Privacy Policy
Contents
- Who We Are
- Who This Policy Covers
- Two Roles, Two Verification Levels
- Data We Collect and Why
- Data We Do Not Collect
- Third Parties We Share Data With
- How Long We Keep Your Data
- Cross-Border Transfers
- How We Protect Your Data
- Your Rights
- Children
- Data Breach Notification
- Marketing
- Automated Decisions
- Kenya — Data Protection Act 2019
- Somalia Note
- Changes to This Policy
- Contact Us
1. Who We Are
Dalfal ("we", "us", "our") operates the Dalfal marketplace — a two-sided platform that connects customers ("kunde") who post tasks with skilled workers ("fundi") who bid on and complete those tasks. Payments are processed through M-Pesa (Kenya) and WaafiPay / EVC Plus (Somalia).
Data controller: Dalfal
Registered address: [to be confirmed before publication]
Email: privacy@dalfal.com
2. Who This Policy Covers
This Privacy Policy applies to personal data we collect through:
- The Dalfal mobile app (Android and iOS).
- The services that run the platform behind the scenes.
- This website (dalfal.com) and any contact forms on it.
- Any messages we send you in connection with your account, such as one-time login codes and payment notifications.
It does not apply to the practices of fundis or third parties whose services you may access through our platform.
3. Two Roles, Two Verification Levels
Dalfal uses an asymmetric verification model matched to the risk each role carries.
Kunde (customer): you post tasks and pay via mobile money. We verify your phone number at sign-up only. We do not collect your selfie, your national ID document, or any biometric data at any point. Your financial accountability is established through the payment service, which is tied to your registered phone number.
Fundi (service provider): you enter customers' homes and receive real money transfers. Before you can take a booking we require full identity verification (KYC): a photo of your government-issued ID (front and back) and a selfie matched against the portrait on your ID. A higher level of identity certainty is proportionate to the responsibility you carry, and it is a condition of receiving payouts.
A kunde who later chooses to earn on the platform can upgrade to fundi status, at which point all sections below that say "Fundi only" apply to them.
4. Data We Collect and Why
4.1 Phone number — all users
What: your mobile number as entered at sign-up and
confirmed by a one-time code.
Why: to create and authenticate your account and to
initiate payments.
Legal basis: performance of a contract.
Stored: on our own secured servers — not with any
third-party database provider.
Kept for: life of account plus 12 months after
closure.
Note: your phone number is never written to
application logs or analytics systems.
4.2 Email address — all users (optional)
What: your email address if you choose the email
sign-up or sign-in path.
Why: to send you a one-time code for registration or
login.
Legal basis: performance of a contract.
Stored: on our own secured servers.
Kept for: life of account plus 12 months after
closure.
4.3 Full name — all users
What: the name you enter during profile setup.
Why: displayed on your fundi profile or shared with
a matched fundi in the context of a job.
Legal basis: performance of a contract.
Stored: on our own secured servers. Never written to
logs or analytics.
Kept for: life of account plus 12 months after
closure.
4.4 Government-issued ID document images — fundi only
What: photographs of the front and back of your
government-issued identity document.
Why: to verify your identity before you can take
bookings and receive payouts.
Legal basis: explicit consent given at the identity
verification step during onboarding. You may withdraw consent at any
time; doing so means we must suspend your fundi account because
identity verification is a condition of the fundi role.
Stored: in a private, secure file store with no
public link. Access is time-limited and restricted to authorised
Dalfal staff only.
Location data: GPS coordinates and all photo metadata
are removed from your image before it is saved — we never keep location
data embedded in your photos.
Kept for: life of account plus 2 years after closure.
4.5 Selfie photograph — fundi only
What: a selfie captured in-app during the identity
verification flow.
Why: to check that your face matches the portrait on
your ID document, confirming you are the person named on the ID.
Legal basis: explicit consent given at the identity
verification step.
Stored: in the same private, secure file store as
your ID images, with the same access restrictions and metadata
removal.
Kept for: life of account plus 2 years after closure.
4.6 ID number — scrambled, plus last 4 digits — fundi only
What: your national ID number is scrambled into an
unreadable form the moment you enter it and the original is discarded
— we never keep it. Only the scrambled version and the last 4 digits
of your number are stored. Your full ID number in readable form is
never stored anywhere by Dalfal.
Why: to prevent the same identity document being
registered to more than one fundi account.
Legal basis: performance of a contract and legitimate
interest (preventing identity fraud).
Stored: on our own secured servers only. Never sent
to third parties.
Kept for: life of account plus 2 years after closure.
4.7 Date of birth — fundi only (typed-ID path)
What: your date of birth as entered during identity
verification.
Why: validated during identity verification
submission.
Legal basis: explicit consent.
Stored: on our own secured servers. Never written to
logs.
Kept for: life of account plus 2 years after closure.
4.8 Payment transaction metadata — all users
What: payment requests, transaction references, wallet
records, and payout references. We do not store your full transaction
history with the payment provider. Your phone number is passed to the
payment provider to initiate payment but is not written to our own
system logs.
Why: to operate the payment system, maintain a wallet
record, enable dispute resolution, and satisfy financial record-keeping
obligations.
Legal basis: performance of a contract. Financial
records are also retained to meet applicable accounting and tax law.
Stored: on our own secured servers. The authoritative
payment record is held by M-Pesa / WaafiPay as the regulated payment
service provider.
Kept for: 7 years from the transaction date.
4.9 Push notification tokens (FCM / APNs) — all users
What: a device token that allows us to send push
notifications to your Android or iOS device.
Why: to send you transactional push notifications
about your account — bid accepted, payout completed, task updated. We
do not send marketing messages via push.
Legal basis: performance of a contract.
Stored: on our own secured servers; passed to Google
(Android) or Apple (iOS) at the time a notification is sent.
Kept for: refreshed on each login; deleted when your
account is closed.
4.10 Task content (title, description, budget, photos) — all users
What: the details you enter when posting a task and
any photos you attach.
Why: to publish your task to fundis who can bid on
it. Task content is the core product data.
Legal basis: performance of a contract.
Stored: text on our own secured servers; photos in a
private, access-controlled file store. GPS and photo metadata are
removed before storage.
Kept for: life of account plus 12 months after
closure.
4.11 In-app messages — all users
Your messages are end-to-end encrypted, which means only you and the person you are chatting with can read them — not even we can. Your messages are scrambled on your own device before they leave your phone. The key that unscrambles them is stored only in a secure area on your device and is never sent to Dalfal.
What we store: only the scrambled, unreadable version
of your messages, plus the envelope around each one — who sent it, who
it is for, which job thread it belongs to, and when it was sent,
delivered, and read. We never store or read the actual words of your
messages.
Why: to route your message to the right thread and
operate the platform.
Legal basis: performance of a contract.
Scrambled message kept for: deleted once delivered
and confirmed received, or after 30 days, whichever is earlier.
Envelope information kept for: life of account plus 12
months after closure.
Because we cannot read your messages, our approach to keeping the platform safe relies on two things: (a) a check that runs on your device before your message is sent, which blocks attempts to share phone numbers in ways that bypass the platform; and (b) if you tap "Report" on a message, your device unscrambles that message locally and you choose whether to send the readable version to Dalfal for review.
4.12 Fundi declared service area — fundi only
What: the region and sub-area you select as your
service coverage when building your profile. This is a declaration you
make; we do not silently track your GPS location.
Why: to match your profile to kunde tasks in your
area.
Legal basis: consent — opt-in, revocable at any time
in your profile settings.
Kept until: you revoke it or close your account.
4.13 Contact form submissions — website visitors
What: name, email address, subject, and message text
you submit via the dalfal.com contact form.
Why: to respond to your enquiry.
Legal basis: legitimate interest (responding to
inbound communications).
Stored: on our own secured servers, accessible to
Dalfal support staff only.
Kept for: up to 12 months from submission, then
deleted unless needed for an ongoing matter.
5. Data We Do Not Collect
- Kunde selfie or ID document. We do not collect biometric data or national ID images from kundes at any point.
- Your full ID number in readable form. We never store a fundi's ID number as entered. Only a scrambled, unreadable version and the last 4 digits are retained.
- Real-time or historical GPS location. We do not track your device location silently. The fundi service area is a declaration you make, not a location log.
- Biometric data beyond the identity verification selfie. No fingerprint, voice print, retina scan, or other biometric is collected.
- Marketing or advertising identifiers. No advertising or marketing tracker is embedded in the app.
- Children's data. See Section 11.
6. Third Parties We Share Data With
We share personal data with the following third parties only where necessary to operate the platform. We share only the minimum data required. We do not sell your personal data.
6.1 M-Pesa / Safaricom (Kenya)
An independent, regulated payment service provider and a separate data controller for the payment transactions it processes. We share your phone number and payment amount when you initiate a payment or receive a payout. We do not share your name, ID number, or identity verification images with the payment provider. Your phone number is not logged by Dalfal in connection with payment events.
6.2 WaafiPay / EVC Plus (Somalia)
Same role and data-sharing scope as M-Pesa above, for Somalia-based transactions.
6.3 Google (push notifications — Android)
Google acts on our instruction to deliver push notifications to your Android device. We share your device's notification token and the notification text (which contains no phone number, ID number, or financial amounts). Operated by Google LLC, USA (cross-border transfer — see Section 8).
6.4 Apple (push notifications — iOS)
Apple acts on our instruction to deliver push notifications to your iOS device. Same scope as Google above. Operated by Apple Inc., USA (cross-border transfer).
6.5 Secure file storage provider
A provider that stores identity verification images (ID front, ID back, selfie) for fundis and task attachment photos on our behalf, in a private store with no public link. Every file is accessible only through a short-lived, single-use link issued by our servers. No identity verification image is ever publicly accessible. The production storage region is to be confirmed before launch.
6.6 One-time code (OTP) delivery provider (to be confirmed)
A provider that sends your one-time login code, acting on our instruction. We share your email address (email path) or phone number (WhatsApp path) solely for this purpose. The provider has not yet been selected for production. When it is, this section will be updated and the provider will be bound by a data-processing agreement.
6.7 Face-match provider (to be confirmed)
A provider that will compare your selfie against your ID portrait to confirm they match, acting on our instruction. This service is currently a placeholder — no biometric data is sent to any external provider in the current build. When a provider is selected, this section will be updated and explicit consent will be collected in the identity verification flow.
6.8 Analytics provider
No analytics tool is currently embedded in the app. If one is added in future, this section will be updated before the integration ships. Any analytics data will comply with strict rules: phone numbers, ID numbers, payment receipts, identity verification image links, full names, and chat text will never appear in any analytics data.
7. How Long We Keep Your Data
| Data category | Who | Kept for |
|---|---|---|
| Phone number | All users | Life of account + 12 months |
| Email address | All users | Life of account + 12 months |
| Full name | All users | Life of account + 12 months |
| ID document images (front + back) | Fundi only | Life of account + 2 years |
| Selfie photograph | Fundi only | Life of account + 2 years |
| ID number (scrambled) + last 4 digits | Fundi only | Life of account + 2 years |
| Date of birth | Fundi only | Life of account + 2 years |
| Payment transaction metadata | All users | 7 years from transaction date |
| Device push notification token | All users | Refreshed on login; deleted on account closure |
| Task content and photos | All users | Life of account + 12 months |
| In-app message (scrambled content) | All users | Deleted on delivery-ack or after 30 days |
| In-app message envelope (routing information) | All users | Life of account + 12 months |
| Fundi service area | Fundi only | Until revoked or account closure |
| Staff access records | Internal | 3 years from record date |
| Contact form submissions | Website visitors | Up to 12 months from submission |
When an account is closed, we delete or anonymise your personal data within the applicable retention window, except where we are required to retain it by law (for example, financial records under applicable tax law) or where it is necessary to establish, exercise, or defend legal claims.
8. Cross-Border Transfers
Where we transfer personal data outside the country of operation, we take steps to ensure appropriate safeguards are in place. For sensitive personal data such as identity verification images, we obtain your explicit consent before any such transfer.
| Recipient | Data transferred | Basis |
|---|---|---|
| Google (USA) — Android push notifications | Device push token, notification text (no phone number or ID data) | Necessity for performance of contract |
| Apple (USA) — iOS push notifications | Device push token, notification text | Necessity for performance of contract |
| Secure file storage provider (region to be confirmed) | Identity verification images (fundi only), task photos | Explicit consent + appropriate safeguards (region to be confirmed before production KYC launch) |
| One-time code delivery provider (to be confirmed) | Email address or phone number | Necessity for performance of contract (provider to be documented before launch) |
| Face-match provider (to be confirmed) | Selfie + ID portrait (fundi only) | Explicit consent + appropriate safeguards (provider to be documented before KYC goes live) |
We do not sell your personal data to third parties and do not share it for advertising or marketing purposes.
9. How We Protect Your Data
9.1 Data isolation
Your personal data is held on our own secured servers. Our systems are built so that one user can never access another user's data — even if there is a bug in our application, a separate security layer in the database enforces this separation automatically.
9.2 Encryption in transit
All communications between the mobile app and our servers travel over an encrypted connection (HTTPS). We do not allow unencrypted connections to any part of our service.
9.3 End-to-end encrypted messages
Your messages are end-to-end encrypted, so only you and the person you are chatting with can read them — not even we can. The key that unscrambles your messages is stored only in a secure area on your own device and is never sent to our servers.
9.4 Login session security
Your login session is protected and expires automatically — after 24 hours for regular users, and 8 hours for staff accounts. Session tokens are never logged or exposed in any readable form in our systems.
9.5 Credentials
Staff login codes are stored in an unreadable, scrambled form — the original code is never kept. A fundi's ID number is scrambled immediately on entry and the original is discarded. We never keep readable versions of these values.
9.6 Identity verification image access controls
Identity verification images are stored in a private store with no public link. Access requires a short-lived, single-use link issued by our servers. Staff may only view identity verification images if that access has been explicitly granted by a senior administrator. Every time a staff member accesses a user's identity verification data, a permanent record of that access is created.
9.7 Location data removed from photos
GPS coordinates and other embedded metadata are removed from all photos (identity verification images and task photos) on our servers before the file is saved.
9.8 Sensitive information never logged
Our system logs never contain phone numbers, national ID numbers, one-time codes, payment transaction identifiers, or login session tokens.
9.9 Staff access records
A permanent, tamper-proof record is kept of every staff and admin action, including every access to a user's personal data. This log cannot be edited or deleted by any staff account.
10. Your Rights
Under applicable data protection law, you have rights regarding your personal data. To exercise any of these rights, email privacy@dalfal.com with the subject line "Data Subject Request — [type of right]". Include your registered phone number so we can identify your account. We will verify your identity before processing your request and will not charge a fee for reasonable requests.
10.1 Right to be informed
You have the right to be told how we use your personal data. This Privacy Policy fulfils that right.
10.2 Right of access
You have the right to ask what personal data we hold about you and to receive a copy of it.
10.3 Right to rectification
If personal data we hold is inaccurate or incomplete, you have the right to ask us to correct it. You can update your name, email, and service area directly in the app. For corrections to identity verification data, email privacy@dalfal.com.
10.4 Right to erasure
You have the right to ask us to delete your personal data where we no longer need it, where you have withdrawn consent (and there is no other lawful basis), or where processing is unlawful. We may be unable to delete data we are required to retain by law or that is necessary to establish, exercise, or defend legal claims.
To request deletion, email privacy@dalfal.com or use the account-closure option in the app.
10.5 Right to object
You have the right to object to processing based on legitimate interests. If you object, we will stop the processing unless we have compelling legitimate grounds that override your interests, or the processing is necessary to establish, exercise, or defend legal claims.
10.6 Right to withdraw consent
Where we process your data on the basis of consent (for example, fundi identity verification biometric data, fundi service area), you may withdraw that consent at any time by contacting privacy@dalfal.com. Withdrawal does not affect the lawfulness of processing done before withdrawal. Withdrawing identity verification consent means we must suspend your fundi account because identity verification is a condition of the fundi role.
10.7 Right to data portability
You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format where technically feasible.
10.8 Right to complain
If you are not satisfied with how we have handled your personal data, you have the right to lodge a complaint with the competent data protection supervisory authority in your jurisdiction (see Sections 15 and 16 below for jurisdiction-specific details).
11. Children
Dalfal is not directed at children. You must be at least 18 years old to create an account. We do not knowingly collect personal data from anyone under 18. If you believe a child has created an account, please contact us at privacy@dalfal.com and we will investigate and delete the account.
12. Data Breach Notification
In the event of a personal data breach that presents a real risk of harm to you, we are committed to:
- Notifying the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, where required by applicable law.
- Contacting you directly in writing without undue delay where the breach is likely to result in a real risk of harm to you personally.
- Including in any notification the nature of the breach, the categories and approximate number of people and records affected, the likely consequences, and the measures taken or proposed.
13. Marketing
We do not currently send any marketing, promotional, or re-engagement messages. All outbound communications are transactional (one-time codes, bid notifications, payment status, job lifecycle events). If we ever introduce marketing communications, we will obtain separate, freely given, specific, and informed consent for each marketing channel before sending, and provide a simple free opt-out in every message.
14. Automated Decisions
Dalfal does not currently make decisions that significantly affect you based solely on automated processing without human review. Fundi identity verification decisions (approved / rejected) are made by admin staff who review your submitted documents manually. The automated face-match service is currently a placeholder and does not perform any real comparison in the current build.
15. Kenya — Data Protection Act 2019
For users in Kenya, Dalfal operates in accordance with the Kenya Data Protection Act 2019 (DPA 2019) and the regulations made under it, including the Data Protection (General) Regulations 2021 and the Data Protection (Registration of Data Controllers and Data Processors) Regulations 2021.
Under the DPA 2019, you have the rights set out in Section 10 above (access, rectification, erasure, restriction, portability, objection, and the right not to be subject to purely automated decisions). You also have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC):
Office of the Data Protection CommissionerWebsite: www.odpc.go.ke
Email: info@odpc.go.ke
The lawful bases we rely on under the DPA 2019 are: performance of a contract (Section 30(1)(b)); legitimate interests (Section 30(1)(f)) where stated; and explicit consent (Section 30(1)(a)) for sensitive personal data including biometric identity verification data.
Dalfal has registered (or will register before processing personal data at scale) with the ODPC as a data controller, as required by the Data Protection (Registration of Data Controllers and Data Processors) Regulations 2021. Our registration reference will be published here once confirmed.
16. Somalia Note
For users in Somalia (including Somaliland and Puntland), formal data-protection legislation comparable to the Kenya DPA 2019 is not yet fully enacted across all parts of the country. We apply the same data protection principles and rights described in this policy to all our users regardless of jurisdiction, consistent with international best practice and the standards of the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention).
We are monitoring the development of applicable data protection law in Somalia and will update this section when enacted legislation or a competent supervisory authority has been confirmed. In the meantime, you can direct any privacy enquiry or complaint to privacy@dalfal.com.
17. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page, notify you via the app or by email if the changes are material, and link to the versioned policy from within the app. The app links to a specific versioned URL, not to an unversioned "latest" page.
Continued use of the app after the effective date of an updated policy constitutes your acceptance of the changes, to the extent permitted by law. For changes that require fresh consent (for example, a new category of sensitive data), we will ask for your consent before the change takes effect.
18. Contact Us
Dalfal — Privacy TeamEmail: privacy@dalfal.com
Subject line: "Privacy Enquiry"
We aim to acknowledge your message within 2 business days and resolve your request within a reasonable period consistent with applicable law.
Also read our Terms of Service.