Privacy Policy

Last updated: 21 March 2026

BukaXp Limited ("BukaXp", "we", "us", "our") is committed to protecting your personal data. This policy explains what information we collect, how we use it, and your rights under UK GDPR and the Data Protection Act 2018.

1. Who We Are

BukaXp Limited is a Nigerian restaurant and catering business based in Derby, UK. We operate the website bukaxp.com. For data protection enquiries, contact us at info@bukaxp.com.

2. Data We Collect

We collect the following personal data when you use our services:

  • Name, email address and phone number — when you place an order, make a table reservation, or create an account.
  • Delivery address and postcode — only for delivery orders.
  • Order details — the dishes you ordered, order total, and order type (delivery or collection).
  • Account credentials — your email and hashed password if you register for an account. We never store plain-text passwords.
  • Contact form messages — any enquiries you send us via the contact page.
  • Technical data — your IP address and browser type, collected automatically via standard server logs.

We do not collect or store payment card details. All payment processing is handled securely by Square (see Section 4).

3. How We Use Your Data

We use your personal data to:

  • Process and fulfil your food orders and send order confirmation and status emails.
  • Manage table reservations and send reservation confirmation emails.
  • Respond to enquiries submitted via our contact form.
  • Send newsletters and promotional emails — only if you have an account or have opted in. You can unsubscribe at any time by contacting us.
  • Comply with our legal and tax obligations.
  • Improve and secure our website.

Our lawful basis for processing is contract performance (to fulfil your order or reservation), legitimate interests (website security and service improvement), and consent (for marketing emails).

4. Third-Party Services

We use the following trusted third-party services to operate our website. Each has its own privacy policy:

  • Square — payment processing. When you pay, you are directed to Square's secure checkout page. Square processes your card details and we never see them. Square Privacy Policy.
  • Supabase — secure database and authentication. Your account and order data is stored on Supabase servers in the EU. Supabase Privacy Policy.
  • Sanity — content management for our menu and website content. No personal data is stored in Sanity. Sanity Privacy Policy.
  • Netlify — website hosting. Netlify may process your IP address as part of standard web hosting. Netlify Privacy Policy.

We do not sell your personal data to any third party.

5. Cookies

Our website uses cookies to make it function properly. We only use essential cookies — we do not currently use advertising or tracking cookies.

Essential cookies we use:

  • bukaxp_token — keeps you logged in to your account during a session.
  • bukaxp_cookie_consent — remembers that you have acknowledged this cookie notice.

These cookies are necessary for the site to work and cannot be disabled without breaking core functionality. They do not track you across other websites.

6. Data Retention

We retain your order and reservation records for up to 7 years to comply with UK tax and accounting regulations. Account data is retained until you request deletion. Newsletter subscription data is retained until you unsubscribe.

7. Your Rights

Under UK GDPR you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate data.
  • Erasure — ask us to delete your data (subject to legal retention requirements).
  • Restriction — ask us to limit how we use your data.
  • Portability — receive your data in a portable format.
  • Objection — object to processing based on legitimate interests.
  • Withdraw consent — opt out of marketing emails at any time.

To exercise any of these rights, email us at info@bukaxp.com. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).

8. Security

We take reasonable technical and organisational measures to protect your data, including encrypted connections (HTTPS), hashed passwords, and access controls. No method of transmission over the internet is 100% secure, but we work to maintain appropriate safeguards.

9. Changes to This Policy

We may update this policy from time to time. The "Last updated" date at the top of this page will always reflect the most recent version. Continued use of our website after changes constitutes acceptance of the updated policy.

10. Contact Us

For any privacy-related questions, please contact us at:

BukaXp Limited

Derby, United Kingdom

info@bukaxp.com

bukaxp.com