KampalaSnap — Privacy Policy

Effective date: 2026-05-22 Last updated: 2026-06-10

This Privacy Policy explains what personal information KampalaSnap collects, what we do with it, who we share it with, how we protect it, how long we keep it, and the rights you have over it.

KampalaSnap is operated by Hobermalo, a business registered in Uganda. We currently focus on East African commerce, but the app and website are accessible to anyone, anywhere. Wherever you are using KampalaSnap from, this policy applies to you.

For the purposes of data protection law, KampalaSnap is the data controller for the personal information you give us. We aim to comply with the Uganda Data Protection and Privacy Act (2019), the EU/UK GDPR where it applies to you, and comparable data-protection rules in the other regions our users reach us from.

If anything here is unclear, write to support@kampalasnap.com and we will reply within 7 days.


1. A quick word on how transactions work

KampalaSnap supports two different ways a buyer can transact with a seller or service provider. The information we collect and the protections we provide are different for each. This matters for the sections below, so we explain it upfront.

1.1 Catalog orders (escrow-protected)

When a buyer pays for a catalog product through the app, the payment goes into escrow. We hold the money via our payment processor until the buyer confirms delivery (or a short window passes after the seller marks the order delivered). Only then do we release it to the seller, less platform fees.

For catalog orders, we collect what's needed to fulfil, deliver, and adjudicate a dispute: delivery contact details, delivery address, a one-time PIN, and the order timeline.

1.2 Direct-contact listings and services (no escrow)

For listings that aren't part of the escrow catalog — typically seller "shop" listings that aren't part of our approved catalog, and most service provider profiles (photographers, plumbers, mechanics, tutors, etc.) — buyers reach the seller or provider directly through the WhatsApp or Call button on the listing or profile.

Those conversations and any payment that results happen between the buyer and the seller, off our platform. We don't see the message content or the payment. What we collect for these is far smaller: we host the public listing or profile, and we record outbound contact events for spam protection and seller analytics. There is no escrow, no delivery PIN, no platform-managed dispute resolution for those transactions, and we are not a party to them. If a direct-contact deal goes wrong, that's between you and the other party — though we will still take action on the listing or account where our community guidelines or terms are clearly broken.

We surface this distinction clearly in the app — escrow-protected listings have a "Pay through KampalaSnap" checkout button; direct listings only have the WhatsApp / Call buttons.


2. What we collect, and why

2.1 When you sign up

You can create an account three ways. Pick whichever you prefer; the account works the same way after signup.

Path A — Phone (SMS one-time code)

What Why
Username Public display name and profile URL
Phone number Login identifier; one-time code delivery
Password Authentication. We store only a one-way hash — we cannot recover or read the original.

Path B — Sign in with Google

What Why
Email address Account identifier and recognition on future sign-ins
Profile name Pre-fills your display name (you can change it)
Profile picture URL Pre-fills your avatar
A stable Google account identifier Lets us recognise you on subsequent Google sign-ins

No password is created.

Path C — Sign in with Apple (iOS)

What Why
Email (real or Apple's private relay) Account identifier. Private-relay addresses work normally.
Full name Used once at signup. Apple only sends this on the first sign-in.
A stable Apple account identifier Recognition on subsequent Apple sign-ins

Phone added later (Path B / C only). If you start with Google or Apple and later open a shop or service, we'll ask you to verify a phone number at that point via SMS one-time code. Phone verification is required for sellers and service providers so we can reach you for payouts, verification, and dispute resolution. Buyers who never sell are not required to give us a phone.

2.2 When you sell or provide a service

What Why
Shop or service name, bio, logo Public profile display
Public contact phone(s) Shown to buyers on your profile so they can WhatsApp or call you
Verification contact info Used during our verification review to reach you
Payout account details (mobile money or bank) Pay you for completed escrow orders
Payout-account verification number Confirms you control the destination account before we send money to it
Catalog product details, photos, videos, prices, stock Your listings
Direct-listing shop product details, photos, videos, prices Your shop listings
Service offerings, pricing, availability Your service profile content

2.3 When you place a catalog order (escrow)

What Why
Recipient name Delivery rider needs to know who to hand it to
Delivery phone Delivery rider can call or text on arrival
Delivery address (landmark + structured location) So the order actually reaches you
Delivery instructions Free text you write for the seller or rider
One-time delivery PIN Final-step proof of delivery that releases the escrow
Optional notes to seller Any extra context you choose to add

2.4 When you use a direct-contact listing or service profile

What Why
The fact that you tapped WhatsApp or Call on a listing Spam / abuse protection; aggregate analytics for the seller and platform
The product, listing, or profile you reached out about Same

We don't see the WhatsApp conversation, the phone call, or any payment that follows. Once you leave the app, the conversation is between you and the other party.

2.5 When you use the app generally

What Why
Orders placed and received Order history; evidence for any dispute
Reviews and ratings Public reputation for sellers and services
Posts, comments, likes Social features in the app
Promotions or ad spend you've paid for Your seller-side spend history
Wallet deposits, balance, and transactions Funds you deposit, escrow earnings, platform fees, ad and subscription spend, and payouts
Saved items, cart, browse history Personalisation so we resurface things you cared about

2.6 What we derive automatically

What Why
Sign-in timestamps and session tokens Session management; revoke sessions if compromised
Failed delivery-PIN attempts on an order Brute-force protection — repeated wrong attempts temporarily lock the PIN flow on that order
Push notification token Send you order updates and chat messages
Order status timeline (paid → delivered → completed, etc.) Auditable history if a dispute opens
Device type, app version, and approximate region inferred from your network Diagnostics and content delivery

2.7 What we deliberately do NOT collect

2.8 Guest sessions — before you sign up

When you open the app or visit the website without signing in, we issue your device an anonymous identifier (a random value stored on the device). We use it to:

We do not associate this identifier with your name, phone, or email (you haven't given us those yet). It expires automatically after 90 days of inactivity. If you sign up, it is linked to your account so we can stitch "what you looked at as a guest" to "what you did as a user." You can clear it any time by signing out or by clearing the app's data via your phone's settings.


3. How we protect your information

We use a layered set of controls to make a breach unlikely and a breach's impact small. We deliberately do not publish the exact configuration — doing so helps no honest user and gives attackers a map. The summary below is accurate without being a recipe.

3.1 Encryption at rest

Personal identifying information is stored encrypted in our database, not in plain text. The sensitive fields covered include:

Where we need to look up an account by phone or email (for login, one-time-code verification, or account linking) we store a separate keyed lookup value alongside the encrypted record — so we can match you without having the plain phone or email sitting in the database.

The cryptographic keys are held outside the database, in a place the database itself does not reach. Someone who only obtained a copy of the database, without the keys, would not be able to read those fields.

3.2 Password storage

Passwords are stored only as a one-way hash using a slow, memory-hard algorithm widely recommended for password storage. We cannot recover your original password, even with full access to our own systems. If you forget it, you reset it via SMS one-time code and we replace the stored hash.

3.3 Network

3.4 Backups

We take daily encrypted backups of the database and store them off the application server. The backup files themselves are encrypted before they leave our server, with a key not stored alongside them. An attacker who intercepts a backup file gets only ciphertext.

3.5 Audit trail

Money-relevant events (wallet credits, debits, withdrawals, escrow releases) and order status changes are written to append-only audit records — no normal application code path edits or deletes them. This means anyone trying to rewrite financial history leaves a visible trail.

3.6 Access inside the team

Only people directly involved in operations, support, or dispute resolution can use our administrative tools. Such access is logged and reviewed.

3.7 Reporting a security concern

If you believe you've found a vulnerability, write to support@kampalasnap.com with SECURITY at the start of the subject line. We acknowledge security reports within 24 hours and investigate promptly. Please do not publicly disclose vulnerabilities before we've had a reasonable window to fix them; we'll always credit responsible reporters who ask to be credited.


4. How long we keep your information

We keep data in three tiers, each with its own retention window.

Tier A — Personal identifying information

Phone numbers, email addresses, names, delivery addresses, delivery contact details, payout account numbers, verification contacts, profile photos.

Transactions, wallet ledger entries, escrow orders, withdrawals, payout method records, dispute records.

Tier C — Behavioural data

Sign-in timestamps, search queries, video views, cart and browse history, ad interactions.

Direct-contact tap events

When you tap a WhatsApp or Call button on a direct-contact listing or service profile, the tap event (who tapped, when, on which listing) is retained alongside the same Tier C window above. The conversation itself happens off our platform and we never see it.

Guest sessions

The anonymous identifier we issue to your device before you sign up (§ 2.8) is retained for 90 days from your last visit. If you don't return within 90 days, the record and any browse data attached to it are hard-deleted. If you sign up, the identifier links to your account and persists with the account.


5. Who we share your information with

We share information with three categories of third party, and only the minimum needed in each case.

5.1 Payment processor (catalog orders, wallet deposits, payouts)

Our payment processor (currently Pesapal — pesapal.com) handles three things on our platform:

For each of these, Pesapal sees the amount, a reference code, the phone number used to pay so they can deliver a receipt, and your email if you provided one. Their own privacy policy governs what they do with that.

Pesapal is a payment service provider licensed by the Bank of Uganda. The wallet ledger we maintain inside the app is an accounting record of your deposits and earnings; the actual funds movement is handled by Pesapal under their licence.

Payouts from your wallet to your external mobile money or bank account go through the relevant mobile money or bank API in the destination country. That provider sees the destination account, the amount, and a reference code.

Direct-contact listings and services do not involve our payment processor, because the payment happens off our platform.

5.2 SMS / messaging provider

One-time codes and some transactional notifications go through an SMS gateway provider. The provider sees the recipient phone number and the message body (typically a 6-digit code). They are not given your name, password, or other identifiers.

5.3 Hosting and storage

The application and database run on a reputable cloud hosting provider. Backups are stored with a separate cloud-storage provider. Image and video files (product photos, profile pictures, dispute evidence) are stored on a reputable object-storage provider. None of these providers can read the encrypted personal fields in §3.1 because the keys are not stored with them.

We choose providers that meet recognised data-protection standards in their jurisdiction.

5.4 Sign-in providers (only if you use them)

If you sign in with Google or Apple, those providers are part of that one specific flow:

Provider What they see What we receive
Google That you signed in to KampalaSnap on a given date with a given Google account Profile name, email, profile picture URL, and a stable account identifier. We don't send anything back to Google.
Apple (iOS) The equivalent for Apple ID Email (real or relay), full name (once, on first sign-in), and a stable account identifier. We don't send anything back to Apple.

Google's privacy policy: https://policies.google.com/privacy Apple's privacy policy: https://www.apple.com/legal/privacy/

If you sign up with phone, neither Google nor Apple is part of the flow.

5.5 Buyers and sellers see each other where they need to

When a buyer places an escrow catalog order, the seller sees the recipient name, delivery address, delivery phone, and delivery instructions on that order. They need this to fulfil it.

When a buyer taps WhatsApp or Call on a direct-contact listing or service profile, the seller or provider sees the buyer's WhatsApp or phone number through the messaging app — that's just how WhatsApp and phone calls work. We don't show your phone number to the seller before you choose to contact them.

5.6 What we never do


6. Your rights

You have the following rights over your personal information. Exercising them is free. We respond within 30 days of a verified request.

6.1 Right to access

Request a copy of the personal information we hold about you, including the encrypted fields decrypted into readable form. Write to support@kampalasnap.com.

6.2 Right to correction

You can edit most profile fields directly in the app (username, shop/service details, payout methods). For fields you can't edit yourself, request a correction by email.

6.3 Right to deletion

Request deletion of your account. We soft-delete the account immediately (it stops working, the profile becomes invisible, the username and phone slot are freed). Tier A personal data is anonymised 30 days later. Tier B financial records are retained for the legal 7-year window, with personal identifiers anonymised. The full mechanics are documented at Delete your account.

6.4 Right to portability

You can request a copy of your data in a machine-readable format (JSON). Write to support@kampalasnap.com.

You can withdraw consent at any time by deleting your account. Some data is structurally required to operate the marketplace at all (we can't deliver an order without a delivery address), so withdrawing consent for any particular field generally means we can no longer serve you.

6.6 Right to object and to complain

If you believe we are mishandling your data, write to support@kampalasnap.com first. If we can't resolve it, you have the right to lodge a complaint with the data-protection authority in your country of residence. For Ugandan users that's the Personal Data Protection Office (Uganda). Users in the EU/UK can complain to the relevant national supervisory authority.


7. Children

KampalaSnap is not directed at children under 18. We do not knowingly collect personal information from children. If you believe a child has signed up, write to support@kampalasnap.com and we will delete the account.


8. International transfers

Our infrastructure operates from data centres outside Uganda, and backups may be stored across multiple regions. By using KampalaSnap you consent to your personal information being transferred to and processed in those locations. Where required by law, we rely on standard contractual clauses or other recognised transfer mechanisms.


9. Changes to this policy

We update this policy when our practices change. The Last updated date at the top reflects the most recent change. For material changes (new categories of data collected, new third-party processors, weakening of any protection described here) we will notify active users in the app at least 14 days before the change takes effect.


10. Contact

We reply within 7 days to privacy requests and within 24 hours to security reports.