Privacy Policy & GDPR Notice
Contents
This Privacy Policy explains how BookAfri ("we," "us," "our") collects, uses, and protects your personal data when you use the BookAfri platform at bookafri.app ("Platform"). It also sets out your rights under the General Data Protection Regulation (GDPR) and Polish data protection law.
Please read this Policy carefully. If you have any questions, contact us at support@bookafri.app before using the Platform.
1. Who We Are
BookAfri is the data controller responsible for your personal data collected through the Platform. We are based in Krakow, Poland and operate within the European Union.
You can contact us about data protection matters at:
Email: support@bookafri.app
Address: Krakow, Poland
2. Data We Collect
Data you provide directly
- Account registration: name, email address, password (hashed), phone number, preferred language
- Profile information: profile photo, address, business name (vendors)
- Orders and bookings: delivery address, order details, booking dates and times
- Payments: billing name, billing address. Payment card details are collected and processed directly by Stripe — we never see or store full card numbers.
- Messages: content of messages sent via AfriChat between you and vendors
- Vendor-specific: bank account details (provided to Stripe for Stripe Connect), tax identification number (NIP), business documentation
- Reviews and contributions: reviews, ratings, and other content you submit
- Support communications: emails and messages you send to our support team
Data collected automatically
- Usage data: pages visited, features used, time spent on the Platform, clickstream data
- Device and connection data: IP address, browser type and version, operating system, device identifiers
- Push notification subscription data: browser push subscription endpoint (if you grant notification permission)
Data from third parties
- Stripe: payment status, transaction identifiers, and Connect account verification status
- Social login providers: basic profile data (name, email) if you choose to sign in via a third-party provider
3. How We Use Your Data
We use your personal data for the following purposes:
- Account management: create and manage your account; authenticate your identity
- Order and booking fulfilment: process payments, manage escrow, coordinate delivery, send order and booking confirmations
- Vendor payouts: initiate Stripe Connect transfers to vendor bank accounts on escrow release
- Platform communications: send transactional emails (order confirmations, booking notifications, payment releases, shipping updates); deliver in-app and push notifications
- Customer support: respond to queries, disputes, and feedback
- Platform safety and integrity: detect and prevent fraud, abuse, and violations of our Terms
- Service improvement: analyse platform usage to improve features and user experience
- Legal compliance: fulfil our legal obligations, including financial record-keeping, tax reporting, and responding to lawful requests from authorities
- Translation: we use MyMemory for AI-assisted translation of Platform content where you have language preferences set
We do not use your personal data for unsolicited marketing without your explicit consent, and we do not sell your personal data to third parties.
4. Legal Bases for Processing (GDPR Article 6)
We only process your personal data when we have a valid legal basis under Regulation (EU) 2016/679 (GDPR) and applicable Polish data protection law. The legal bases we rely on are:
- Performance of a contract (Art. 6(1)(b)): Processing necessary to fulfil your orders, bookings, and payments; operate your account; and deliver our services to you.
- Legitimate interests (Art. 6(1)(f)): Improving the Platform; fraud detection; platform security; communicating about your active transactions. We have assessed that these interests are not overridden by your rights and freedoms under Polish and EU law.
- Legal obligation (Art. 6(1)(c)): Maintaining financial records; responding to lawful requests from Polish courts, UODO, or other regulators; complying with anti-money laundering obligations under Polish law.
- Consent (Art. 6(1)(a)): Sending push notifications; non-essential cookies; marketing communications (where applicable). You may withdraw consent at any time without affecting prior processing.
5. Who We Share Your Data With
We share your data only with third parties necessary to deliver our services. All third-party processors are bound by data processing agreements and handle your data in accordance with GDPR.
| Processor | Purpose | Location |
|---|---|---|
| Stripe | Payment processing, fraud prevention, Stripe Connect vendor payouts. Stripe acts as a co-controller for payment data and has its own Privacy Policy. | USA (Standard Contractual Clauses) |
| SendGrid (Twilio) | Transactional email delivery (order confirmations, booking notifications, payment release emails) | USA (Standard Contractual Clauses) |
| Cloudinary | Image storage and optimisation for product and profile photos | USA (Standard Contractual Clauses) |
| Hetzner Online | Cloud server infrastructure and database hosting | Germany (EU) |
| Coolify | Application deployment and management platform | EU |
| MyMemory | AI translation services for multilingual content | Italy (EU) |
We may also disclose your data to: law enforcement or regulatory authorities where required by law; professional advisers (lawyers, accountants) bound by confidentiality; and, in the event of a merger or acquisition, the acquiring entity (you will be notified in advance).
Vendors on our Platform see only the personal data necessary to fulfil your order or booking (name, delivery address, contact for coordination). They are independent data controllers for their own processing of this data.
6. AI-Powered Features
The Platform uses AI-assisted translation through MyMemory (operated by Translated S.r.l., Italy) to support multilingual content. This service may process text content you submit — such as product descriptions or messages — to provide translations.
MyMemory is located within the EU and processes data in accordance with GDPR. No personal identifying information is submitted to MyMemory beyond what is strictly necessary for translation.
How to opt out: Log in to your account, go to Settings, and update your language preference to your native language — this disables automatic translation. You may also contact us at support@bookafri.app to request that translation features be disabled for your account.
7. International Data Transfers
Some of our processors, including Stripe and SendGrid, are located outside the European Economic Area (EEA), primarily in the United States. Where we transfer data to countries not deemed adequate by the European Commission, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, which provide appropriate safeguards for your data.
You may request a copy of the relevant transfer mechanisms by contacting us at support@bookafri.app.
8. How Long We Keep Your Data
We retain your personal data for as long as your account is active and for a period thereafter as necessary to comply with our legal obligations. Specific retention periods:
- Account data: retained for the duration of your account and deleted within 90 days of account closure, unless longer retention is legally required
- Transaction and financial records: retained for 5 years from the transaction date to comply with Polish accounting and tax law
- Order and booking records: retained for 3 years after the transaction to handle potential disputes or warranty claims
- Communications (support emails, AfriChat): retained for 2 years
- Usage and log data: retained for 12 months
- Push notification subscriptions: retained until you withdraw consent or the subscription becomes inactive
After the applicable retention period, data is securely deleted or anonymised.
9. Security
We implement appropriate technical and organisational security measures to protect your personal data, including: encrypted data transmission (TLS/HTTPS); hashed password storage; access controls limiting data access to authorised personnel only; and regular security reviews.
Payment card data is handled exclusively by Stripe, which is PCI DSS compliant. We never store full card numbers.
Despite these measures, no Internet transmission or electronic storage system is 100% secure. If you believe your account has been compromised, contact us immediately at support@bookafri.app.
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and, where required, notify you directly without undue delay.
11. Children
The Platform is not directed at children under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, please contact us at support@bookafri.app and we will delete it promptly.
12. Your Rights Under GDPR
As a data subject in the European Economic Area (EEA), including Poland, you have the following rights regarding your personal data under Regulation (EU) 2016/679 (GDPR):
To exercise any of these rights, contact us at support@bookafri.app. We will respond within 30 days. We may need to verify your identity before processing your request. Exercising these rights is free of charge.
Please note that certain rights are subject to exceptions — for example, we cannot delete transaction records that we are legally required to retain for tax or accounting purposes.
You also have the right to manage your notification preferences and account data directly in your account settings.
13. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. The updated version will be posted at bookafri.app/privacy with an updated "Last updated" date. Where changes are material, we will notify you by email or platform notification before they take effect. We encourage you to review this Policy periodically.
14. Contact and Supervisory Authority Complaints
For any questions, requests, or concerns about this Privacy Policy or our data practices, please contact us:
BookAfri
Krakow, Poland
Email: support@bookafri.app
If you are not satisfied with our response, or if you believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the Polish supervisory authority:
Urząd Ochrony Danych Osobowych (UODO)
President of the Personal Data Protection Office
ul. Stawki 2, 00-193 Warsaw, Poland
Website: uodo.gov.pl
Email: kancelaria@uodo.gov.pl
If you reside in another EEA member state, you also have the right to lodge a complaint with the data protection authority in your country of residence.