Privacy Policy

Effective Date: 1st October 2026

1. Introduction

Chapaa Technologies Limited ("Chapaa", "we", "us" or "our") is committed to protecting your personal data and handling it lawfully, fairly, transparently and securely.

This Privacy Policy explains how we collect, use, share, store and protect personal data, how long we retain it, and how you may exercise your privacy rights in connection with our mobile applications, website, digital platforms and related services.

Our services may include fundraising, group contributions, payment facilitation, transaction management, digital wallets and related digital financial services, as made available from time to time. The personal data processed will depend on the services you use and the requirements applicable to them.

Where Chapaa determines the purposes and means of processing your personal data, it acts as the data controller. Where a financial institution or another service provider independently processes your information, its role and applicable privacy notice will be identified in connection with the relevant service.

Chapaa's address is Plot No. 10, Block No. 45A, New Bagamoyo Road, Dar es Salaam, Tanzania. Privacy enquiries and requests may be directed to [email protected]

2. Scope

This Policy applies to personal data processed by Chapaa in providing and administering its services, managing business relationships and undertaking related operational, security and compliance activities.

It covers information relating to account holders, campaign organizers, contributors, beneficiaries, group members, authorized approvers, customers and representatives of institutional clients, partners and service providers.

It applies across our applications, website, portals, payment interfaces, integrated systems, communications and other online or offline channels, including information lawfully received from third parties.

Wallet-related processing falls within this Policy where wallet features are made available. Any additional requirements concerning identity verification, transaction monitoring, provider responsibilities or other specific processing will be explained through the relevant service privacy notice.

New or expanded services fall within this Policy where their processing is consistent with the purposes and safeguards described herein. Where additional or materially different processing is introduced, Chapaa will provide the required supplementary notice and obtain consent or other authorization where necessary.

3. Personal Data We Collect

Depending on the services you use and your interaction with Chapaa, we may collect the following categories of personal data where relevant and necessary:

Identity and Contact Information: Names, telephone numbers, email addresses, physical or postal addresses, dates of birth and identification details required for registration or verification.

Account and Security Information: Account identifiers, login credentials, verification status, authentication records, access permissions, security settings and records of authorized representatives or approvers.

Campaign and Participation Information: Campaign descriptions, fundraising purposes, organizer and beneficiary details, group membership, contribution commitments, messages, supporting documents and content submitted in connection with a collection or campaign.

Payment, Wallet and Transaction Information: Payment references, amounts, dates, transaction status, contribution records, balances, funding and withdrawal instructions, recipient details, fees, refunds, reversals and dispute records.

Verification and Compliance Information: Documents and records reasonably required to verify identity, authority, beneficiaries, campaign purposes or transactions, and to undertake applicable fraud prevention and regulatory checks.

Technical and Usage Information: Internet Protocol (IP) addresses, device and browser information, application version, access times, service interactions, error logs and security records, together with information collected through cookies or similar technologies where deployed.

Communications and Preferences: Enquiries, complaints, support correspondence, notification preferences, consent records and records of withdrawal or objection.

Business Relationship Information: Contact, professional, contractual and payment information relating to representatives of institutional clients, partners, suppliers and other persons engaging with Chapaa.

4. How We Collect Personal Data

Chapaa collects personal data through the following sources:

Directly from You: When you register, verify your identity, create or join a campaign, make a contribution, submit a transaction instruction, upload content or communicate with us.

Through Our Platforms: Automatically when you access or use our applications, website or other digital channels, through system logs and any cookies or similar technologies deployed, subject to applicable notices and choices.

From Other Participants: When an organizer, contributor, beneficiary, group administrator or authorized representative provides information relevant to your participation, a payment or the administration of a campaign.

From Financial and Payment Providers: When providers supply transaction confirmations, settlement information, verification results or other records necessary to facilitate and reconcile an authorized service.

From Verification and Other Lawful Sources: Where necessary and permitted, from identity verification providers, institutional partners, public authorities, lawful public records or other relevant sources for the stated verification or compliance purpose.

5. How We Use Personal Data

Chapaa uses personal data, where relevant and necessary, for the following purposes:

Account Administration: To register users, verify account information, manage access permissions and maintain account security.

Campaign and Group Management: To establish and administer campaigns, register participants and beneficiaries, record contributions, manage approval arrangements and provide authorized users with relevant statements and updates.

Payment and Wallet Services: To facilitate authorized contributions, wallet funding, transfers and withdrawals; verify transaction status; reconcile records; calculate disclosed charges; and administer refunds, reversals and payment disputes.

Verification and Compliance: To verify identity and authority, assess campaign or transaction information, prevent fraud and misuse, and undertake checks required by law or applicable provider arrangements.

Service Communications: To send confirmations, security alerts, campaign updates, contribution reminders and other operational messages, subject to applicable communication preferences and consent requirements.

Customer Support: To respond to enquiries, investigate complaints, resolve service issues and handle personal data requests.

Platform Security and Improvement: To detect unauthorized activity, troubleshoot faults, monitor performance and improve service functionality and accessibility.

Marketing and Engagement: To communicate about Chapaa's services, features and opportunities, subject to applicable consent requirements. You may opt out of marketing communications at any time.

6. Lawful Basis for Processing

Chapaa processes personal data only where permitted by applicable data protection law. We identify the lawful basis appropriate to each activity and obtain consent where required.

Where processing relies on consent, we will explain the purpose and seek a freely given, specific and informed indication of your agreement. Optional consent requests will be distinguished from information necessary to provide a service or meet a legal obligation.

You may withdraw consent through the available settings, unsubscribe facility or by contacting [email protected]. Withdrawal will not affect the lawfulness of processing undertaken beforehand.

Where processing is permitted without consent, Chapaa will rely only on a lawful ground applicable to the circumstances. A service agreement or requirement imposed by a business partner does not, by itself, remove an applicable consent requirement.

Sensitive personal data will be processed with prior written consent unless a specific statutory exception applies.

7. Sharing of Personal Data

Chapaa may share personal data with the following categories of recipients where necessary for the purposes described in this Policy and permitted by applicable law:

Financial and Payment Providers: Banks, mobile money operators, payment service providers and wallet service partners involved in authorized transactions, verification, settlement, reconciliation and dispute resolution.

Campaign Participants and Administrators: Organizers, beneficiaries, group administrators and authorized approvers who require relevant information to administer contributions, approve withdrawals or account for campaign funds.

Operational Service Providers: Providers of hosting, storage, communications, technical support, security and other services supporting Chapaa's operations.

Verification and Professional Service Providers: Identity verification providers, fraud prevention specialists, auditors, legal advisers and other professionals engaged for relevant verification, compliance or advisory purposes.

Authorities and Legally Authorized Recipients: Regulators, courts, law enforcement agencies and other recipients where disclosure is required or permitted by law, including for legal proceedings or investigations.

Chapaa does not sell personal data. Sharing information for another organization's independent marketing purposes will require your separate consent.

8. Cookies, Device Permissions and Similar Technologies

Chapaa's website and applications may use cookies, local storage, software development kits and similar technologies to maintain sessions, remember preferences, support security and assess service performance.

Depending on the features deployed, these technologies may be used for essential functions, preferences, analytics and diagnostics, and marketing where enabled and subject to applicable consent requirements.

Information about the technologies deployed, their purposes, relevant providers and duration will be provided through an appropriate notice or preference facility. Technologies requiring consent will remain disabled until that consent is obtained.

Device permissions will be requested when relevant to a feature, with an explanation of the intended access and use. Where contact access is enabled, it will be limited to the selection or action you authorize.

You may manage optional technologies, notifications and device permissions through the available application, browser or device settings.

9. Data Security

Chapaa implements appropriate technical and organizational measures to protect personal data against unauthorized access, disclosure, alteration, loss, misuse or destruction, taking account of the sensitivity of the information and the risks associated with the relevant service.

These measures include restricting access according to personnel responsibilities, user roles and campaign approval permissions; applying secure authentication, encryption and controls for transmitting and storing information; monitoring access and transaction activity; maintaining audit records and investigating suspected misuse; reviewing access permissions; requiring confidentiality commitments; and maintaining backup, recovery and incident response procedures.

Where a personal data breach occurs, Chapaa will take appropriate steps to contain it, assess its consequences and reduce further harm. We will notify the Personal Data Protection Commission and affected individuals where required by law, within the applicable timelines.

You should protect your account credentials and devices, use available security features and promptly report suspected unauthorized access to [email protected]. Do not disclose passwords, PINs, one-time passwords or payment authentication codes to other users or persons claiming to provide support.

10. Data Retention and Disposal

Chapaa retains personal data only for as long as necessary to fulfil its stated purpose, meet applicable legal obligations or establish, exercise or defend legal claims.

Retention periods are determined by the nature of the information, the duration of the relevant account, campaign or service, applicable recordkeeping requirements and any continuing need for verification, reconciliation or dispute resolution.

Account Records: Retained during the active relationship and for a justified period afterwards to resolve outstanding matters and meet applicable obligations.

Campaign and Contribution Records: Retained while the campaign is active and for the period necessary to complete disbursements, account for contributions and address disputes or applicable reporting requirements.

Wallet and Transaction Records: Retained for the periods required by applicable financial, payment, tax and other recordkeeping obligations.

Verification and Compliance Records: Retained for the applicable verification, fraud prevention and statutory compliance periods.

When personal data is no longer required, Chapaa will securely delete, destroy or irreversibly anonymize it.

11. International Data Transfers

Where necessary for our services or operations, personal data may be transferred to, stored in or accessed from countries outside Tanzania, including through hosting, technical support, verification or payment service arrangements.

Before undertaking such a transfer, Chapaa will assess its necessity, the protection available in the destination country and the safeguards applied by the recipient. We will obtain the required permit from the Personal Data Protection Commission and comply with its conditions and other applicable legal requirements.

Appropriate safeguards may include contractual restrictions on use and onward disclosure, confidentiality obligations, access controls, encryption and secure retention and disposal requirements.

Relevant information about the destination, recipient, purpose and safeguards will be provided through the applicable service or supplementary privacy notice. Consent will be obtained where required.

12. Children's Personal Data

Chapaa's account registration and transaction services are intended for persons aged eighteen (18) years or above, unless a particular service expressly permits younger users under appropriate lawful authorization and safeguards.

A child may be a beneficiary of a campaign managed by an adult or an authorized institution. Where this involves processing the child's personal data, Chapaa will require appropriate authorization from a parent, guardian or other legally authorized representative, unless another lawful basis applies.

Information about a child must be limited to what is necessary for the campaign or service. Organizers must not publish identity documents, contact details, precise residential locations or unnecessary sensitive information about a child.

Public use of a child's name, photograph, health information or personal story will require the applicable authorization and consideration of the child's safety and best interests.

A parent, guardian or legally authorized representative may contact [email protected] to enquire about the handling of a child's personal data or exercise applicable rights on the child's behalf.

13. Your Rights and How to Exercise Them

Subject to applicable law and the circumstances of processing, you may:

Request confirmation of whether Chapaa processes your personal data and obtain access to that information;

Request correction or updating of inaccurate or incomplete personal data;

Request deletion, destruction or blocking of personal data where the legal conditions are met;

Withdraw consent where processing relies on consent;

Object to direct marketing or other processing where the law provides a right to object;

Exercise applicable rights concerning decisions made solely through automated processing.

Requests may be submitted to [email protected], identifying the right you wish to exercise and providing sufficient information to locate the relevant records.

You may lodge a complaint with the Personal Data Protection Commission if you believe your personal data has been handled unlawfully or your request has not been appropriately addressed.

14. Changes to This Policy

Chapaa may update this Policy to reflect changes in its services, technology, personal data processing practices or applicable legal requirements. The current version will be available through our applications and website and will indicate its effective date.

Where a change materially affects how we handle your personal data or exercise your rights, we will provide a prominent notice through the relevant platform or another appropriate communication channel before implementation, except where an earlier change is required by law.

Where a change requires fresh consent or another legal authorization, Chapaa will obtain it before undertaking the relevant processing. Continued use of our platforms or services does not, by itself, constitute consent to a new processing purpose.

15. Contact Information

For enquiries, requests or complaints concerning this Policy or the handling of your personal data, please contact:

Chapaa Technologies Limited
Attention: Privacy Enquiries
Plot No. 10, Block No. 45A, New Bagamoyo Road
Dar es Salaam, Tanzania
Email: [email protected]

Please identify your correspondence as a "Privacy Enquiry", "Personal Data Request" or "Privacy Complaint" to assist us in directing it to the responsible person. Do not include passwords, PINs, one-time passwords, payment authentication codes or unnecessary sensitive information.