Governance
Privacy Policy
Last updated: 26 September 2026
SmartSadaka ("SmartSadaka", "we", "us") provides a church financial management platform, made up of a web system for church administrators and a mobile app for church members. This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, and the rights you have over it.
We process personal data in line with the Personal Data Protection Act, 2022 of the United Republic of Tanzania and its regulations.
1. Who is responsible for your data
Each church or conference that uses SmartSadaka decides which member records are entered into the system and how they are used. For that data the church acts as the data controller and SmartSadaka acts as a data processor on the church's behalf. For data we collect for our own purposes (for example, demo requests from our website), SmartSadaka is the controller.
2. Data we collect
Church members (mobile app and records kept by the church)
- Identity and contact details: full name, phone number, email address, physical address and profile photo.
- Membership details: membership number, date of birth, gender, marital status, membership status, baptism status and baptism date, and ministries you belong to.
- Financial records: tithes, offerings and other contributions, pledges, stewardship goals and their transactions, and the payment or bank receipts you upload as proof of payment.
- Account security data: your app PIN (stored only in hashed form, so we cannot read it) and one-time verification codes (OTPs).
- Community content: posts, comments, likes and follows you make in the app.
- Device data: a push-notification token for your device so we can send you notifications.
Church administrators and staff
- Name, email address, phone number, role and permissions, and login activity (including OTP logins).
- Where the payroll feature is used: employee details and salary records entered by the church.
Website visitors
- Information you submit in the demo request form: church name, your name, phone number, email address and message.
3. How we use your data
- To create and manage your account and verify your identity (OTP by SMS, WhatsApp or email).
- To record contributions, pledges and goals, and to produce receipts, statements and reports for you and your church.
- To send receipts, reminders, announcements and notifications by SMS, WhatsApp, email or push notification.
- To help church treasurers and leaders with accounting, budgeting and reporting to the conference.
- To keep the platform secure, prevent fraud and investigate misuse.
- To respond to demo requests and support enquiries.
- To meet legal, accounting and audit obligations.
We do not sell personal data and we do not use it for third-party advertising.
4. Legal basis
We process personal data because it is needed to provide the service you or your church signed up for, because of legal and accounting obligations, because of legitimate interests such as keeping the platform secure, or on the basis of your consent (for example, receiving notifications). You can withdraw consent at any time.
5. Who we share data with
Data is visible only to authorised people in your church, according to the roles and permissions the church sets. We also use these service providers to run the platform:
- SMS providers (such as Mobishastra) to deliver OTPs and messages.
- Meta (WhatsApp Business Platform) to deliver WhatsApp messages and receipts.
- Google Firebase Cloud Messaging to deliver push notifications.
- Email providers to deliver OTPs and notices.
- Stripe to process payments made by churches for messaging credits. We do not store card details.
- Hosting providers that store our servers and backups.
Some of these providers may process data outside Tanzania. Where that happens we rely on appropriate safeguards as required by the Personal Data Protection Act. We may also disclose data where the law requires it, for example to a court or regulator.
6. How we protect your data
- Encrypted connections (HTTPS) between your device and our servers.
- Passwords and PINs are stored hashed, never in plain text.
- One-time codes for login, and role-based access so staff only see what their role allows.
- Activity logs of important actions, and regular backups.
No system is completely secure. If a breach affects your personal data, we will notify your church and the relevant authority as required by law.
7. How long we keep data
We keep member and financial records for as long as your church uses SmartSadaka and afterwards for as long as needed to meet accounting, audit and legal requirements. Demo request details are kept only as long as needed to follow up. When data is no longer needed it is deleted or anonymised.
8. Your rights
Under the Personal Data Protection Act you have the right to:
- Know what personal data is held about you and get a copy of it.
- Ask for incorrect or incomplete data to be corrected.
- Ask for your data to be deleted or its use restricted, where the law allows.
- Object to certain uses of your data and withdraw consent you have given.
- Complain to the Personal Data Protection Commission (PDPC).
Because your church manages your member record, please first contact your church office. You can also contact us directly using the details below and we will work with your church to respond.
9. Children
Churches may keep records of members under 18 (for example, children's offerings). Such records should be entered by the church with the consent of a parent or guardian. The mobile app is intended for users aged 18 and over, or younger users with a parent or guardian's permission.
10. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top shows when it last changed. Significant changes will be communicated through the app or your church.
11. Contact us
SmartSadaka Tanzania
Email: info@smartsadaka.co.tz
Phone: +255 753 417 792