1. Our commitment
Mboka Connect uses the personal data necessary to operate its platform: account creation, exchanges between members, listings, bookings, travel companions and paid services.
We limit the data we collect, the people who can access it and how long it is retained.
We do not sell your personal data. A Premium or Pro subscription does not provide access to other members’ private data.
For any questions about your data, contact: contact@mbokaconnect.app
The full identity and contact details of the platform operator acting as the data controller are provided in the legal notice, accessible from the application.
2. The data we process
Depending on how you use Mboka, we process:
- Account data: your name, email address, account identifier and information needed to sign in.
- Profile data: your photograph, description, country, city and telephone number when you provide them.
- Activity data: listings, posts, reviews, travel plans, connection requests, bookings, messages and shared files.
- Paid services data: subscription plan and status, payment references, amounts, purchases of listing promotions and necessary billing information.
- Payout data: information needed to receive your earnings, depending on the payout methods offered.
- Verification data: proof of identity or professional activity when you request a badge, together with the outcome and date of the check.
- Support and security data: support requests, reports, moderation decisions and technical logs needed to protect the service.
- Travel assistant data: questions submitted to the assistant, the context needed to answer them and a usage counter.
- Referral data: the code used and the information needed to award referral benefits.
Mandatory fields are identified when the information is collected. Without the information essential to a feature, that feature may not be available. Optional data is not required for services that do not need it.
Some information may come from your chosen sign-in provider, a payment service provider or another member, particularly when they send you a message or submit a report.
3. Why we use your data
We use your data to:
- Provide the services you request: account management, messaging, posts, bookings, the assistant and subscriptions. This processing is based on the performance of the relevant contract.
- Assess a verification request, using only the supporting documents necessary for the service requested.
- Prevent fraud, protect accounts, handle reports and diagnose incidents. This processing is based on our legitimate interest in providing a secure service while respecting users’ rights.
- Maintain accounting records and meet applicable regulatory obligations. This processing is based on a legal obligation.
- Carry out optional audience measurement and use trackers that require consent, only with your agreement.
Accepting the terms of use does not constitute general consent to advertising or to every use of your data.
4. What other members can see
The information visible to others depends on the area you use and the audience indicated before publication.
Your display name, photograph and badges may appear alongside your profile, listings, reviews or posts. Group content is accessible according to that group’s rules.
Your email address, telephone number, supporting documents and payment information are not automatically made public.
If you include personal information in a listing, post or message yourself, anyone with access to that content will be able to read it and may copy it.
A subscription does not allow anyone to bypass your privacy choices or force you to accept a connection.
5. Access by Mboka and its service providers
Authorised people at Mboka access only the information necessary for their duties: support, security, verification, operations management and moderation.
Verification documents are accessible only to the people responsible for reviewing them. Administrative access to confidential data is controlled and logged.
Service providers are involved according to the features used:
- Google / Firebase Authentication: sign-in and authentication.
- Railway: hosting of the relevant services and data.
- Resend: sending emails necessary for the service.
- Stripe and Stripe Connect: available payments, subscriptions and payouts.
- pawaPay: Mobile Money payouts when enabled.
- Anthropic: responses from the travel assistant.
- FlightAPI.io: flight searches.
- Giphy and Tenor: searching for and displaying GIFs and stickers.
- Google Analytics for Firebase: optional audience measurement.
- Sentry: error diagnostics.
We limit the data shared to what is necessary. Payment service providers may also process certain information to meet their own regulatory obligations.
Before you request a callback from a partner, you are informed of the partner’s identity and which contact details will be shared with them.
Information may be disclosed to competent authorities when required by law, or retained for the defence of legal claims.
6. Payments and supporting documents
Card details are entered through the payment service provider’s payment flow. Mboka does not retain your full card number or card security code.
We retain the references and information needed to track payments, subscriptions and refunds and to meet accounting obligations.
For badges, identity documents are not published or used for advertising purposes.
The copy of a supporting document is deleted no later than 30 days after the final verification decision. If the decision is disputed, only the information necessary to handle the dispute is retained. It is then deleted within 30 days of the dispute being closed, unless an obligation or legal dispute justifies restricted archiving.
We retain a separate, minimal record of the check: the document category, date, outcome and badge validity. This record does not include a complete copy of the document.
Checks carried out directly by a financial service provider are subject to that provider’s own obligations and retention periods.
7. Messaging and location
The level of protection for a conversation is indicated in the application. End-to-end encryption is distinguished from the protection of communications between your device and our servers.
When a conversation is described as end-to-end encrypted, the scope of the protection actually provided is explained. Content or situations not covered by that protection are identified before you send anything.
Certain operational information remains necessary, including the participants, sending times and message delivery data.
If you voluntarily report a message, the information attached to your report may be shared with the moderation team for review.
Location sharing is optional and limited to individual occasions. Mboka does not track your location in the background. Refusing location access does not prevent you from using other features.
Location information embedded in published photographs is removed before the photographs are made available to other members.
A recipient may save, capture or forward content they receive. Encryption and disappearing messages do not prevent these actions.
8. Travel assistant
The assistant uses an artificial intelligence service provided by Anthropic.
The questions you submit and the extracts needed to answer them are sent to that provider. Mboka does not automatically add your name, email address, telephone number or supporting documents to these requests.
However, if you include this information in your question, it forms part of the content transmitted. Avoid including passwords, identity documents or banking information.
Mboka does not retain the content of exchanges after the assistant session ends and does not record it in its diagnostic logs. The counter needed to enforce usage limits is retained for a maximum of 30 days.
The provider’s processing and retention periods, any security exceptions and its terms governing data use are presented in a notice accessible before the first exchange. The absence of a history stored by Mboka does not automatically mean that the provider retains no data.
9. Audience measurement and trackers
Audience measurement is optional. It remains disabled until you have accepted it.
Accepting and refusing are equally straightforward. Your choice is remembered for six months, unless you change it or a change requires a new decision.
You can change your choice in the privacy settings. Refusing does not prevent access to Mboka’s main features.
Audience measurement events do not contain your name, email address, telephone number, message content or documents. They are not linked to your Mboka account identifier.
Any technical identifiers used remain personal data when they make it possible to distinguish a user or device. We therefore do not automatically describe this measurement as anonymous.
Individual audience measurement data is retained for a maximum of two months. Statistics may be kept for longer only if they have been effectively anonymised.
Tools necessary for sign-in and security are distinguished from optional tools. The privacy manager specifies the trackers used, their purposes, providers and retention periods.
Third-party content, including certain GIFs, may transmit an IP address to its provider when loaded. Where the service uses trackers that require consent, they are activated only after you have agreed.
10. Retention periods
We apply the following rules:
Active accounts: information necessary for an account is retained while the account is in use. Data that is no longer needed is deleted without waiting for the account to be closed.
Inactive accounts: after three years without a sign-in or authenticated use of the account, we send a warning. If activity does not resume within 30 days, the account is closed and the deletion rules below apply. Any ongoing transaction or dispute is handled separately.
Account deletion: the profile is hidden and account access is disabled as soon as deletion is confirmed. Data used for day-to-day operations is deleted from active systems within a maximum of 30 days.
Backups: residual copies expire within a maximum of 30 additional days after deletion from active systems. They are isolated from day-to-day use. If a backup is restored, deletion requests are reapplied.
Disappearing messages: these stop being displayed when the selected period expires. Their content and files are deleted from active systems within 24 hours, and then from backups within a maximum of 30 days, except for information retained as part of a report or a justified dispute.
Ordinary messages: these are retained to provide the conversation history until they are deleted or the account closure rules apply. The interface distinguishes between deleting messages for yourself and deleting them for everyone.
Verification documents: these are deleted according to the rules in Section 6. The minimal record of the check is retained while the badge is valid, and then for up to one year after the badge is withdrawn or the account is closed, to handle disputes and prevent abuse.
Security and access logs: these are retained for a maximum of six months during normal operations. In the event of an incident, relevant information may be isolated and retained for the duration of the necessary investigation or proceedings.
Bug reports: these are retained for a maximum of 30 days. They must not contain passwords, supporting documents or conversation content.
Support requests: these are retained for one year after the case is closed, unless a dispute creates a justified need for longer retention.
Reports and moderation decisions: these are retained for one year after closure to handle appeals and repeated abuse, unless proceedings justify a longer retention period.
Records of consent: these are retained while the relevant consent is being relied upon, and then for three years after it is withdrawn or replaced, as a minimal record kept separately from audience measurement data.
Invoices and accounting records: where French accounting retention rules apply, these are retained for ten years from the end of the relevant financial year. Only the data necessary to meet this obligation is archived for that purpose.
Disputes and legal obligations: data that is strictly necessary may be retained for the duration of the relevant proceedings or obligation, with restricted access.
11. Deletion and anonymisation
You can request deletion through your account settings or by emailing contact@mbokaconnect.app.
Deletion does not immediately remove invoices, ongoing transactions or information needed to meet a legal obligation.
Some content may remain in other members’ histories where this is still necessary and justified. You may request a review of content that continues to identify you.
Replacing a name with “Deleted account” is not sufficient to make all data anonymous. Data is considered anonymised only if it can no longer identify you by means reasonably likely to be used.
12. Hosting and international transfers
Processing locations vary according to the services used and their providers. Transfers to, or access from, countries outside the European Economic Area may occur.
Where the GDPR applies, these transfers must rely on an appropriate legal mechanism and, where necessary, additional safeguards.
The list of providers, countries concerned and safeguards actually used is accessible from this policy. You may request information or a copy of the safeguards by emailing contact@mbokaconnect.app.
13. Security and incidents
We limit access to data according to each person’s responsibilities. Administrative accounts use enhanced authentication.
Supporting documents, backups and confidential data are protected by appropriate access controls. Passwords, sign-in codes and confidential content are not recorded in diagnostic tools.
In the event of a personal data breach, we assess the risks and make the required notifications to the authorities and the people affected.
14. Your rights
Where the GDPR applies, you may, subject to the conditions set out in the applicable legislation:
- Access your data.
- Have inaccurate information corrected.
- Request the erasure of your data.
- Request the restriction of certain processing.
- Object to processing based on legitimate interests.
- Request the portability of the relevant data.
- Withdraw your consent to optional processing that relies on it.
Email contact@mbokaconnect.app, specifying your request.
We do not routinely request an identity document. Proportionate verification may be necessary where there is reasonable doubt.
We respond without undue delay, normally within one month. An extension of two months is possible where justified by the complexity or number of requests; you will be informed within the first month.
If your request is refused or limited, we explain why.
You can lodge a complaint with the CNIL: https://www.cnil.fr/fr/plaintes
Another authority may also be competent, depending on your circumstances.
15. Updates
This policy is updated when our processing activities change.
You are informed of significant changes. Any new use requiring your consent is not activated until that consent has been obtained.
Contact: contact@mbokaconnect.app