BookAfri Legal

Privacy Policy & GDPR Notice

Last updated: 1 August 2026  ·  Controller: BookAfri, Krakow, Poland

This Privacy Policy explains how BookAfri ("we," "us," "our") collects, uses, and protects your personal data when you use the BookAfri platform at bookafri.app ("Platform"). It also sets out your rights under the General Data Protection Regulation (GDPR) and Polish data protection law.

Please read this Policy carefully. If you have any questions, contact us at support@bookafri.app before using the Platform.


1. Who We Are

BookAfri is the data controller responsible for your personal data collected through the Platform. We are based in Krakow, Poland and operate within the European Union.

You can contact us about data protection matters at:
Email: support@bookafri.app
Address: Krakow, Poland


2. Data We Collect

Data you provide directly

  • Account registration: name, email address, password (hashed), phone number, preferred language
  • Profile information: profile photo, address, business name (vendors)
  • Orders and bookings: delivery address, order details, booking dates and times
  • Payments: billing name, billing address. Payment card details are collected and processed directly by Stripe — we never see or store full card numbers.
  • Messages: content of messages sent via AfriChat between you and vendors
  • Vendor-specific: bank account details (provided to Stripe for Stripe Connect), tax identification number (NIP), business documentation
  • Reviews and contributions: reviews, ratings, and other content you submit
  • Support communications: emails and messages you send to our support team

Data collected automatically

  • Usage data: pages visited, features used, time spent on the Platform, clickstream data
  • Device and connection data: IP address, browser type and version, operating system, device identifiers
  • Push notification subscription data: browser push subscription endpoint (if you grant notification permission)

Data from third parties

  • Stripe: payment status, transaction identifiers, and Connect account verification status
  • Social login providers: basic profile data (name, email) if you choose to sign in via a third-party provider

3. How We Use Your Data

We use your personal data for the following purposes:

  • Account management: create and manage your account; authenticate your identity
  • Order and booking fulfilment: process payments, manage escrow, coordinate delivery, send order and booking confirmations
  • Vendor payouts: initiate Stripe Connect transfers to vendor bank accounts on escrow release
  • Platform communications: send transactional emails (order confirmations, booking notifications, payment releases, shipping updates); deliver in-app and push notifications
  • Customer support: respond to queries, disputes, and feedback
  • Platform safety and integrity: detect and prevent fraud, abuse, and violations of our Terms
  • Service improvement: analyse platform usage to improve features and user experience
  • Legal compliance: fulfil our legal obligations, including financial record-keeping, tax reporting, and responding to lawful requests from authorities
  • Translation: we use MyMemory for AI-assisted translation of Platform content where you have language preferences set

We do not use your personal data for unsolicited marketing without your explicit consent, and we do not sell your personal data to third parties.


4. Legal Bases for Processing (GDPR Article 6)

We only process your personal data when we have a valid legal basis under Regulation (EU) 2016/679 (GDPR) and applicable Polish data protection law. The legal bases we rely on are:

  • Performance of a contract (Art. 6(1)(b)): Processing necessary to fulfil your orders, bookings, and payments; operate your account; and deliver our services to you.
  • Legitimate interests (Art. 6(1)(f)): Improving the Platform; fraud detection; platform security; communicating about your active transactions. We have assessed that these interests are not overridden by your rights and freedoms under Polish and EU law.
  • Legal obligation (Art. 6(1)(c)): Maintaining financial records; responding to lawful requests from Polish courts, UODO, or other regulators; complying with anti-money laundering obligations under Polish law.
  • Consent (Art. 6(1)(a)): Sending push notifications; non-essential cookies; marketing communications (where applicable). You may withdraw consent at any time without affecting prior processing.

5. Who We Share Your Data With

We share your data only with third parties necessary to deliver our services. All third-party processors are bound by data processing agreements and handle your data in accordance with GDPR.

ProcessorPurposeLocation
Stripe Payment processing, fraud prevention, Stripe Connect vendor payouts. Stripe acts as a co-controller for payment data and has its own Privacy Policy. USA (Standard Contractual Clauses)
SendGrid (Twilio) Transactional email delivery (order confirmations, booking notifications, payment release emails) USA (Standard Contractual Clauses)
Cloudinary Image storage and optimisation for product and profile photos USA (Standard Contractual Clauses)
Hetzner Online Cloud server infrastructure and database hosting Germany (EU)
Coolify Application deployment and management platform EU
MyMemory AI translation services for multilingual content Italy (EU)

We may also disclose your data to: law enforcement or regulatory authorities where required by law; professional advisers (lawyers, accountants) bound by confidentiality; and, in the event of a merger or acquisition, the acquiring entity (you will be notified in advance).

Vendors on our Platform see only the personal data necessary to fulfil your order or booking (name, delivery address, contact for coordination). They are independent data controllers for their own processing of this data.


6. AI-Powered Features

The Platform uses AI-assisted translation through MyMemory (operated by Translated S.r.l., Italy) to support multilingual content. This service may process text content you submit — such as product descriptions or messages — to provide translations.

MyMemory is located within the EU and processes data in accordance with GDPR. No personal identifying information is submitted to MyMemory beyond what is strictly necessary for translation.

How to opt out: Log in to your account, go to Settings, and update your language preference to your native language — this disables automatic translation. You may also contact us at support@bookafri.app to request that translation features be disabled for your account.


7. International Data Transfers

Some of our processors, including Stripe and SendGrid, are located outside the European Economic Area (EEA), primarily in the United States. Where we transfer data to countries not deemed adequate by the European Commission, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, which provide appropriate safeguards for your data.

You may request a copy of the relevant transfer mechanisms by contacting us at support@bookafri.app.


8. How Long We Keep Your Data

We retain your personal data for as long as your account is active and for a period thereafter as necessary to comply with our legal obligations. Specific retention periods:

  • Account data: retained for the duration of your account and deleted within 90 days of account closure, unless longer retention is legally required
  • Transaction and financial records: retained for 5 years from the transaction date to comply with Polish accounting and tax law
  • Order and booking records: retained for 3 years after the transaction to handle potential disputes or warranty claims
  • Communications (support emails, AfriChat): retained for 2 years
  • Usage and log data: retained for 12 months
  • Push notification subscriptions: retained until you withdraw consent or the subscription becomes inactive

After the applicable retention period, data is securely deleted or anonymised.


9. Security

We implement appropriate technical and organisational security measures to protect your personal data, including: encrypted data transmission (TLS/HTTPS); hashed password storage; access controls limiting data access to authorised personnel only; and regular security reviews.

Payment card data is handled exclusively by Stripe, which is PCI DSS compliant. We never store full card numbers.

Despite these measures, no Internet transmission or electronic storage system is 100% secure. If you believe your account has been compromised, contact us immediately at support@bookafri.app.

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and, where required, notify you directly without undue delay.


10. Cookies and Tracking

We use cookies and similar technologies to operate and improve the Platform. The types of cookies we use:

  • Strictly necessary cookies: Required for the Platform to function (session management, authentication, security). These cannot be disabled.
  • Functional cookies: Remember your preferences (language, display settings).
  • Analytics cookies: Help us understand how the Platform is used (page visits, feature usage) in aggregated, anonymised form.

We do not use third-party advertising or tracking cookies for ad targeting.

Stripe: Stripe may set cookies for fraud prevention and payment session management. See Stripe's Cookie Policy for details.

You can manage cookie preferences through your browser settings. Disabling strictly necessary cookies will affect Platform functionality.


11. Children

The Platform is not directed at children under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, please contact us at support@bookafri.app and we will delete it promptly.


12. Your Rights Under GDPR

As a data subject in the European Economic Area (EEA), including Poland, you have the following rights regarding your personal data under Regulation (EU) 2016/679 (GDPR):

Right of Access (Art. 15) Request a copy of the personal data we hold about you.
Right to Rectification (Art. 16) Request correction of inaccurate or incomplete data.
Right to Erasure (Art. 17) Request deletion of your data where we no longer have a legal basis to retain it.
Right to Restriction (Art. 18) Request that we limit processing of your data in certain circumstances.
Right to Portability (Art. 20) Receive your data in a structured, machine-readable format where technically feasible.
Right to Object (Art. 21) Object to processing based on legitimate interests, including profiling.
Right to Withdraw Consent Withdraw consent at any time where processing is consent-based, without affecting prior processing.
Right not to be Profiled Not to be subject to decisions based solely on automated processing that significantly affect you.

To exercise any of these rights, contact us at support@bookafri.app. We will respond within 30 days. We may need to verify your identity before processing your request. Exercising these rights is free of charge.

Please note that certain rights are subject to exceptions — for example, we cannot delete transaction records that we are legally required to retain for tax or accounting purposes.

You also have the right to manage your notification preferences and account data directly in your account settings.


13. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. The updated version will be posted at bookafri.app/privacy with an updated "Last updated" date. Where changes are material, we will notify you by email or platform notification before they take effect. We encourage you to review this Policy periodically.


14. Contact and Supervisory Authority Complaints

For any questions, requests, or concerns about this Privacy Policy or our data practices, please contact us:

BookAfri
Krakow, Poland
Email: support@bookafri.app

If you are not satisfied with our response, or if you believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the Polish supervisory authority:

Urząd Ochrony Danych Osobowych (UODO)
President of the Personal Data Protection Office
ul. Stawki 2, 00-193 Warsaw, Poland
Website: uodo.gov.pl
Email: kancelaria@uodo.gov.pl

If you reside in another EEA member state, you also have the right to lodge a complaint with the data protection authority in your country of residence.

Terms & Conditions