Privacy
Privacy policy
This policy explains how ShambaBoy collects, uses, shares, protects, retains, and deletes personal data when you use the ShambaBoy mobile app, website, support channels, and connected farm services.
Effective 19 July 2026 · Last updated 20 July 2026
1. Who this policy covers
This policy covers ShambaBoy account holders and people whose information is entered into ShambaBoy by a farm, employer, institution, or authorized team member. A farm or institution may decide which work records its authorized users create and who can see them. If your data was added by one of those organizations, you may contact both that organization and ShambaBoy about it.
ShambaBoy is intended only for people aged 18 or older. We do not knowingly provide accounts to children under 18. Contact us if you believe a child's personal data has been submitted.
2. Data we collect
- Account and profile data. Name, phone number, email, password hash and authentication records, account type, farm or institution membership, role, job title, language, time zone, profile photo, and contact address such as city, county or region, postal code, and country. Where identity or worker verification is used, this may include a national ID number, passport or other credential, credential images, work experience, and verification status.
- Age and date of birth. Onboarding asks for a date of birth to confirm that you are at least 18 and derives your age from it. The completed profile currently sends and stores the derived age; an unfinished onboarding draft, including the selected birth date, may remain on the device until onboarding is completed or the local draft is cleared.
- Farm, worker, and operations data. Farm details and coordinates; memberships, invitations, applications, jobs, worker credentials and reviews; tasks, assignments, attendance, approvals, notes and audit history; crop, livestock, inventory, project, procurement, accounting, payroll, training, compliance, grievance, and monitoring or reporting records.
- Precise location and proof metadata. With foreground location permission, verification features can capture precise GPS coordinates, altitude, accuracy, capture time, device identifier, provider, and mocked-location or integrity signals. We use these details for task proof, attendance, training evidence, farm mapping, weather at a selected farm location, and fraud or quality checks. The current app does not continuously track location in the background.
- Photos, video, files, chat, and audio. Profile and farm images, task or attendance proof, identity and credential files, receipts, compliance documents, training evidence, project files, chat messages and attachments, voice notes or other audio, transcripts, and the file and capture metadata needed to upload, display, sync, and verify that content.
- Device, notification, and usage data. App and operating-system version, device model and identifiers, client type, IP address, user agent, session and login activity, security events, push token, notification preferences and delivery status, app interactions, feature activity, navigation breadcrumbs, timestamps, and server logs.
- Offline and sync data. The app stores operational records, media references, queued changes, sync status, conflict details, timestamps, and device or idempotency identifiers locally so supported work can continue with limited connectivity and synchronize later.
- Billing and purchase data. Billing contact details, selected plan, amount, currency, transaction reference, payment status, purchase or subscription history, refunds, and limited payment-method metadata. Card and mobile-money checkout is handled by Paystack and participating financial or mobile-money providers. ShambaBoy does not receive your complete card number, PIN, or payment OTP from the hosted checkout.
- Crash and performance diagnostics. When diagnostics are active, Sentry may receive crash reports, errors, performance traces, app and device details, breadcrumbs, and ShambaBoy's numeric account ID. We configure diagnostics not to intentionally attach your name, phone number, or GPS location. Screen and session replay is disabled for the current release, so we do not collect replay recordings of your app sessions.
We receive data directly from you, automatically from your device and use of the service, from an authorized farm or institution, from other users who work with you, and from processors such as payment and notification providers.
3. How and why we use data
- Create accounts, authenticate users, manage roles, and provide support.
- Operate farm workflows, worker and job features, offline sync, communication, reporting, billing, and the features you or your organization request.
- Verify work and evidence using location, timestamps, media, device and approval metadata; detect duplicate, altered, suspicious, or low-quality submissions; and protect farms, workers, and the service from abuse.
- Send service messages and user-controlled push, email, or SMS notifications.
- Diagnose failures, measure reliability and feature performance, improve the app, and develop new functionality using aggregated or de-identified information where practical.
- Comply with law, enforce agreements, resolve disputes, maintain appropriate audit records, and protect legal rights and safety.
Depending on the context, we process data to perform our contract with you or your organization, with your consent, to meet a legal obligation, or for legitimate interests such as service security, fraud prevention, support, and product reliability. You can withdraw consent for optional processing, but this does not affect processing already completed and some features may no longer work.
4. When data is shared
We do not sell personal data and do not use it for third-party behavioral advertising. We share only what is reasonably needed in these circumstances:
- Your farm or organization. Authorized owners, managers, supervisors, workers, reviewers, and administrators may see records according to their role and the workflow. A job application or a feature you deliberately share may make selected profile or verification data available to the recipient. Raw identity documents are restricted more tightly than ordinary profile information.
- Service processors. These include cloud hosting, database and file-storage providers; email, SMS, support and notification services (including Expo and the Apple or Google push networks); maps and weather services; Sentry for crash and performance diagnostics; Paystack and payment networks for billing; and AI, document, or voice-processing providers only when a feature needing that processing is used. Amazon Web Services is used for certain storage and communications functions where configured.
- User-directed partners. We may provide records to a buyer, auditor, exporter, certification body, carbon programme, or other operational partner when you or an authorized organization directs the sharing or the workflow clearly requires it.
- Legal and safety recipients. Courts, regulators, law-enforcement authorities, professional advisers, or other parties when required by law or reasonably necessary to protect rights, safety, the service, or its users.
- Business changes. A prospective or actual successor may receive data as part of a merger, financing, reorganization, or sale, subject to appropriate confidentiality and applicable law.
5. Security and encryption
We use administrative, technical, and organizational safeguards designed for the type of data involved. These include HTTPS/TLS connections, hashed account passwords, operating-system secure storage for authentication credentials where supported, encryption for selected sensitive stored values, role-based access controls, session controls, audit logs, and restricted access to production systems.
Offline records are held in the app's private local storage and receive the protections provided by your device and operating system. Uploaded or exported files can also exist outside ShambaBoy on a device or in a destination you choose, so use a device lock and protect shared files. No storage or transmission method can be guaranteed completely secure.
6. Retention and deletion
We keep data while an account or farm relationship is active and for as long as it is reasonably needed for the purposes above. Retention varies by record and is based on operational need, shared farm-record integrity, legal and accounting obligations, dispute handling, security and fraud prevention, audit requirements, backup cycles, and processor requirements. When data is no longer needed, we delete it, de-identify it, or restrict access as appropriate.
Local offline data can remain while the account is signed in. Signing out, including after an account-deletion request, clears account-scoped SQLite, cache, queued-upload, and local file data before another account can use the app. Uninstalling the app also removes its local storage. Unsynced drafts or uploads may be lost when local data is cleared.
You can request deletion from the app or through our public account-deletion page. Eligible deletion requests are acknowledged within 48 hours and completed within 30 days. Limited payment, legal, security, fraud-prevention, shared farm audit, and request records may be retained where required or reasonably necessary. We de-identify or limit those records where practical, and keep them only while the applicable reason remains. Provider backups and logs are removed through their normal protected overwrite or deletion cycles.
When deletion is finalized, we do not keep the raw phone number in the deletion safeguard. We may retain a keyed, one-way identifier derived from the normalized phone number, together with limited registration-safeguard audit records. We use these only to prevent delayed messages or records from reconnecting deleted account data and to let a genuinely new account verify the same number through a short-lived registration process. The identifier is not used to contact the deleted user and cannot by itself reveal the phone number. We restrict access and retain these safeguards only while reasonably necessary for deletion integrity, security, fraud prevention, and related legal obligations. You may exercise the rights described below, although a request may be limited where retaining the safeguard remains necessary and lawful.
7. International and cross-border processing
ShambaBoy serves users in Kenya, but ShambaBoy and its processors may store or process data in other countries, including where cloud, diagnostics, notification, payment, mapping, weather, AI, or communications providers operate. Privacy laws in those countries may differ. We use contractual, access, security, and other safeguards appropriate to the data and comply with applicable cross-border transfer requirements.
8. Your choices and rights
Depending on applicable law, you may ask to access, correct, delete, restrict, or object to processing of your personal data; withdraw consent; request a portable copy; or complain to the competent data-protection authority. You can update supported profile and notification settings in the app and manage camera, microphone, photo, file, location, and notification permissions in your device settings.
Email support@shambaboy.com to exercise a right. We may need to verify your identity and authority before acting. If a farm or institution controls the requested record, we may coordinate with it. A request can be limited where law permits, including to protect another person's rights or preserve required records.
9. What ShambaBoy does not decide
ShambaBoy organizes farm activity records, evidence, reports, and operational performance signals. ShambaScore is not a credit score. ShambaBoy does not monitor credit, provide financial products or services, or make lending or financial-eligibility decisions. It also does not issue farm or worker certifications or carbon credits. Certification bodies, carbon programmes, standards bodies, and other relevant partners make those decisions under their own rules. ShambaBoy does not guarantee approval, certification, pricing, savings, income, or another external outcome.
10. Changes and contact
We may update this policy as the service or legal requirements change. We will update the date above and provide additional notice in the app or by another appropriate channel when a change is material.
For privacy questions, requests, or concerns, contact ShambaBoy at support@shambaboy.com.
