmission).
- Erasure: request permanent deletion where data is no longer necessary, subject to statutory retention (Section 10).
- Objection (Articles 7–8): object to legitimate-interest processing, especially direct marketing — marketing stops immediately upon objection.
- Restriction: request a temporary processing pause (e.g., while an accuracy dispute is resolved).
- Portability: receive your data in a structured, machine-readable format and transmit it elsewhere where technically feasible.
- Breach Information: be notified without undue delay of any breach likely to create high risk to your rights.
- Complaint to the CNDP (Article 36): if you believe your rights have been violated, first contact us at [email protected] so we can resolve the matter; you may then lodge a complaint with the National Commission for the Control of Personal Data Protection at www.cndp.ma.
Exercise any right at [email protected], which also reaches our data-protection (CIL/DPO) contact. We respond to verified requests within 30 days and may require identity proof to prevent unauthorized access.
18. Policy Changes & Contact
We may update this Policy to reflect new features, legal requirements, or CNDP guidance. Material changes are notified via in-app notice and/or email, and the "Last Updated" date is revised. Continued use after notification constitutes acceptance. If you disagree, stop using the Store app and exercise your deletion right under Section 11.
For questions, rights requests, or complaints, contact EVODOO SARL: