This Privacy Policy explains how the operator of this site and the Qoba ERP web and mobile applications (collectively, “Qoba”, “we”, “our”, or “us”) collect, use, disclose, and protect information when you access or use qoba.io or any Qoba mobile app. This policy is written for a multi-tenant ERP platform used by businesses to manage users, roles and permissions, customers, suppliers, sales, purchases, expenses and reports.
1. Data controller / contact
The data controller for the Qoba service is the operator of qoba.io. If you have questions about this policy, data subject requests, or want to reach our privacy point of contact, email [email protected].
2. What types of information we collect
We collect categories of information necessary for operating a multi-tenant ERP for businesses, including:
Account & identity data
- User name, business name, email address, phone, role and permission settings, username, and password (hashed).
Customer / supplier & transaction data
- Customer and supplier contact details, addresses, tax IDs, invoices, line items, product/service descriptions, prices, quantities, and invoice numbers.
Financial & payment data
- Payment references, invoices, receipts, bank account identifiers, or last-4 card digits if provided. Qoba does not store full card numbers unless you explicitly configure a payment processor that requires it — see “Sharing and disclosure” below.
Device & usage data
- IP address, device type, browser and OS, timestamps, logs, crash reports, app version, analytics, and feature usage.
Files & attachments
- Documents you upload (e.g., contracts, receipts, CSV import files, images) related to business operations.
Cookies & tracking
- Cookies, local storage, and similar technologies used for authentication, session management, preferences, and anonymous analytics.
3. How we use your information (purposes)
We process data for these primary reasons:
- To provide, operate, maintain and improve the Qoba platform (authentication, multi-tenant separation, data storage, reporting, backups).
- To enable business workflows (invoice creation, purchase records, expense tracking, reporting).
- To communicate with you (account notices, security alerts, support responses).
- For security, fraud detection, and to investigate abuse.
- To comply with legal obligations (tax, accounting, law enforcement requests).
- For analytics and product improvement (aggregated / anonymous analytics).
4. Legal bases (where applicable)
Where required by law (for example, within the EU/EEA under GDPR), we rely on:
- Contractual necessity — processing necessary to perform the contract with the customer (e.g., provide the ERP service).
- Legitimate interests — platform security, fraud prevention, analytics (with safeguards).
- Consent — for optional features that request explicit consent (e.g., non-essential tracking).
- Legal obligation — for compliance with tax, accounting and legal requests.
5. Sharing and disclosure
We may share data with:
- Service providers who perform services on our behalf (cloud hosting, email, SMS, backups, analytics, payment processors). They only receive the data necessary to perform their function and must follow our instructions.
- Payment processors for payment functionality (e.g., M-Pesa, Stripe, PayPal, or other local PSPs) — these providers have their own privacy policies and terms.
- Legal or regulatory authorities when required by law, court order, or to respond to lawful requests.
- Acquirers or third parties in connection with a business sale, merger or reorganization (with notice to affected customers).
If any SDKs used by our app collect data (analytics or advertising), we disclose them and their data practices in line with applicable app store requirements.
6. Data retention & deletion
We retain your data only as long as necessary to provide services and meet legal obligations (for example, accounting and tax record retention periods required in your jurisdiction).
- Active account data: retained while the account is active.
- Backups and logs: retained for a limited period for recovery and security purposes.
- Deletion requests: upon valid deletion requests, we will remove personal data subject to (a) legal retention obligations, and (b) reasonable time to complete deletion from backups and caches.
7. Security
We implement administrative, technical and physical safeguards to protect data (access controls, encryption in transit, secure backups, role-based access). No online system is 100% secure — if we become aware of a security breach affecting personal data, we will follow applicable breach notification laws and notify affected parties in accordance with legal requirements.
8. International transfers
Because our services may use infrastructure and subprocessors located in multiple countries, your data may be transferred across borders. Where transfers are subject to data protection rules, we use legally recognized transfer mechanisms or contractual safeguards.
9. Your rights (where applicable)
Depending on your jurisdiction, you may have rights to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete personal data.
- Request deletion or restriction of processing.
- Obtain a machine-readable copy (data portability).
- Object to or limit processing in certain situations.
- Withdraw consent where we rely on it.
To exercise a right, contact [email protected]. We will respond within applicable legal timelines.
10. Cookies and similar technologies
We use cookies and similar technologies for authentication, preferences, analytics, and improving the user experience. You can control cookie settings through your browser and account preferences. For analytics cookies and non-essential tracking, we provide an opt-out option where applicable.
11. Children
Qoba is offered to businesses and is not intended for children under 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided information to Qoba, contact us and we will take steps to remove such information.
12. Third-party links and embedded content
Qoba may contain links or integrations with third-party services (payment gateways, analytics, maps). Those third parties have their own privacy policies; we are not responsible for their practices. Review third-party policies before using those integrations.
13. Changes to this policy
We may update this policy to reflect changes in regulations, product features, or business practices. When we make material changes, we will post a notice on our site and update the “Last updated” date.
14. How to contact us
If you have questions, complaints, or wish to exercise your rights, email [email protected] or use the contact method provided in the app.