HaFa is an app for messages, voice and video calls, status updates, money and small shops. This policy explains what information HaFa handles, why, who else is involved, how long it is kept, and the choices and rights you have. We have tried to write it in plain words. Where the law gives you more rights than this policy describes, you have those rights.
Who we are
HaFa is provided by its operator ("HaFa", "we", "us"). For personal information handled under this policy, we are the data controller.
You can contact us about privacy through HaFa's Help page in the app. Our data protection lead can be reached the same way.
The short version
- We cannot read your messages or listen to your calls. Messages, voice notes, photos, files, status updates, live location and calls are end-to-end encrypted with the Signal protocol. Our servers carry them sealed and cannot open them.
- Your address book stays on your phone. We do not upload it to find out who you know.
- Notifications carry no content. The push we send through Google only wakes the app up; your phone builds the notification after it decrypts the message.
- We do not sell your information, and we do not show ads based on your conversations. Nothing from your conversations is ever used for marketing.
- Money needs more information. To send and receive money, the law requires us and our payment partners to know who you are. Identity documents are encrypted on your phone and can only be opened by HaFa staff who review them.
What we collect and why
Your account
- Phone number. Your phone number is your account. We send it to our SMS provider to deliver a one-time code that proves the number is yours.
- @tag, name, photo and About line. Your @tag is public on HaFa: anyone can look it up exactly. Your name, profile photo and About line are sent to the people you chat with, end-to-end encrypted; the server does not store them in readable form.
- Hide my number. If you turn this on, people who find you by @tag see a masked number, and our directory does not give out your full number. People you message, people who already have your number, and members of groups you are in can still see it, because messages are addressed by phone number.
- Find me by phone number. You choose whether someone who types your number can find you. Your @tag can always be found.
- Device and security keys. When you set up HaFa, your phone creates keys in its secure hardware. We receive the public keys, a device identifier, and an attestation from your phone's maker that the keys are real. Every request your phone makes to us is signed with them. We also check basic device safety (such as whether a screen lock is set) so we can set safe limits for money on that phone.
Messages, calls and status
- Content. The content of messages, calls, status updates, voice notes, media and shared live locations is end-to-end encrypted. We cannot read, hear or see it.
- Delivery information. To deliver a message, our server sees which phone number it is for, which number sent it, when, and its size. A sealed message waits on our server only until your phone collects it, and for at most 30 days if it never does (72 hours by default). We do not keep a log of who talked to whom after delivery.
- Media. Photos, videos, voice notes and files are encrypted on your phone before upload. The key travels only inside the encrypted message. We store the encrypted file for up to 30 days so the recipient can download it.
- Calls. Calls are connected directly between phones where possible. When a direct connection is not possible, the call is passed through our relay server, which carries the encrypted audio and video without being able to decode it.
- Groups are delivered as separate encrypted messages to each member. There is no group server that can read group content.
- Status updates are encrypted to each person who can see them and disappear after at most 24 hours.
- Things done only on your phone. Suggested replies are learned on your phone and never sent to us. Voice-note transcripts are made on your phone; the sound is not sent to us to be transcribed.
Contacts
If you let HaFa read your contacts, they are read and matched on your phone. We do not upload your address book. When you look someone up by @tag or number, we answer that one exact question and do not keep the question.
If you set "Who can see when I'm online" to My contacts, your phone tells our server which phone numbers are your HaFa contacts, so the server knows who may see your online status. This list is used only for that, is never combined with anything else, and is deleted with your account. If you choose Everyone or Nobody, no list is sent.
Online status
While HaFa is open, your phone tells our server every so often that you are online. We keep only the time of the last signal and show others a rough answer (online, within the hour, today, a while ago), never the exact time. You choose who sees it, and choosing Nobody means you do not see anyone else's either.
Notifications
We use Firebase Cloud Messaging, a Google service, to wake your phone when something arrives. We store the notification token your phone gives us. The notification we send contains no message text and no sender; it only tells the app to check for new messages.
Location
HaFa does not track your location. Location is used only in these cases, and only when you choose them:
- Sharing a location or live location in a chat. It is end-to-end encrypted. Live location is shared for the time you choose (15 minutes, 1 hour or 8 hours) and only while HaFa is open. To show an address, your phone may ask Android's address lookup, which on most phones is provided by Google.
- Maps. Map tiles are loaded from a map-tile provider, which learns roughly which area is on your screen, as with any online map. Directions open in Google Maps if you ask for them.
- Offers nearby is off until you turn it on. When it is on, your phone sends only a coarse area of about 5 km by 5 km (and the areas around it), never your exact position, and only while the app is open. We do not store the area against your account or device.
- Nearby mode (Bluetooth). When you turn Nearby on, your phone announces your @tag over Bluetooth, and phones that meet exchange your phone number, name, @tag and public keys so they can carry sealed messages for each other. The phones carrying a message cannot read it. Nearby is off until you turn it on.
Money
If you use HaFa's wallet and payments:
- Transactions. We keep a ledger of your wallet: amounts, currencies, fees, dates, the other party's @tag or number, the payment method and reference, and the status of each payment. We need this to run the service and the law requires us to keep it.
- Payment partners. Payments, cash-in and cash-out, mobile money, airtime and bill payments are processed by licensed payment partners. They receive what they need to complete the payment, such as your number, name, amount and reference, and they may keep it under their own legal obligations.
- Exchange rates are fetched from a public exchange-rate provider. No personal information is sent to it.
- Identity verification (KYC). To raise your limits, and to use money features in many countries, you must verify your identity. Depending on your country this may be a national identity number, bank verification number, photo ID, a selfie, proof of address, tax number, or business registration papers. These are encrypted on your phone with a key that only HaFa's verification service can open, and are reviewed by trained HaFa staff. They are shown to a reviewer only while reviewing, are not downloaded, and every access is recorded. Where required, we check them with official registries or our payment partners.
- Fraud and safety. We use your device's security checks, your verification level and your payment history to set limits, prevent fraud and meet anti-money-laundering and sanctions rules.
Shops, businesses and riders
- Business profile and catalogue. A published shop catalogue (names, prices, descriptions, photos and videos) is public on purpose and is not end-to-end encrypted. We review and moderate it. Location details are removed from product photos.
- Orders placed in a chat are part of that chat and are end-to-end encrypted.
- Promotions. A business that pays to promote an offer nearby gives us the offer, the budget and the area. We count how many times it was shown, as totals without identifying who saw it.
- Riders who apply to deliver for shops give us their vehicle, licence and papers, a photo and optionally a guarantor, so HaFa can vet them.
Chat backup
If you turn on encrypted backup, your chats are encrypted on your phone with a key protected by a passphrase only you know. We store the encrypted backup and can see only that it exists, its date and its size. We cannot read it and cannot reset your passphrase. After 10 wrong passphrase attempts the key is destroyed. Turning backup off deletes our copy.
Marketing profile (only with your consent)
You can choose, separately and at any time, to let HaFa learn which kinds of shops, features and offers interest you, so we can show you more relevant offers inside HaFa. It is off unless you turn it on. It is built from daily counts of things you do in the app (such as shop categories you open or offers you dismiss), never from your conversations. You can see it, erase it, or withdraw consent in the app; withdrawing deletes it. It is kept for 180 days.
Feedback and support
If you suggest a feature or contact support, we receive what you write, your account, and your app version, language and platform, so we can reply.
What we do not collect
We do not use third-party advertising or analytics tools, and we do not sell or rent personal information. We do not use your conversations to target advertising, and we could not if we wanted to.
Why we are allowed to use your information
Where the law asks for a legal basis (for example the UK GDPR, the EU GDPR, Nigeria's NDPA and Kenya's Data Protection Act):
- To provide the service you asked for (contract): your account, delivering messages and calls, running your wallet, backups you turn on.
- To meet legal obligations: identity verification, keeping transaction records, anti-money-laundering, sanctions and fraud checks, answering lawful requests.
- Legitimate interests, balanced against your rights: keeping HaFa secure, preventing spam and abuse, device safety checks, improving reliability.
- Consent, which you can withdraw at any time: the marketing profile, offers nearby, location sharing, contacts access, notifications and Bluetooth Nearby.
Biometric data: face matching on a selfie, where it is used for verification, is done only for that purpose, with your explicit consent, and the selfie is kept only as the verification record.
Who we share information with
We share information only as described here:
- The people you communicate with, who receive what you send them.
- Service providers who work for us under contract and only on our instructions: cloud hosting (our servers are in London, United Kingdom), SMS delivery for sign-in codes, push notifications (Google Firebase Cloud Messaging), map tiles and address lookup, and payment partners.
- Payment partners and banks, to complete payments you make, under their own licences and legal duties.
- Authorities, when the law requires it, such as a valid court order, or to protect someone from serious harm. We can only provide what we have: we do not have the content of your messages or calls.
- A buyer or successor, if HaFa is reorganised, merged or sold, under this policy.
International transfers
HaFa's servers are in the United Kingdom, and some of our providers operate in other countries. When your information moves between countries, we protect it with the safeguards the law requires, such as adequacy decisions, the UK International Data Transfer Agreement or the EU Standard Contractual Clauses, and equivalent measures under Nigerian, Kenyan, South African and other laws. Some countries require certain financial records to be kept in the country; where they do, we keep them there.
How long we keep information
- Sealed messages waiting for delivery: until delivered, at most 30 days.
- Encrypted media files: 30 days.
- Status updates: at most 24 hours.
- Online status: only the last signal.
- Encrypted backup: until you turn backup off or delete your account, and no more than 180 days after your account was last active.
- Marketing profile: 180 days, or until you withdraw consent.
- Account details: while your account is open. Your @tag is never given to anyone else, even after deletion, so nobody can pretend to be you.
- Transaction records and approved identity documents: for as long as financial and anti-money-laundering laws require after your account closes (usually 5 to 7 years, depending on the country).
- Rejected or withdrawn verification documents: deleted within 90 days.
- Support and feedback messages: up to 2 years.
Security
End-to-end encryption uses the Signal protocol with post-quantum key agreement. On your phone, HaFa's database is encrypted with a key held in the phone's secure hardware. Every request to our servers is signed by your device. Identity documents are encrypted before they leave your phone. No system is perfectly secure, so if a breach affects you we will tell you and the regulators as the law requires.
Your choices and rights
In the app you can: hide your number, choose who can find you by number, choose who sees your online status and your mode, turn off offers nearby, stop sharing location, turn Nearby off, turn backup off, and view, erase or withdraw your marketing profile.
Depending on where you live, you also have the right to:
- access the personal information we hold about you and get a copy;
- correct it if it is wrong;
- delete it (subject to the records the law makes us keep);
- object to or restrict some uses, and withdraw consent at any time;
- move your information to another service (data portability);
- not be subject to decisions based solely on automated processing that significantly affect you, and ask for a person to review one;
- complain to a data protection regulator.
To use these rights, or to delete your account, contact us through HaFa's Help page in the app. We will answer within one month (or sooner where local law requires), and we may need to confirm it is you.
Where you live
- United Kingdom: you can complain to the Information Commissioner's Office (ico.org.uk).
- European Economic Area: you can complain to the data protection authority in your country.
- Nigeria: you have the rights in the Nigeria Data Protection Act 2023 and can complain to the Nigeria Data Protection Commission.
- Kenya: you have the rights in the Data Protection Act 2019 and can complain to the Office of the Data Protection Commissioner.
- South Africa: you have the rights in the Protection of Personal Information Act (POPIA) and can complain to the Information Regulator.
- California, United States: under the CCPA, as amended by the CPRA, you can ask to know, delete and correct personal information and limit the use of sensitive personal information. We do not sell or share personal information for cross-context behavioural advertising, and we will not treat you differently for using your rights. An authorised agent may make a request for you.
- Elsewhere: we apply the rights in this policy to everyone, and more where your local law gives more.
Children
You must be at least 13 years old to use HaFa, or older if your country sets a higher age for using a service like this without a parent's consent. You must be at least 18 to use the wallet, payments, identity verification, shops, promotions or to apply as a rider. We do not knowingly collect information from children below these ages. If you believe a child is using HaFa against these rules, contact us and we will close the account.
Changes to this policy
If we change this policy, we will update the effective date and, for important changes, tell you in the app before they take effect. Earlier versions are available on request.
Contact
The operator of HaFa
Privacy questions and requests: HaFa's Help page in the app