The short version
- ✓We collect only what we need to run the platform and improve your experience.
- ✓We never sell your personal data.
- ✓We use IP geolocation solely to comply with Bank of Ghana currency rules — not to profile you.
- ✓Ghana users have rights under the Data Protection Act 2012 (Act 843).
- ✓You can delete your account and data at any time.
What We Collect
Information you provide
- Name, email address, and phone number
- Billing and payment information (processed securely via Paystack — we never store full card details)
- Travel preferences, itinerary details, and booking history
- Profile information and photos you choose to upload
- Communications you send to us (support requests, feedback)
Automatically collected
- Device information (device type, operating system, browser)
- IP address and approximate geographic location — used solely to determine your currency (GHS for Ghana users, per Bank of Ghana Notice BG/GOV/SEC/2022/04)
- Usage data (pages visited, features used, time spent)
- Referral source and affiliate tracking data
How We Use It
- Provide, maintain, and improve the Service
- Process bookings, payments, and refunds
- Generate personalized travel itineraries using AI
- Send booking confirmations, updates, and customer support communications
- Send promotional emails (with your consent — you can unsubscribe at any time)
- Analyze usage patterns to improve user experience
- Detect and prevent fraud or security incidents
- Comply with legal obligations including Ghana's Data Protection Act (Act 843) and Bank of Ghana directives
We use cookies and similar technologies to enhance your experience, remember preferences, track referral codes, and analyze site traffic. Your IP-based country is cached for 24 hours in your browser's local storage (akw_geo_cache) solely to serve compliant currency pricing without repeated geolocation calls.
You can control cookie preferences through your browser settings. Essential cookies required for site functionality cannot be disabled.
Third-Party Services
Paystack
Payment processing. Handles your payment information securely in accordance with PCI DSS standards. We do not store your full card details.
Supabase
Database and authentication infrastructure. Your account data is stored with encryption at rest.
Resend
Email delivery for transactional and marketing communications.
Vercel
Website hosting and edge network. Processes request headers including IP address.
ipapi.co
IP geolocation used exclusively to determine your country for currency display compliance. No personal profile is created or stored with them.
- With hosts and experience providers to fulfill your bookings (name, contact details, booking info only)
- With service providers as described in Section 4
- To comply with legal obligations, court orders, or government requests (including Ghana DPC inquiries)
- To protect the rights, safety, and property of Akwaaba and its users
- In connection with a merger, acquisition, or sale of assets (you will be notified in advance)
Data Retention
We retain your personal information for as long as your account is active or as needed to provide services. Booking records are retained for a minimum of 3 years for legal and accounting purposes under Ghana Revenue Authority requirements. You may request deletion of your account and data at any time by contacting support@akwaaba.app.
Security
We implement industry-standard security measures including encryption in transit (TLS 1.3), encryption at rest, secure JWT-based authentication with short token lifetimes, and regular security reviews aligned with the Cyber Security Authority of Ghana (Act 1038). However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
Your Rights
All users
- Access, correct, or delete your personal information
- Opt out of marketing communications (unsubscribe link in every email)
- Request a copy of your data in a portable format
- Withdraw consent where processing is based on consent
- Delete your account entirely via Settings → Account → Delete Account
GDPR rights (EU/EEA residents)
You have the right to lodge a complaint with a supervisory authority, restrict or object to processing, and data portability under the General Data Protection Regulation.
CCPA rights (California residents)
You have the right to know what data we collect, request deletion, and opt out of sale (we do not sell personal data), without discrimination for exercising these rights.
Ghana Data Protection Act (Act 843)
DPC Registration
Akwaaba App Labs is registered as a Data Controller with the Ghana Data Protection Commission (dataprotection.org.gh) in compliance with the Data Protection Act 2012 (Act 843).
Under Act 843, Ghana-based data subjects have the following rights:
- Right to be informed about the collection and use of your data
- Right of access — you may request a copy of personal data we hold about you
- Right to correction of inaccurate or incomplete data
- Right to erasure — request deletion of your personal data
- Right to object to processing of your personal data
- Right to complain to the Data Protection Commission at dataprotection.org.gh
To exercise any of these rights, contact our Data Protection Officer at privacy@akwaaba.app. We will respond within 21 days as required by Act 843.
Children's Privacy
Our Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected such information in error, please contact us immediately at privacy@akwaaba.app and we will delete it promptly.
International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including the United States (Supabase, Vercel, Resend infrastructure) and Ghana (Paystack processing). We ensure appropriate contractual safeguards are in place for all international transfers, consistent with Ghana's Data Protection Act and applicable international standards.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website, updating the "Last updated" date, and sending an email notification for significant changes. Continued use of the Service after changes constitutes acceptance.
Contact & Data Protection Officer
For privacy questions, data subject requests, or DPC-related matters: