1.About this policy
MyDaraja Technologies Limited, a company registered in Ghana with its office in Accra (“MyDaraja”, “we”, “us”), operates the MyDaraja mobile and web applications (the “Platform”). We are the data controller for the personal data described here.
This policy explains what personal data we collect, why, who we share it with, how long we keep it, and what rights you have. It applies to students, business accounts, content partners, delivery riders, and our own staff.
We process personal data under the Data Protection Act, 2012 (Act 843) of Ghana, and we are answerable to the Data Protection Commission.
Where we handle data on behalf of a partner university or business, they are the controller and their own notice applies alongside this one.
This policy does not cover third-party sites you reach through the Platform. Read their notices before giving them anything.
2.Who can use MyDaraja
You must be 18 or over. Some features are further limited to enrolled students of partner universities.
We do not knowingly collect data from anyone under 18. If you believe we have, write to info@mydaraja.africa and we will delete it.
3.What we collect
You give us: your name, email address and phone number; a password, which we store only as a salted hash and never in readable form; your university, campus, faculty and year of study; and, if you choose to add them, a profile photo, bio, date of birth and address.
You create: posts, polls and votes, hangouts, job listings and the applications and résumés sent through them, comments and reactions, marketplace and accommodation listings, direct messages, and meetings you schedule.
Business and rider onboarding: business application details, and for delivery riders a photograph, contact details, vehicle type and registration, and a national identification number.
Payments: the amount, currency, purpose, status, reference and settlement time of each transaction, your coin balance, and your subscription or paid-post history.
Automatically: your IP address, device name and identifier, browser or app user-agent, and when each session was created and last active. If you turn on notifications, a push token for your device.
From others: Google, if you sign in with it or connect your calendar; Paystack, which tells us whether a payment succeeded and how it was paid; your university, for enrolment checks; and other users, if they report you.
We also keep moderation records — reports made and received, warnings, suspensions and bans — and audit records of what our administrators do.
We never see your card number, mobile money PIN or one-time authorisation codes. Those go straight to Paystack and never touch our systems.
We do not ask for sensitive data — health, religion, politics, ethnicity. You may still put it in a post, a bio or a wellness report; if you do, you are choosing to share it, and we handle it on that basis. Please do not share more than the situation needs.
4.Why we use it
We only use your data where we have a lawful reason to:
| What we do | Why we are allowed to |
|---|---|
| What we doRun your account, and show you the right campus and faculty content | Why we are allowed toTo deliver the service you signed up for |
| What we doPublish your posts and listings, deliver messages, notifications and meetings | Why we are allowed toTo deliver the service you signed up for |
| What we doTake payments for coins, subscriptions, boosts and paid posts | Why we are allowed toTo deliver the service, and to meet our tax and accounting duties |
| What we doVerify students, businesses and riders | Why we are allowed toOur legitimate interest in a platform where people are who they claim to be |
| What we doModerate content, handle reports, and enforce our rules | Why we are allowed toOur legitimate interest in a safe community, and our legal duties |
| What we doDetect and investigate fraud, abuse and security incidents | Why we are allowed toOur legitimate interest in protecting users, and our legal duties |
| What we doKeep audit records of administrative action | Why we are allowed toAccountability, and our legal duties |
| What we doUnderstand how features are used, so we can improve them | Why we are allowed toOur legitimate interest in a product that works |
| What we doSend marketing and product announcements | Why we are allowed toYour consent, which you can withdraw at any time |
Where we rely on legitimate interests, we have weighed them against your rights first. Ask us at info@mydaraja.africa and we will explain the reasoning for any particular use.
We will not start using your data for something materially different without telling you, and asking your permission where that is required.
5.What other people can see
Visible to your community layer: your name and profile photo, and your posts, listings, comments and reactions.
Visible only to you and the recipient: direct messages and their attachments.
Visible to our moderators: anything reported or escalated, plus the account details needed to act on it and your moderation history.
Never shown publicly: your password, payment details, session and audit records, national identification number, date of birth and address.
You stay in control: edit or delete your content, change your profile, block other users, and end any active session from the app.
7.How long we keep it
We keep data only as long as we need it, or as long as the law requires:
| What | How long |
|---|---|
| WhatYour account and profile | How longUntil you delete your account, which erases it immediately |
| WhatYour posts, listings and messages | How longUntil you delete them, or until you delete your account |
| WhatOne-time verification codes | How long5 minutes |
| WhatSign-in tokens | How long15 minutes for access, 7 days for the refresh token |
| WhatSession and device records | How long12 months from the end of the session |
| WhatPayment and financial records | How long6 years, as required for accounting and tax |
| WhatRider records, including identification numbers | How long6 years after the partnership ends |
| WhatModeration and report records | How long3 years after the matter is resolved |
| WhatAdministrative audit records | How long6 years |
Deleting your account from the app is immediate and cannot be undone. It erases your profile, sessions, sign-in tokens and verification codes, and your business or rider record, and frees your email address and phone number to be registered again. We keep only what the law requires us to keep — chiefly financial records — and anything needed to defend a legal claim.
We may keep moderation records in anonymised form for longer, so that repeat behaviour can still be recognised.
8.Your rights
You have the right to:
- see the data we hold about you, and get a copy;
- correct anything wrong or out of date;
- delete your data;
- object to or restrict what we do with it, including profiling and marketing;
- withdraw consent at any time, where consent is what we relied on;
- take your data elsewhere, in a machine-readable format; and
- complain to the Data Protection Commission.
Write to info@mydaraja.africa. We will reply within 30 days, and tell you if we need longer because the request is complex.
We may ask you to confirm who you are first. Requests are free unless they are repetitive or excessive, in which case we may charge a reasonable fee or decline — and we will say why.
If we turn a request down, we will give our reasons and tell you how to complain.
9.Automated decisions
We use automated systems to order your feed, decide which community layers you see, and flag possible fraud or rule-breaking.
No decision that seriously affects you — suspending or banning your account, or refusing a verification or business application — is ever made by software alone. A person reviews it first.
You can contest any such decision and ask a person to look it over again by writing to info@mydaraja.africa. Tell us what you think we got wrong, and we will reply.
10.Where we keep it, and how we protect it
Some of the providers in section 6 store data outside Ghana — our object storage, push notifications and sign-in run on infrastructure hosted abroad. We choose providers who commit to recognised data-protection terms, and we rely on those terms to keep your data as protected as it would be here. Ask us at info@mydaraja.africa about any particular provider.
We protect your data by:
- encrypting everything in transit with TLS;
- storing passwords only as salted hashes;
- issuing short-lived access tokens, with every session individually visible and revocable by you;
- limiting staff access to what each role actually needs; and
- logging every administrative and moderation action.
No system is perfectly secure, and we cannot promise otherwise. Keep your password to yourself, and tell us at info@mydaraja.africa the moment you suspect someone else is using your account.
If data is breached in a way that puts you at risk, we will notify the Data Protection Commission without undue delay, and tell you directly where the risk to you is high.
12.Changes, and how to reach us
We may update this policy. If a change matters, we will tell you in the app or by email at least 14 days before it takes effect. The version and date at the top of this page always show what is currently in force.
For anything to do with your data or this policy:
Please come to us first — we would rather fix it than have you chase it. If you are still unhappy, you can complain to the Data Protection Commission of Ghana, and nothing here stops you going to court.
This policy is governed by Ghanaian law. If any part of it turns out to be unenforceable, the rest still stands.
End of Policy