Dalfal Dalfal

Privacy Policy

Last updated: 2026-07-04

Also see our Terms of Service.

Contents

  1. Who We Are
  2. Who This Policy Covers
  3. Two Roles, Two Verification Levels
  4. Data We Collect and Why
  5. Data We Do Not Collect
  6. Third Parties We Share Data With
  7. How Long We Keep Your Data
  8. Cross-Border Transfers
  9. How We Protect Your Data
  10. Your Rights
  11. Children
  12. Data Breach Notification
  13. Marketing
  14. Automated Decisions
  15. Kenya — Data Protection Act 2019
  16. Somalia Note
  17. Changes to This Policy
  18. Contact Us

1. Who We Are

Dalfal ("we", "us", "our") operates the Dalfal marketplace — a two-sided platform that connects customers ("kunde") who post tasks with skilled workers ("fundi") who bid on and complete those tasks. Payments are processed through M-Pesa (Kenya) and WaafiPay / EVC Plus (Somalia).

Data controller: Dalfal
Registered address: [to be confirmed before publication]
Email: privacy@dalfal.com

2. Who This Policy Covers

This Privacy Policy applies to personal data we collect through:

  • The Dalfal mobile app (Android and iOS).
  • The services that run the platform behind the scenes.
  • This website (dalfal.com) and any contact forms on it.
  • Any messages we send you in connection with your account, such as one-time login codes and payment notifications.

It does not apply to the practices of fundis or third parties whose services you may access through our platform.

3. Two Roles, Two Verification Levels

Dalfal uses an asymmetric verification model matched to the risk each role carries.

Kunde (customer): you post tasks and pay via mobile money. We verify your phone number at sign-up only. We do not collect your selfie, your national ID document, or any biometric data at any point. Your financial accountability is established through the payment service, which is tied to your registered phone number.

Fundi (service provider): you enter customers' homes and receive real money transfers. Before you can take a booking we require full identity verification (KYC): a photo of your government-issued ID (front and back) and a selfie matched against the portrait on your ID. A higher level of identity certainty is proportionate to the responsibility you carry, and it is a condition of receiving payouts.

A kunde who later chooses to earn on the platform can upgrade to fundi status, at which point all sections below that say "Fundi only" apply to them.

4. Data We Collect and Why

4.1 Phone number — all users

What: your mobile number as entered at sign-up and confirmed by a one-time code.
Why: to create and authenticate your account and to initiate payments.
Legal basis: performance of a contract.
Stored: on our own secured servers — not with any third-party database provider.
Kept for: life of account plus 12 months after closure.
Note: your phone number is never written to application logs or analytics systems.

4.2 Email address — all users (optional)

What: your email address if you choose the email sign-up or sign-in path.
Why: to send you a one-time code for registration or login.
Legal basis: performance of a contract.
Stored: on our own secured servers.
Kept for: life of account plus 12 months after closure.

4.3 Full name — all users

What: the name you enter during profile setup.
Why: displayed on your fundi profile or shared with a matched fundi in the context of a job.
Legal basis: performance of a contract.
Stored: on our own secured servers. Never written to logs or analytics.
Kept for: life of account plus 12 months after closure.

4.4 Government-issued ID document images — fundi only

What: photographs of the front and back of your government-issued identity document.
Why: to verify your identity before you can take bookings and receive payouts.
Legal basis: explicit consent given at the identity verification step during onboarding. You may withdraw consent at any time; doing so means we must suspend your fundi account because identity verification is a condition of the fundi role.
Stored: in a private, secure file store with no public link. Access is time-limited and restricted to authorised Dalfal staff only.
Location data: GPS coordinates and all photo metadata are removed from your image before it is saved — we never keep location data embedded in your photos.
Kept for: life of account plus 2 years after closure.

4.5 Selfie photograph — fundi only

What: a selfie captured in-app during the identity verification flow.
Why: to check that your face matches the portrait on your ID document, confirming you are the person named on the ID.
Legal basis: explicit consent given at the identity verification step.
Stored: in the same private, secure file store as your ID images, with the same access restrictions and metadata removal.
Kept for: life of account plus 2 years after closure.

4.6 ID number — scrambled, plus last 4 digits — fundi only

What: your national ID number is scrambled into an unreadable form the moment you enter it and the original is discarded — we never keep it. Only the scrambled version and the last 4 digits of your number are stored. Your full ID number in readable form is never stored anywhere by Dalfal.
Why: to prevent the same identity document being registered to more than one fundi account.
Legal basis: performance of a contract and legitimate interest (preventing identity fraud).
Stored: on our own secured servers only. Never sent to third parties.
Kept for: life of account plus 2 years after closure.

4.7 Date of birth — fundi only (typed-ID path)

What: your date of birth as entered during identity verification.
Why: validated during identity verification submission.
Legal basis: explicit consent.
Stored: on our own secured servers. Never written to logs.
Kept for: life of account plus 2 years after closure.

4.8 Payment transaction metadata — all users

What: payment requests, transaction references, wallet records, and payout references. We do not store your full transaction history with the payment provider. Your phone number is passed to the payment provider to initiate payment but is not written to our own system logs.
Why: to operate the payment system, maintain a wallet record, enable dispute resolution, and satisfy financial record-keeping obligations.
Legal basis: performance of a contract. Financial records are also retained to meet applicable accounting and tax law.
Stored: on our own secured servers. The authoritative payment record is held by M-Pesa / WaafiPay as the regulated payment service provider.
Kept for: 7 years from the transaction date.

4.9 Push notification tokens (FCM / APNs) — all users

What: a device token that allows us to send push notifications to your Android or iOS device.
Why: to send you transactional push notifications about your account — bid accepted, payout completed, task updated. We do not send marketing messages via push.
Legal basis: performance of a contract.
Stored: on our own secured servers; passed to Google (Android) or Apple (iOS) at the time a notification is sent.
Kept for: refreshed on each login; deleted when your account is closed.

4.10 Task content (title, description, budget, photos) — all users

What: the details you enter when posting a task and any photos you attach.
Why: to publish your task to fundis who can bid on it. Task content is the core product data.
Legal basis: performance of a contract.
Stored: text on our own secured servers; photos in a private, access-controlled file store. GPS and photo metadata are removed before storage.
Kept for: life of account plus 12 months after closure.

4.11 In-app messages — all users

Your messages are end-to-end encrypted, which means only you and the person you are chatting with can read them — not even we can. Your messages are scrambled on your own device before they leave your phone. The key that unscrambles them is stored only in a secure area on your device and is never sent to Dalfal.

What we store: only the scrambled, unreadable version of your messages, plus the envelope around each one — who sent it, who it is for, which job thread it belongs to, and when it was sent, delivered, and read. We never store or read the actual words of your messages.
Why: to route your message to the right thread and operate the platform.
Legal basis: performance of a contract.
Scrambled message kept for: deleted once delivered and confirmed received, or after 30 days, whichever is earlier.
Envelope information kept for: life of account plus 12 months after closure.

Because we cannot read your messages, our approach to keeping the platform safe relies on two things: (a) a check that runs on your device before your message is sent, which blocks attempts to share phone numbers in ways that bypass the platform; and (b) if you tap "Report" on a message, your device unscrambles that message locally and you choose whether to send the readable version to Dalfal for review.

4.12 Fundi declared service area — fundi only

What: the region and sub-area you select as your service coverage when building your profile. This is a declaration you make; we do not silently track your GPS location.
Why: to match your profile to kunde tasks in your area.
Legal basis: consent — opt-in, revocable at any time in your profile settings.
Kept until: you revoke it or close your account.

4.13 Contact form submissions — website visitors

What: name, email address, subject, and message text you submit via the dalfal.com contact form.
Why: to respond to your enquiry.
Legal basis: legitimate interest (responding to inbound communications).
Stored: on our own secured servers, accessible to Dalfal support staff only.
Kept for: up to 12 months from submission, then deleted unless needed for an ongoing matter.

5. Data We Do Not Collect

  • Kunde selfie or ID document. We do not collect biometric data or national ID images from kundes at any point.
  • Your full ID number in readable form. We never store a fundi's ID number as entered. Only a scrambled, unreadable version and the last 4 digits are retained.
  • Real-time or historical GPS location. We do not track your device location silently. The fundi service area is a declaration you make, not a location log.
  • Biometric data beyond the identity verification selfie. No fingerprint, voice print, retina scan, or other biometric is collected.
  • Marketing or advertising identifiers. No advertising or marketing tracker is embedded in the app.
  • Children's data. See Section 11.

6. Third Parties We Share Data With

We share personal data with the following third parties only where necessary to operate the platform. We share only the minimum data required. We do not sell your personal data.

6.1 M-Pesa / Safaricom (Kenya)

An independent, regulated payment service provider and a separate data controller for the payment transactions it processes. We share your phone number and payment amount when you initiate a payment or receive a payout. We do not share your name, ID number, or identity verification images with the payment provider. Your phone number is not logged by Dalfal in connection with payment events.

6.2 WaafiPay / EVC Plus (Somalia)

Same role and data-sharing scope as M-Pesa above, for Somalia-based transactions.

6.3 Google (push notifications — Android)

Google acts on our instruction to deliver push notifications to your Android device. We share your device's notification token and the notification text (which contains no phone number, ID number, or financial amounts). Operated by Google LLC, USA (cross-border transfer — see Section 8).

6.4 Apple (push notifications — iOS)

Apple acts on our instruction to deliver push notifications to your iOS device. Same scope as Google above. Operated by Apple Inc., USA (cross-border transfer).

6.5 Secure file storage provider

A provider that stores identity verification images (ID front, ID back, selfie) for fundis and task attachment photos on our behalf, in a private store with no public link. Every file is accessible only through a short-lived, single-use link issued by our servers. No identity verification image is ever publicly accessible. The production storage region is to be confirmed before launch.

6.6 One-time code (OTP) delivery provider (to be confirmed)

A provider that sends your one-time login code, acting on our instruction. We share your email address (email path) or phone number (WhatsApp path) solely for this purpose. The provider has not yet been selected for production. When it is, this section will be updated and the provider will be bound by a data-processing agreement.

6.7 Face-match provider (to be confirmed)

A provider that will compare your selfie against your ID portrait to confirm they match, acting on our instruction. This service is currently a placeholder — no biometric data is sent to any external provider in the current build. When a provider is selected, this section will be updated and explicit consent will be collected in the identity verification flow.

6.8 Analytics provider

No analytics tool is currently embedded in the app. If one is added in future, this section will be updated before the integration ships. Any analytics data will comply with strict rules: phone numbers, ID numbers, payment receipts, identity verification image links, full names, and chat text will never appear in any analytics data.

7. How Long We Keep Your Data

Data category Who Kept for
Phone number All users Life of account + 12 months
Email address All users Life of account + 12 months
Full name All users Life of account + 12 months
ID document images (front + back) Fundi only Life of account + 2 years
Selfie photograph Fundi only Life of account + 2 years
ID number (scrambled) + last 4 digits Fundi only Life of account + 2 years
Date of birth Fundi only Life of account + 2 years
Payment transaction metadata All users 7 years from transaction date
Device push notification token All users Refreshed on login; deleted on account closure
Task content and photos All users Life of account + 12 months
In-app message (scrambled content) All users Deleted on delivery-ack or after 30 days
In-app message envelope (routing information) All users Life of account + 12 months
Fundi service area Fundi only Until revoked or account closure
Staff access records Internal 3 years from record date
Contact form submissions Website visitors Up to 12 months from submission

When an account is closed, we delete or anonymise your personal data within the applicable retention window, except where we are required to retain it by law (for example, financial records under applicable tax law) or where it is necessary to establish, exercise, or defend legal claims.

8. Cross-Border Transfers

Where we transfer personal data outside the country of operation, we take steps to ensure appropriate safeguards are in place. For sensitive personal data such as identity verification images, we obtain your explicit consent before any such transfer.

Recipient Data transferred Basis
Google (USA) — Android push notifications Device push token, notification text (no phone number or ID data) Necessity for performance of contract
Apple (USA) — iOS push notifications Device push token, notification text Necessity for performance of contract
Secure file storage provider (region to be confirmed) Identity verification images (fundi only), task photos Explicit consent + appropriate safeguards (region to be confirmed before production KYC launch)
One-time code delivery provider (to be confirmed) Email address or phone number Necessity for performance of contract (provider to be documented before launch)
Face-match provider (to be confirmed) Selfie + ID portrait (fundi only) Explicit consent + appropriate safeguards (provider to be documented before KYC goes live)

We do not sell your personal data to third parties and do not share it for advertising or marketing purposes.

9. How We Protect Your Data

9.1 Data isolation

Your personal data is held on our own secured servers. Our systems are built so that one user can never access another user's data — even if there is a bug in our application, a separate security layer in the database enforces this separation automatically.

9.2 Encryption in transit

All communications between the mobile app and our servers travel over an encrypted connection (HTTPS). We do not allow unencrypted connections to any part of our service.

9.3 End-to-end encrypted messages

Your messages are end-to-end encrypted, so only you and the person you are chatting with can read them — not even we can. The key that unscrambles your messages is stored only in a secure area on your own device and is never sent to our servers.

9.4 Login session security

Your login session is protected and expires automatically — after 24 hours for regular users, and 8 hours for staff accounts. Session tokens are never logged or exposed in any readable form in our systems.

9.5 Credentials

Staff login codes are stored in an unreadable, scrambled form — the original code is never kept. A fundi's ID number is scrambled immediately on entry and the original is discarded. We never keep readable versions of these values.

9.6 Identity verification image access controls

Identity verification images are stored in a private store with no public link. Access requires a short-lived, single-use link issued by our servers. Staff may only view identity verification images if that access has been explicitly granted by a senior administrator. Every time a staff member accesses a user's identity verification data, a permanent record of that access is created.

9.7 Location data removed from photos

GPS coordinates and other embedded metadata are removed from all photos (identity verification images and task photos) on our servers before the file is saved.

9.8 Sensitive information never logged

Our system logs never contain phone numbers, national ID numbers, one-time codes, payment transaction identifiers, or login session tokens.

9.9 Staff access records

A permanent, tamper-proof record is kept of every staff and admin action, including every access to a user's personal data. This log cannot be edited or deleted by any staff account.

10. Your Rights

Under applicable data protection law, you have rights regarding your personal data. To exercise any of these rights, email privacy@dalfal.com with the subject line "Data Subject Request — [type of right]". Include your registered phone number so we can identify your account. We will verify your identity before processing your request and will not charge a fee for reasonable requests.

10.1 Right to be informed

You have the right to be told how we use your personal data. This Privacy Policy fulfils that right.

10.2 Right of access

You have the right to ask what personal data we hold about you and to receive a copy of it.

10.3 Right to rectification

If personal data we hold is inaccurate or incomplete, you have the right to ask us to correct it. You can update your name, email, and service area directly in the app. For corrections to identity verification data, email privacy@dalfal.com.

10.4 Right to erasure

You have the right to ask us to delete your personal data where we no longer need it, where you have withdrawn consent (and there is no other lawful basis), or where processing is unlawful. We may be unable to delete data we are required to retain by law or that is necessary to establish, exercise, or defend legal claims.

To request deletion, email privacy@dalfal.com or use the account-closure option in the app.

10.5 Right to object

You have the right to object to processing based on legitimate interests. If you object, we will stop the processing unless we have compelling legitimate grounds that override your interests, or the processing is necessary to establish, exercise, or defend legal claims.

10.6 Right to withdraw consent

Where we process your data on the basis of consent (for example, fundi identity verification biometric data, fundi service area), you may withdraw that consent at any time by contacting privacy@dalfal.com. Withdrawal does not affect the lawfulness of processing done before withdrawal. Withdrawing identity verification consent means we must suspend your fundi account because identity verification is a condition of the fundi role.

10.7 Right to data portability

You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format where technically feasible.

10.8 Right to complain

If you are not satisfied with how we have handled your personal data, you have the right to lodge a complaint with the competent data protection supervisory authority in your jurisdiction (see Sections 15 and 16 below for jurisdiction-specific details).

11. Children

Dalfal is not directed at children. You must be at least 18 years old to create an account. We do not knowingly collect personal data from anyone under 18. If you believe a child has created an account, please contact us at privacy@dalfal.com and we will investigate and delete the account.

12. Data Breach Notification

In the event of a personal data breach that presents a real risk of harm to you, we are committed to:

  • Notifying the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, where required by applicable law.
  • Contacting you directly in writing without undue delay where the breach is likely to result in a real risk of harm to you personally.
  • Including in any notification the nature of the breach, the categories and approximate number of people and records affected, the likely consequences, and the measures taken or proposed.

13. Marketing

We do not currently send any marketing, promotional, or re-engagement messages. All outbound communications are transactional (one-time codes, bid notifications, payment status, job lifecycle events). If we ever introduce marketing communications, we will obtain separate, freely given, specific, and informed consent for each marketing channel before sending, and provide a simple free opt-out in every message.

14. Automated Decisions

Dalfal does not currently make decisions that significantly affect you based solely on automated processing without human review. Fundi identity verification decisions (approved / rejected) are made by admin staff who review your submitted documents manually. The automated face-match service is currently a placeholder and does not perform any real comparison in the current build.

15. Kenya — Data Protection Act 2019

For users in Kenya, Dalfal operates in accordance with the Kenya Data Protection Act 2019 (DPA 2019) and the regulations made under it, including the Data Protection (General) Regulations 2021 and the Data Protection (Registration of Data Controllers and Data Processors) Regulations 2021.

Under the DPA 2019, you have the rights set out in Section 10 above (access, rectification, erasure, restriction, portability, objection, and the right not to be subject to purely automated decisions). You also have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC):

Office of the Data Protection Commissioner
Website: www.odpc.go.ke
Email: info@odpc.go.ke

The lawful bases we rely on under the DPA 2019 are: performance of a contract (Section 30(1)(b)); legitimate interests (Section 30(1)(f)) where stated; and explicit consent (Section 30(1)(a)) for sensitive personal data including biometric identity verification data.

Dalfal has registered (or will register before processing personal data at scale) with the ODPC as a data controller, as required by the Data Protection (Registration of Data Controllers and Data Processors) Regulations 2021. Our registration reference will be published here once confirmed.

16. Somalia Note

For users in Somalia (including Somaliland and Puntland), formal data-protection legislation comparable to the Kenya DPA 2019 is not yet fully enacted across all parts of the country. We apply the same data protection principles and rights described in this policy to all our users regardless of jurisdiction, consistent with international best practice and the standards of the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention).

We are monitoring the development of applicable data protection law in Somalia and will update this section when enacted legislation or a competent supervisory authority has been confirmed. In the meantime, you can direct any privacy enquiry or complaint to privacy@dalfal.com.

17. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page, notify you via the app or by email if the changes are material, and link to the versioned policy from within the app. The app links to a specific versioned URL, not to an unversioned "latest" page.

Continued use of the app after the effective date of an updated policy constitutes your acceptance of the changes, to the extent permitted by law. For changes that require fresh consent (for example, a new category of sensitive data), we will ask for your consent before the change takes effect.

18. Contact Us

Dalfal — Privacy Team
Email: privacy@dalfal.com
Subject line: "Privacy Enquiry"

We aim to acknowledge your message within 2 business days and resolve your request within a reasonable period consistent with applicable law.

Also read our Terms of Service.

© 2026 Dalfal. Privacy Policy · Terms of Service

This document is a draft pending advocate review. It is not yet legally effective. See legal@dalfal.com with any questions.