Shujaa Pay — Privacy Policy
| Document Title | Privacy Policy |
| Platform | Shujaa Pay (www.shujaapay.com) |
| Operating Company | Shujaa Tech Company Limited (registered Tanzanian company) |
| Version | 2.0 |
| Effective Date | 25 June 2026 |
| Last Updated | 25 June 2026 |
| Prepared By | Shujaa Tech Company Limited |
| Data Protection Contact | privacy@shujaapay.com · support@shujaapay.com |
[LEGAL REVIEW REQUIRED: This Policy has been revised to address findings of an internal legal audit. It must be reviewed and certified by qualified Tanzanian data-protection counsel before reliance. Items requiring verification are marked inline.]
1. Introduction
Shujaa Pay (“we”, “us”, “our”, or “the Platform”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, share, and protect information when you use:
- Our website (www.shujaapay.com)
- Our API and backend services (api.shujaapay.com) — used to operate the Platform (not a public third-party developer API)
- Seller dashboards and related web applications
- Payment pages, order tracking, and receipt flows
- Admin and support channels
This Policy is prepared in alignment with the Personal Data Protection Act, 2022 of the United Republic of Tanzania and other applicable laws.
Data Controller: Shujaa Tech Company Limited operates Shujaa Pay and determines the purposes and means of processing personal data described in this Policy.
By using Shujaa Pay, you acknowledge that you have read and understood this Privacy Policy. Where consent is required by law, we will obtain it before processing your data for the stated purpose.
2. Who This Policy Applies To
| User Type | Description |
|---|---|
| Sellers | Registered users who create payment links and receive payouts |
| Buyers | Individuals who pay through payment links (typically without a permanent account) |
| Website Visitors | Anyone who browses our public website |
| Administrators | Authorised Shujaa Pay staff who operate the platform |
| Job Applicants & Partners | Individuals who contact us for employment or business partnerships |
2.1 Social Commerce Context
Shujaa Pay is designed for social commerce. Buyers and Sellers typically meet independently on social media platforms (including WhatsApp, Instagram, Facebook, and TikTok) before a Seller shares a Shujaa Pay Payment Link. Shujaa Pay does not access, collect, or process the content of your private social media conversations. When a Buyer opens a Payment Link and submits their details, that information is collected directly by Shujaa Pay on our payment page — not from the social media platform.
3. Personal Data We Collect
3.1 Seller Registration and Account Data
When you register as a Seller, we collect:
| Data Category | Examples | Purpose |
|---|---|---|
| Identity | First name, last name, email, phone number | Account creation, authentication, communication |
| Business | Business name, business type, region, registration number, tax ID, address, city, country | Seller profile, compliance, reporting |
| Security | Password (stored hashed), session data, device info, IP address, login history | Authentication, fraud prevention |
| Financial | Available balance, escrow balance, payout history, preferred payout method | Wallet and payout operations |
| Preferences | Email, SMS, and push notification settings | Communication preferences |
| Profile | Profile picture, date of birth (if provided) | Account personalisation |
3.2 Seller KYC Data
Before withdrawals, Sellers must submit:
| Data Category | Examples | Purpose |
|---|---|---|
| Government ID | Full legal name, NIDA number, NIDA card images (front and back) | Identity verification, anti-fraud, regulatory compliance |
| Biometric | Selfie photograph | Liveness verification, identity matching |
| Mobile Money | Mobile money number, provider (M-Pesa, Tigo Pesa, Airtel Money, Halo Pesa), registered account name | Payout destination verification, name matching against NIDA |
KYC data is classified as sensitive personal data and receives enhanced protection.
3.3 Buyer Transaction Data
Buyers do not create standing accounts. For each transaction, we may collect:
| Data Category | Examples | Purpose |
|---|---|---|
| Contact | Name, phone number, email (if provided) | Order processing, OTP verification, receipts |
| Transaction | Payment amount, payment method, payment reference, order details | Escrow, tracking, dispute resolution |
| Verification | OTP codes (hashed after use), confirmation timestamps | Delivery confirmation, dispute filing |
3.4 Payment and Order Data
| Data Category | Examples | Purpose |
|---|---|---|
| Orders | Product name, amount, delivery address, courier details, status history | Escrow management, fulfilment tracking |
| Payments | Transaction IDs, PSP references, mobile money provider, payment status | Payment processing, reconciliation |
| Escrow | Hold status, release type, release timestamps, hold reasons | Fund protection |
| Disputes | Category, description, evidence, resolution, communications | Conflict resolution |
3.5 Automatically Collected Data
When you access our Platform, we automatically collect:
| Data Category | Examples | Purpose |
|---|---|---|
| Technical | IP address, browser type, device type, operating system | Security, analytics, troubleshooting |
| Usage | Pages visited, features used, API request metadata | Service improvement |
| Cookies | Session cookies, preference cookies (where used) | Authentication, user experience |
3.6 Communications Data
| Data Category | Examples | Purpose |
|---|---|---|
| Support | Emails, messages, and call records with support@shujaapay.com | Customer support, dispute assistance |
| Notifications | Email and SMS delivery logs | Transactional and service communications |
3.7 Administrator Data
Authorised administrators have accounts with email, role, login history, 2FA challenge records, and audit logs of actions performed on the Platform.
3.8 Job Applicants and Business Partners
When you apply for employment or contact us regarding a business partnership, we may collect:
| Data Category | Examples | Purpose |
|---|---|---|
| Contact | Name, email, phone number | Responding to your enquiry |
| Application | CV/resume, cover letter, qualifications, references | Recruitment assessment |
| Partnership | Company name, role, proposal details | Evaluating partnership opportunities |
We retain applicant and partner enquiry data only as long as needed for the recruitment or partnership process, plus any period required by law.
4. How We Use Your Data
We process personal data for the following purposes:
| Purpose | Legal Basis |
|---|---|
| Providing our services — payment links, escrow, payouts, order tracking | Contract performance |
| Identity verification (KYC) — before seller withdrawals | Legal obligation, legitimate interest, consent where required |
| Payment processing — via licensed PSP (Selcom) | Contract performance, legal obligation |
| Dispute resolution — investigating and resolving conflicts | Contract performance, legitimate interest |
| Security — fraud detection, account lockout, admin 2FA | Legitimate interest, legal obligation |
| Communication — transactional emails, SMS OTPs, service updates | Contract performance, consent where required |
| Compliance — anti-money laundering, regulatory reporting | Legal obligation |
| Improvement — analytics, bug fixes, feature development | Legitimate interest |
| Marketing — promotional communications (Sellers only, where opted in) | Consent (not sent until opt-in infrastructure is active) |
We do not sell your personal data to third parties.
4.1 Buyer Consent on the Payment Page
Buyers do not create standing accounts. When a Buyer opens a Payment Link and submits their name, phone number, and (optionally) email to pay, we collect that data to process the Order, send OTP verification, provide receipts, and handle disputes.
Before or at the point of collection, the payment page presents:
- A clear notice that personal data will be processed as described in this Policy
- A link to this Privacy Policy
- Confirmation that by proceeding with payment, the Buyer acknowledges this Policy and consents to processing necessary to complete the transaction (contract performance)
Where consent is separately required by law for optional processing (e.g., marketing), we obtain it explicitly and separately from payment.
[LEGAL REVIEW REQUIRED: Confirm the exact lawful basis and consent wording for buyer data collection under the Personal Data Protection Act, 2022, and implement the corresponding UI on the payment page.]
5. How We Share Your Data
We share personal data only when necessary and with appropriate safeguards:
| Recipient | What Is Shared | Why |
|---|---|---|
| Selcom (PSP) | Payment amounts, mobile money numbers, transaction references | Payment collection and disbursement |
| Mobile Money Operators | Payment instructions via PSP | Processing M-Pesa, Tigo Pesa, Airtel Money, Halo Pesa transactions |
| Email Provider (Hostinger) | Email addresses, message content | Transactional email delivery |
| SMS Gateway | Phone numbers, OTP messages | Verification and notifications |
| Hosting Provider | All data stored on our servers | Infrastructure hosting |
| Law Enforcement / Regulators | As required by valid legal request | Legal compliance |
| Professional Advisors | As needed under confidentiality | Legal, audit, or compliance advice |
We require third-party processors to protect your data through contractual data processing terms and security standards appropriate to the sensitivity of the data.
Between Users: Sellers can see Buyer contact details associated with their orders. Buyers can see Seller business name and order details on payment pages. KYC documents are never shared with Buyers or other Sellers.
5.1 Sellers as Data Processors
When a Seller receives a Buyer's contact details through an Order, the Seller processes that data for order fulfilment (e.g., arranging delivery). In that limited context, the Seller acts as a data processor (or independent controller, as determined by applicable law) and must:
- Use Buyer data only for fulfilling the specific Order and related communication
- Not sell, share, or use Buyer data for unrelated marketing without separate lawful basis and consent
- Protect Buyer data with appropriate security measures
- Delete or return Buyer data when no longer needed for the Order, subject to legal retention requirements
Shujaa Pay requires Sellers to comply with the Personal Data Protection Act, 2022, and applicable data-protection obligations as a condition of using the Platform.
[LEGAL REVIEW REQUIRED: Confirm whether Sellers are processors or independent controllers in this context and whether a formal Seller Data Processing Addendum is required.]
5.2 Seller Account Termination and Buyer Data
If a Seller's account is terminated, Shujaa Pay retains Buyer transaction data as required for escrow, disputes, legal obligations, and audit purposes (see Section 7). The terminated Seller loses access to Buyer contact details through the Platform. Historical Order records remain subject to our retention schedule.
6. International Data Transfers
Our primary data processing occurs in the United Republic of Tanzania. Where personal data is processed or stored outside Tanzania, we ensure appropriate safeguards consistent with the Personal Data Protection Act, 2022.
| Provider / Purpose | Likely Location | Safeguard |
|---|---|---|
| Hosting (VPS) | [LEGAL REVIEW REQUIRED: confirm server jurisdiction, e.g., Tanzania / EU / other] | Contractual data-processing terms, access controls, encryption in transit |
| Email (Hostinger) | [LEGAL REVIEW REQUIRED: confirm] | TLS, contractual protections |
| Payment (Selcom) | Tanzania | Licensed PSP, regulated processing |
| Cloud / backup services | [LEGAL REVIEW REQUIRED: confirm if used] | Encryption, access restrictions, contractual safeguards |
We do not transfer data internationally without appropriate safeguards. See our Security Policy for technical protections applied to data at rest and in transit, including KYC document storage.
[LEGAL REVIEW REQUIRED: Confirm actual hosting, email, backup, and KYC storage locations and document the specific transfer mechanisms (e.g., standard contractual clauses, adequacy decisions) required under PDPA 2022.]
7. Data Retention
We retain personal data only as long as necessary for the purposes described in this Policy:
| Data Type | Retention Period |
|---|---|
| Seller account data | Duration of account + 5 years after closure (or longer if required by law) |
| KYC documents | Duration of account + 7 years (regulatory and AML requirements) |
| Transaction and escrow records | 7 years minimum (financial record-keeping) |
| Buyer transaction data | 5 years from transaction date |
| Dispute records | 7 years from resolution |
| Security and audit logs | 2 years minimum |
| Marketing preferences | Until consent is withdrawn |
| Support communications | 3 years from last interaction |
After retention periods expire, data is securely deleted or anonymised.
8. Data Security
We implement technical and organisational measures to protect your data, including:
- TLS encryption for data in transit
- Password hashing (irreversible) for credentials
- Role-based access control for staff and administrators
- Mandatory admin 2FA for back-office access
- Account lockout after failed login attempts
- OTP verification for buyer receipt confirmation and sensitive actions
- Audit logging for admin financial actions
- Environment-based secrets — no credentials in source code
- Regular backups and incident response procedures
See our Security Policy for full details.
Despite our efforts, no method of transmission or storage is 100% secure. If you believe your account has been compromised, contact us immediately at support@shujaapay.com.
9. Your Rights
Under the Personal Data Protection Act, 2022, and applicable law, you may have the following rights:
| Right | Description |
|---|---|
| Access | Request a copy of personal data we hold about you |
| Rectification | Request correction of inaccurate or incomplete data |
| Erasure | Request deletion of your data (subject to legal retention requirements) |
| Restriction | Request limitation of processing in certain circumstances |
| Objection | Object to processing based on legitimate interests |
| Portability | Request your data in a structured, machine-readable format (where applicable) |
| Withdraw Consent | Withdraw consent for marketing or optional processing at any time |
To exercise your rights, contact support@shujaapay.com with:
- Your full name and registered email or phone number
- A clear description of your request
- Proof of identity (to prevent unauthorised access to your data)
We will respond within 30 days (or the period required by law). We may refuse requests that are manifestly unfounded, excessive, or would compromise other individuals’ rights or legal obligations.
10. Cookies and Tracking Technologies
Our website may use cookies and similar technologies for:
| Cookie Type | Purpose |
|---|---|
| Essential | Authentication, security, session management |
| Functional | Remembering preferences |
| Analytics | Understanding how visitors use our website (aggregated, anonymised where possible) |
Analytics provider: We use [LEGAL REVIEW REQUIRED: name the analytics tool, e.g., Google Analytics, Plausible, Vercel Analytics, or state "no third-party analytics currently deployed"] for website usage analytics. Where deployed, analytics cookies collect aggregated usage data and do not identify individual Buyers on payment pages.
You can control cookies through your browser settings. Disabling essential cookies may affect Platform functionality.
We do not use cookies for third-party advertising networks at this time.
11. Children’s Privacy
Shujaa Pay is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If we discover that we have collected data from a minor, we will delete it promptly. Parents or guardians who believe a child has provided data to us should contact support@shujaapay.com.
12. Marketing Communications
We may send Sellers promotional emails about new features, offers, or platform updates only if you have opted in or where permitted by law. You can unsubscribe at any time by:
- Clicking the unsubscribe link in any marketing email
- Updating notification preferences in your Seller dashboard
- Emailing support@shujaapay.com
Transactional communications (payment confirmations, OTP codes, payout notifications, security alerts) are not optional as they are essential to the service.
13. Automated Decision-Making
We may use automated systems for:
- Fraud detection — flagging suspicious transactions or accounts
- Account lockout — after repeated failed login attempts
- Auto-release — releasing escrow after defined delivery and waiting periods (unless a dispute is active)
You have the right to request human review of decisions that significantly affect you, where required by law. Contact support@shujaapay.com for review requests.
14. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will:
- Contain and investigate the breach without undue delay
- Notify the Personal Data Protection Commission as required by law
- Notify affected individuals where the breach is likely to result in high risk to their rights
- Document the breach and remedial actions taken
15. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. When we make material changes:
- We will update the “Last Updated” date at the top of this document
- We will notify registered Sellers via email or dashboard notice
- We will post the updated Policy on www.shujaapay.com
Continued use of the Platform after changes constitutes acknowledgment of the updated Policy.
16. Complaints
If you believe we have not handled your personal data properly, you may:
- Contact us first: support@shujaapay.com — we will investigate and respond
- Lodge a complaint with the Personal Data Protection Commission (PDPC) of Tanzania if you are not satisfied with our response
| PDPC | Personal Data Protection Commission, Tanzania |
| Website | www.pdpc.go.tz (verify current URL) |
17. Contact Us
For privacy-related questions, data subject requests, or security concerns:
| Platform | Shujaa Pay |
| privacy@shujaapay.com | |
| Support | support@shujaapay.com |
| Phone | +255 746 259 442 |
| Location | Zanzibar, United Republic of Tanzania |
| Data Protection Officer (DPO) | [LEGAL REVIEW REQUIRED: appoint an independent DPO or external DPO service and record name/organisation here] |
| DPO Contact | privacy@shujaapay.com |
[ACTION REQUIRED: Appoint an independent Data Protection Officer (or engage an external DPO service). The DPO should be capable of operating independently of day-to-day technical operations. Provision and monitor a dedicated
privacy@shujaapay.commailbox.]
18. Related Documents
| Document | Description |
|---|---|
| Terms and Conditions | Rules governing use of the Platform |
| Security Policy | How we protect systems and data |
| AML Policy | Anti-money laundering and counter-terrorist financing controls |
19. Document Control
| Version | Date | Author | Changes |
|---|---|---|---|
| 1.0 | 22 June 2026 | Mohamed Hafidh Mohamed | Initial release |
| 2.0 | 25 June 2026 | Shujaa Tech Company Limited | Legal audit remediation: independent DPO placeholder, buyer consent mechanism, international transfers table, social commerce data flows, seller-as-processor, applicants data, analytics naming, fixed document links, seller termination data handling |
© 2026 Shujaa Pay. All rights reserved.
This Privacy Policy is provided for transparency and compliance purposes. It does not constitute legal advice. For legal review specific to your business or regulatory obligations, consult qualified counsel in Tanzania.
