Privacy Policy
Last updated: 26 September 2026
Information We Collect
We collect information you provide during registration (name, email, mobile, ID, address), transaction data, device and usage data, and any documents you upload for KYC or payment verification.
How We Use It
To verify identity, process transactions, comply with AML/CFT regulations, provide customer support, and improve our services. We do not sell your data to third parties.
Sharing & Disclosure
We may share information with banks, regulators, and law-enforcement where required by law, and with service providers (e.g., SMS gateways) under strict confidentiality agreements.
Security
We use AES-256 encryption at rest, TLS in transit, role-based access controls, and comprehensive audit logging. Access to your data is restricted to authorised staff only.
Data Retention
We retain transaction records for at least 7 years as required by BoT regulations. KYC records are retained as long as the account is active and for the statutory retention period thereafter.
Your Rights
You have the right to access, correct, or request deletion of your data (subject to legal retention obligations). Contact privacy@rafiki.co.tz.
Cookies
We use essential cookies for session management. Analytics cookies are only set with your consent.
Updates
We may update this policy. Material changes will be notified in-app and by email.
Contact
For privacy questions: privacy@rafiki.co.tz or +255 22 100 1000.