Legal

Privacy policy

Naya connects customers with independent beauty, grooming and wellness professionals for at-home services in Kigali, Rwanda. This policy explains what personal data we process, why, who sees it, and the rights Rwandan law gives you. It is written to comply with Law No. 058/2021 on the Protection of Personal Data and Privacy.

Last updated 1 September 2026

Who is responsible for your data

Naya is the data controller for the personal data described in this policy. Registration with Rwanda's National Cyber Security Authority (NCSA) as a data controller, and the contact details of our Data Protection Officer, are published here once issued: NCSA registration [to be completed by Naya] · DPO contact [to be completed by Naya]. You can raise any privacy matter through the contact options in the app or website and it will be routed to the DPO.

What we collect

  • Account data: name, email address, phone number, profile photo, saved addresses, favourites and notification preferences.
  • Booking data: the service or package booked, price, date and time, the service address you provide (shared with your assigned professional), notes, status history and reviews.
  • Payment data: amount, payment method (MTN Mobile Money, Airtel Money or cash), transaction references, and payout details for professionals and ambassadors (mobile money number). We never store mobile money PINs — payments are processed by your mobile money provider.
  • Professional data: application details, portfolio images, services, working areas, availability, earnings and payout history.
  • Ambassador data: the application you submit (including social media handles and audience information), referral activity, commissions and payout history.
  • Guest booking data: name, phone and email when you book without an account.
  • Device and usage data: push-notification device tokens, app and page interactions, and technical logs used for security and product improvement.

Why we process it (lawful bases)

  • To perform our contract with you: creating, confirming, fulfilling and tracking bookings; processing payments and payouts; running the ambassador programme you joined.
  • With your consent: optional marketing communications and any processing where we ask you first. You may withdraw consent at any time without affecting processing that already happened.
  • For our legitimate interests, balanced against your rights: preventing fraud and abuse, securing accounts and improving the service.
  • To comply with legal obligations, including tax, consumer protection and data protection law.

Who sees your data

  • Your professional(s): your name, service address, phone number and the booking details needed to deliver the service — nothing more. They do not see your payment details or your history with other professionals.
  • Customers: a professional's public profile (name, photo, services, ratings and reviews).
  • Ambassadors never see customer personal details: referral activity is shown to them in masked form only (reference numbers, service categories and amounts).
  • Providers acting under our instructions: cloud hosting and database (Supabase), push notification delivery (Google Firebase) and transactional email delivery (Resend). Mobile money payments are processed by MTN and Airtel under their own terms.
  • Authorities, where disclosure is required by law or needed to protect the safety of customers and professionals.
  • We do not sell personal data.

Where data is stored (cross-border transfers)

Our hosting and email providers store data on infrastructure located outside Rwanda. Law No. 058/2021 permits storing personal data outside Rwanda only on defined grounds, including authorisation from the supervisory authority, your consent, or necessity for performing your contract. Naya relies on these grounds and maintains its cross-border compliance with the NCSA: authorisation reference [to be completed by Naya]. All providers are required to protect your data to at least the standard described in this policy.

How long we keep it

Account data is kept while your account is active. Booking, payment, payout and commission records are kept for as long as needed to run the service, resolve disputes and meet legal retention duties (including tax). Price and service snapshots inside completed bookings form part of the financial record and are retained with it. Data that is no longer needed is deleted or irreversibly anonymised.

Your rights

  • Access: confirmation of what personal data we hold about you, and a copy of it.
  • Rectification: correction of inaccurate or incomplete data — much of it editable directly in the app.
  • Erasure: deletion of personal data we no longer have a lawful reason to keep. You can request account deletion at any time.
  • Objection: object to processing — including an absolute right to object to direct marketing at any time.
  • Withdrawal of consent: wherever processing is based on consent, withdraw it at any time.
  • To exercise any right, contact us via the app or the DPO contact above; we respond within the timelines the law sets. If you are unsatisfied, you have the right to lodge a complaint with the National Cyber Security Authority (NCSA), Rwanda's supervisory authority for personal data.

Messages we send you

  • Transactional messages — booking confirmations, status updates, payment receipts, appointment reminders, payout and ambassador account updates — are part of operating your bookings and account. You control channels (in-app, push, email) and reminder timing in notification settings; essential account and security messages may still be sent where necessary.
  • Marketing messages are sent only with your consent, and each one includes a way to opt out. Opting out of marketing never affects transactional messages.
  • Quiet hours: reminders respect a night-time window (by default 21:00–07:00 Kigali time) and are delivered after it ends.

Security and breach notification

We protect personal data with access controls (including row-level database security), encryption in transit, least-privilege service access and audit logging of administrative actions. If a personal data breach occurs, we will notify the NCSA within 48 hours of becoming aware of it and deliver a full report within 72 hours, and we will inform affected users without undue delay where the breach is likely to put their rights at risk — as Articles 43–45 of Law No. 058/2021 require.

Children

Naya is intended for adults. We do not knowingly process children's personal data without the consent of a parent or legal guardian as required by law. If you believe a child has created an account, contact us and we will remove it.

Changes to this policy

We may update this policy as the service or the law evolves. The date above always reflects the current version, and material changes are announced in the app before they take effect. Continued use of Naya after a change takes effect means the updated policy applies.

Still need a hand?

Our Kigali team answers every message within one working day.