What personal data we collect, why, who we share it with, how long we keep it, and the choices and rights you have. Written to match what the Platform actually does.
This document is governed by the laws of Uganda. If you have a question about it, write to hello@wellnesstobook.com.
1. Who is responsible for your data
Wellness to Book is the data controller for personal data collected through the Platform. We process personal data in accordance with the Data Protection and Privacy Act, 2019 and the Data Protection and Privacy Regulations, 2021, which are overseen in Uganda by the Personal Data Protection Office.
Questions, requests or complaints: hello@wellnesstobook.com.
2. What we collect
a. Information you give us
- Account — name, email, phone number, password, and whether you are a Client or Provider.
- Profile — photo, location (city and area), languages, about text.
- Onboarding answers — the questions we ask when you join. Some are optional and some are sensitive by nature (for example a health condition you choose to disclose so a Provider can serve you safely).
- Booking details — the address for an in-home service, the date and time, and any notes you add.
- Messages — chat between Clients and Providers, including voice notes and images sent in chat.
- Reviews — ratings and written feedback.
- Support — what you tell us when you contact us or report someone.
b. Identity verification data (sensitive)
If you apply to be verified, we collect:
- Identity or business documents — for example a national ID or passport, a trading licence, or a business registration certificate, and the document number.
- A selfie for mobile providers, and for the Client blue tick, two selfies.
A facial image used to confirm that you are a real, specific person is biometric data and is treated as special personal data under the Data Protection and Privacy Act, 2019. We only collect it with your explicit consent, which we ask for before you submit anything, and you can decline — you simply will not receive a verified badge.
c. Information collected automatically
- Device and usage — app version, device type, pages and services viewed, searches made.
- Approximate location — from your device (only if you allow it) or from your IP address, used to show services near you and to apply Provider privacy zones. Your coordinates are rounded and held only for your current session; we do not build a location history for you.
- Live tracking — during an active booking, a mobile Provider's approximate position may be shared with that Client for the duration of the journey only.
- Cookies — see our Cookie Policy.
d. Payment information
Mobile money numbers and payment references are processed to complete a transaction. Card details are entered directly with our licensed payment partners — we never see or store full card numbers.
3. Why we use it, and our lawful basis
| What we do | Why | Lawful basis |
|---|---|---|
| Create and run your account | To let you use the Platform | Performance of a contract |
| Take and manage bookings | To connect you with a Provider and complete the service | Performance of a contract |
| Process payments and payouts | To charge, refund and pay Providers | Contract; legal obligation |
| Verify identity and business documents | Trust and safety; to reduce fake profiles and fraud | Consent (for biometric data); legitimate interest; legal obligation where anti-money-laundering rules apply |
| Show services near you and recommend services | To make the Platform useful | Legitimate interest; consent for precise device location |
| Enable chat between Client and Provider | To arrange a booking safely on-platform | Performance of a contract |
| Investigate reports, disputes and safety incidents | To protect people using the Platform | Legitimate interest; legal obligation |
| Send booking notifications | So you know what is happening with your booking | Performance of a contract |
| Send marketing and personalised digests | To tell you about relevant services | Consent — you can unsubscribe at any time |
| Keep accounting and tax records | Because the law requires it | Legal obligation |
4. Automated checks on verification images
We use automated image analysis to help review verification submissions. It checks image quality, whether an image appears artificially generated or manipulated, and whether a selfie matches the profile photo.
These checks involve third-party artificial-intelligence providers, and some of them operate outside Uganda. The current providers and their locations are listed in the table below, and are also shown to you on the consent screen before you submit anything.
Two safeguards matter here:
- No decision is made about you by a machine alone. An automated check can flag a submission, but approval, rejection and suspension are reviewed by a person on our team. You may ask us to explain a decision and to review it again.
- You can decline. Verification is optional. If you do not consent, we do not send your images anywhere — you simply do not get a verified badge.
5. Who we share data with
- The other party to your booking. A Provider sees the name, phone number, address and booking notes they need to deliver your service. A Client sees the Provider's public profile.
- Service providers who work for us (processors), listed below. They may only use the data to provide their service to us.
- Payment and mobile money partners, to take payment and make payouts.
- Authorities, where we are legally required to disclose, or where it is necessary to prevent serious harm or investigate a crime.
- A buyer or successor, if the business is sold or reorganised. We would tell you first.
We do not sell your personal data.
Who processes data for us
| Who | What they do for us | What they see |
|---|---|---|
| Hostinger (hosting) | Runs our servers and database | Platform data at rest |
| Flutterwave and mobile money operators (MTN, Airtel) | Take payments and make payouts | Payment details, amounts, phone numbers |
| Pusher | Delivers chat messages in real time | Chat content in transit |
| Google Firebase | Push notifications to the apps | Device tokens, notification content |
| Email delivery provider | Sends booking and account emails | Email address, message content |
| OpenAI (United States) | Automated checks on verification images | Identity document images, selfies |
If we add or change a processor that handles verification images, the consent screen and this table update together — the list above is generated from what is actually switched on.
6. Sending data outside Uganda
Some of the services above are located outside Uganda. That means some personal data — including, for verification, your identity document and selfie — is transferred outside the country for processing.
Under section 19 of the Data Protection and Privacy Act, 2019, personal data may be processed outside Uganda where the receiving country has adequate protection or where you have consented to the transfer. For verification images we rely on your explicit consent, which we ask for separately, and which names the processors and their countries at the time you give it. You may withdraw that consent by deleting your account, which deletes those images.
7. How long we keep things
| Data | How long |
|---|---|
| Account and profile | While your account is open |
| Identity documents and selfies | While your account is open and verified. Deleted when you delete your account. Rejected submissions are deleted after 90 days. |
| Bookings, invoices and payment records | Retained after account closure where tax and accounting law requires it |
| Chat messages | While your account is open, and longer if needed for an open dispute or safety investigation |
| Reviews | May remain visible after account closure, shown without your personal details |
| Approximate session location | Your current session only |
8. Your rights
Under the Data Protection and Privacy Act, 2019 you have the right to:
- Be told what we hold about you and why — that is what this document is for.
- Access a copy of your personal data.
- Correct anything inaccurate — most of it you can edit yourself in your profile.
- Delete your account and personal data. See Delete your account. Your identity documents, selfies and verification records are actually deleted. Booking and payment records are kept only where the law requires.
- Object to processing based on our legitimate interests, and to stop marketing at any time.
- Withdraw consent where we relied on it, including consent for verification images.
- Complain to us, and to the Personal Data Protection Office in Uganda if you are not satisfied with our answer.
To exercise any of these, write to hello@wellnesstobook.com. We will respond within the time the law allows and may ask you to confirm your identity first.
9. How we protect data
- Traffic is encrypted in transit (HTTPS).
- Identity documents and selfies are stored outside the public web area of our servers and are released only to you or to a member of our verification team through an authenticated request. They are not reachable by a public link.
- Access to verification material inside our team is restricted by permission.
- In our Android apps, chat screens are marked secure so the operating system blocks screenshots and screen recording. This protection is not available on the website, and no platform can stop someone photographing a screen with another device.
- No system is perfectly secure. If a breach occurs that is likely to harm you, we will notify you and the Personal Data Protection Office as the law requires.
10. Children
The Platform is for people aged 18 and over. We do not knowingly collect data from children. A service may be booked for a person under 18 only where a parent or guardian arranges it and is present. If you believe a child has given us data, contact us and we will delete it.
11. If you are outside Uganda
The Platform is operated from Uganda and intended for services delivered in Uganda. If you access it from elsewhere, you do so on your own initiative. Where the data-protection law of your country applies to us — for example the GDPR in the European Union or the UK GDPR — we will honour the rights it gives you, including access, correction, deletion, objection and portability. Write to us and say which country you are in.
12. Changes
If we change how we use personal data, we will update this page and the date at the top, and tell you in the app or by email where the change is significant. Where a change requires your consent, we will ask for it again rather than assume it.
13. Contact
Wellness to Book — hello@wellnesstobook.com — https://wellnesstobook.com