Privacy Policy
Who We Are
Limba is a marketplace and parcel delivery platform that connects shoppers, travelers, and local businesses. We operate the Limba mobile application (available on Android and iOS) and the website at trylimba.com.
For the purposes of applicable data protection law, Limba is the data controller responsible for your personal information. Our contact details are in Section 14.
Information We Collect
We collect information in three ways: information you give us directly, information generated by your use of our services, and information from third parties.
Information you provide
| Category | Examples | When collected |
|---|---|---|
| Account details | Full name, email address, phone number, country | Registration |
| Password | Stored as a bcrypt hash — we never store your password in plain text | Registration |
| Profile | Profile photo | Optional, any time |
| Identity (KYC) | Government-issued ID scan, facial selfie | KYC verification (required for withdrawals) |
| Financial | Mobile money phone number and operator; card details are handled entirely by Fincra and never stored by Limba | Deposits and withdrawals |
| Communications | Messages sent via in-app chat | When you message another user |
| Support | Content of support requests, dispute descriptions | When you contact us |
Information generated automatically
- Device information: Device type, operating system version, unique device identifiers, and app version.
- Usage data: Features you interact with, pages viewed on the website, session duration, and crash reports.
- Location data: Approximate location (IP-based) for fraud prevention; precise GPS location only when you explicitly grant permission and only while using delivery-related features.
- Log data: IP address, timestamps, and HTTP request metadata when you use our website or API.
- Push tokens: Firebase Cloud Messaging token used to deliver push notifications to your device.
Information from third parties
- Fincra: Payment status and transaction identifiers from our payment processor.
- Firebase: Analytics and crash data from Google Firebase services.
How We Use Your Information
| Purpose | Legal basis | Data used |
|---|---|---|
| Creating and managing your account | Contract performance | Name, email, phone, password |
| Processing transactions and operating your wallet | Contract performance | Transaction history, payment details |
| Verifying your identity (KYC) | Legal obligation & contract | ID document, selfie |
| Fraud detection and security | Legitimate interest | Device info, IP, usage patterns |
| Sending transactional notifications | Contract performance | Email, push token |
| Customer support and dispute resolution | Contract performance & legitimate interest | Account info, communications |
| Improving our services | Legitimate interest | Anonymised usage data, crash reports |
| Legal compliance | Legal obligation | All data as required |
| Marketing communications | Consent | Email — only if you opt in |
We do not sell your personal data to third parties. We do not use your data to train AI or machine learning models.
Payment Processing
All payment transactions on Limba — including wallet top-ups via mobile money or card, and withdrawals to mobile money — are processed by Fincra, our licensed payment service provider. When you make a payment:
- Mobile money: Your phone number and operator are sent to Fincra to initiate a USSD payment prompt. Limba stores your phone number to process the request; Fincra retains it subject to their own privacy policy.
- Card payments: You enter your card details on a secure Fincra-hosted page that opens inside the Limba app. Your card number, expiry, and CVV are transmitted directly to Fincra and are never stored on Limba's servers.
Limba stores only the outcome of transactions (amounts, timestamps, status) and Fincra's internal reference identifiers — never raw card data.
Identity Verification (KYC)
To comply with financial regulations and protect our users against fraud, we require identity verification ("Know Your Customer" or KYC) before enabling wallet withdrawals. This involves:
- A scan or photo of a valid government-issued identity document (national ID, passport, or driver's licence).
- A real-time selfie used to verify that the document matches the person submitting it. We use on-device face detection technology; the selfie is captured via your camera but your biometric data is not stored as a biometric template.
KYC documents are stored securely and are accessible only to authorised Limba staff for the purpose of verification. They are not shared with third parties except where required by law. Documents are retained for a minimum of five years after account closure to satisfy regulatory requirements.
Location Data
The Limba app may request access to your device's location for the following purposes:
- Delivery features: To help you set accurate pickup and drop-off points when creating or accepting a parcel delivery request.
- Fraud prevention: To detect unusual account activity from unexpected geographic locations.
Location access is always optional and must be explicitly granted by you through your device's permission system. You can revoke location access at any time through your device settings. The Limba website uses only IP-based approximate location and does not access your device's GPS.
We do not sell, share, or use location data for advertising purposes.
Communications & Notifications
Push notifications
We use Firebase Cloud Messaging (a Google service) to deliver push notifications to your device. These notifications include payment confirmations, order status updates, new messages, and delivery alerts. You can disable push notifications at any time in your device settings or within the Limba app under Settings → Notifications.
We send transactional emails (e.g. OTP codes, payment receipts, security alerts) to the email address you registered with. These are essential to the service and cannot be opted out of while your account is active.
We only send promotional or marketing emails if you have explicitly opted in. You can unsubscribe from marketing emails at any time by clicking the unsubscribe link in any such email.
In-app video and audio calls
Limba offers in-app video and audio calling between users. Calls are facilitated using WebRTC technology. Audio and video streams are transmitted peer-to-peer where possible; metadata (call initiation, duration) is processed by our servers. Calls are not recorded or stored by Limba.
Your camera and microphone are only accessed during active calls and only with your explicit permission.
Sharing Your Information
We do not sell your personal data. We share your information only in the following circumstances:
With other Limba users
When you participate in a transaction (e.g. as a shopper or traveler), your name and profile photo are visible to the other party. Your contact details are not shared unless you choose to share them in chat.
With service providers
- Fincra — payment processing
- Google Firebase — push notifications, crash reporting, and analytics
- Hosting infrastructure — our servers and database providers process data on our behalf under confidentiality agreements
For legal reasons
We may disclose your information if required to do so by law, court order, or governmental authority, or if we believe disclosure is necessary to protect the safety of any person, prevent fraud, or enforce our Terms of Service.
Business transfers
If Limba is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you before your data is transferred and becomes subject to a different privacy policy.
Data Security
We implement industry-standard technical and organisational measures to protect your personal data, including:
- Encryption in transit: All communication between your device and our servers uses TLS 1.2 or higher. The Limba app enforces certificate pinning on our production domain, preventing interception by unauthorised parties.
- Encryption at rest: Sensitive data including passwords (stored as bcrypt hashes) and authentication tokens are stored in encrypted form.
- Secure token storage: Authentication tokens on your device are stored using the iOS Keychain and Android Keystore, isolated from other apps.
- Access controls: Access to personal data is limited to authorised Limba staff who require it to perform their role. Admin actions are logged.
- Two-factor authentication: Administrative access to our systems requires two-factor authentication.
No method of transmission over the internet is 100% secure. While we take your security seriously, we cannot guarantee absolute security and encourage you to use a strong, unique password and keep your device updated.
Data Retention
| Data type | Retention period |
|---|---|
| Account information | For the lifetime of your account, plus 30 days after deletion request |
| Transaction records | 7 years (financial regulatory requirement) |
| KYC documents | 5 years after account closure (regulatory requirement) |
| Chat messages | For the lifetime of the conversation, deleted upon account deletion request |
| Server logs | 90 days |
| Crash & analytics data | 90 days (anonymised after 30 days) |
| Deactivated session tokens | Immediately purged |
When you request account deletion, we will delete or anonymise your personal data within 30 days, except where we are required by law to retain it (such as transaction records).
Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your account and personal data (subject to legal retention requirements).
- Restriction: Request that we restrict processing of your data in certain circumstances.
- Portability: Receive your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interests.
- Withdraw consent: Where processing is based on consent (e.g. marketing emails), withdraw that consent at any time.
To exercise any of these rights, contact us at privacy@trylimba.com. We will respond within 30 days. You can also delete your account directly from the Limba app under Settings → Account → Delete Account.
Children's Privacy
Limba is not directed at individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. If we become aware that we have collected personal data from a minor without verifiable parental consent, we will delete that information promptly.
If you believe a minor has provided us with personal data, please contact us at privacy@trylimba.com.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:
- Update the "Last updated" date at the top of this page.
- Notify you by email or in-app notification at least 14 days before the changes take effect.
- Where required by law, seek your renewed consent.
Continued use of the Limba app or website after changes take effect constitutes your acceptance of the updated policy.
Contact Us
For any questions, concerns, or requests related to this Privacy Policy or your personal data, please contact us:
- Email: privacy@trylimba.com
- General enquiries: contact@trylimba.com
- Website: trylimba.com
We aim to respond to all privacy-related requests within 30 days.
