KampalaSnap — Privacy Policy
Effective date: 2026-05-22 Last updated: 2026-06-10
This Privacy Policy explains what personal information KampalaSnap collects, what we do with it, who we share it with, how we protect it, how long we keep it, and the rights you have over it.
KampalaSnap is operated by Hobermalo, a business registered in Uganda. We currently focus on East African commerce, but the app and website are accessible to anyone, anywhere. Wherever you are using KampalaSnap from, this policy applies to you.
For the purposes of data protection law, KampalaSnap is the data controller for the personal information you give us. We aim to comply with the Uganda Data Protection and Privacy Act (2019), the EU/UK GDPR where it applies to you, and comparable data-protection rules in the other regions our users reach us from.
If anything here is unclear, write to support@kampalasnap.com and we will reply within 7 days.
1. A quick word on how transactions work
KampalaSnap supports two different ways a buyer can transact with a seller or service provider. The information we collect and the protections we provide are different for each. This matters for the sections below, so we explain it upfront.
1.1 Catalog orders (escrow-protected)
When a buyer pays for a catalog product through the app, the payment goes into escrow. We hold the money via our payment processor until the buyer confirms delivery (or a short window passes after the seller marks the order delivered). Only then do we release it to the seller, less platform fees.
For catalog orders, we collect what's needed to fulfil, deliver, and adjudicate a dispute: delivery contact details, delivery address, a one-time PIN, and the order timeline.
1.2 Direct-contact listings and services (no escrow)
For listings that aren't part of the escrow catalog — typically seller "shop" listings that aren't part of our approved catalog, and most service provider profiles (photographers, plumbers, mechanics, tutors, etc.) — buyers reach the seller or provider directly through the WhatsApp or Call button on the listing or profile.
Those conversations and any payment that results happen between the buyer and the seller, off our platform. We don't see the message content or the payment. What we collect for these is far smaller: we host the public listing or profile, and we record outbound contact events for spam protection and seller analytics. There is no escrow, no delivery PIN, no platform-managed dispute resolution for those transactions, and we are not a party to them. If a direct-contact deal goes wrong, that's between you and the other party — though we will still take action on the listing or account where our community guidelines or terms are clearly broken.
We surface this distinction clearly in the app — escrow-protected listings have a "Pay through KampalaSnap" checkout button; direct listings only have the WhatsApp / Call buttons.
2. What we collect, and why
2.1 When you sign up
You can create an account three ways. Pick whichever you prefer; the account works the same way after signup.
Path A — Phone (SMS one-time code)
| What | Why |
|---|---|
| Username | Public display name and profile URL |
| Phone number | Login identifier; one-time code delivery |
| Password | Authentication. We store only a one-way hash — we cannot recover or read the original. |
Path B — Sign in with Google
| What | Why |
|---|---|
| Email address | Account identifier and recognition on future sign-ins |
| Profile name | Pre-fills your display name (you can change it) |
| Profile picture URL | Pre-fills your avatar |
| A stable Google account identifier | Lets us recognise you on subsequent Google sign-ins |
No password is created.
Path C — Sign in with Apple (iOS)
| What | Why |
|---|---|
| Email (real or Apple's private relay) | Account identifier. Private-relay addresses work normally. |
| Full name | Used once at signup. Apple only sends this on the first sign-in. |
| A stable Apple account identifier | Recognition on subsequent Apple sign-ins |
Phone added later (Path B / C only). If you start with Google or Apple and later open a shop or service, we'll ask you to verify a phone number at that point via SMS one-time code. Phone verification is required for sellers and service providers so we can reach you for payouts, verification, and dispute resolution. Buyers who never sell are not required to give us a phone.
2.2 When you sell or provide a service
| What | Why |
|---|---|
| Shop or service name, bio, logo | Public profile display |
| Public contact phone(s) | Shown to buyers on your profile so they can WhatsApp or call you |
| Verification contact info | Used during our verification review to reach you |
| Payout account details (mobile money or bank) | Pay you for completed escrow orders |
| Payout-account verification number | Confirms you control the destination account before we send money to it |
| Catalog product details, photos, videos, prices, stock | Your listings |
| Direct-listing shop product details, photos, videos, prices | Your shop listings |
| Service offerings, pricing, availability | Your service profile content |
2.3 When you place a catalog order (escrow)
| What | Why |
|---|---|
| Recipient name | Delivery rider needs to know who to hand it to |
| Delivery phone | Delivery rider can call or text on arrival |
| Delivery address (landmark + structured location) | So the order actually reaches you |
| Delivery instructions | Free text you write for the seller or rider |
| One-time delivery PIN | Final-step proof of delivery that releases the escrow |
| Optional notes to seller | Any extra context you choose to add |
2.4 When you use a direct-contact listing or service profile
| What | Why |
|---|---|
| The fact that you tapped WhatsApp or Call on a listing | Spam / abuse protection; aggregate analytics for the seller and platform |
| The product, listing, or profile you reached out about | Same |
We don't see the WhatsApp conversation, the phone call, or any payment that follows. Once you leave the app, the conversation is between you and the other party.
2.5 When you use the app generally
| What | Why |
|---|---|
| Orders placed and received | Order history; evidence for any dispute |
| Reviews and ratings | Public reputation for sellers and services |
| Posts, comments, likes | Social features in the app |
| Promotions or ad spend you've paid for | Your seller-side spend history |
| Wallet deposits, balance, and transactions | Funds you deposit, escrow earnings, platform fees, ad and subscription spend, and payouts |
| Saved items, cart, browse history | Personalisation so we resurface things you cared about |
2.6 What we derive automatically
| What | Why |
|---|---|
| Sign-in timestamps and session tokens | Session management; revoke sessions if compromised |
| Failed delivery-PIN attempts on an order | Brute-force protection — repeated wrong attempts temporarily lock the PIN flow on that order |
| Push notification token | Send you order updates and chat messages |
| Order status timeline (paid → delivered → completed, etc.) | Auditable history if a dispute opens |
| Device type, app version, and approximate region inferred from your network | Diagnostics and content delivery |
2.7 What we deliberately do NOT collect
- Your government ID, passport, or national ID number
- Your precise real-time location (delivery addresses come from what you type at checkout)
- Your contact list, your photos library, or any files outside what you explicitly upload
- Tracking identifiers used to advertise to you off the platform
2.8 Guest sessions — before you sign up
When you open the app or visit the website without signing in, we issue your device an anonymous identifier (a random value stored on the device). We use it to:
- Remember what you browsed across app restarts so what you looked at last time can resurface
- Carry your browse history forward to your new account if you later sign up — without making you start over
We do not associate this identifier with your name, phone, or email (you haven't given us those yet). It expires automatically after 90 days of inactivity. If you sign up, it is linked to your account so we can stitch "what you looked at as a guest" to "what you did as a user." You can clear it any time by signing out or by clearing the app's data via your phone's settings.
3. How we protect your information
We use a layered set of controls to make a breach unlikely and a breach's impact small. We deliberately do not publish the exact configuration — doing so helps no honest user and gives attackers a map. The summary below is accurate without being a recipe.
3.1 Encryption at rest
Personal identifying information is stored encrypted in our database, not in plain text. The sensitive fields covered include:
- Phone numbers (login phone, contact phones, delivery phones)
- Email addresses received via OAuth or set later
- Recipient names, delivery addresses, delivery instructions
- Payout account numbers and the names on payout accounts
- Verification contact details
- Order delivery PINs
Where we need to look up an account by phone or email (for login, one-time-code verification, or account linking) we store a separate keyed lookup value alongside the encrypted record — so we can match you without having the plain phone or email sitting in the database.
The cryptographic keys are held outside the database, in a place the database itself does not reach. Someone who only obtained a copy of the database, without the keys, would not be able to read those fields.
3.2 Password storage
Passwords are stored only as a one-way hash using a slow, memory-hard algorithm widely recommended for password storage. We cannot recover your original password, even with full access to our own systems. If you forget it, you reset it via SMS one-time code and we replace the stored hash.
3.3 Network
- All client traffic is over HTTPS
- Internal database and cache services are not exposed to the public internet
- Administrative interfaces sit behind authentication and additional access controls
- Rate limits apply to authentication, payment, and verification endpoints to slow credential stuffing and brute force
3.4 Backups
We take daily encrypted backups of the database and store them off the application server. The backup files themselves are encrypted before they leave our server, with a key not stored alongside them. An attacker who intercepts a backup file gets only ciphertext.
3.5 Audit trail
Money-relevant events (wallet credits, debits, withdrawals, escrow releases) and order status changes are written to append-only audit records — no normal application code path edits or deletes them. This means anyone trying to rewrite financial history leaves a visible trail.
3.6 Access inside the team
Only people directly involved in operations, support, or dispute resolution can use our administrative tools. Such access is logged and reviewed.
3.7 Reporting a security concern
If you believe you've found a vulnerability, write to
support@kampalasnap.com with SECURITY at the start of the
subject line. We acknowledge security reports within 24 hours and
investigate promptly. Please do not publicly disclose vulnerabilities
before we've had a reasonable window to fix them; we'll always
credit responsible reporters who ask to be credited.
4. How long we keep your information
We keep data in three tiers, each with its own retention window.
Tier A — Personal identifying information
Phone numbers, email addresses, names, delivery addresses, delivery contact details, payout account numbers, verification contacts, profile photos.
- While your account is active: kept as long as your account is active.
- After you delete your account: soft-deleted immediately, then anonymised after 30 days. The 30-day window lets us reverse accidental deletions and resolve any dispute opened just before deletion.
Tier B — Financial and legal records
Transactions, wallet ledger entries, escrow orders, withdrawals, payout method records, dispute records.
- Kept for 7 years from the date of the record, or longer where a specific jurisdiction we operate in requires it.
- This is a tax and financial-record requirement, not a choice.
- During this window the personal identifiers (name, phone, address) on those records are anonymised once the Tier A 30-day window closes; only the amounts, timestamps, and account pointers remain.
Tier C — Behavioural data
Sign-in timestamps, search queries, video views, cart and browse history, ad interactions.
- Kept 90–365 days depending on the data type, then aggregated into per-day counts that no longer identify any individual user.
Direct-contact tap events
When you tap a WhatsApp or Call button on a direct-contact listing or service profile, the tap event (who tapped, when, on which listing) is retained alongside the same Tier C window above. The conversation itself happens off our platform and we never see it.
Guest sessions
The anonymous identifier we issue to your device before you sign up (§ 2.8) is retained for 90 days from your last visit. If you don't return within 90 days, the record and any browse data attached to it are hard-deleted. If you sign up, the identifier links to your account and persists with the account.
5. Who we share your information with
We share information with three categories of third party, and only the minimum needed in each case.
5.1 Payment processor (catalog orders, wallet deposits, payouts)
Our payment processor (currently Pesapal — pesapal.com) handles three things on our platform:
- Catalog order checkout — when you pay for a catalog item
- Wallet deposits — when you add funds to your in-app wallet
- Subscription and promotion charges that go through card / mobile money directly (rather than via wallet balance)
For each of these, Pesapal sees the amount, a reference code, the phone number used to pay so they can deliver a receipt, and your email if you provided one. Their own privacy policy governs what they do with that.
Pesapal is a payment service provider licensed by the Bank of Uganda. The wallet ledger we maintain inside the app is an accounting record of your deposits and earnings; the actual funds movement is handled by Pesapal under their licence.
Payouts from your wallet to your external mobile money or bank account go through the relevant mobile money or bank API in the destination country. That provider sees the destination account, the amount, and a reference code.
Direct-contact listings and services do not involve our payment processor, because the payment happens off our platform.
5.2 SMS / messaging provider
One-time codes and some transactional notifications go through an SMS gateway provider. The provider sees the recipient phone number and the message body (typically a 6-digit code). They are not given your name, password, or other identifiers.
5.3 Hosting and storage
The application and database run on a reputable cloud hosting provider. Backups are stored with a separate cloud-storage provider. Image and video files (product photos, profile pictures, dispute evidence) are stored on a reputable object-storage provider. None of these providers can read the encrypted personal fields in §3.1 because the keys are not stored with them.
We choose providers that meet recognised data-protection standards in their jurisdiction.
5.4 Sign-in providers (only if you use them)
If you sign in with Google or Apple, those providers are part of that one specific flow:
| Provider | What they see | What we receive |
|---|---|---|
| That you signed in to KampalaSnap on a given date with a given Google account | Profile name, email, profile picture URL, and a stable account identifier. We don't send anything back to Google. | |
| Apple (iOS) | The equivalent for Apple ID | Email (real or relay), full name (once, on first sign-in), and a stable account identifier. We don't send anything back to Apple. |
Google's privacy policy: https://policies.google.com/privacy Apple's privacy policy: https://www.apple.com/legal/privacy/
If you sign up with phone, neither Google nor Apple is part of the flow.
5.5 Buyers and sellers see each other where they need to
When a buyer places an escrow catalog order, the seller sees the recipient name, delivery address, delivery phone, and delivery instructions on that order. They need this to fulfil it.
When a buyer taps WhatsApp or Call on a direct-contact listing or service profile, the seller or provider sees the buyer's WhatsApp or phone number through the messaging app — that's just how WhatsApp and phone calls work. We don't show your phone number to the seller before you choose to contact them.
5.6 What we never do
- Sell or rent your personal information to advertisers
- Hand contact details to sellers you haven't transacted or chosen to contact
- Allow third-party advertising SDKs to collect identified data from the app
- Hand over data to anyone except in response to a lawful order from the competent authorities in the jurisdiction concerned, or as required to resolve a dispute you've opened with us
6. Your rights
You have the following rights over your personal information. Exercising them is free. We respond within 30 days of a verified request.
6.1 Right to access
Request a copy of the personal information we hold about you, including the encrypted fields decrypted into readable form. Write to support@kampalasnap.com.
6.2 Right to correction
You can edit most profile fields directly in the app (username, shop/service details, payout methods). For fields you can't edit yourself, request a correction by email.
6.3 Right to deletion
Request deletion of your account. We soft-delete the account immediately (it stops working, the profile becomes invisible, the username and phone slot are freed). Tier A personal data is anonymised 30 days later. Tier B financial records are retained for the legal 7-year window, with personal identifiers anonymised. The full mechanics are documented at Delete your account.
6.4 Right to portability
You can request a copy of your data in a machine-readable format (JSON). Write to support@kampalasnap.com.
6.5 Right to withdraw consent
You can withdraw consent at any time by deleting your account. Some data is structurally required to operate the marketplace at all (we can't deliver an order without a delivery address), so withdrawing consent for any particular field generally means we can no longer serve you.
6.6 Right to object and to complain
If you believe we are mishandling your data, write to support@kampalasnap.com first. If we can't resolve it, you have the right to lodge a complaint with the data-protection authority in your country of residence. For Ugandan users that's the Personal Data Protection Office (Uganda). Users in the EU/UK can complain to the relevant national supervisory authority.
7. Children
KampalaSnap is not directed at children under 18. We do not knowingly collect personal information from children. If you believe a child has signed up, write to support@kampalasnap.com and we will delete the account.
8. International transfers
Our infrastructure operates from data centres outside Uganda, and backups may be stored across multiple regions. By using KampalaSnap you consent to your personal information being transferred to and processed in those locations. Where required by law, we rely on standard contractual clauses or other recognised transfer mechanisms.
9. Changes to this policy
We update this policy when our practices change. The Last updated date at the top reflects the most recent change. For material changes (new categories of data collected, new third-party processors, weakening of any protection described here) we will notify active users in the app at least 14 days before the change takes effect.
10. Contact
- Privacy enquiries, data access / correction / deletion / portability requests: support@kampalasnap.com
- Security reports (suspected breach, vulnerability disclosure): support@kampalasnap.com — put
SECURITYat the start of the subject line for faster routing - General enquiries: support@kampalasnap.com
We reply within 7 days to privacy requests and within 24 hours to security reports.