Skip to content

Legal

Privacy notice

What personal data Daazia collects when you book event rentals, why we need it, who we share it with, how long we keep it, and the rights you have under Ghana's Data Protection Act, 2012 (Act 843).

Version
1.0
Last updated
Governing law
Ghana
Contents (17 sections)
  1. 1Who we are
  2. 2What we collect
  3. 3What we never receive
  4. 4Why we use it, and our legal basis
  5. 5Location data
  6. 6Photographs and evidence
  7. 7Who we share it with
  8. 8Where your data is processed
  9. 9How long we keep it
  10. 10How we protect it
  11. 11Your rights
  12. 12Cookies
  13. 13Messages we send you
  14. 14Children
  15. 15Automated decisions
  16. 16Changes to this notice
  17. 17Contact and complaints

1.Who we are

Daazia operates Daazia, a managed marketplace for event rentals in Ghana. We are the data controller for the personal data described in this notice, which means we decide what we collect and why, and we are accountable for it under the Data Protection Act, 2012 (Act 843).

This notice covers our website, the customer and supplier portals, and the messages we send about bookings. It sits alongside our terms of service.

Suppliers on the marketplace are separate businesses. When a supplier uses your details to fulfil your booking, they act as a controller for their own records too, and their own privacy practices apply to what they keep.

2.What we collect

We collect what a booking actually needs, and no more.

Account and identity

  • your name, phone number and email address, and a profile photo if you add one;
  • your language preference and notification settings, including any quiet hours you set;
  • sign-in records: the one-time codes we send (never your password, because there is none), the devices and sessions on your account, and whether two-factor authentication is enabled.

Your event and venue

  • event type, name, date, setup and pickup times, and expected guest count;
  • the venue: your map pin, GhanaPostGPS code, landmark, access instructions and, where you save an address, its label;
  • the on-site contact name and phone number you give us, which may be someone else’s;
  • your budget range and any notes or attachments you add to an event brief.

Bookings and money

  • quotes, bookings, items and quantities, change orders and cancellations;
  • payment records: amount, currency, status, timestamps and the reference returned by our payment provider; deposit, refund and claim records;
  • for suppliers: business and legal name, verification documents, warehouse locations, service areas, and payout bank or mobile-money details.

Fulfilment and trust

  • delivery, setup, pickup and inspection records, checklists, handover code confirmations and exception notes;
  • photographs, video and signatures captured as proof of handover and condition;
  • coarse location captured while a delivery or pickup task is in progress (see below);
  • claims, disputes, the messages and evidence in them, and reviews you write.

Technical and message data

  • IP address, browser and device information, and pages requested — used for security, rate limiting and diagnosing faults;
  • records that a booking notification was sent and whether it was delivered, on which channel.

We do not collect special-category data such as health, religious or political information, and we ask you not to put it in event briefs, notes or dispute messages.

3.What we never receive

Payments are taken on the hosted pages of a payment service provider licensed by the Bank of Ghana. Card numbers, expiry dates, CVV codes and mobile-money PINs are entered on the provider’s pages and never reach our systems. We receive the payment reference, amount, currency and status.

We never ask for a mobile-money PIN, and no one from Daazia will ever ask for one by phone, SMS or WhatsApp. Treat any such request as fraud and report it to us.

Supplier payout beneficiary details are encrypted before they are stored, and are visible only to the finance staff who need them to release a payout.

4.Why we use it, and our legal basis

Running your booking
Creating quotes, taking payment, holding and refunding deposits, dispatching delivery and pickup, and settling suppliers. Basis: performance of our contract with you.
Keeping you informed
Booking, payment, delivery and dispute updates by SMS, WhatsApp, email or in-app. Basis: performance of our contract — these are service messages, not marketing.
Trust, safety and fraud prevention
Verifying suppliers, rate limiting, bot checks, reviewing unmatched payments, and investigating claims and disputes. Basis: our legitimate interest in a marketplace that is safe to transact on, and legal obligation where anti-fraud rules apply.
Records, tax and accounting
Keeping invoices, payment records, payouts and withholding records. Basis: legal obligation.
Improving the service
Diagnosing errors, measuring supplier performance and improving search results using aggregated booking data. Basis: legitimate interest, with the least identifying data that answers the question.
Marketing
Offers and product news, only if you opt in. Basis: your consent, which you can withdraw at any time.

Where we rely on legitimate interest, we have weighed it against your rights and use the narrowest data that achieves the purpose. You can object — see your rights below.

5.Location data

Location is central to delivery, so we are specific about it:

  • Your venue pin is data you enter, not data we track. It is kept with the event and booking, and shared with the assigned supplier so the crew can find you.
  • Crew location is captured only while a delivery or pickup task is actually in progress, at low precision, and stops when the task is completed or cancelled. It is used to show you delivery status and to resolve disputes about whether and when a crew arrived.
  • We do not track customers. The app does not collect your location in the background, and we do not build location profiles or sell location data.

Address lookups and map tiles are served by our mapping provider, which receives the coordinates being looked up in order to answer. We do not send your name, phone number or booking reference with those requests.

6.Photographs and evidence

Handover, setup, pickup and inspection photographs exist to protect both sides of a booking: they are what a deposit deduction or a damage claim has to be proved against.

  • They are stored in private storage, never on a public URL, and are served only through links that expire after a few minutes.
  • We strip embedded metadata — including GPS coordinates and camera EXIF — from every uploaded image before it is stored.
  • They are visible only to you, the supplier assigned to that booking, and the staff handling the claim or dispute. They are not published, not used in marketing, and not shown on supplier profiles.
  • Evidence files cannot be edited or deleted by the person who uploaded them, so a record cannot be altered after a dispute starts.

Please keep evidence photographs to the items and the site. If people appear incidentally, that is fine; do not upload photographs of people as the subject, or of documents you do not need to share.

7.Who we share it with

The supplier on your booking

Once a booking is confirmed, the assigned supplier sees what they need to fulfil it: your name, the phone number to call, the items and quantities, the event, setup and pickup times, and the venue pin, GhanaPostGPS code, landmark and access notes. Suppliers who were invited to quote but not selected see the event requirements, not your contact details or exact venue.

Service providers who process data for us

These providers act on our instructions under contract, and may only use the data to provide their service to us:

  • Application hosting (Vercel) — serves the website and portals.
  • Database, authentication and file storage (Supabase) — where account, booking and evidence data lives.
  • Payments (Paystack) — takes payment, processes refunds and sends payouts.
  • Maps and geocoding (Google Maps Platform) — map tiles, place lookups and distance calculations.
  • Messaging — our SMS, WhatsApp and email delivery providers, which receive the phone number or address and the message content.
  • Error monitoring (Sentry) — technical diagnostics, configured not to send personal data, with sensitive fields, phone numbers and account details redacted from our logs.
  • Bot protection (Cloudflare Turnstile) — where we need to confirm a request is not automated.

Others

  • Authorities and advisers — where the law requires it, or to establish or defend a legal claim, including our auditors, insurers and lawyers under a duty of confidence.
  • A buyer or successor — if the business is sold or restructured, with this notice continuing to apply to the data transferred.

We do not sell your personal data, and we do not share it for advertising.

8.Where your data is processed

We keep data in the region closest to Ghana that our providers offer, but several of the providers above are international and process data outside Ghana — typically in the European Union, the United Kingdom or the United States.

Where data leaves Ghana we rely on written contracts with each provider that impose equivalent protection and limit them to processing on our instructions, in line with the cross-border requirements of Act 843. You can ask us for the current list of processors and the countries involved.

9.How long we keep it

We keep personal data only as long as the purpose needs, or the law requires. In outline:

Account and profile
While your account is open. After you close it we delete or anonymise your profile, keeping only what the records below require.
Bookings, quotes and events
Six years from the end of the tax year in which the booking falls, because they are the underlying records for payments and tax.
Payments, deposits, refunds and payouts
Six years, as required by Ghanaian tax and accounting law and by our payment provider's own record-keeping obligations.
Handover, setup and pickup photographs
Until the 24-hour claim window closes and the deposit is settled — then 12 months, so a late complaint can still be checked. Photographs tied to a claim or dispute are kept until it is closed and the appeal period has passed.
Delivery location pings
90 days, then deleted. Retained longer only where a specific dispute about that delivery is open.
Claims and disputes
Six years from resolution, as they can lead to a legal claim.
Supplier verification documents
For as long as the supplier is active on the marketplace, and five years after they leave, for anti-fraud and regulatory purposes.
Reviews
Published reviews stay up while the supplier is listed. If you close your account, we detach your name and keep the review text and scores.
Notification logs and audit logs
Delivery records of the messages we send: 12 months. Security and staff-action audit logs: two years.
Error diagnostics
90 days.

Once a period expires we delete the data or strip it of anything that identifies you. Where we must keep a financial record, we keep the record itself and remove what is not needed to support it.

10.How we protect it

  • Data is encrypted in transit, and access is enforced in the database itself — row by row, per account — not only in the app, so one bug cannot open another customer’s bookings.
  • All uploads go to private storage and are reached only through short-lived signed links. Files are checked by content, not by their filename, and image metadata is stripped before storage.
  • Staff access is least-privilege and role-based; staff who can touch money or personal data must pass two-factor authentication, large refunds and payout changes need a second approver, and every override is written to an append-only audit log with a reason.
  • Our logs redact phone numbers, account identifiers and other sensitive fields, and we keep personal data out of URLs.
  • Secrets are held server-side only, and we run automated checks for leaked credentials.

No system is perfectly secure. If a breach affects your personal data and creates a real risk to you, we will notify you and the Data Protection Commission as required, and tell you what to do.

11.Your rights

Under the Data Protection Act, 2012 (Act 843) you can ask us to:

  • Tell you what we hold and give you a copy of it;
  • Correct anything inaccurate or incomplete — you can edit most of your details in your account settings yourself;
  • Delete or block data we no longer have a reason to keep;
  • Stop processing that you object to, including stopping marketing messages, which you can also turn off in your notification settings;
  • Withdraw consent where we relied on it, without affecting what we did before you withdrew it.

Write to privacy@daazia.com from the email address on your account, or ask us from within your account. We may need to verify your identity before we act — that protects you as much as us. We aim to respond within 30 days and will tell you if a request will take longer and why.

Some data we cannot delete on request: payment, deposit, refund, claim and dispute records we must keep for tax, accounting or legal reasons. In that case we restrict them to those purposes and tell you what we kept and why.

12.Cookies

We use a small number of strictly necessary cookies and nothing else. They keep you signed in, protect against cross-site request forgery, and carry the request identifier we use to trace an error back to a single request.

We do not use advertising cookies, cross-site trackers or third-party analytics profiles, which is why you are not asked to accept a cookie banner. Browsing the public listings does not require a session at all. Blocking necessary cookies will stop you from signing in.

13.Messages we send you

Service messages — quote responses, payment confirmations, delivery and pickup updates, deposit refunds, claims and disputes — are part of the service. You can choose channels and set quiet hours in your notification settings, but you cannot turn off messages about a booking you have, because they are how the booking works.

Marketing messages are opt-in and separate. Every one has an unsubscribe or STOP option, and turning marketing off has no effect on your bookings. WhatsApp messages are sent using pre-approved templates and only where WhatsApp is a channel you have accepted.

14.Children

The platform is for adults: you must be 18 or over to hold an account, and we do not knowingly collect data about children. If you believe a child has given us personal data, write to privacy@daazia.com and we will delete it.

15.Automated decisions

We do not make decisions about you by automated means alone that have a legal or similarly significant effect. Some processes are automated but supervised:

  • search ranking uses objective supplier metrics — acceptance, punctuality, item accuracy, dispute rate — and does not profile you;
  • rate limits and bot checks may temporarily block a request; you can contact support to have it reviewed;
  • a payment that cannot be matched, or a deposit deduction above a threshold, is routed to a person, not decided automatically.

16.Changes to this notice

We update this notice when the service or the law changes. The version and date at the top of the page show the current edition, and for changes that materially affect you we give notice before they take effect. Material changes to how we use data under consent will be put to you for a fresh choice.

17.Contact and complaints

For anything in this notice, or to exercise a right, write to privacy@daazia.com. For help with a booking, support@daazia.com is faster.

If we do not resolve your concern, you can complain to Ghana’s Data Protection Commission dpc.gov.gh. We would rather hear from you first, so we can fix it.

See also our terms of service, which govern bookings, deposits, cancellations and disputes.