Legal
Privacy Policy
Effective Date: December 6, 2024 | Last Updated: July 8, 2026
Introduction
Welcome to Defolt Labs. This Privacy Policy explains how Defolt Labs Limited (registered in Tanzania, Reg. No. 191146913, registered with the Personal Data Protection Commission of Tanzania under registration number 0-000-007-324) collects, uses, protects, and handles your information across our products.
We believe privacy is a right, not a luxury. We only collect what we need to deliver our services, and we don't use your data for advertising, profiling, or any purpose beyond what you signed up for.
This policy applies to:
- Nyaraka: our document automation platform (hosted by Defolt Labs).
- Vinono: our escrow marketplace for custom cakes (hosted by Defolt Labs).
- Defolt Retail System (DRS): our self-hosted retail management system (runs on your server). Special note: for DRS, most of your business data lives on your own infrastructure and is not seen by Defolt Labs. See the DRS section below.
- defoltlabs.com and any future Defolt Labs product.
If you have questions about this policy, please contact us at info@defoltlabs.com.
Our Role Under the Personal Data Protection Act
Under the Tanzanian Personal Data Protection Act, 2022, we act in different roles depending on the product:
- Nyaraka: Defolt Labs decides why and how your personal data is processed. We are the Data Controller for your Nyaraka account, wallet, and any documents you save with us.
- Vinono: Defolt Labs decides why and how buyer and baker personal data are processed on the marketplace. We are the Data Controller for Vinono accounts, orders, payouts, and reviews.
- DRS: Your shop's data (customers, sales, inventory, staff) lives on your server. When you run DRS, you are the Data Controller for that data. Defolt Labs is the Data Controller only for the subscription-billing data you provide directly to us (owner name, email, phone, payment history).
What Data We Collect
We collect only the information necessary to provide our services. Here is what we may collect, grouped by product.
1. Account Information (all hosted products)
When you create an account with Nyaraka or Vinono, we collect:
- Full name.
- Email address.
- Phone number (optional for Nyaraka, required for Vinono buyers and bakers so we can reach you about your order).
- Company name (optional).
- Password (hashed with bcrypt; never stored in plain text).
2. Nyaraka: Document Generation Data
When you use Nyaraka to generate documents, you may provide:
- Customer names and contact information.
- Business addresses.
- Invoice details (amounts, descriptions, dates).
- Custom text, logos, or branding elements.
- Any other content you choose to include in your documents.
Important: this data is only used to generate your documents. Unless you explicitly choose to save a document to your account, this content is deleted immediately after generation.
3. Vinono: Marketplace Data
On Vinono we hold additional data specific to buying and selling cakes:
For buyers:
- Delivery addresses (street, city, phone contact for delivery).
- Order history (items, dates, amounts, statuses).
- Pickup PINs (encrypted at rest; only you can view yours).
- Review content you post about bakers you have ordered from.
- Payment channel identifiers (for example, the M-Pesa number used to pay). Full card or wallet credentials are handled by our licensed payment partner; we do not store them.
For bakers:
- Baker profile (display name, bio, city, shelf items and photos).
- Payout channel (for example, MPESA:0712345678). Displayed to you in masked form when shown outside your own account.
- Earnings and payout history.
- Aggregate ratings and review counts.
- Optional identity documents you upload as part of onboarding (for example, NIDA or TIN), used only to verify you.
4. Transaction and Billing Data
To process payments and maintain billing records, we collect:
- Nyaraka wallet top-up amounts and transaction history.
- Vinono order-level ledger entries (gross, commission, payout).
- DRS subscription invoices and payment status.
- Payment references from our payment partner. We do not store full card numbers or mobile-money PINs.
- Usage-based billing logs (documents generated, API calls made).
5. Templates You Create (Nyaraka)
If you build templates in the Nyaraka workshop:
- Template designs and layouts.
- Template metadata (name, category, description).
- Which templates you use to generate documents.
6. API Developer Data (Nyaraka)
If you use the Nyaraka API:
- API keys (generated by you, managed in your dashboard).
- API usage logs (endpoints called, request timestamps, response codes).
- Developer documentation access history.
7. DRS: What We Do and Do Not Collect
Because DRS runs on your own server, the split is important:
What Defolt Labs collects and holds about your DRS install:
- Owner / billing contact name, email, phone.
- Subscription invoice history and payment status (via Selcom).
- Grace-lock state pings your install sends us to confirm subscription status.
- Bug reports, support tickets, and any logs or screenshots you attach to them.
What stays on your server and never reaches Defolt Labs:
- Product catalogue, brands, categories, suppliers.
- Batches, cost prices, FIFO ledger.
- Customer names or contact details you record in DRS.
- Sales, till receipts, cashier and supervisor overrides.
- Reports, dashboards, exports (unless you send them to us for support).
For that shop data, you are the Data Controller under the Personal Data Protection Act, 2022. Your obligations toward your own customers and staff (retention, subject access requests, data breach notifications) are yours, not ours. We are happy to help you meet them, but we cannot exercise them for you because we do not hold the data.
8. Automatically Collected Data
When you visit our website or use our hosted services (Nyaraka, Vinono), we automatically collect:
- IP address.
- Browser type and version.
- Device information (type, operating system).
- Pages visited and time spent.
- Referral source (how you found us).
We use this data only for technical diagnostics, security monitoring, and service improvement, not for advertising or tracking.
How We Use Your Data
We process your data solely to deliver the services you requested. Here's how:
Service Delivery
- Account management: to create, maintain, and secure your account.
- Document generation (Nyaraka): to produce the documents you request based on your input.
- Order lifecycle (Vinono): to route an order from draft, through payment and escrow, to PIN release and payout.
- Subscription and grace-lock (DRS): to keep your DRS install in the correct lock state based on payment status.
- Billing & payments: to process wallet top-ups, order payments, or monthly subscriptions, and to generate invoices.
- API access: to authenticate your requests and provide programmatic access to our platform.
- Customer support: to respond to your inquiries and troubleshoot issues.
Security & Compliance
- Fraud prevention: to detect and prevent unauthorized access, abuse, or fraudulent transactions (including self-purchase on Vinono).
- Legal compliance: to comply with applicable Tanzanian laws, regulations, and legal processes.
- Audit & record keeping: to maintain financial records for accounting and tax purposes.
Service Improvement
- Error monitoring: to identify and fix technical issues.
- Performance optimization: to improve speed, reliability, and user experience.
- Feature development: to understand which features are most valuable and build better tools.
What we DON'T do with your data:
- ❌ We do not use your data for targeted advertising.
- ❌ We do not sell, rent, or trade your data to third parties.
- ❌ We do not build user profiles or track you across the web.
- ❌ We do not use your data for analytics beyond service improvement.
- ❌ We do not share your data with marketers or data brokers.
Who We Share Data With
We share the minimum data necessary with a small number of service providers so that our products work:
- Selcom Mobile: licensed Tanzanian payment institution. Handles escrow for Vinono, wallet top-ups for Nyaraka, and DRS subscription billing. Receives buyer / payer name, phone, order reference, and amount.
- Pesapal: where used, licensed regional payment processor. Same scope as above.
- Cloud infrastructure providers: host our hosted services (Nyaraka, Vinono). Under contract not to access your data.
- Google (Sign-in with Google): when you choose that sign-in method, Google receives sign-in metadata; we receive your name and email from Google.
- Regulators and courts: where required by law, court order, or a lawful request from a Tanzanian government authority.
Document Generation Data Policy (Nyaraka)
This is the most important part of our Nyaraka privacy commitment.
Temporary Processing by Default
When you generate a document using Nyaraka:
- You provide data (names, addresses, invoice details, etc.).
- We process that data to generate your document (PDF, HTML, etc.).
- You receive the document.
- We immediately delete the input data unless you choose to save it.
Optional Document Storage
You may choose to save documents to your account for future reference. If you do:
- The document and its associated data are stored in your account.
- You can access, download, edit, or delete saved documents at any time.
- Saved documents remain in your account until you delete them or close your account.
Exception: Transaction Records
Even if you don't save a document, we keep transaction logs (e.g., "User generated 1 invoice on [date], cost: 500 TSH"). These logs are necessary for billing accuracy, fraud prevention, and financial auditing.
Data Security
We take data security seriously and implement industry-standard practices to protect your information.
Encryption
- In transit: all data transmitted between your device and our servers is encrypted using TLS.
- At rest: sensitive data (passwords, API keys, saved documents, Vinono PINs) is encrypted in our databases.
Access Control
- Access to user data is restricted to authorized personnel only.
- We use role-based access controls and multi-factor authentication for internal systems.
- Contractors and service providers sign confidentiality agreements.
No system is 100% secure. While we do everything reasonably possible to protect your data, you should also take precautions (use strong passwords, enable two-factor authentication, don't share API keys or PINs).
Your Rights Under the Personal Data Protection Act
You have the following rights regarding personal data we hold about you:
1. Right to Access
You can request a copy of all personal data we hold about you. We will provide this in a machine-readable format (JSON, CSV).
2. Right to Correction
If any of your personal data is inaccurate or incomplete, you can update it in your account settings or contact us for assistance.
3. Right to Deletion
You can request deletion of your account and associated data, except transaction records (required for legal compliance) and anonymized or aggregated data used for analytics.
4. Right to Data Portability
You can export your saved documents, templates, orders, and account data at any time from your dashboard.
5. Right to Lodge a Complaint
You may lodge a complaint with the Personal Data Protection Commission of Tanzania if you believe your rights have been infringed. Details: pdpc.go.tz.
How to Exercise Your Rights
To exercise any of these rights:
- Email us: info@defoltlabs.com
- Subject line: "Data Subject Request - [Your Name]"
- Include: your account email, the specific right you're exercising, and any relevant details.
We will respond within 30 days (or sooner if required by law).
If your request relates to shop data in a DRS install, please talk to the owner of that install. That data lives on their server, not ours (see §7 above).
Data Retention Overview
Here's a summary of how long we keep different types of data:
| Data Type | Retention Period | Reason |
|---|---|---|
| Account information | Until account deletion | Service delivery |
| Nyaraka document input (unsaved) | Immediately deleted | Privacy by design |
| Nyaraka saved documents and templates | Until you delete or close account | User choice |
| Vinono order history and reviews | Order: 7 to 10 years; reviews: FIFO-capped at 1,000 per baker | Legal + platform integrity |
| Vinono pickup PINs | 72 hours after delivery | PIN handshake window |
| Transaction records (all products) | 7 to 10 years (or as required by law) | Legal compliance, audit |
| Nyaraka API usage logs | 12 months | Billing, abuse prevention |
| DRS shop data (on your server) | You decide | You are the Controller |
| DRS subscription billing records | 7 to 10 years | Legal compliance, audit |
Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
Defolt Labs Limited
Wastaafu St, Mikocheni
Kinondoni, Dar es Salaam, Tanzania
Registration No.: 191146913
PDPC Registration: 0-000-007-324
Email: info@defoltlabs.com
Website: defoltlabs.com
Phone: +255 797 140 800
For data subject requests (access, deletion, correction), please use the subject line: "Data Subject Request - [Your Name]"
We will respond within 30 days.
Thank you for trusting Defolt Labs with your data. We take that responsibility seriously.
If you have feedback on how we can improve our privacy practices, we'd love to hear from you at info@defoltlabs.com.
This policy is designed to be transparent, fair, and easy to understand. If any part is unclear, please don't hesitate to reach out.
Also see: Terms of Service
