← Back to Bhaba

Privacy Policy

Last updated: March 28, 2026 · Effective: March 28, 2026

Bhaba Limited ("Bhaba", "we", "our", or "us") operates the Bhaba mobile application (available on Google Play and the Apple App Store) and the website at https://bhabalimited.com (collectively, the "Service"). We are committed to protecting and respecting your privacy.

This Privacy Policy explains what personal information we collect when you use our Service, why we collect it, how we use and share it, how long we keep it, and the rights available to you. Please read this policy carefully. By using our Service you confirm that you have read and understood this policy.

If you do not agree with this policy, please do not use our Service. If you have any questions, please contact us at privacy@bhabalimited.com.

1. Who We Are

Bhaba Limited is a technology company incorporated in Tanzania. We operate Bhaba, Tanzania's super marketplace platform that connects buyers with sellers of products and services. Our registered address is Dar es Salaam, Tanzania.

For the purposes of applicable data protection laws, Bhaba Limited is the data controller responsible for your personal information collected through the Service.

2. Information We Collect

We collect information in the following ways:

2.1 Information You Provide Directly

  • Account registration: name, email address, phone number, password, and optional profile photo when you create a Bhaba account.
  • Vendor/service-provider profiles: business name, business category, business address, bank or mobile-money account details (for payouts), and any government-issued identification documents required for verification.
  • Orders and transactions: delivery address, payment method details (we do not store full card numbers — see Section 11), order history, and transaction amounts.
  • Communications: messages you send through in-app chat, support tickets, reviews, ratings, and any other content you submit.
  • Identity verification: national ID, passport, or other documents if required to verify your identity for compliance purposes.

2.2 Information We Collect Automatically

  • Device information: device type, operating system and version, unique device identifiers (Android ID, advertising ID), hardware model, and mobile network information.
  • Log and usage data: IP address, browser type, pages or screens visited, time and date of access, referring URLs, search queries within the app, clicks, and session duration.
  • Location data: with your permission we collect approximate or precise GPS location to show nearby sellers, calculate delivery distances, and confirm delivery. You may disable location access in your device settings; some features may not work correctly without it.
  • Push notifications: if you grant permission, we collect a device token to send order updates, promotions, and service announcements.

2.3 Information From Third Parties

  • Social sign-in: if you log in via Google or Facebook we receive your name, email, and profile picture from those providers as permitted by your settings there.
  • Payment providers: M-Pesa, Tigo Pesa, Airtel Money, and card payment processors confirm payment status and may share transaction reference numbers with us.
  • Analytics partners: aggregated and anonymised analytics from Google Analytics and Firebase Analytics.

3. How We Use Your Information

We use the information we collect to:

  • Create and manage your account and authenticate your identity.
  • Process orders, payments, and payouts to vendors and service providers.
  • Facilitate communications between buyers, sellers, and delivery personnel.
  • Provide customer support and respond to your inquiries.
  • Personalise the Service — including showing you relevant products, services, and recommendations based on your browsing and purchase history.
  • Send transactional notifications (order confirmation, shipping updates, delivery confirmation).
  • Send marketing communications, promotions, and newsletters where you have given consent or where permitted by applicable law; you can opt out at any time.
  • Detect, investigate, and prevent fraud, abuse, and other illegal activity, and enforce our Terms of Service.
  • Comply with legal obligations, including tax and anti-money-laundering requirements.
  • Improve and develop our products, features, and services through analytics and research.
  • Conduct internal reporting and business analytics.
  • Verify vendor and service-provider identities and credentials as required by Tanzanian law and our marketplace policies.

5. Sharing Your Information

We do not sell your personal information. We may share your information with:

  • Vendors and service providers on the platform: order details (name, delivery address, phone number) necessary to fulfil your purchase.
  • Delivery partners: your name, phone number, and delivery address to complete delivery of goods you purchase.
  • Payment processors: M-Pesa (Vodacom Tanzania), Tigo Pesa, Airtel Money, and card payment gateways receive payment information solely to process transactions.
  • Cloud infrastructure providers: we use cloud hosting services that store data on our behalf under confidentiality agreements.
  • Analytics and advertising partners: anonymised or aggregated data with Google Analytics, Firebase, and similar services.
  • Legal and regulatory authorities: when required by law, court order, or governmental authority; or when necessary to protect the rights, property, or safety of Bhaba, our users, or others.
  • Business transfers: if Bhaba is acquired, merged, or undergoes an asset sale, your information may be transferred as part of that transaction, subject to the same privacy protections.

7. Data Retention

We retain your personal information for as long as necessary to provide the Service and fulfil the purposes described in this policy, unless a longer retention period is required or permitted by law.

  • Active accounts: we retain your account data for the lifetime of your account plus 90 days after deletion to allow for account recovery.
  • Transaction records: order and payment records are retained for a minimum of 7 years for tax and accounting compliance under Tanzanian law.
  • Verification documents: identity documents are retained for the duration required by applicable KYC/AML regulations.
  • Log data: server logs are retained for up to 12 months for security and debugging purposes.
  • Marketing consent records: retained until you withdraw consent, plus a reasonable period for compliance records.

When personal data is no longer needed we securely delete or anonymise it.

7. Your Rights

Depending on your location and applicable law, you may have the following rights regarding your personal information:

  • Access: request a copy of the personal information we hold about you.
  • Correction: request that we correct inaccurate or incomplete information.
  • Deletion: request that we delete your personal information ("right to be forgotten"), subject to legal retention requirements.
  • Data portability: receive your personal data in a structured, machine-readable format.
  • Objection: object to processing based on legitimate interests or for direct marketing.
  • Restriction: request that we restrict processing in certain circumstances.
  • Withdraw consent: where processing is based on your consent, withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us at privacy@bhabalimited.com. We will respond within 30 days. You may also delete your account directly from the app under Settings → Account → Delete Account, which will initiate the account and data deletion process.

8. Children's Privacy

The Bhaba Service is not directed at children under the age of 13, and we do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@bhabalimited.com and we will promptly delete that information.

Users between the ages of 13 and 18 may only use the Service with the consent and under the supervision of a parent or legal guardian.

9. Data Security

We implement industry-standard technical and organisational measures to protect your personal information against unauthorised access, loss, misuse, disclosure, alteration, or destruction. These measures include:

  • Encryption of data in transit using TLS 1.2 or higher.
  • Encryption of sensitive data at rest (passwords are hashed using bcrypt).
  • Access controls ensuring that only authorised personnel can access personal data.
  • Regular security audits and vulnerability assessments.
  • Firebase App Check to protect our APIs from abuse.

Despite our efforts, no method of transmission over the Internet or electronic storage is completely secure. If you believe your account has been compromised, please contact support@bhabalimited.com immediately.

10. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your experience, remember your preferences, and analyse how the Service is used. Specifically, we use:

  • Strictly necessary cookies: required for authentication and basic site functionality.
  • Performance/analytics cookies: Google Analytics cookies that help us understand user behaviour in aggregate.
  • Preference cookies: remember your language, currency, and display preferences.

You can control or delete cookies through your browser settings. Please note that disabling cookies may affect the functionality of our website. Our mobile app uses Firebase Analytics SDKs rather than browser cookies; you may opt out of Firebase Analytics via your device's advertising ID settings.

11. Third-Party Services

Our Service integrates with the following third-party services. Each has its own privacy policy that governs how they process your data:

  • Google (Firebase, Analytics, Maps, Sign-In): policies.google.com/privacy
  • Vodacom Tanzania (M-Pesa): payment processing.
  • Tigo Tanzania (Tigo Pesa): payment processing.
  • Airtel Tanzania (Airtel Money): payment processing.
  • Vercel: web hosting and edge computing.

We are not responsible for the privacy practices of third-party services. We encourage you to review their privacy policies.

12. International Data Transfers

Bhaba Limited is based in Tanzania. Some of our service providers (such as Google and Vercel) are based outside Tanzania and may process your data in other countries, including the United States and the European Economic Area. We take steps to ensure that any such transfers are subject to appropriate safeguards, such as data processing agreements that include standard contractual clauses or equivalent protections.

13. Google Play and Mobile App Specific Disclosures

In compliance with Google Play Developer Program Policies, we provide the following specific disclosures for our Android application:

  • Data collected: as described in Section 2, we collect account information, device identifiers, location data (with permission), usage data, and payment information.
  • Data shared: we share data with vendors, delivery partners, and payment processors as described in Section 5. We do not sell personal data.
  • Security practices: data is encrypted in transit. Users may request deletion of their data at any time (see Section 7).
  • Sensitive permissions:
    • Location (foreground): used to show nearby vendors and calculate delivery distance.
    • Camera: used to allow users and vendors to upload product photos and profile pictures.
    • Storage/Photos: used to allow users to select images from their device gallery.
    • Push notifications: used to deliver order status updates; can be disabled in device settings.
  • Account deletion: you can delete your account and all associated data from within the app under Settings → Account → Delete Account, or by emailing privacy@bhabalimited.com. Deletion is completed within 30 days, subject to legal retention requirements.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes we will notify you by updating the "Last updated" date at the top of this page and, where required by law, by providing more prominent notice (such as an in-app notification or email). Your continued use of the Service after the effective date of the revised policy constitutes your acceptance of the changes. We encourage you to review this page periodically.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Privacy team:

Bhaba Limited

Dar es Salaam, Tanzania

Privacy enquiries: privacy@bhabalimited.com

General support: support@bhabalimited.com

Website: https://bhabalimited.com