Effective 6 September 2026
Privacy Policy
This policy explains what Hajenda collects, why it is used, where it is shared, and the choices available to providers and booking clients.
Information we collect
Provider data includes name, email, business profile, service catalogue, availability, plan status, notification tokens, and verified settlement metadata. Hajenda stores only the masked last four account digits and the verified account name—not the full bank account number after setup. Client booking data includes name, required email, WhatsApp number, optional note, selected service or package, appointment time, and payment references. We also process security and operational logs.
How we use information
We use data to create accounts, display booking pages, generate available slots, prevent double-booking, process and reconcile payments and refunds, send confirmations and reminders, provide support, detect abuse, meet legal obligations, and improve reliability.
Service providers
Necessary data may be processed by Paystack for client payments and web subscriptions, Google Play and RevenueCat for Android subscriptions, cloud hosting and PostgreSQL providers, Cloudflare R2 for business logos, and email or notification delivery providers. Each receives only the information needed for its role.
Storage and security
Business images are stored in object storage, not in the database. Passwords are hashed. Access to provider APIs requires authentication, sensitive configuration stays server-side, and payment webhooks are verified and processed idempotently. No system is risk-free, so suspected incidents are investigated and handled under the incident process.
Retention
We keep account and booking information while needed to provide the service and for applicable tax, payment, dispute, fraud-prevention, and legal obligations. Data that is no longer required is deleted or de-identified. Exact retention periods are documented in Hajenda’s internal retention schedule.
Your choices
You may update your profile, change notification permission, manage subscriptions in the billing channel used, and request access, correction, export, or deletion of your personal data. Providers are responsible for responding to client requests concerning booking information they control.
Children
Provider accounts are restricted to adults aged 18 or older. Hajenda is not designed for children to operate commercial provider accounts.
Contact
Privacy and deletion requests can be sent to [email protected]. See the account deletion instructions.
