Privacy Policy
Onevia Booking — how we collect, use and protect your information
- App Name
- Onevia Booking
- Developer
- Onestore Technologies Limited
- Country
- Tanzania, East Africa
- Contact
- support@onevia.co.tz | +255 652 307 878
- Website
- www.onevia.co.tz
- Account Deletion
- Request Account & Data Deletion
📋 Table of Contents
1 · Introduction
Welcome to Onevia Booking ("Onevia", "we", "our", or "us").
Onevia is a digital hospitality booking platform developed and operated by Onestore Technologies Limited, a company based in Dar es Salaam, Tanzania. Our platform enables users to book accommodation (including hotels, lodges, guest houses, and apartments) and to reserve conference and event venues across Tanzania and beyond.
This Privacy Policy explains how we collect, use, disclose, store, and protect your personal information when you use:
- The Onevia mobile application (the "App")
- Our website: www.onevia.co.tz
- Any related services (collectively, the "Services")
By accessing, downloading, installing, or using Onevia, you confirm that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree with any part of this policy, you should discontinue use of our Services.
2 · Information We Collect
We collect only the information necessary to provide, operate, improve, and secure our Services.
2.1 Information You Provide Directly
- Account Information: full name, profile details, email address, and phone number used for registration, verification, and communication
- Authentication Data: passwords are securely stored in encrypted (hashed) form — we never store plain-text passwords
- Payment Information: mobile money details (M-Pesa, Airtel Money, Tigo Pesa, Halopesa) and card information (Visa, Mastercard), processed securely through certified third-party payment gateways; your Onevia wallet balance and transactions
- Booking Information: reservation details including check-in/check-out dates, number of guests, room preferences, event details, and any special requests
- User Content: reviews, ratings, feedback, and other content you submit
- Customer Support Communications: messages, inquiries, or requests sent to our support team
- Identity Verification Data (KYC): identification documents (National ID, Passport, or TIN) when required by law, payment providers, or service partners — primarily for property owners and partners
2.2 Information Collected Automatically
- Device Information: device ID, operating system version, device model, and manufacturer
- Usage Data: features accessed, screens viewed, time spent, interactions, and crash reports
- Network Information: IP address, mobile network, and carrier name
- Log Data: access times, pages visited, navigation paths, and system activity
- Location Data: approximate or precise location (only where you have granted permission) to provide location-based services such as nearby accommodation
- Cookies & Tracking Technologies: session cookies, preference cookies, and analytics identifiers used to enhance functionality and user experience
2.3 Information from Third Parties
- Service Partners: booking confirmations, availability data, and service-related updates from hotels and venue providers
- Payment Providers: transaction confirmations and verification data from mobile money services and card payment processors
We ensure that all data collected is relevant, limited to what is necessary, and handled in accordance with applicable data protection laws and industry best practices.
3 · How We Use Your Information
3.1 To Provide and Manage Our Services
- Creating and managing your user account
- Processing bookings for hotels, lodges, guest houses, apartments, and conference/event halls
- Facilitating secure payments and issuing receipts and booking confirmations
- Communicating booking status, payment deadlines, and check-in instructions (including by SMS)
- Sharing necessary booking details with property owners and service partners to fulfil your reservations
3.2 To Improve and Personalize Your Experience
- Analyzing usage patterns to enhance performance and functionality
- Personalizing recommendations based on your preferences, search history, and location
- Conducting testing to improve usability, design, and service quality
3.3 For Safety, Security, and Legal Compliance
- Detecting, preventing, and investigating fraud, suspicious transactions, and unauthorized access
- Verifying user identity and the legitimacy of bookings (including KYC where required)
- Enforcing our Terms of Service and internal policies
- Complying with applicable laws in Tanzania
3.4 For Communications and Customer Support
- Sending transactional communications: booking confirmations, payment receipts, cancellations, and reminders
- Providing important service announcements and policy changes
- Responding to your inquiries and feedback
3.5 For Marketing and Promotions
- Sending promotional messages, special offers, and personalized deals via email, SMS, or in-app notifications
- Recommending services, destinations, or properties based on your activity
You may opt out of marketing communications at any time by following the unsubscribe instructions or adjusting your account settings.
4 · Legal Basis for Processing Personal Data
We process your personal data only where we have a valid legal basis to do so.
4.1 Contractual Necessity
Where processing is necessary to perform a contract with you — processing and managing your bookings, facilitating payments, and providing customer support.
4.2 Legitimate Interests
Where necessary for our legitimate business interests — preventing fraud, ensuring platform security, improving our Services, and conducting analytics — carefully balanced against your privacy rights.
4.3 Consent
Where required by law, including for marketing communications, precise location access, and certain cookies. You may withdraw consent at any time.
4.4 Legal Obligations
Where necessary to comply with legal and regulatory obligations under Tanzanian law and other applicable jurisdictions.
5 · Information Sharing & Disclosure
5.1 Sharing with Service Partners
When you make a booking, we share relevant information (name, contact details, booking details, payment reference) with the property or venue responsible for fulfilling your reservation. Partners are required to use your data only for booking fulfilment and to maintain appropriate security measures.
5.2 Payment Processors
We share necessary payment-related information with certified and secure payment providers, including mobile money services and card networks compliant with PCI-DSS. Onevia does not store full card details on its servers.
5.3 Technology and Service Providers
We engage trusted providers for hosting, analytics, SMS delivery, and communication tools. They process data on our behalf under strict contractual obligations and may not use your information for their own purposes.
5.4 Legal and Regulatory Disclosure
We may disclose personal data when required to comply with applicable laws, respond to lawful requests, protect the rights and safety of Onevia or our users, or prevent fraud and illegal activities.
5.5 Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the new entity. We will ensure continued protection of your data and notify users before any significant changes.
5.6 Sharing with Your Consent
We may share your information with third parties where you have provided explicit consent.
6 · Data Security
We implement appropriate technical and organizational security measures, including:
- Encryption of data in transit using TLS 1.2/1.3 (HTTPS) for all communications
- Encryption of sensitive data at rest, including passwords (hashed with bcrypt) and payment references
- Access controls: only authorized personnel with a legitimate need access personal data
- Regular security reviews and vulnerability assessments
- Secure coding practices to prevent common vulnerabilities (OWASP Top 10)
- Incident response procedures with timely notification in the event of a data breach
- PCI-DSS compliant payment processing through certified third-party gateways
7 · Data Retention
We retain your data only as long as necessary to fulfil the purposes described in this policy or as required by law:
| Data Category | Retention Period |
|---|---|
| Account information | Duration of account + 3 years after closure |
| Booking records | 7 years (tax and legal compliance) |
| Payment transaction data | 7 years (financial regulations) |
| Customer support communications | 3 years from last interaction |
| App usage and analytics data | 2 years (anonymized after 12 months) |
| Marketing preferences | Until consent is withdrawn or account is closed |
| Device and log data | 12 months |
8 · App Permissions
The Onevia App requests the following device permissions. You can manage all optional permissions in your device Settings at any time:
| Permission | Purpose | Status |
|---|---|---|
| Location (Precise) | Show hotels and services near your exact location and personalize search results | Optional |
| Location (Approximate) | General area-based search results | Optional |
| Camera | Upload a profile photo or property images | Optional |
| Storage / Photos | Save booking confirmations and receipts to your device | Optional |
| Push Notifications | Send booking confirmations, reminders, and deal alerts | Optional |
| Internet Access | Connect to Onevia servers — required for all features | Required |
| Network State | Check connectivity before processing transactions | Required |
9 · Children's Privacy
The Onevia App and Services are not directed at children under the age of 13 (or 16 in jurisdictions where a higher age threshold applies). We do not knowingly collect personal information from children.
If you are a parent or guardian and believe a child has provided us with personal information, please contact us immediately. Upon verification, we will promptly delete such information.
Users between 13 and 18 may use the App only with verifiable parental or guardian consent. By using the App, users represent that they are 18 years of age or older, or that they have obtained appropriate parental consent.
10 · Your Privacy Rights
Depending on your location, you have the following rights. To exercise any of them, contact us at support@onevia.co.tz:
Request a copy of the personal data we hold about you.
Request correction of inaccurate or incomplete data.
Request deletion of your personal data ("Right to be Forgotten").
Request your data in a structured, machine-readable format.
Request that we limit how we process your data.
Object to processing based on legitimate interests, including marketing.
Withdraw consent at any time without affecting prior lawful processing.
Request human review of automated decisions that significantly affect you.
11 · Cookies & Tracking Technologies
11.1 Types of Cookies and Technologies We Use
- Strictly Necessary: essential for operation — authentication, session management, fraud prevention. Cannot be disabled.
- Functional: remember your preferences including language, currency, and display settings.
- Analytics: aggregated data to understand user interaction (e.g. Firebase Analytics).
- Marketing: relevant offers and personalized deals (with your consent).
11.2 Consent and Control
Where required by law, we obtain your consent before using non-essential tracking technologies. You can manage preferences through browser settings (web) or device settings (mobile). Disabling certain technologies may affect feature availability.
12 · International Data Transfers
Onevia operates primarily in Tanzania, East Africa. Due to the global nature of our Services, your personal data may be processed or stored in countries outside Tanzania where our infrastructure or partners operate.
When transferring personal data across borders, we implement appropriate safeguards including:
- Standard Contractual Clauses (SCCs): approved contractual frameworks ensuring data protection obligations
- Adequacy Decisions: transfers to countries recognized as providing adequate data protection
- Data Processing Agreements: binding agreements requiring confidentiality and security
13 · Third-Party Services & Links
The Onevia App may contain links to third-party websites, services, or platforms. This Privacy Policy does not apply to those third-party services.
We encourage you to review the privacy policies of any third-party services you access through Onevia. Third-party SDKs integrated into the App (such as Firebase) may collect certain data independently in accordance with their own privacy policies.
14 · Do Not Track Signals
Some browsers transmit "Do Not Track" (DNT) signals. Currently there is no universally accepted standard for how applications should respond to such signals, and Onevia does not currently alter data collection practices in response to them.
You can manage your privacy preferences directly through App settings or by contacting us at support@onevia.co.tz.
15 · Account Deletion & Data Removal
You may request deletion of your Onevia account and associated personal data at any time through the following methods:
- In-App: go to Profile → Delete account
- Online Form: submit a request via our Account & Data Deletion page
- Email: send a deletion request to support@onevia.co.tz from your registered email address
Upon receiving a verified request, we will:
- Delete or anonymize your personal profile and account data — in most cases immediately, and in all cases within 30 days
- Retain booking records and transaction data for up to 7 years as required by Tanzanian tax and financial regulations
- Retain data necessary to comply with legal obligations, resolve disputes, or enforce agreements
16 · Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Post the updated policy on our website and within the App
- Update the "Last updated" date at the top of this policy
- Notify you via email or in-app notification for significant changes
- Where required by law, obtain your renewed consent
Your continued use of Onevia after the effective date of any changes constitutes acceptance of the updated policy.
17 · Contact Us
For any questions, concerns, or data requests regarding this Privacy Policy, please reach out:
Organization
Onestore Technologies Limited
support@onevia.co.tz
Phone
+255 652 307 878
Address
3rd Floor, Victoria House, Dar es Salaam, Tanzania
Website
www.onevia.co.tz
Response Time
Within 30 days of receipt
If you are not satisfied with our response, you have the right to lodge a complaint with the relevant data protection authority in your jurisdiction.
© 2026 Onestore Technologies Limited. All rights reserved.
Onevia Booking · Dar es Salaam, Tanzania · support@onevia.co.tz