GafExpress Privacy Policy

Last updated: 27 August 2026

This policy explains how the current GafExpress product handles information. Feature availability depends on account role and provider configuration.

Who operates GafExpress

TODO — owner must confirm legal entity operating GafExpress. This policy describes the GafExpress marketplace, messaging, business, staff, tenant, payment and production-management services.

Information we collect

Depending on the features you use, we process account and profile details (including name, email, phone number, date of birth and profile image); authentication and verification records; business registration and director information; addresses and location coordinates; products, orders and delivery details; payment references and payment evidence; private messages, calls and uploads; staff, contract, attendance and compensation records; tenant applications, identity documents and tenancy records; farm and production records; AI prompts and responses; and security, delivery and audit records. Passwords and verification codes are stored in hashed form by the backend rather than as readable text.

Sensitive information

Features may process NIN submissions, NIN hash and last four digits, identity documents, bank details, payment proofs, home or delivery addresses, precise location, private communications, staff and tenant documents, signatures, and business director information. Only provide this information when the relevant feature requires it.

How we use information

We use information to create and secure accounts; verify contact, identity or business information where a real provider or authorised review is available; operate the marketplace, orders, delivery and payments; provide messaging and uploads; manage business, staff, tenant and farm workflows; send transactional communications; provide support; prevent fraud and investigate security events; and produce AI-assisted plans or drafts when you request those features.

Identity and business verification

Submitting a NIN, document or registration number does not by itself mean that it is verified. Where configured, GafExpress sends business registration information to Dojah or uses an authorised backend review. GafExpress is not the Corporate Affairs Commission or another government authority. NIN verification is unavailable in production until an authoritative provider is configured.

Payments

Paystack processes supported online payments and receives transaction details such as amount, currency, customer email and a transaction reference. GafExpress stores payment references, status and audit records, but the current code does not store payment-card numbers. Some business workflows also allow bank details and payment-proof uploads.

Messages and uploads

We process private messages, read state, contact requests, call-session information and attachments such as images, video, voice notes and documents so participants can communicate. We also process profile images, product media, identity and contract documents, attendance proofs and production evidence. Relevant participants and authorised business users can access content according to their role.

Service providers

The current service uses MongoDB-compatible database hosting for application records, Railway for backend hosting, Netlify for web hosting, Cloudinary for media and document storage, Paystack for payments, Brevo for transactional email, and Google Places or Address Validation for address features. Termii may receive phone numbers and verification messages when SMS is configured. Dojah may receive business verification details when configured. A Groq-compatible AI provider may receive prompts and relevant production context when an AI-assisted feature is used. OpenAI may receive uploaded images for safety moderation before publication; Google Cloud Vision remains an alternative image moderation provider. These providers process information under their own terms and retention practices.

Retention

GafExpress currently keeps records for as long as needed to operate the relevant feature, maintain security and audit history, resolve disputes, and meet applicable transaction or legal obligations. Exact retention periods have not yet been legally approved. Payment, transaction and audit records may require longer retention. Third-party providers may retain information independently under their agreements. LEGAL REVIEW REQUIRED.

Your choices and rights

You can review and edit supported profile and business fields in the app, control what you submit, and ask GafExpress to help with access, correction or other privacy requests. Some verified fields are locked to protect integrity. Self-service account deletion is available from Settings → Account → Delete account, with public instructions at /delete-account. Eligible profile data is removed or anonymised while transaction, chat, security, audit, employment, tenancy, or business records may be retained when required. Users can privately report accounts, messages, and listings; safety rules are published at /community-guidelines.

Security

GafExpress uses measures including authenticated access, role and business scoping, hashed passwords and verification codes, and server-side verification state. No internet service can guarantee absolute security.

Children

POLICY DECISION REQUIRED — the repository does not establish a minimum age rule. The owner and legal adviser must decide and document the applicable age policy before making an age-related claim.

International processing

Service providers may process information in countries where they or their infrastructure operate. Provider locations, contracts and any required transfer safeguards require owner and legal review. We do not claim that all information remains in one country.

Contact

TODO — owner must provide privacy contact email. Until that contact is confirmed, use the support channel already available to you in GafExpress for a privacy question.