Privacy Policy

Version 2026-05-19 · Plain-English summary of how we handle your data.

1. What we collect

  • Account data: email, full name, phone number, role (tenant / landlord / agent), preferred language, and the version of our T&Cs you accepted.
  • Lister profile (landlords + agents): profile image link, years in real estate, primary locality, WhatsApp / alternate contact details, and a fee schedule.
  • Verification documents (Ghana Card / passport / real-estate licence / business certificate) uploaded for the Verified badge.
  • Listings: title, description, location, photos, videos, pricing, amenities.
  • Lead-capture submissions: when you fill the WhatsApp / Phone / Email form on a listing, we record the name and contact details you typed, the channel you picked, the message (for email leads), and which property it was for.
  • Browsing activity: favourites, saved searches, and read/unread state for notifications.

2. How we store it

In plain terms: your phone number and the contact details tenants leave for you are scrambled before they are saved, so they cannot be read straight out of our database. Your password is stored in a form that even we cannot turn back into your password. Your ID documents are not on the public internet. The specifics, if you want them:

  • Phones, WhatsApp, alt phone, and tenant lead PII are encrypted at the column level using Fernet with a key we never log.
  • We also keep a one-way HMAC-SHA256 lookup hash of phone numbers so operators can find a record without us decrypting the live data.
  • Passwords are argon2id-hashed. We can never see or recover your password. We only verify it.
  • Verification documents live in a private object-storage bucket gated by short-lived signed URLs. Public listing photos live in a separate public-read bucket with EXIF stripped.

3. Who sees what

  • Public: the listing title, description, photos, price, location, lister’s self-described role (landlord / agent), verification badge status, profile image, years in real estate, and fee schedule.
  • The lister of a property: sees the name + contact details + message of any tenant who filled the contact form on that property. They do not see your broader account data.
  • Admins: see verification documents during review (audit-logged), feedback / support / callback submissions, and listings that tenants have reported.
  • Other tenants: see nothing about you.

4. What we never do

  • Sell your data to third parties. Ever.
  • Place tracking cookies for advertisers. We use session cookies only, which are essential under Ghana’s Data Protection Act and exempt from the consent banner.
  • Surface your contact details on a listing publicly. Tenants must fill the contact form, which generates a single audited lead row.

5. Your rights

  • Export: one-click JSON export of your profile, listings, conversations, payments, and leads from Settings.
  • Delete: account deletion is one click in Settings — we hard-delete auth + tokens + leads and anonymise historical listings so other parties’ conversations don’t break.
  • Correction: edit any of your data in Settings. Phone-number changes require the verified-email step.

6. Subprocessors we use

  • Paystack: payment processing for subscriptions and listing credits. Only the necessary order / customer fields are sent.
  • Cloudflare R2: encrypted object storage for listing media and verification documents (in production).
  • Resend / AWS SES: transactional email (verification, password reset, lead notifications).
  • Google OAuth: optional sign-in. If you use it we receive your name, email, and profile image only.

7. Children

MoveGH is not for under-18s. We don’t knowingly collect data from minors; if you believe we have, email hello@movegh.example and we’ll wipe it.

8. Contact

Data-rights requests, complaints, or just questions: /support (in-app) or hello@movegh.example.
ExploreAccount