Legal

Privacy Policy

Effective date: 27 September 2026

HaFa is an app for messages, voice and video calls, status updates, money and small shops. This policy explains what information HaFa handles, why, who else is involved, how long it is kept, and the choices and rights you have. We have tried to write it in plain words. Where the law gives you more rights than this policy describes, you have those rights.

Who we are

HaFa is provided by its operator ("HaFa", "we", "us"). For personal information handled under this policy, we are the data controller.

You can contact us about privacy through HaFa's Help page in the app. Our data protection lead can be reached the same way.

The short version

What we collect and why

Your account

Messages, calls and status

Contacts

If you let HaFa read your contacts, they are read and matched on your phone. We do not upload your address book. When you look someone up by @tag or number, we answer that one exact question and do not keep the question.

If you set "Who can see when I'm online" to My contacts, your phone tells our server which phone numbers are your HaFa contacts, so the server knows who may see your online status. This list is used only for that, is never combined with anything else, and is deleted with your account. If you choose Everyone or Nobody, no list is sent.

Online status

While HaFa is open, your phone tells our server every so often that you are online. We keep only the time of the last signal and show others a rough answer (online, within the hour, today, a while ago), never the exact time. You choose who sees it, and choosing Nobody means you do not see anyone else's either.

Notifications

We use Firebase Cloud Messaging, a Google service, to wake your phone when something arrives. We store the notification token your phone gives us. The notification we send contains no message text and no sender; it only tells the app to check for new messages.

Location

HaFa does not track your location. Location is used only in these cases, and only when you choose them:

Money

If you use HaFa's wallet and payments:

Shops, businesses and riders

Chat backup

If you turn on encrypted backup, your chats are encrypted on your phone with a key protected by a passphrase only you know. We store the encrypted backup and can see only that it exists, its date and its size. We cannot read it and cannot reset your passphrase. After 10 wrong passphrase attempts the key is destroyed. Turning backup off deletes our copy.

You can choose, separately and at any time, to let HaFa learn which kinds of shops, features and offers interest you, so we can show you more relevant offers inside HaFa. It is off unless you turn it on. It is built from daily counts of things you do in the app (such as shop categories you open or offers you dismiss), never from your conversations. You can see it, erase it, or withdraw consent in the app; withdrawing deletes it. It is kept for 180 days.

Feedback and support

If you suggest a feature or contact support, we receive what you write, your account, and your app version, language and platform, so we can reply.

What we do not collect

We do not use third-party advertising or analytics tools, and we do not sell or rent personal information. We do not use your conversations to target advertising, and we could not if we wanted to.

Why we are allowed to use your information

Where the law asks for a legal basis (for example the UK GDPR, the EU GDPR, Nigeria's NDPA and Kenya's Data Protection Act):

Biometric data: face matching on a selfie, where it is used for verification, is done only for that purpose, with your explicit consent, and the selfie is kept only as the verification record.

Who we share information with

We share information only as described here:

International transfers

HaFa's servers are in the United Kingdom, and some of our providers operate in other countries. When your information moves between countries, we protect it with the safeguards the law requires, such as adequacy decisions, the UK International Data Transfer Agreement or the EU Standard Contractual Clauses, and equivalent measures under Nigerian, Kenyan, South African and other laws. Some countries require certain financial records to be kept in the country; where they do, we keep them there.

How long we keep information

Security

End-to-end encryption uses the Signal protocol with post-quantum key agreement. On your phone, HaFa's database is encrypted with a key held in the phone's secure hardware. Every request to our servers is signed by your device. Identity documents are encrypted before they leave your phone. No system is perfectly secure, so if a breach affects you we will tell you and the regulators as the law requires.

Your choices and rights

In the app you can: hide your number, choose who can find you by number, choose who sees your online status and your mode, turn off offers nearby, stop sharing location, turn Nearby off, turn backup off, and view, erase or withdraw your marketing profile.

Depending on where you live, you also have the right to:

To use these rights, or to delete your account, contact us through HaFa's Help page in the app. We will answer within one month (or sooner where local law requires), and we may need to confirm it is you.

Where you live

Children

You must be at least 13 years old to use HaFa, or older if your country sets a higher age for using a service like this without a parent's consent. You must be at least 18 to use the wallet, payments, identity verification, shops, promotions or to apply as a rider. We do not knowingly collect information from children below these ages. If you believe a child is using HaFa against these rules, contact us and we will close the account.

Changes to this policy

If we change this policy, we will update the effective date and, for important changes, tell you in the app before they take effect. Earlier versions are available on request.

Contact

The operator of HaFa
Privacy questions and requests: HaFa's Help page in the app