Legal

Privacy Policy

Last updated: 26 September 2026

Information We Collect

We collect information you provide during registration (name, email, mobile, ID, address), transaction data, device and usage data, and any documents you upload for KYC or payment verification.

How We Use It

To verify identity, process transactions, comply with AML/CFT regulations, provide customer support, and improve our services. We do not sell your data to third parties.

Sharing & Disclosure

We may share information with banks, regulators, and law-enforcement where required by law, and with service providers (e.g., SMS gateways) under strict confidentiality agreements.

Security

We use AES-256 encryption at rest, TLS in transit, role-based access controls, and comprehensive audit logging. Access to your data is restricted to authorised staff only.

Data Retention

We retain transaction records for at least 7 years as required by BoT regulations. KYC records are retained as long as the account is active and for the statutory retention period thereafter.

Your Rights

You have the right to access, correct, or request deletion of your data (subject to legal retention obligations). Contact privacy@rafiki.co.tz.

Cookies

We use essential cookies for session management. Analytics cookies are only set with your consent.

Updates

We may update this policy. Material changes will be notified in-app and by email.

Contact

For privacy questions: privacy@rafiki.co.tz or +255 22 100 1000.