Legal

Privacy policy.

What we collect, why, who else sees it, and how to get it corrected, exported, or deleted.

Last updated .

Who this applies to.

This policy covers personal data SenteMe handles for three groups: people who create a campaign (coordinators), people who contribute to one (contributors), and visitors who browse public pages. SenteMe is operated by Mea Global Inc, a Delaware-registered corporation. Mea Global Inc is the data controller for everything described below. Where mobile-money or other payment partners are also data controllers, or where our email and infrastructure providers act as processors, they appear by name in the relevant section.

Governing law.

Mea Global Inc is a US legal entity, so this policy is governed in the first instance by US federal privacy and consumer-protection law and by the laws of the State of Delaware where the company is incorporated. Because SenteMe serves users across Africa, Europe, and other regions, additional privacy regimes apply on top of the US baseline based on where each user sits: the Uganda Data Protection and Privacy Act 2019 (and equivalent acts in Kenya, Rwanda, and the other countries we operate in) for African users; the EU and UK GDPR for European users and EU/UK residents in the diaspora; the California Consumer Privacy Act (CCPA / CPRA) for California residents. Where one of these regional regimes gives you stronger rights than the US baseline does, those stronger rights apply, local law tops US law in your favour, not the other way around.

What we collect.

When you create an account we collect your name, email, and password hash. When you create a campaign we collect the title, description, target, location, and any cover image you upload. When you contribute we collect the amount, the mobile-money number you paid from (so we can issue refunds if needed), and the name you choose to display publicly. If you are a coordinator, we additionally collect identity-verification data before your first withdrawal: images of your government-issued identity document, a short selfie used for a biometric liveness check and a face match against the document photo, and device and network signals captured during the verification. This verification is performed by our identity-verification provider, Didit, acting as our processor; we store the verification outcome and the extracted document details, and the underlying images are held by the provider under our agreement with them. Identity verification exists for one purpose: making sure the person withdrawing money from a campaign is who they claim to be. It is required by our AML / CFT policy and is never used for marketing. When you visit any page, including a public event page, we log standard server access information (IP address, user agent, page path, timestamp) for security and abuse detection, and we use a third-party product-analytics provider to see how people move through the product (which buttons get used, where people get stuck) through anonymised session replays and heatmaps. That provider never receives your mobile-money number, and it masks text input by default so the amounts and names you type are not captured. We do not run advertising trackers on any page.

Why we use it.

Your email is used to send you transactional notifications about your campaign (contributions, withdrawals, milestones) and password resets. We do not send marketing email; if we ever start, you will get a clear opt-in first. Campaign content (title, description, contributor list, disbursement log) is published on the public event page that anyone with the link can see, that is the whole point of the product. Mobile-money numbers are kept private; they never appear on the public page. Server logs are kept for the minimum time we need to detect abuse and reconcile payments.

Who sees what.

Public event pages are visible to anyone with the link. Contributors who select "anonymous" appear as "Anonymous" on the public list but are still linked to their account internally so they can come back to pay a pledge or claim a refund. Coordinators and the SenteMe support team can see contributor names and emails on the dashboard for their own events. We do not share contributor lists with other campaigns, sell them to third parties, or use them for marketing on other platforms.

Who we share data with.

We share the minimum data needed with the sub-processors that run the operational stack. The list below is point-in-time and is updated when a sub-processor is added or replaced, we keep it on this page (rather than in our Terms or Trust pages) because sub-processor disclosure is a transparency obligation, not a load-bearing part of how the platform is designed. As of today: our licensed mobile-money payment partner is PawaPay (receives the recipient phone number, amount, and an internal reference for each contribution and disbursement); coordinator identity verification is performed by Didit (receives the identity-document images, the selfie used for the liveness check and face match, and device and network signals you submit during verification, and returns the verification outcome to us); transactional email is sent through Mailgun (receives recipient email, subject, and body); account data and event data are hosted on Supabase (database and authentication, under their own SOC 2 controls); product-usage analytics run through a third-party analytics provider (receives anonymised interaction events, session replays with text masked, and coarse device and country signals, never your mobile-money number or contributor identity). We do not share data with advertising networks, because we do not run advertising. If we are required by a binding legal order to disclose data to a government or law-enforcement agency, we will do so, and where the law allows we will tell you first.

Where we store it.

Your account and event data lives on Supabase infrastructure (currently in EU-Central). Mobile-money transactions flow through our licensed payment partner's infrastructure (which itself spans the corridor country and the partner's EU operating jurisdiction). Server-side logs are kept on Coolify infrastructure (Hetzner, Falkenstein DE). Email content moves through Mailgun (US / EU). Backups of the database are encrypted and retained for thirty days. As a US-incorporated entity, Mea Global Inc relies on standard contractual clauses (SCCs) and equivalent transfer mechanisms where partners or users sit outside the United States, so that data covered by EU / UK GDPR and the African data-protection acts named above is transferred and processed lawfully.

How long we keep it.

Account data is kept for as long as you have an active account. Closed accounts are anonymised within ninety days, except where we need to keep specific records longer for accounting, tax, or anti-fraud reasons (typically seven years for transaction records). Public event pages and their contributor lists remain visible after the event ends so contributors can return to them; coordinators can request that a specific event be taken down via support.

Your rights.

Wherever you live, you can ask us to: tell you what we have on you, correct anything that is wrong, delete your account (subject to the retention rules above), or export a copy of your data in a standard format. Email [email protected] to make any of these requests; we aim to respond within thirty days. On top of this baseline, your local privacy regime may give you additional rights. Users in Uganda have the rights granted by the Data Protection and Privacy Act 2019, including access, rectification, erasure, objection, and complaint to the Personal Data Protection Office. Users in Kenya have the rights granted by the Data Protection Act 2019 (access, correction, deletion, objection, complaint to the ODPC). Users in Rwanda have the rights granted by Law N° 058/2021. Users in the EU and UK have the rights granted by GDPR and UK-GDPR (access, rectification, erasure, restriction, objection, portability, and complaint to your data-protection authority). Users in California have the rights granted by CCPA / CPRA. We honour the strongest rights you are entitled to under any law that applies to you, not the weakest.

Cookies and similar.

We use a small number of first-party cookies needed for the platform to work: a session cookie that keeps you signed in, a CSRF cookie that protects form submissions, and a preferences cookie for things like dark mode. We also use a third-party product-analytics provider that sets two cookies of its own to measure how the product is used; it does not advertise to you or sell your data, and the amounts and names you type are masked before they reach it. We do not set advertising cookies, and we do not let any tracker follow you off SenteMe onto Google or Meta.

Security.

Passwords are hashed with bcrypt before they touch our database, we cannot read them and neither can anyone who got hold of the database. Database access is locked down by Supabase Row-Level Security so that even the dashboard only sees the events and contributions you own. Production secrets are stored outside the codebase and rotated when a team member leaves. We are not yet SOC 2 certified, we will pursue certification once volume justifies the audit cost. If we discover a security incident that involves your personal data we will notify you within 72 hours of confirming it.

Children.

SenteMe is intended for users 18 and older. We do not knowingly collect personal data from anyone under 18. If you become aware that a minor has created an account on SenteMe, email us and we will close the account and delete the data.

When we change this policy.

When we make a substantive change, a new category of data, a new partner, a new use, we will email all coordinators and post a banner on the dashboard at least seven days before the change takes effect. Less material edits (clarifications, typos) take effect when we publish them. The "Last updated" date at the top of this page changes any time the page changes.

How to reach us.

Email [email protected] for any privacy question, data-export request, formal access / rectification / erasure / restriction / objection / portability request, supervisory-authority complaint, or to report a suspected misuse of your data. The inbox is monitored by our Data Protection Officer and the compliance team. For account-specific issues sign in to SenteMe first so we can verify it is you asking before we act on the request.

See also: Terms · Trust & safety · Pricing.