The protection of your personal information is a top priority for EVODOO SARL, the company behind the Drayk platform. We understand that the trust you place in us is essential, and we are fully committed to respecting and protecting your privacy every time you use our application or visit our website.
Please read this Privacy and Cookie Policy (the "Policy") carefully to understand our practices regarding the collection, use, protection, and sharing of your personal data. By downloading, installing, or using the Drayk application — whether on a smartphone, tablet, or any similar device — you acknowledge that you have read and understood this Policy.
Our mobile application and associated services (collectively, the "Application" or "Services") are operated and controlled by EVODOO SARL, which acts as the data controller under Moroccan Law No. 09-08 relating to the protection of personal data.
1. Commitment to Privacy
We are dedicated to maintaining the highest standards of data protection, guided by the following core principles:
- Data Minimization: We collect only the personal information that is strictly necessary to provide, secure, and continuously improve our Services.
- Purpose Limitation: Your personal data is processed exclusively for specific, legitimate purposes and is never used in ways incompatible with those purposes.
- Transparency: We are open and honest about the data we collect, why we collect it, how we use it, and with whom we share it.
- Data Security: We implement robust administrative, technical, and physical security measures to protect your data from unauthorized access, disclosure, alteration, or destruction.
- Your Rights: We respect and actively facilitate your rights to access, correct, delete, and control your personal data at any time.
- Legal Compliance: All data processing is conducted in strict compliance with Moroccan Law No. 09-08 and applicable international best practices.
2. Information We Collect
To provide you with a safe, seamless, and personalized experience on Drayk, we collect the following categories of personal information:
2.1 Account & Identity Information
- Phone Number: Used as your primary identifier for account creation, login via One-Time Password (OTP), and two-factor authentication.
- Full Name: Provided at registration and used for personalizing your experience and processing orders.
- Email Address: Optional, used for account communications and promotional updates (if you consent).
- Profile Photo: Optional avatar image you may upload to personalize your account.
2.2 Location Information
- Precise GPS Location (When-In-Use): Collected when you open the app and grant location permission, used to show nearby restaurants, calculate delivery distances, estimate delivery fees, and verify your location is within a deliverable area. We request location access only "While Using the App" — we do not track your location in the background.
- Saved Delivery Addresses: Physical addresses you save to your account, including city, street address, and optional delivery instructions (e.g., floor number, gate code). You may save up to 10 addresses.
2.3 Order & Transaction Information
- Food Delivery Orders: Items ordered, quantities, special instructions, selected restaurant, order timestamps, order status history, total amount, delivery fee, applied promotions or coupons, and payment method (cash, card, or wallet).
- Courier Service Orders: Pickup address, pickup contact name and phone number, delivery address, delivery contact name and phone number, errand description, estimated package value, and delivery instructions.
- Order History: A complete record of past orders used to generate personalized recommendations and enable easy reordering.
2.4 Payment Information
When you choose to pay by card, your payment details (card number, cardholder name, expiry date, CVV) are processed exclusively by our certified Moroccan payment gateway partner. EVODOO does not store, process, or have access to your raw payment card details on its own servers. All card transactions are secured by PCI-DSS compliant infrastructure.
2.5 Referral & Attribution Data
To attribute referrals when you join Drayk through a friend's invite link, we temporarily collect and store the following device fingerprint data for up to 72 hours:
- IP Address: Your device's internet protocol address at the time you clicked the referral link.
- User Agent: Your browser or operating system identifier string.
- Screen Dimensions: Your device screen width and height (used as part of the fingerprint).
- Platform: Whether you are on iOS or Android.
- Referral Code: The unique referral code of the person who invited you.
This data is used solely to match you with the person who referred you and attribute any applicable rewards. It is automatically purged after 72 hours. This process is entirely anonymous to third parties — the referrer receives only a notification that their code was successfully used.
2.6 Wishlist Data
Items and restaurants you save to your wishlist are stored in your account to provide a personalized browsing experience across sessions and devices.
2.7 Reviews & User-Generated Content
Written reviews, star ratings, and any other feedback you submit regarding restaurants, products, or drivers are collected and may be publicly displayed on the platform after moderation. By submitting a review, you grant Drayk a non-exclusive license to display it on the platform.
2.8 Device & Technical Information
- Device type, model, and operating system version
- App version and build number
- IP address and network type
- Preferred language setting
- Unique device tokens used for push notification delivery
- Crash logs, error reports, and app performance diagnostics (collected via Sentry — see Section 5)
2.9 Usage & Behavioral Data
- Search queries entered within the app
- Restaurant and product pages viewed
- Features accessed and interaction patterns
- Session duration and frequency of use
This data is used in aggregate form to understand how our platform is used and to continuously improve the user experience.
2.10 Companion & Third-Party Data
In certain scenarios — such as courier orders where you provide pickup or delivery contact details for another person — we may collect the name and phone number of that third party. By providing such information, you confirm that you have obtained the prior informed consent of the individual concerned and that you are authorized to share their personal data with our platform.
3. Legal Basis for Processing
In accordance with Moroccan Law No. 09-08, we process your personal data based on the following legal grounds:
- Performance of a Contract: Processing necessary to deliver the services you requested — including order processing, delivery, payment, and account management.
- Legitimate Interests: Processing necessary for our legitimate interests in operating a safe and fraud-free platform, including fraud detection, security monitoring, and service analytics — provided these interests do not override your fundamental rights.
- Consent: Processing for which you have given explicit, freely given consent — including receiving marketing communications, promotional push notifications, and participating in our referral program. You may withdraw your consent at any time.
- Legal Obligation: Processing required by applicable Moroccan laws, including tax record-keeping, financial reporting obligations, and responding to lawful requests from public authorities.
4. How We Use Your Information
Your personal data is used for the following specific, legitimate purposes:
- Account Creation & Management: Creating and maintaining your Drayk account, verifying your identity via OTP, managing your login sessions, and processing account updates.
- Order Processing & Fulfillment: Transmitting your order details to the selected restaurant or courier, calculating delivery fees, applying promotions, tracking order status, and coordinating delivery.
- Delivery Location Services: Using your location to display nearby restaurants, verify your delivery address is within our service area, and calculate accurate delivery distances and fees.
- Payment Processing: Facilitating secure payment transactions via our certified payment gateway partner.
- Referral Attribution: Identifying and crediting referrals when you or a friend uses a referral code, and generating any applicable reward coupons.
- Customer Support: Responding to your inquiries, resolving complaints, investigating disputes, and providing technical assistance.
- Fraud Prevention & Security: Detecting, investigating, and preventing fraudulent transactions, unauthorized account access, platform abuse, and other illegal activities.
- Service Improvement & Analytics: Analyzing aggregated usage data to understand platform performance, improve features, fix bugs, and enhance the overall user experience.
- Personalization: Displaying relevant restaurant recommendations, personalized promotions, and reorder suggestions based on your order history and preferences.
- Marketing & Promotions (with your consent): Sending promotional offers, seasonal campaigns, and platform updates via push notification or email. You may opt out at any time through your device notification settings or by contacting us.
- Legal Compliance: Fulfilling our obligations under Moroccan tax, financial, and regulatory law, and responding to lawful requests from judicial or government authorities.
5. Third-Party Services & SDKs
The Drayk application integrates the following third-party services, each of which may collect or process certain data in accordance with their own privacy policies:
- Google Maps Platform (Google LLC): We use the Google Maps SDK for iOS and Android to display maps, enable location search (autocomplete), and calculate delivery distances and routing. Google may collect your device's location data and usage data in accordance with Google's Privacy Policy.
- Meta WhatsApp Business API (Meta Platforms, Inc.): We use Meta's WhatsApp Business Cloud API to deliver One-Time Password (OTP) verification codes to your phone number. When we send you an OTP, your phone number and the OTP message are transmitted to Meta's servers, which may be located in the United States. Meta's processing of this data is governed by WhatsApp's Privacy Policy.
- Sentry (Functional Software, Inc.): We use Sentry for real-time application crash monitoring and error reporting. When the Drayk app encounters a technical error, Sentry automatically collects diagnostic information including the error details, app state at the time of the crash, device type, operating system version, and app version. This data is used solely to identify and fix technical issues. Sentry's data processing is governed by Sentry's Privacy Policy.
- Moroccan Payment Gateway: For card payments, your payment information is transmitted directly to our certified Moroccan payment gateway partner. This partner is PCI-DSS certified and processes your payment data under its own security and privacy framework. EVODOO does not receive or store raw card data.
We carefully vet all third-party service providers and require them to maintain appropriate data protection and confidentiality standards through contractual agreements.
6. Sharing of Information
We do not sell your personal data. We share your data only in the following limited circumstances:
- Partner Restaurants: Order-specific information — including your name, delivery address, ordered items, and any special instructions — is shared with the restaurant fulfilling your order. Restaurants use this information solely to prepare and package your order. If you opt in to a restaurant's own marketing, that restaurant becomes an independent data controller for those communications.
- Delivery Drivers & Couriers: For delivery orders, your delivery address, building access instructions, and order reference are shared with the driver assigned to deliver your order. For courier orders, pickup and delivery contact information is shared with the assigned courier.
- Payment Processors: Encrypted payment details are transmitted to our certified payment gateway for transaction processing.
- EVODOO Group Companies: Data may be shared within the EVODOO corporate group under uniform data protection guidelines to support integrated service delivery.
- Technology & Infrastructure Providers: We share data with contracted technology vendors (hosting, databases, analytics) under strict confidentiality agreements that prohibit them from using your data for any purpose other than providing services to us.
- Legal Authorities: We may disclose your personal data when required by applicable Moroccan law, court order, or lawful government request, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
- Business Transfers: If EVODOO is involved in a merger, acquisition, or asset sale, your personal data may be transferred to the successor entity, subject to equivalent privacy protections. You will be notified of any such transfer.
7. International Data Transfers
Drayk operates primarily in Morocco, and your personal data is primarily stored and processed within Morocco. However, certain of our third-party service providers — including Meta (WhatsApp) and Sentry — operate servers located in the United States and/or other countries outside Morocco.
When your data is transferred internationally, we ensure that such transfers are governed by appropriate safeguards, including:
- Data processing agreements with third parties that impose obligations equivalent to those required by Moroccan Law No. 09-08;
- Reliance on the recipient country's recognized adequacy of data protection frameworks where applicable;
- Limiting international transfers to what is strictly necessary for service delivery (e.g., OTP delivery via WhatsApp, crash reporting via Sentry).
For questions regarding international data transfers, please contact us at contact@evodoo.ma.
8. Information Security
Protecting your personal data is a technical and organizational priority. We implement the following security measures:
- Encryption in Transit: All data transmitted between the Drayk app and our servers is encrypted using TLS (Transport Layer Security) — never sent over plain HTTP.
- Credential Security: OTP codes are hashed using HMAC-SHA256 before being stored — plaintext codes are never persisted to our database. Refresh tokens are stored only as cryptographic hashes using the same technique.
- Token Architecture: Access tokens have a 15-minute lifespan and are cryptographically signed JWTs. Refresh tokens are high-entropy opaque tokens (256 bits of randomness) rotated on every use — a reused token is treated as a security breach indicator.
- Payment Security: Raw payment card data is never transmitted to or stored on EVODOO's servers. All card data is handled exclusively by our PCI-DSS certified payment gateway partner.
- Access Controls: Access to personal data within our systems is restricted on a need-to-know basis. Only personnel with a legitimate operational requirement can access your data.
- Rate Limiting & Brute Force Protection: All authentication endpoints are protected by strict rate limiters to prevent OTP brute-force attacks, credential stuffing, and SMS flooding.
- Infrastructure Security: Our servers operate behind firewalls and network intrusion detection systems. Application panics and errors are logged and monitored without exposing user data.
While we implement industry-standard security practices, no method of digital storage or internet transmission is 100% secure. We therefore cannot guarantee absolute security. We encourage you to use a strong, unique password (if applicable) and to keep your device software updated.
9. Data Retention Periods
We retain your personal data for as long as necessary to fulfill the purposes outlined in this Policy, subject to the following retention periods:
- Active Account Data: Retained while your account is active and during the 15-day cancellable deletion grace period.
- Order Records: Retained for a minimum of 5 years after order completion, in compliance with Moroccan commercial and tax record-keeping obligations.
- OTP Verification Records: Automatically expired after 5 minutes and permanently deleted after 24 hours.
- Session & Refresh Tokens: Automatically expire after 7 days and are deleted upon logout or token rotation.
- Referral Fingerprint Data: Automatically purged 72 hours after collection, or immediately upon successful attribution — whichever occurs first.
- Crash Reports: Retained by Sentry for a rolling 90-day period for debugging purposes.
- Support Communications: Retained for up to 2 years from the date of resolution for quality assurance and legal compliance purposes.
- Anonymized Analytics Data: May be retained indefinitely in de-identified, aggregated form that cannot be linked back to any individual.
Following the applicable retention period, your data will be securely deleted or permanently anonymized.
10. Account Deletion
You have the right to delete your Drayk account and all associated personal data at any time. Account deletion can be requested in the following ways:
- In-App: Navigate to Profile → Profile details → Delete account and follow the on-screen instructions.
- By Email: Send a deletion request to contact@evodoo.ma from the email address or phone number registered to your account. Include "Account Deletion Request" in the subject line.
Upon receiving your verified request:
- You are signed out when the request is submitted. Your account remains accessible by signing in during the grace period so that you can review and cancel the request.
- Your personal profile data is permanently deleted or anonymized after the 15-day grace period expires unless you cancel first.
- Data required by law, including order and tax records, may be retained in a de-identified, access-restricted form for the applicable statutory period or to resolve disputes.
Cancellation is available until the displayed deadline. Once processing completes, deletion is irreversible; profile details, saved addresses, wishlists, and referral credits cannot be restored.
11. Push Notifications
With your permission, Drayk may send you push notifications to your device. These include:
- Transactional Notifications: Real-time order status updates (order confirmed, preparing, out for delivery, delivered), OTP codes for verification, and account security alerts. These are essential to service delivery and are not marketing communications.
- Promotional Notifications: Special offers, new restaurant alerts, seasonal campaigns, and referral program updates. These are sent only with your consent.
To deliver push notifications, we collect and store your device's push notification token. You can manage or withdraw your consent for push notifications at any time through your device's operating system notification settings (iOS: Settings → Notifications → Drayk; Android: Settings → Apps → Drayk → Notifications). Disabling promotional notifications will not affect transactional order-status notifications.
12. Cookies & Local Storage
Website Cookies
When you visit the Drayk website (drayk.ma), we may use the following types of cookies:
- Essential Cookies: Strictly necessary for the website to function properly (e.g., session management, language preferences). These cannot be disabled.
- Functional Cookies: Remember your preferences and settings to personalize your experience (e.g., language selection).
- Analytics Cookies: Used to understand how visitors interact with our website in aggregate (e.g., pages visited, time on site). This data is anonymized and used solely to improve our website.
You can control cookie preferences through your browser settings. Disabling certain cookies may impact website functionality.
Mobile Application Local Storage
The Drayk mobile application uses on-device local storage (SQLite database via the Drift library) to store the following data locally on your device:
- Cached restaurant and menu data for faster load times and offline browsing
- Your recent search history within the app
- Encrypted authentication tokens stored securely via the operating system's secure keystore (Keychain on iOS, Keystore on Android)
You can clear all locally stored app data by uninstalling the Drayk application or by clearing the app's data through your device's application management settings.
13. Children's Privacy
The Drayk platform is intended exclusively for users who are 18 years of age or older. Our Services involve financial transactions, food ordering, and delivery logistics, which require legal majority under Moroccan law.
We do not knowingly collect, use, or share personal information from individuals under the age of 18. If you are a parent or guardian and believe that your child has provided us with personal information without your consent, please contact us immediately at contact@evodoo.ma. Upon verification, we will promptly delete the information from our systems.
If you are under 18, please do not create an account on Drayk or submit any personal information through our platform.
14. Do Not Track Signals
Our application does not currently modify its operations in response to "Do Not Track" (DNT) browser signals. This is due to the absence of a universally adopted, standardized regulatory framework for DNT signals. We continue to monitor industry developments and will review our approach once a clear international standard is established.
15. Your Privacy Rights
Under Moroccan Law No. 09-08 and in alignment with internationally recognized privacy standards, you have the following rights regarding your personal data:
- Right of Access: The right to request a copy of all personal data we hold about you, including information on how it is processed and with whom it is shared.
- Right of Rectification: The right to request the correction of inaccurate, incomplete, or outdated personal data held in your account.
- Right to Erasure ("Right to be Forgotten"): The right to request the permanent deletion of your personal data when it is no longer necessary for the purposes for which it was collected, subject to legal retention obligations.
- Right to Object: The right to object to processing based on legitimate interests, in particular for direct marketing purposes. Upon objection to marketing, we will cease processing your data for that purpose immediately.
- Right to Restrict Processing: The right to request that we temporarily pause processing your data in certain circumstances (e.g., while a dispute over accuracy is resolved).
- Right to Data Portability: The right to receive a copy of your personal data in a structured, machine-readable format and to transmit it to another service provider where technically feasible.
- Right to be Informed of Data Breaches: If a data breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with our legal obligations.
- Right to Lodge a Complaint: You have the right to lodge a complaint with the Moroccan National Commission for the Control of Personal Data Protection (CNDP) at www.cndp.ma if you believe your data rights have been violated.
To exercise any of the above rights, please contact us at contact@evodoo.ma. We will respond to verified requests within 30 days. We may require proof of identity to protect against unauthorized data access.
16. Policy Modifications
We reserve the right to update or modify this Policy at any time to reflect changes in our data practices, legal requirements, or platform features. When we make material changes to this Policy, we will notify you through one or more of the following methods:
- A prominent in-app notification when you next open the Drayk application;
- An email notification to your registered email address (if provided);
- An update to the "Last Updated" date at the top of this page.
Your continued use of the Drayk platform after notification constitutes your acceptance of the updated Policy. If you do not agree with the modified Policy, you should discontinue use of the platform and may request account deletion.
17. Contact Us
For any questions, concerns, privacy rights requests, or complaints regarding this Policy or our data practices, please contact EVODOO SARL through the following channels: