Privacy Policy
Privacy Policy for Hebron Connect
Data Collection & Processing Overview
Personal Information Collected
Identity Data: First name, last name, email address, phone number
Profile Data: Profile images, profile thumbnails, user preferences
Authentication Data: Passwords (hashed), OTP codes, device tokens
Communication Data: Room messages, announcements, questions/answers
Financial Data: Wallet balances, transaction amounts, payment methods, mobile money details
Usage Data: Device information, IP addresses, access logs, API usage patterns
Content Data: Room documents, event images, contribution details, room descriptions
Data Processing Activities
User Registration & Verification: Phone number verification via SMS/WhatsApp OTP
Financial Transactions: Mobile money processing (MTN, Orange Money)
Real-time Communications: Push notifications, email notifications, WhatsApp messaging
File Storage: Document and image storage via AWS S3
Room Management: Member management, role assignments, access control
Event Organization: Event creation, scheduling, and management
Contribution Tracking: Financial contribution monitoring and verification
Privacy Policy Structure Requirements
1. Introduction & Scope
Clear statement about data collection and processing
Applicability to all users (room owners, admins, members)
Contact information for privacy inquiries
Last updated date and version control
2. Information We Collect
Personal Information: Names, emails, phone numbers, profile data
Financial Information: Wallet balances, transaction history, payment methods
Communication Data: Messages, announcements, documents shared in rooms
Technical Information: Device tokens, IP addresses, browser information
Usage Analytics: How users interact with the platform
3. How We Use Your Information
Account Management: User registration, authentication, profile management
Service Delivery: Room creation, member management, event organization
Financial Processing: Mobile money transactions, contribution tracking
Communication: Sending OTPs, notifications, updates
Security: Fraud prevention, account security, data protection
Service Improvement: Analytics, feature development, user experience enhancement
4. Data Sharing & Third-Party Services
Mobile Money Providers: MTN Mobile Money, Orange Money (transaction processing)
Communication Services:
Twilio (SMS, WhatsApp messaging)
Meta WhatsApp Business API
Email service providers
Cloud Storage: AWS S3 (document and image storage)
Push Notifications: Firebase (device notifications)
Payment Processing: Maviance S3P API (financial transactions)
Analytics: Usage tracking and performance monitoring
5. Data Security Measures
Encryption: Data encryption in transit and at rest
Access Controls: Role-based access to sensitive data
Authentication: Multi-factor authentication via OTP
Secure APIs: Laravel Passport authentication
Regular Audits: Security monitoring and vulnerability assessments
Data Backup: Secure backup and recovery procedures
6. Data Retention
Account Data: Retained while account is active
Financial Records: Retained for legal and regulatory compliance
Communication Data: Retained based on room settings and user preferences
Deleted Accounts: Soft delete with data retention for recovery purposes
Transaction Records: Long-term retention for audit and compliance
7. User Rights & Controls
Access Rights: View and download personal data
Correction Rights: Update profile information and preferences
Deletion Rights: Request account deletion (with limitations for financial data)
Data Portability: Export personal data in standard formats
Communication Preferences: Opt-out of non-essential communications
Room Privacy: Control room visibility and member access
8. Financial Data Specifics
Mobile Money Integration: Data sharing with MTN and Orange Money
Transaction Monitoring: Fraud detection and compliance monitoring
Wallet Security: Multi-layer security for financial data
Audit Trails: Complete transaction history and logging
Regulatory Compliance: Adherence to financial data protection laws
9. International Data Transfers
AWS S3: Data storage in secure cloud infrastructure
Third-Party APIs: Data sharing with international service providers
Adequacy Decisions: Compliance with international data protection standards
Safeguards: Appropriate measures for cross-border data transfers
10. Children's Privacy
Age Restrictions: Minimum age requirements for account creation
Parental Consent: Requirements for users under legal age
Data Protection: Special protections for minors' data
Verification: Age verification processes
11. Cookies & Tracking
Essential Cookies: Required for platform functionality
Analytics Cookies: Usage tracking and performance monitoring
Preference Cookies: User settings and preferences
Third-Party Cookies: Integration with external services
Cookie Management: User control over cookie preferences
12. Communication & Notifications
OTP Delivery: SMS, WhatsApp, and email verification
Push Notifications: Real-time updates and alerts
Email Communications: Service updates and important notices
WhatsApp Integration: Business messaging and notifications
Opt-out Options: User control over communication preferences
13. Room Privacy & Data Sharing
Private Rooms: Data visibility within room boundaries
Member Access: Who can see what information in rooms
Document Sharing: Privacy controls for shared files
Event Information: Privacy settings for event details
Financial Transparency: Balance visibility for room admins/owners
14. Legal Basis for Processing
Contract Performance: Necessary for service delivery
Legitimate Interests: Service improvement and security
Consent: Marketing communications and optional features
Legal Obligations: Compliance with financial regulations
Vital Interests: Account security and fraud prevention
15. Updates & Changes
Policy Updates: How users will be notified of changes
Version Control: Clear versioning and change tracking
User Consent: Requirements for material changes
Effective Dates: When changes take effect
16. Contact Information
Privacy Officer: Designated privacy contact
Data Protection Authority: Relevant regulatory body
Support Channels: How to reach privacy support
Response Times: Expected response timeframes
Terms and Conditions
Privacy Policy FAQs
What is a privacy policy?
A privacy policy outlines how personal data is collected, used, and protected by a platform.
Why is it important?
It ensures transparency and builds trust with users regarding their sensitive information handling.
How is data protected?
Data is protected through encryption, secure access controls, and compliance with legal regulations to safeguard user information.
Who needs a privacy policy?
Any platform handling personal data should have a privacy policy to comply with laws.
What is Hebron Connect?
Hebron Connect is a community management platform facilitating financial collaboration and secure data sharing.
How often should it be updated?
Privacy policies should be reviewed and updated regularly to reflect changes in data practices and regulations.
Contact Us
Get in touch for privacy policy inquiries and platform support at Hebron Connect.
Privacy Policy Subscription
Stay updated on privacy compliance solutions.
