Summary — the short version
- We collect only the data needed to run the PayGO platform on your behalf.
- We never sell your data or your customers' data to third parties.
- Data is stored on Firebase (Google Cloud, EU/Africa regions) with encryption at rest and in transit.
- You can request data export or deletion at any time by emailing us.
GreenLeaf Technology Solutions Limited ("GreenLeaf", "we", "us", or "our") is committed to protecting the privacy of everyone who uses the PayGO platform. This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and your rights under applicable law — including the Tanzania Personal Data Protection Act, 2022 (PDPA).
This Policy applies to the PayGO web dashboard, PayGO Touch mobile app, REST API, and all related services (collectively, the "Platform"). It covers two groups of people:
- Clients / Tenant Users — company administrators, technicians, sales representatives, and other staff who log in to manage their organisation's solar operations.
- End Customers — individuals whose data is entered into the Platform by a Tenant (solar device buyers on PAYG plans). GreenLeaf acts as a data processor for this data; the Tenant is the data controller.
1. Data We Collect
1.1 Account and Identity Data (Tenant Users)
- Full name, email address, phone number, job title, and role.
- Username, hashed password, and session tokens.
- Organisation name, billing address, and payment details.
1.2 End Customer Data (entered by Tenants)
- Full name, national ID number, phone number, and physical address.
- GPS coordinates of the installation site.
- Contract details: device serial number, plan type, payment history, and outstanding balance.
- OpenPAYGO token history and device activation records.
- dMRV evidence: installation photos, survey responses, and verification step records.
1.3 Usage and Technical Data
- IP address, browser type, device type, and operating system.
- Pages visited, features used, and timestamps of actions (audit log).
- API request logs including endpoints called, HTTP status codes, and response times.
- Error reports and crash diagnostics.
1.4 Data We Do Not Collect
- We do not collect biometric data.
- We do not access the microphone or contacts on mobile devices.
- We do not track users across third-party websites.
- Camera access (for dMRV photo evidence) is only activated when you explicitly trigger a photo capture within the app.
2. How We Use Your Data
We use collected data for the following purposes:
- Platform delivery — authenticating users, processing payments, generating OpenPAYGO tokens, managing devices and contracts, and delivering SMS notifications to End Customers.
- dMRV compliance — recording and transmitting installation evidence for carbon credit and regulatory reporting workflows.
- REA reporting — submitting required customer data to the Tanzania Rural Energy Agency (REA) Prospect API on behalf of Tenants.
- Billing and account management — invoicing, subscription management, and support.
- Security and fraud prevention — monitoring for unauthorised access, rate limiting, and audit logging.
- Product improvement — analysing aggregated, anonymised usage patterns to improve features and reliability. We do not use identifiable End Customer data for this purpose.
- Legal obligations — complying with court orders, regulatory requirements, or lawful government requests.
3. Legal Basis for Processing
Under the Tanzania PDPA and applicable data protection frameworks, we process personal data on the following legal bases:
- Contract performance — processing is necessary to provide the Platform services under our agreement with you.
- Legitimate interests — security monitoring, fraud prevention, and product analytics, where these do not override your fundamental rights.
- Legal obligation — complying with regulatory reporting requirements (e.g. REA submissions).
- Consent — where we rely on consent (e.g. marketing communications), you may withdraw it at any time.
4. Data Sharing and Disclosure
We do not sell personal data. We share data only in the following circumstances:
4.1 Sub-processors and Service Providers
We engage trusted third-party processors who handle data strictly on our instructions:
- Google Firebase / Google Cloud — database (Firestore), hosting, authentication, and Cloud Functions. Data is stored in the europe-west1 (Belgium) and africa-south1 (Johannesburg) regions.
- Africa's Talking — SMS delivery for payment confirmations and token delivery to End Customers.
- Mobile money providers (Vodacom M-Pesa, Airtel Money, Tigo Pesa) — payment processing; data shared is limited to what is required to initiate and confirm a transaction.
4.2 Regulatory Bodies
Tenant-directed REA Prospect API submissions transmit End Customer data to the Tanzania Rural Energy Agency as required for off-grid energy reporting. Tenants authorise and control these submissions.
4.3 Legal Requirements
We may disclose data if required by law, court order, or to protect the rights, property, or safety of GreenLeaf, our Clients, or the public. We will notify affected Clients of such requests where permitted.
4.4 Business Transfers
If GreenLeaf is involved in a merger, acquisition, or sale of assets, Client Data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.
5. Data Retention
- Active accounts — data is retained for the duration of your subscription.
- Post-cancellation — Client Data is retained for 30 days after account termination to allow data export, then permanently deleted unless a longer retention period is required by law.
- Audit logs — retained for 12 months for security and compliance purposes.
- Billing records — retained for 7 years as required by Tanzanian tax law.
- dMRV records — retained for the period required by applicable carbon credit and REA regulations, typically 10 years.
6. Data Security
We implement the following technical and organisational measures to protect your data:
- Encryption in transit — all data transmitted between the app and our servers uses TLS 1.2 or higher (HTTPS).
- Encryption at rest — Firestore and Cloud Storage data is encrypted at rest using AES-256.
- Authentication — passwords are hashed using bcrypt. Sessions use short-lived JWT tokens with refresh token rotation.
- Access control — role-based access ensures users can only access data relevant to their role and tenant.
- Audit logging — all create, update, and delete actions are logged with user identity and timestamp.
- Penetration testing — the Platform undergoes periodic security reviews.
No system is completely secure. In the event of a data breach affecting your data, we will notify you within 72 hours of becoming aware of it, as required by applicable law.
7. Cookies and Local Storage
The Platform uses the following client-side storage:
- Session storage — JWT access tokens and temporary UI state, cleared when the browser tab is closed.
- Local storage — user preferences (e.g. language, theme) and offline payment queues in the PayGO Touch app.
- Firebase Authentication cookies — used to maintain your login session across page refreshes.
We do not use third-party advertising or tracking cookies. You can clear local storage via your browser or device settings at any time; this will log you out of the Platform.
8. International Data Transfers
Data is processed primarily in the EU (Belgium — Google Cloud europe-west1) and South
Africa (africa-south1). Google LLC is certified under the EU–US Data Privacy Framework.
All international transfers are governed by Google's Data Processing Addendum, which incorporates
Standard Contractual Clauses where applicable.
9. Your Rights
Under the Tanzania PDPA and applicable law, you have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Correction — request correction of inaccurate or incomplete data.
- Deletion — request deletion of your data, subject to legal retention obligations.
- Data portability — request your data in a structured, machine-readable format (CSV or JSON export).
- Objection — object to processing based on legitimate interests.
- Restriction — request that we restrict processing of your data in certain circumstances.
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.
To exercise any of these rights, email privacy@greenleaf.co.tz. We will respond within 30 days. We may ask you to verify your identity before processing a request. There is no fee for exercising your rights unless requests are manifestly unfounded or excessive.
Note for End Customers: If you are a solar device buyer (End Customer) and wish to access or delete your data, please contact the solar company that sold you the device. They are the data controller for your records and are responsible for handling your request. You may also contact us directly and we will direct your request to the relevant Tenant.
10. Children's Privacy
The Platform is intended for business use only. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor's data has been entered into the Platform in error, please contact us at privacy@greenleaf.co.tz and we will work with the Tenant to address the issue promptly.
11. Tenant Responsibilities (Data Controller Obligations)
When you use the Platform to manage End Customer data, you act as the data controller and GreenLeaf acts as a data processor on your behalf. As a Tenant, you are responsible for:
- Obtaining valid, informed consent from End Customers before collecting their personal data.
- Providing End Customers with a clear privacy notice explaining how their data is used.
- Ensuring that data entered into the Platform is accurate and up to date.
- Responding to End Customer data access, correction, or deletion requests.
- Complying with the Tanzania PDPA and any other applicable data protection regulations in your jurisdiction.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by email or in-Platform notice at least 14 days before the changes take effect. The date at the top of this page reflects when the Policy was last updated. Continued use of the Platform after the effective date constitutes acceptance of the updated Policy.
13. Contact and Complaints
For privacy-related questions, requests, or concerns:
- Email: privacy@greenleaf.co.tz
- General support: support@greenleaf.co.tz
- Address: GreenLeaf Technology Solutions Limited, Dar es Salaam, Tanzania
If you are not satisfied with our response, you have the right to lodge a complaint with the Tanzania Personal Data Protection Commission or another competent supervisory authority in your jurisdiction.
Also read our Terms of Service
The agreement governing your use of the PayGO platform.