Skip to content
InstaOrder
How it works Platform Pricing Apps Courier policy
English العربية
Vendor sign-in

InstaOrder · Vendor application

Vendor Privacy Policy

How InstaOrder collects, uses, stores and shares information when you use the InstaOrder Vendor app and Vendor Panel to request and manage deliveries.

Effective22 September 2026
Version1.1
Applies tocom.instaorder.vendor · vendor.instaorder.app
PlatformsAndroid · iOS · Web

Contents

  1. Who this policy covers
  2. What we collect
  3. Permissions and browser settings
  4. How we use your information
  5. Vendor-to-vendor confidentiality
  6. Who we share information with
  7. Marketing and communications
  8. Aggregated and de-identified data
  9. Storage, security and location
  10. Retention and deletion
  11. Your choices
  12. Children
  13. Changes to this policy
  14. Contact us

The short version

  • We collect what we need to run deliveries for your business: your phone number, your business details, the location of your shop, and a record of your trips, orders and wallet.
  • We never show your business data to another vendor. Your order volumes, revenue, customers, pricing and wallet are not visible to anyone you compete with.
  • We use your data to operate the service, to improve and develop the platform, and to market InstaOrder's own products and services to you.
  • Location is used only while the app is open, to place your shop on the map. We do not track you in the background.
  • You can ask us for a copy of your data, correct it, or close your account at any time.
  • The Vendor Panel keeps your sign-in in your own browser's storage. There are no advertising cookies and no third-party trackers on it.

Who this policy covers

This policy is issued by the team behind InstaOrder (“InstaOrder”, “we”, “us”), a delivery service operating in Egypt. We are the ones responsible for the information described here, and you can reach us at any time using Section 14.

It applies to the InstaOrder Vendor mobile application, the Vendor Panel at vendor.instaorder.app, and the InstaOrder services you reach through them. It covers you as a vendor account holder, and it covers the individual people who use the account on your business's behalf — the owner and any registered workers.

Our InstaPilot courier app and our internal administration tools are governed by their own notices. Where this policy refers to “your data”, it means both your business information and the personal data of the people who operate your account.

What we collect

We collect only what the service needs to function, plus the technical data any mobile app generates in normal use. We do not buy personal data about you from third parties, and we do not use advertising identifiers or cross-app tracking.

Data inventory — InstaOrder Vendor v1.1.0 and the Vendor Panel
Category What it includes Why we hold it
Account identityphone, otp Your mobile number, and the one-time codes we send to it by SMS to sign you in. To create and secure your account. This is how you log in — we do not use passwords.
Business profilecompany_name, address, business_type Business name, owner or manager name, business type, street address, and email address if you choose to give one. To register your business, route couriers to you, and issue invoices and statements.
People on the accountworkers The name and mobile number of the owner, and of each worker you register to use the account on the business's behalf. To sign each of them in under your account, and to show you who acted on it.
Shop logologo The image you upload for your shop, if you upload one. To identify your business in the apps and to the courier taking your delivery.
Business locationlatitude, longitude, district The map coordinates you pin for your shop during registration, and the district we derive from them. To work out which district your shop falls in, and to dispatch a courier to the right door.
Operational recordstrips, orders, order_cost Delivery requests, trip and order status, order values, dates and times, and the name and phone number of the courier assigned to each trip. To dispatch, track and settle deliveries, and to resolve disputes.
Financial recordsbalance, transactions Your prepaid wallet balance, allowance limit, and the ledger of charges, credits and settlements in EGP. To bill you correctly and to meet our accounting and tax obligations.
Push notificationsfcm_token The notification token your phone is issued by Firebase Cloud Messaging, and the one your browser is issued if you allow notifications in the Vendor Panel. To alert you when an order is accepted, a courier is assigned, or a trip changes state. The token identifies the device, not you, and is released when you sign out of it.
Device and diagnosticsapp_version, os, crash App version, operating system version, device model, language setting, network type, crash reports and performance measurements. To keep the app working, deliver over-the-air updates, and diagnose faults.
Support correspondencetickets Messages, calls and attachments you send us when you contact support. To answer you and to keep a record of what was agreed.

Your session credentials are stored in your device's secure keystore. We never see or store your device passcode or biometrics.

Device permissions and browser settings

The app asks for three optional permissions. You can grant or withdraw each of them at any time from Settings > Permissions in the app, or from your device settings. The app remains usable if you decline, though some features will not work.

Location — while the app is open only

We request location access so that the registration map can centre on where you are standing, so you can drop a pin on your shop, and so we can suggest a street address for it. Location is read only while the app is in the foreground and only at the moment you use the map. The app does not collect your location in the background, does not run a location service when it is closed, and does not build a movement history. What we store is a single coordinate pair for your business address — not a trail.

Notifications

Used to alert you about orders, trips and account activity. Declining this permission does not affect anything else in the app.

Camera

Requested so that you can take a photo when the app asks for one — for example a delivery document or proof of delivery. The camera is opened only when you deliberately start a capture. We do not access the camera in the background, and we collect no image unless you take one and submit it.

The Vendor Panel in your browser

The panel asks your browser for permission to show notifications when you sign in, and works without it if you decline. It keeps your session, your language and your light-or-dark preference in your own browser's storage, on that device — clearing the site's data signs you out of it and nothing else. There are no advertising cookies, no analytics tags and no third-party scripts on the panel. A browser you sign out of stops receiving that shop's notifications, so sign out of a shared computer rather than closing the tab.

How we use your information

We use the information described in Section 2 for the following purposes.

  • Providing the service. Registering and verifying your business, authenticating you, dispatching couriers, tracking deliveries, and operating your wallet.
  • Billing and finance. Charging delivery fees, reconciling your wallet, issuing statements, collecting what is owed, and keeping our own accounts in order.
  • Safety, security and fraud prevention. Detecting misuse, protecting couriers and vendors, investigating incidents, and enforcing our terms.
  • Support. Answering your questions and resolving disputes between you and a courier or a recipient.
  • Improving and developing the platform. Analysing how the service is used to improve routing, pricing, coverage, reliability and the design of our apps; testing changes; and researching, building and launching new products and features.
  • Business analytics and planning. Measuring demand, capacity, courier supply and commercial performance across cities, districts and business types, to plan where and how we grow.
  • Marketing our own services to you. Telling you about InstaOrder features, offers, pricing changes and services that may be relevant to your business, by push notification, SMS, email, phone or in the app. See Section 7.
  • Legal compliance. Responding to lawful requests from courts, regulators and law enforcement, and establishing or defending legal claims.

We may also use your information for other purposes that are compatible with those listed above and that serve the operation, improvement, security or growth of the InstaOrder platform. Where a new purpose is materially different from those described here, we will update this policy and tell you before it takes effect.

Vendor-to-vendor confidentiality

This is the commitment that matters most to the businesses on our platform, so we state it plainly and without qualification.

Our commitment

We do not disclose your data to another vendor. No vendor on InstaOrder can see, request, buy or be given another vendor's order volumes, revenue, delivery costs, negotiated pricing, wallet balance or transaction history, customer or recipient details, business location, contact details, or trip records.

This applies whether or not the other vendor is a competitor, whether or not they operate in your district, and whether or not they ask. It applies to our staff as well: access to vendor records inside InstaOrder is restricted to employees who need it to do their job, and is logged.

Two narrow exceptions exist, and neither involves handing your records to a competitor:

  • Operational disclosure to couriers. A courier assigned to your delivery is shown what they need to complete it — your business name, pick-up address and contact number, and the order details. They are bound by their own agreement with us and may not use it for anything else. Equally, we show you the assigned courier's name and phone number for the duration of the trip.
  • Aggregated and de-identified insights. We may publish or share market-level statistics that cannot identify you or your business, as described in Section 8.

Who we share information with

We share your information only with the categories of recipient below, and only for the purposes stated.

  • Couriers on your deliveries — limited to what the delivery requires, as described in Section 5.
  • Service providers who run our infrastructure, acting on our instructions and under contract. These currently include Google (Firebase Cloud Messaging for push notifications, and Google Maps for map display and address lookup on Android and in the browser), Apple (map display and address lookup on iPhone), Expo (over-the-air app updates and crash and performance diagnostics), our cloud hosting and database providers, and our SMS gateway for one-time login codes.
  • Payment, banking and collection partners, where they are needed to settle your account.
  • Professional advisers — auditors, accountants and lawyers — under a duty of confidentiality.
  • Authorities, where we are legally required to disclose, or where disclosure is necessary to protect our rights, our users or the public.
  • A successor, if InstaOrder is involved in a merger, acquisition, financing or sale of assets. We will tell you before your data becomes subject to a different privacy policy.

These providers process your data on our behalf under written terms that restrict them to our instructions. They are not permitted to use your data for their own purposes.

Marketing and communications

We send two kinds of message, and they are not the same thing.

Service messages tell you that an order was accepted, a courier was assigned, a trip completed, your wallet is low, or your account status changed. These are part of the service. You cannot opt out of them while your account is active, though you can silence push notifications from your device.

Marketing messages tell you about InstaOrder features, promotions, pricing and services. We send these by push notification, in-app message, SMS, email or phone. You can opt out of marketing at any time by using the unsubscribe link in an email, replying to stop an SMS, turning off notifications, or writing to us at the address in Section 14. Opting out of marketing does not stop service messages, and does not affect the price or quality of the service you receive.

We market our own products and services. We do not sell your contact details to third parties for their own marketing.

Aggregated and de-identified data

We produce statistics from the platform as a whole — delivery volumes by district, average delivery times, courier availability, seasonal demand, and similar measures. These are computed across many vendors and stripped of anything that identifies a business or a person.

What this permits, and what it does not

We may use, publish, license and share aggregated and de-identified data for any lawful purpose, including research, benchmarking, marketing, partnerships and public reporting, without further notice to you. We will not re-identify it, and we will not construct it in a way that reveals an individual vendor — including where a district or category is small enough that a single business could be inferred.

Aggregated data of this kind can no longer be traced back to you, so the choices in Section 11 do not apply to it.

Storage, security and location

We protect your data with encryption in transit (HTTPS/TLS on every request), short-lived access tokens that expire within 24 hours, storage of session credentials in your device's hardware-backed secure keystore, role-based access control inside our systems, and logging of internal access to vendor records.

A session is a pair of credentials, not a stored password: an access token that expires within a day and is renewed behind the scenes, and a renewal token that is replaced every time it is used and discarded altogether when you sign out. Signing out ends both, on that device, immediately.

Our servers and databases are operated by cloud providers whose facilities may be located outside Egypt. Where your data is stored or processed outside Egypt, we do so under terms that require an equivalent standard of protection.

No system is perfectly secure. If something goes wrong in a way that is likely to affect you, we will tell you.

Retention and deletion

We keep your data for as long as your account is active, and afterwards only as long as we have a reason to.

  • Account and profile data — kept while your account is open, then removed once it is closed and settled.
  • Trip, order and wallet records — kept while we still need them for accounting and to settle any dispute, which can outlast the account itself.
  • Support correspondence — kept while the matter is open, and for a reasonable period afterwards.
  • Diagnostics and crash reports — kept only while they are useful for fixing faults.
  • Notification tokens — released when you sign out of that phone or browser, or uninstall the app.

To close your account and request deletion of your data, email it@instaorder.app or use the account deletion form at instaorder.app/en/delete-account. We aim to confirm within 30 days and will tell you what, if anything, we are keeping and why.

Your choices

These are commitments we make to you directly. Ask, and we will:

  • tell you what information we hold about you, and why;
  • send you a copy of it;
  • correct anything that is wrong or incomplete;
  • close your account and delete what we hold, as described in Section 10;
  • stop sending you marketing, without changing the service you get; and
  • stop a particular use of your information wherever we can do that and still run deliveries for you.

To ask for any of these, contact us using Section 14. We aim to respond within 30 days. We will usually ask you to confirm a one-time code sent to your registered number first, so that nobody can make a request in your name.

Children

InstaOrder Vendor is a business tool for registered commercial vendors. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If we learn that we have, we will delete it.

Changes to this policy

We may update this policy as the service changes. When we do, we will revise the effective date at the top and increment the version. If a change materially affects how we use your data, we will tell you in the app or by message before it takes effect.

Continuing to use the app after a change takes effect means you accept the updated policy.

Contact us

For any question about this policy, or to ask for any of the things in Section 11, reach us at:

Service
InstaOrder
Email
it@instaorder.app
Phone
[SUPPORT PHONE]
Operating in
Egypt
© 2026 InstaOrder. All rights reserved. Home · العربية