Back

Privacy Policy

How MyDaraja collects, uses, discloses, retains and protects your personal data — and the rights you have over it.

Last reviewed
4 September 2026
Data controller
MyDaraja Technologies Limited

1.About this policy

1.1

MyDaraja Technologies Limited, a company registered in Ghana with its office in Accra (“MyDaraja”, “we”, “us”), operates the MyDaraja mobile and web applications (the “Platform”). We are the data controller for the personal data described here.

1.2

This policy explains what personal data we collect, why, who we share it with, how long we keep it, and what rights you have. It applies to students, business accounts, content partners, delivery riders, and our own staff.

1.3

We process personal data under the Data Protection Act, 2012 (Act 843) of Ghana, and we are answerable to the Data Protection Commission.

1.4

Where we handle data on behalf of a partner university or business, they are the controller and their own notice applies alongside this one.

1.5

This policy does not cover third-party sites you reach through the Platform. Read their notices before giving them anything.

2.Who can use MyDaraja

2.1

You must be 18 or over. Some features are further limited to enrolled students of partner universities.

2.2

We do not knowingly collect data from anyone under 18. If you believe we have, write to info@mydaraja.africa and we will delete it.

3.What we collect

3.1

You give us: your name, email address and phone number; a password, which we store only as a salted hash and never in readable form; your university, campus, faculty and year of study; and, if you choose to add them, a profile photo, bio, date of birth and address.

3.2

You create: posts, polls and votes, hangouts, job listings and the applications and résumés sent through them, comments and reactions, marketplace and accommodation listings, direct messages, and meetings you schedule.

3.3

Business and rider onboarding: business application details, and for delivery riders a photograph, contact details, vehicle type and registration, and a national identification number.

3.4

Payments: the amount, currency, purpose, status, reference and settlement time of each transaction, your coin balance, and your subscription or paid-post history.

3.5

Automatically: your IP address, device name and identifier, browser or app user-agent, and when each session was created and last active. If you turn on notifications, a push token for your device.

3.6

From others: Google, if you sign in with it or connect your calendar; Paystack, which tells us whether a payment succeeded and how it was paid; your university, for enrolment checks; and other users, if they report you.

3.7

We also keep moderation records — reports made and received, warnings, suspensions and bans — and audit records of what our administrators do.

We never see your card number, mobile money PIN or one-time authorisation codes. Those go straight to Paystack and never touch our systems.

3.9

We do not ask for sensitive data — health, religion, politics, ethnicity. You may still put it in a post, a bio or a wellness report; if you do, you are choosing to share it, and we handle it on that basis. Please do not share more than the situation needs.

4.Why we use it

4.1

We only use your data where we have a lawful reason to:

What we doRun your account, and show you the right campus and faculty contentWhy we are allowed toTo deliver the service you signed up for
What we doPublish your posts and listings, deliver messages, notifications and meetingsWhy we are allowed toTo deliver the service you signed up for
What we doTake payments for coins, subscriptions, boosts and paid postsWhy we are allowed toTo deliver the service, and to meet our tax and accounting duties
What we doVerify students, businesses and ridersWhy we are allowed toOur legitimate interest in a platform where people are who they claim to be
What we doModerate content, handle reports, and enforce our rulesWhy we are allowed toOur legitimate interest in a safe community, and our legal duties
What we doDetect and investigate fraud, abuse and security incidentsWhy we are allowed toOur legitimate interest in protecting users, and our legal duties
What we doKeep audit records of administrative actionWhy we are allowed toAccountability, and our legal duties
What we doUnderstand how features are used, so we can improve themWhy we are allowed toOur legitimate interest in a product that works
What we doSend marketing and product announcementsWhy we are allowed toYour consent, which you can withdraw at any time
4.2

Where we rely on legitimate interests, we have weighed them against your rights first. Ask us at info@mydaraja.africa and we will explain the reasoning for any particular use.

4.3

We will not start using your data for something materially different without telling you, and asking your permission where that is required.

5.What other people can see

5.1

Visible to your community layer: your name and profile photo, and your posts, listings, comments and reactions.

5.2

Visible only to you and the recipient: direct messages and their attachments.

5.3

Visible to our moderators: anything reported or escalated, plus the account details needed to act on it and your moderation history.

5.4

Never shown publicly: your password, payment details, session and audit records, national identification number, date of birth and address.

5.5

You stay in control: edit or delete your content, change your profile, block other users, and end any active session from the app.

6.Who we share it with

We do not sell your personal data, and we do not hand it to anyone for their own marketing.

6.2

We use these providers to run the Platform. Each is bound by contract to use your data only for the work we give them:

ProviderPaystackWhat they doTakes and settles paymentsWhat they receiveYour name, email and transaction details
ProviderDigitalOcean SpacesWhat they doStores images, documents and mediaWhat they receiveFiles you upload, and their metadata
ProviderGoogleWhat they doSign-in, and calendar entries for meetingsWhat they receiveYour Google account identity; meeting details
ProviderFirebase Cloud MessagingWhat they doDelivers push notificationsWhat they receiveYour push token and the notification text
ProviderOur email providerWhat they doSends account and service emailWhat they receiveYour name, email address and message content
ProviderOur hosting providerWhat they doRuns the servers and databaseWhat they receiveWhatever is needed to operate the Platform
6.3

We also share with partner universities, only as needed to confirm enrolment; with businesses and content partners, only what you choose to send them, such as a job application; with our lawyers, accountants and insurers, in confidence; and with the police, courts or regulators, where the law requires it or someone’s safety demands it.

6.4

If MyDaraja is ever sold or merged, your data may transfer with the business. We will tell you before it becomes subject to a different privacy policy.

6.5

We may publish aggregated statistics that cannot identify anyone. That is not personal data and this policy does not restrict it.

7.How long we keep it

7.1

We keep data only as long as we need it, or as long as the law requires:

WhatYour account and profileHow longUntil you delete your account, which erases it immediately
WhatYour posts, listings and messagesHow longUntil you delete them, or until you delete your account
WhatOne-time verification codesHow long5 minutes
WhatSign-in tokensHow long15 minutes for access, 7 days for the refresh token
WhatSession and device recordsHow long12 months from the end of the session
WhatPayment and financial recordsHow long6 years, as required for accounting and tax
WhatRider records, including identification numbersHow long6 years after the partnership ends
WhatModeration and report recordsHow long3 years after the matter is resolved
WhatAdministrative audit recordsHow long6 years
7.2

Deleting your account from the app is immediate and cannot be undone. It erases your profile, sessions, sign-in tokens and verification codes, and your business or rider record, and frees your email address and phone number to be registered again. We keep only what the law requires us to keep — chiefly financial records — and anything needed to defend a legal claim.

7.3

We may keep moderation records in anonymised form for longer, so that repeat behaviour can still be recognised.

8.Your rights

8.1

You have the right to:

  • see the data we hold about you, and get a copy;
  • correct anything wrong or out of date;
  • delete your data;
  • object to or restrict what we do with it, including profiling and marketing;
  • withdraw consent at any time, where consent is what we relied on;
  • take your data elsewhere, in a machine-readable format; and
  • complain to the Data Protection Commission.
8.2

Write to info@mydaraja.africa. We will reply within 30 days, and tell you if we need longer because the request is complex.

8.3

We may ask you to confirm who you are first. Requests are free unless they are repetitive or excessive, in which case we may charge a reasonable fee or decline — and we will say why.

8.4

If we turn a request down, we will give our reasons and tell you how to complain.

9.Automated decisions

9.1

We use automated systems to order your feed, decide which community layers you see, and flag possible fraud or rule-breaking.

No decision that seriously affects you — suspending or banning your account, or refusing a verification or business application — is ever made by software alone. A person reviews it first.

9.3

You can contest any such decision and ask a person to look it over again by writing to info@mydaraja.africa. Tell us what you think we got wrong, and we will reply.

10.Where we keep it, and how we protect it

10.1

Some of the providers in section 6 store data outside Ghana — our object storage, push notifications and sign-in run on infrastructure hosted abroad. We choose providers who commit to recognised data-protection terms, and we rely on those terms to keep your data as protected as it would be here. Ask us at info@mydaraja.africa about any particular provider.

10.2

We protect your data by:

  • encrypting everything in transit with TLS;
  • storing passwords only as salted hashes;
  • issuing short-lived access tokens, with every session individually visible and revocable by you;
  • limiting staff access to what each role actually needs; and
  • logging every administrative and moderation action.
10.3

No system is perfectly secure, and we cannot promise otherwise. Keep your password to yourself, and tell us at info@mydaraja.africa the moment you suspect someone else is using your account.

10.4

If data is breached in a way that puts you at risk, we will notify the Data Protection Commission without undue delay, and tell you directly where the risk to you is high.

11.Cookies

11.1

We use cookies only to keep you signed in and your session secure. We do not use advertising cookies, and we do not run third-party analytics or tracking on the Platform.

11.2

Because these cookies are essential to signing in, there is nothing here to opt out of — blocking them in your browser will simply stop the Platform working.

11.3

If we ever add analytics or any other non-essential cookie, we will ask your permission before setting it, and update this policy first.

12.Changes, and how to reach us

12.1

We may update this policy. If a change matters, we will tell you in the app or by email at least 14 days before it takes effect. The version and date at the top of this page always show what is currently in force.

12.2

For anything to do with your data or this policy:

MyDaraja Technologies LimitedAccra, GhanaEmail: info@mydaraja.africa
12.3

Please come to us first — we would rather fix it than have you chase it. If you are still unhappy, you can complain to the Data Protection Commission of Ghana, and nothing here stops you going to court.

12.4

This policy is governed by Ghanaian law. If any part of it turns out to be unenforceable, the rest still stands.

End of Policy