How Nishati Safi collects, uses, and protects your personal information.
Nishati Safi ("we", "our", or "us") operates the Nishati Safi mobile application — a platform that connects gas-cylinder consumers, agents, distributors, and manufacturers across Tanzania. This policy applies to all users of the app on Android and iOS devices.
Package identifiers: com.nishati_poc (Android) | app.nishatisafi.ega (iOS).
We collect only the information necessary to provide and improve our services.
| Category | What We Collect | Why |
|---|---|---|
| Account & Identity | Full name, phone number, email address, NIN (National Identification Number), profile photo | Account creation, identity verification, and KYC compliance |
| Location | Precise and approximate GPS coordinates | Showing nearby agents, gas stations, and delivery tracking |
| Biometric | Fingerprint verification result (pass/fail — raw biometric data is NOT stored) | Secure transaction authorisation for customer orders |
| Camera / Media | QR code scans, uploaded documents (ID photos, business registration) | Product scanning, agent application verification |
| Payment | Transaction references, payment status, mobile-money numbers | Processing and recording gas cylinder purchases |
| Device & Usage | Device model, OS version, app version, session logs | Bug fixing, performance monitoring, fraud prevention |
| Communications | OTP codes received via SMS (auto-filled, not stored) | Two-factor authentication at sign-in |
The app requests the following device permissions. You can revoke any permission at any time from your device settings.
We share your information only in the following limited circumstances:
We retain your personal data for as long as your account is active or as needed to provide services. Transaction records are kept for a minimum of 5 years to comply with financial regulations. You may request deletion of your account and data at any time (see Section 8).
Location data used for delivery is deleted within 30 days after a transaction is completed. OTP codes are never stored after use.
We implement industry-standard security measures including HTTPS/TLS encryption for all data in transit, encrypted storage for sensitive credentials using flutter_secure_storage, and access controls limiting who within our organisation can view your data.
Biometric data (fingerprints) is processed entirely on your device using the OS-level biometric API. We never receive or store raw biometric data on our servers.
While we take every precaution, no system is 100% secure. If you suspect unauthorised access to your account, contact us immediately.
You have the right to:
To exercise any of these rights, contact us at the address in Section 10.
The Nishati Safi app is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with their information, please contact us and we will delete it promptly.
We may update this Privacy Policy from time to time. When we do, we will update the "Effective" date at the top of this page and notify you via an in-app notification for material changes. Continued use of the app after changes are published constitutes acceptance of the updated policy.
If you have any questions, concerns, or requests regarding this Privacy Policy, please reach out to us: