Legal
Privacy notice
What personal data Daazia collects when you book event rentals, why we need it, who we share it with, how long we keep it, and the rights you have under Ghana's Data Protection Act, 2012 (Act 843).
- Version
- 1.0
- Last updated
- Governing law
- Ghana
Contents (17 sections)
- 1Who we are
- 2What we collect
- 3What we never receive
- 4Why we use it, and our legal basis
- 5Location data
- 6Photographs and evidence
- 7Who we share it with
- 8Where your data is processed
- 9How long we keep it
- 10How we protect it
- 11Your rights
- 12Cookies
- 13Messages we send you
- 14Children
- 15Automated decisions
- 16Changes to this notice
- 17Contact and complaints
1.Who we are
Daazia operates Daazia, a managed marketplace for event rentals in Ghana. We are the data controller for the personal data described in this notice, which means we decide what we collect and why, and we are accountable for it under the Data Protection Act, 2012 (Act 843).
This notice covers our website, the customer and supplier portals, and the messages we send about bookings. It sits alongside our terms of service.
Suppliers on the marketplace are separate businesses. When a supplier uses your details to fulfil your booking, they act as a controller for their own records too, and their own privacy practices apply to what they keep.
2.What we collect
We collect what a booking actually needs, and no more.
Account and identity
- your name, phone number and email address, and a profile photo if you add one;
- your language preference and notification settings, including any quiet hours you set;
- sign-in records: the one-time codes we send (never your password, because there is none), the devices and sessions on your account, and whether two-factor authentication is enabled.
Your event and venue
- event type, name, date, setup and pickup times, and expected guest count;
- the venue: your map pin, GhanaPostGPS code, landmark, access instructions and, where you save an address, its label;
- the on-site contact name and phone number you give us, which may be someone else’s;
- your budget range and any notes or attachments you add to an event brief.
Bookings and money
- quotes, bookings, items and quantities, change orders and cancellations;
- payment records: amount, currency, status, timestamps and the reference returned by our payment provider; deposit, refund and claim records;
- for suppliers: business and legal name, verification documents, warehouse locations, service areas, and payout bank or mobile-money details.
Fulfilment and trust
- delivery, setup, pickup and inspection records, checklists, handover code confirmations and exception notes;
- photographs, video and signatures captured as proof of handover and condition;
- coarse location captured while a delivery or pickup task is in progress (see below);
- claims, disputes, the messages and evidence in them, and reviews you write.
Technical and message data
- IP address, browser and device information, and pages requested — used for security, rate limiting and diagnosing faults;
- records that a booking notification was sent and whether it was delivered, on which channel.
We do not collect special-category data such as health, religious or political information, and we ask you not to put it in event briefs, notes or dispute messages.
3.What we never receive
Payments are taken on the hosted pages of a payment service provider licensed by the Bank of Ghana. Card numbers, expiry dates, CVV codes and mobile-money PINs are entered on the provider’s pages and never reach our systems. We receive the payment reference, amount, currency and status.
We never ask for a mobile-money PIN, and no one from Daazia will ever ask for one by phone, SMS or WhatsApp. Treat any such request as fraud and report it to us.
Supplier payout beneficiary details are encrypted before they are stored, and are visible only to the finance staff who need them to release a payout.
4.Why we use it, and our legal basis
- Running your booking
- Creating quotes, taking payment, holding and refunding deposits, dispatching delivery and pickup, and settling suppliers. Basis: performance of our contract with you.
- Keeping you informed
- Booking, payment, delivery and dispute updates by SMS, WhatsApp, email or in-app. Basis: performance of our contract — these are service messages, not marketing.
- Trust, safety and fraud prevention
- Verifying suppliers, rate limiting, bot checks, reviewing unmatched payments, and investigating claims and disputes. Basis: our legitimate interest in a marketplace that is safe to transact on, and legal obligation where anti-fraud rules apply.
- Records, tax and accounting
- Keeping invoices, payment records, payouts and withholding records. Basis: legal obligation.
- Improving the service
- Diagnosing errors, measuring supplier performance and improving search results using aggregated booking data. Basis: legitimate interest, with the least identifying data that answers the question.
- Marketing
- Offers and product news, only if you opt in. Basis: your consent, which you can withdraw at any time.
Where we rely on legitimate interest, we have weighed it against your rights and use the narrowest data that achieves the purpose. You can object — see your rights below.
5.Location data
Location is central to delivery, so we are specific about it:
- Your venue pin is data you enter, not data we track. It is kept with the event and booking, and shared with the assigned supplier so the crew can find you.
- Crew location is captured only while a delivery or pickup task is actually in progress, at low precision, and stops when the task is completed or cancelled. It is used to show you delivery status and to resolve disputes about whether and when a crew arrived.
- We do not track customers. The app does not collect your location in the background, and we do not build location profiles or sell location data.
Address lookups and map tiles are served by our mapping provider, which receives the coordinates being looked up in order to answer. We do not send your name, phone number or booking reference with those requests.
6.Photographs and evidence
Handover, setup, pickup and inspection photographs exist to protect both sides of a booking: they are what a deposit deduction or a damage claim has to be proved against.
- They are stored in private storage, never on a public URL, and are served only through links that expire after a few minutes.
- We strip embedded metadata — including GPS coordinates and camera EXIF — from every uploaded image before it is stored.
- They are visible only to you, the supplier assigned to that booking, and the staff handling the claim or dispute. They are not published, not used in marketing, and not shown on supplier profiles.
- Evidence files cannot be edited or deleted by the person who uploaded them, so a record cannot be altered after a dispute starts.
Please keep evidence photographs to the items and the site. If people appear incidentally, that is fine; do not upload photographs of people as the subject, or of documents you do not need to share.
8.Where your data is processed
We keep data in the region closest to Ghana that our providers offer, but several of the providers above are international and process data outside Ghana — typically in the European Union, the United Kingdom or the United States.
Where data leaves Ghana we rely on written contracts with each provider that impose equivalent protection and limit them to processing on our instructions, in line with the cross-border requirements of Act 843. You can ask us for the current list of processors and the countries involved.
9.How long we keep it
We keep personal data only as long as the purpose needs, or the law requires. In outline:
- Account and profile
- While your account is open. After you close it we delete or anonymise your profile, keeping only what the records below require.
- Bookings, quotes and events
- Six years from the end of the tax year in which the booking falls, because they are the underlying records for payments and tax.
- Payments, deposits, refunds and payouts
- Six years, as required by Ghanaian tax and accounting law and by our payment provider's own record-keeping obligations.
- Handover, setup and pickup photographs
- Until the 24-hour claim window closes and the deposit is settled — then 12 months, so a late complaint can still be checked. Photographs tied to a claim or dispute are kept until it is closed and the appeal period has passed.
- Delivery location pings
- 90 days, then deleted. Retained longer only where a specific dispute about that delivery is open.
- Claims and disputes
- Six years from resolution, as they can lead to a legal claim.
- Supplier verification documents
- For as long as the supplier is active on the marketplace, and five years after they leave, for anti-fraud and regulatory purposes.
- Reviews
- Published reviews stay up while the supplier is listed. If you close your account, we detach your name and keep the review text and scores.
- Notification logs and audit logs
- Delivery records of the messages we send: 12 months. Security and staff-action audit logs: two years.
- Error diagnostics
- 90 days.
Once a period expires we delete the data or strip it of anything that identifies you. Where we must keep a financial record, we keep the record itself and remove what is not needed to support it.
10.How we protect it
- Data is encrypted in transit, and access is enforced in the database itself — row by row, per account — not only in the app, so one bug cannot open another customer’s bookings.
- All uploads go to private storage and are reached only through short-lived signed links. Files are checked by content, not by their filename, and image metadata is stripped before storage.
- Staff access is least-privilege and role-based; staff who can touch money or personal data must pass two-factor authentication, large refunds and payout changes need a second approver, and every override is written to an append-only audit log with a reason.
- Our logs redact phone numbers, account identifiers and other sensitive fields, and we keep personal data out of URLs.
- Secrets are held server-side only, and we run automated checks for leaked credentials.
No system is perfectly secure. If a breach affects your personal data and creates a real risk to you, we will notify you and the Data Protection Commission as required, and tell you what to do.
11.Your rights
Under the Data Protection Act, 2012 (Act 843) you can ask us to:
- Tell you what we hold and give you a copy of it;
- Correct anything inaccurate or incomplete — you can edit most of your details in your account settings yourself;
- Delete or block data we no longer have a reason to keep;
- Stop processing that you object to, including stopping marketing messages, which you can also turn off in your notification settings;
- Withdraw consent where we relied on it, without affecting what we did before you withdrew it.
Write to privacy@daazia.com from the email address on your account, or ask us from within your account. We may need to verify your identity before we act — that protects you as much as us. We aim to respond within 30 days and will tell you if a request will take longer and why.
Some data we cannot delete on request: payment, deposit, refund, claim and dispute records we must keep for tax, accounting or legal reasons. In that case we restrict them to those purposes and tell you what we kept and why.
13.Messages we send you
Service messages — quote responses, payment confirmations, delivery and pickup updates, deposit refunds, claims and disputes — are part of the service. You can choose channels and set quiet hours in your notification settings, but you cannot turn off messages about a booking you have, because they are how the booking works.
Marketing messages are opt-in and separate. Every one has an unsubscribe or STOP option, and turning marketing off has no effect on your bookings. WhatsApp messages are sent using pre-approved templates and only where WhatsApp is a channel you have accepted.
14.Children
The platform is for adults: you must be 18 or over to hold an account, and we do not knowingly collect data about children. If you believe a child has given us personal data, write to privacy@daazia.com and we will delete it.
15.Automated decisions
We do not make decisions about you by automated means alone that have a legal or similarly significant effect. Some processes are automated but supervised:
- search ranking uses objective supplier metrics — acceptance, punctuality, item accuracy, dispute rate — and does not profile you;
- rate limits and bot checks may temporarily block a request; you can contact support to have it reviewed;
- a payment that cannot be matched, or a deposit deduction above a threshold, is routed to a person, not decided automatically.
16.Changes to this notice
We update this notice when the service or the law changes. The version and date at the top of the page show the current edition, and for changes that materially affect you we give notice before they take effect. Material changes to how we use data under consent will be put to you for a fresh choice.
17.Contact and complaints
For anything in this notice, or to exercise a right, write to privacy@daazia.com. For help with a booking, support@daazia.com is faster.
If we do not resolve your concern, you can complain to Ghana’s Data Protection Commission — dpc.gov.gh. We would rather hear from you first, so we can fix it.
See also our terms of service, which govern bookings, deposits, cancellations and disputes.