GafExpress Privacy Policy
Last updated: 27 August 2026
This policy explains how the current GafExpress product handles information. Feature availability depends on account role and provider configuration.
Who operates GafExpress
TODO — owner must confirm legal entity operating GafExpress. This policy describes the GafExpress marketplace, messaging, business, staff, tenant, payment and production-management services.
Information we collect
Depending on the features you use, we process account and profile details (including name, email, phone number, date of birth and profile image); authentication and verification records; business registration and director information; addresses and location coordinates; products, orders and delivery details; payment references and payment evidence; private messages, calls and uploads; staff, contract, attendance and compensation records; tenant applications, identity documents and tenancy records; farm and production records; AI prompts and responses; and security, delivery and audit records. Passwords and verification codes are stored in hashed form by the backend rather than as readable text.
Sensitive information
Features may process NIN submissions, NIN hash and last four digits, identity documents, bank details, payment proofs, home or delivery addresses, precise location, private communications, staff and tenant documents, signatures, and business director information. Only provide this information when the relevant feature requires it.
How we use information
We use information to create and secure accounts; verify contact, identity or business information where a real provider or authorised review is available; operate the marketplace, orders, delivery and payments; provide messaging and uploads; manage business, staff, tenant and farm workflows; send transactional communications; provide support; prevent fraud and investigate security events; and produce AI-assisted plans or drafts when you request those features.
Identity and business verification
Submitting a NIN, document or registration number does not by itself mean that it is verified. Where configured, GafExpress sends business registration information to Dojah or uses an authorised backend review. GafExpress is not the Corporate Affairs Commission or another government authority. NIN verification is unavailable in production until an authoritative provider is configured.
Payments
Paystack processes supported online payments and receives transaction details such as amount, currency, customer email and a transaction reference. GafExpress stores payment references, status and audit records, but the current code does not store payment-card numbers. Some business workflows also allow bank details and payment-proof uploads.
Messages and uploads
We process private messages, read state, contact requests, call-session information and attachments such as images, video, voice notes and documents so participants can communicate. We also process profile images, product media, identity and contract documents, attendance proofs and production evidence. Relevant participants and authorised business users can access content according to their role.
Service providers
The current service uses MongoDB-compatible database hosting for application records, Railway for backend hosting, Netlify for web hosting, Cloudinary for media and document storage, Paystack for payments, Brevo for transactional email, and Google Places or Address Validation for address features. Termii may receive phone numbers and verification messages when SMS is configured. Dojah may receive business verification details when configured. A Groq-compatible AI provider may receive prompts and relevant production context when an AI-assisted feature is used. OpenAI may receive uploaded images for safety moderation before publication; Google Cloud Vision remains an alternative image moderation provider. These providers process information under their own terms and retention practices.
Retention
GafExpress currently keeps records for as long as needed to operate the relevant feature, maintain security and audit history, resolve disputes, and meet applicable transaction or legal obligations. Exact retention periods have not yet been legally approved. Payment, transaction and audit records may require longer retention. Third-party providers may retain information independently under their agreements. LEGAL REVIEW REQUIRED.
Your choices and rights
You can review and edit supported profile and business fields in the app, control what you submit, and ask GafExpress to help with access, correction or other privacy requests. Some verified fields are locked to protect integrity. Self-service account deletion is available from Settings → Account → Delete account, with public instructions at /delete-account. Eligible profile data is removed or anonymised while transaction, chat, security, audit, employment, tenancy, or business records may be retained when required. Users can privately report accounts, messages, and listings; safety rules are published at /community-guidelines.
Security
GafExpress uses measures including authenticated access, role and business scoping, hashed passwords and verification codes, and server-side verification state. No internet service can guarantee absolute security.
Children
POLICY DECISION REQUIRED — the repository does not establish a minimum age rule. The owner and legal adviser must decide and document the applicable age policy before making an age-related claim.
International processing
Service providers may process information in countries where they or their infrastructure operate. Provider locations, contracts and any required transfer safeguards require owner and legal review. We do not claim that all information remains in one country.
Contact
TODO — owner must provide privacy contact email. Until that contact is confirmed, use the support channel already available to you in GafExpress for a privacy question.