Privacy Policy
How BOBTechWaves collects, uses, and protects personal data across the Digital Cards Portal and related services.
Privacy Policy
How BOBTechWaves collects, uses, and protects personal data across the Digital Cards Portal and related services.
Overview
This Privacy Policy explains how BOBTechWaves ("we", "us", "our") collects, uses, discloses, and protects personal data when you use the Digital Cards Portal, Events Portal, BuildCost/BOQ Portal, or interact with an event created through our Services.
There are two categories of people this policy covers: Account Holders (the businesses and individuals who register and use the portal) and Participants (event guests whose contact details an Account Holder provides to us so we can generate and deliver their digital card). Where an Account Holder submits Participant Data to us, the Account Holder is the data controller for that data and we act as a data processor on their instructions, consistent with Section 10 of our Terms & Conditions.
What We Collect
From Account Holders
- Name, email address, phone number, and password (stored as a secure hash, never in plain text).
- Business/event details you provide (event name, type, date, venue, client contact details).
- Payment confirmation details relevant to processing your payment (we do not store full card or mobile money PINs - these are handled directly by our payment processor).
- Usage data: login activity, actions taken in the portal, and basic device/ browser information, for security and support purposes.
From / about Participants (your guests)
- Full name.
- Phone number (used for SMS delivery, WhatsApp sending, and phone call confirmation, where your Package includes these).
- Email address, where supplied (used for email delivery of digital cards, where your Package includes this).
- Invitation type and any notes the Account Holder records against them.
- WhatsApp sending status (pending, sent, or failed) and SMS delivery status (pending, delivered, or failed) for their card, the outcome of any confirmation phone call made to them, and, if they attend, their QR check-in record (time and result of scanning).
We do not independently collect Participant Data from any source other than the Account Holder who creates the event.
Why We Collect It
- To create, operate, and secure Account Holder accounts.
- To generate personalised digital cards and QR codes.
- To deliver digital cards and messages via SMS, WhatsApp, Email, and phone call, depending on the Package selected.
- To verify guests at check-in using their QR code.
- To call guests to confirm receipt or attendance, on Packages that include this service.
- To process payments for Services.
- To provide customer support and respond to enquiries.
- To maintain the security, integrity, and proper functioning of the Services, including detecting misuse.
- To comply with legal obligations under Tanzanian law.
We do not use Participant Data for advertising, and we do not sell personal data to any third party.
Third Parties We Share Data With
We share the minimum data necessary with the following categories of service providers, solely to deliver the Services:
| Provider type | Data shared | Purpose |
|---|---|---|
| SMS gateway (e.g. Beem Africa) | Guest phone number, message content, sender name | Deliver digital cards via SMS and track delivery status |
| WhatsApp messaging provider | Guest phone number, card image, message content | Send digital cards via WhatsApp |
| Email delivery provider | Guest email address, card content | Deliver digital cards via email, where selected |
| Payment processor (e.g. Selcom) | Payment amount and reference; payment method details you enter directly with the processor | Process payment for Services |
| Hosting / infrastructure provider | All data stored in the portal, as encrypted at rest where supported | Host and run the Services |
Each of these providers processes data under their own privacy terms; we choose providers that are appropriate for handling personal data and limit what we share with them to what is necessary. We may also disclose data where required by Tanzanian law, court order, or to protect the rights, property, or safety of BOBTechWaves, our Account Holders, or the public.
Confirmation phone calls to guests are made directly by our team using the phone number provided, and are not routed through a third-party voice or call-centre provider.
Data Retention
- Account Holder data is retained for as long as the account is active, and for a reasonable period afterward to comply with legal, accounting, or dispute- resolution needs.
- Participant Data for a given event is retained for the duration of the event lifecycle and a reasonable period after (for reporting and support purposes), after which it may be archived or deleted.
- An Account Holder may request deletion of a completed event's Participant Data at any time, subject to Section 6.
- We may retain limited records beyond these periods where required by law (e.g. financial records) or to resolve disputes.
Your Rights
Subject to Tanzania's Personal Data Protection Act, 2022, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request deletion of your data, subject to our legal and contractual retention obligations.
- Object to or restrict certain processing of your data.
- Withdraw consent where processing is based on consent, without affecting processing carried out before withdrawal.
Participants who wish to exercise these rights over their own data should contact the Account Holder who created the event, as they control that data; the Account Holder may relay the request to us. Account Holders may contact us directly using the details in Section 12.
Security Measures
We apply the following safeguards across the Services:
No system is perfectly secure. We cannot guarantee absolute security of data transmitted to us, and you provide data at your own risk. We will notify affected Account Holders without undue delay if we become aware of a data breach affecting their data, as required by applicable law.
Cookies & Sessions
We use strictly necessary session cookies to keep you signed in and to protect against cross-site request forgery. We do not use third-party advertising or tracking cookies. If you choose "Remember me" at login, a longer-lived cookie is used to keep you signed in on that device; you can revoke this at any time by logging out.
Children's Data
The Services are intended for use by adults creating and managing events. Where an event (for example, a birthday or graduation) includes minors as Participants, the Account Holder is responsible for ensuring they have appropriate parental or guardian consent to provide that minor's contact details to us for card delivery. We do not knowingly collect personal data directly from children, and Account Holder registration is not intended for use by minors.
Cross-Border Transfers
Some Third-Party Providers we use (SMS gateways, WhatsApp messaging infrastructure, hosting) may process or route data through servers located outside Tanzania. Where this occurs, we take reasonable steps to use providers with appropriate safeguards for personal data. By using the Services, you acknowledge that data may be processed outside Tanzania as necessary to deliver the Services.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be indicated by updating the "Last updated" date above. Continued use of the Services after a change takes effect constitutes acceptance of the revised policy.
Contact Us
For any question about this Privacy Policy, or to exercise a data protection right, contact:
- BOBTechWaves - Dar es Salaam, Tanzania
- Phone / WhatsApp: +255 656 345 149
- Email: info@bobtechwaves.co.tz
- Website: bobtechwaves.co.tz
See also our Terms & Conditions.