Version 1.0 — Working Draft for Legal Review
This Privacy Policy explains how NIHILOBA, through SHIDA, collects, uses, retains and protects personal data necessary to operate the platform.
1. Service Operator
SHIDA is developed and operated by NIHILOBA.
The official contact details of the legal entity responsible for relevant personal-data processing will be published in this policy before final commercial launch.
For questions concerning your data, use SHIDA's official contact methods or support.
2. Our Principle
SHIDA follows a data-minimization principle:
collect and use only information reasonably necessary to operate, secure, improve and provide SHIDA services.
SHIDA is also designed around an important rule:
phone numbers are not displayed publicly.
3. Information SHIDA May Process
Depending on the features you use, SHIDA may process:
- your WhatsApp number;
- your language;
- your name or display name;
- your country, city or general area where necessary;
- information relating to your user account;
- your Personal SHIDA profiles;
- organizations you create, join or manage;
- organization roles and permissions;
- information required to verify an organization or representative;
- job vacancies;
- applications;
- recruitment information and application history;
- messages relating to certain applications or interactions;
- Wenze shops;
- products, variants, prices and stock;
- carts and orders;
- delivery or pickup information where necessary;
- service-provider profiles and offers;
- bookings and service requests;
- restaurants, Malewa, menus and orders;
- hotels, rooms and reservations;
- accommodation listings and visit requests;
- Wewa information required to handle a ride request;
- payment and transaction-status information where payment features are used;
- statistics and operational information generated through use of SHIDA;
- support requests;
- reports, moderation actions and security information;
- technical data required to operate and protect the service.
SHIDA does not necessarily collect every category for every user.
4. Why SHIDA Uses This Information
SHIDA may process information to:
- create and manage your user identity;
- store your language;
- provide Personal SHIDA functionality;
- create and manage organizations;
- enforce roles and permissions;
- operate marketplaces;
- publish and display content;
- process orders and bookings;
- manage applications;
- facilitate service-related communication;
- provide statistics and management tools;
- record and verify certain transactions;
- prevent fraud and abuse;
- protect users and the platform;
- provide support;
- comply with legal obligations;
- improve SHIDA.
5. WhatsApp Number
Your WhatsApp number is necessary for SHIDA's WhatsApp experience and may be used to identify your account.
Your phone number is not displayed publicly on SHIDA.
SHIDA should avoid unnecessarily exposing phone numbers through APIs, public interfaces, technical logs or content presented to other users.
Users may nevertheless choose to communicate contact information themselves through free-text messages or content. SHIDA recommends sharing personal information only when necessary.
6. Public Information
Certain information is intended to become public when you choose to publish content or make an activity discoverable.
Depending on the service, this may include:
- public or business name;
- description;
- product;
- service;
- price;
- photos;
- availability;
- city or general area;
- establishment information;
- job vacancy;
- other information necessary for public discovery.
SHIDA should avoid making administrative, private or internal information public merely because a user or organization uses the platform.
7. Organization Data
A person may use SHIDA personally and also manage one or more organizations.
Organization data should be kept separate, where reasonably possible, from the personal data of representatives or other members.
Internal organization information such as certain reports, analytics, inventory information, operational data, roles or notes is not intended to be public unless a feature expressly requires publication.
8. Recruitment and Candidates
When a candidate applies for a vacancy, certain information may be transmitted or made available to the recruiting organization.
Organizations using SHIDA Recruitment must process candidate information only for legitimate recruitment purposes and in accordance with applicable requirements.
SHIDA may retain information required for application tracking, security, support and applicable obligations.
9. Wenze, Orders and Delivery
When a user places an order, SHIDA may process information required for the order, products, quantities, seller, payment, pickup or delivery.
An exact address should be requested only where necessary for delivery or another specific feature.
10. Accommodation and Visits
Public accommodation information should be limited to information required for discovery.
Exact private addresses and private contact information should not be unnecessarily exposed.
Where SHIDA uses a specific procedure for sharing information following mutual confirmation of a visit or another stage, that procedure should be respected.
11. Wewa and Location
Where a user chooses to share location for Wewa or another feature requiring location, SHIDA may process that location to perform the relevant request.
Location data should not be retained longer than necessary for operation, security or applicable obligations.
Older location information may be deleted, aggregated or anonymized where no longer required.
12. Payments
Where SHIDA provides payment functionality, certain data may be processed with third-party payment providers.
SHIDA may retain payment references, amounts, currencies, statuses and information required for reconciliation, security, support and applicable obligations.
SHIDA should avoid collecting or storing sensitive payment credentials where they can be processed directly by the relevant payment provider.
13. Statistics and Business Analytics
SHIDA may generate statistical information relating to visits, views, orders, bookings, sales, inventory and other activities.
Certain statistics may be provided to relevant users or organizations.
Private Business data should not be made public without a clear functional reason.
14. Support, Security and Moderation
Authorized NIHILOBA personnel may access certain information where necessary to:
- provide support;
- resolve technical issues;
- investigate reports;
- prevent fraud;
- protect users;
- secure and operate SHIDA;
- comply with legal obligations.
Internal access should be limited to appropriate needs.
15. Providers and Third-Party Services
SHIDA may use providers including:
- WhatsApp / Meta;
- hosting services;
- databases;
- image-storage services;
- payment services;
- technical security and operational tools.
These providers may process certain information to the extent required to provide their services.
16. Data Retention
SHIDA retains data for the period reasonably necessary for the purposes for which it is processed, security, service administration or compliance with legal obligations.
Retention periods may differ by data category and feature.
Where appropriate, information may be deleted, anonymized or aggregated.
17. Security
NIHILOBA implements reasonable measures intended to protect data against unauthorized access, loss, alteration or unauthorized disclosure.
No information system can guarantee absolute security.
Users must also protect their phone, WhatsApp and authentication mechanisms.
18. International Transfers
SHIDA may use providers or infrastructure located in different countries.
Where applicable law requires it, NIHILOBA must use appropriate mechanisms for international transfers of personal data.
This section must be finalized with the exact provider and legal-framework information.
19. Legal Bases
Applicable legal bases for data processing may depend on jurisdiction, data category and functionality.
They may include performance of a contract, compliance with legal obligations, legitimate interests or consent where consent is required.
This section must be finalized through legal review.
20. Your Rights
Depending on applicable law, you may have rights concerning your personal data, including:
- access to certain data;
- correction;
- deletion where applicable;
- restriction of certain processing;
- objection to certain processing;
- withdrawal of consent where processing relies on consent;
- data portability where provided by applicable law;
- submitting a complaint to a competent supervisory authority.
Use SHIDA's official contact methods to exercise applicable rights.
21. Data Deletion
SHIDA may provide commands or interfaces to delete certain profiles or request deletion of information.
A deletion request does not necessarily result in immediate deletion of all information where certain data must be retained for legal, security, fraud-prevention or dispute-management reasons.
22. Minors
Certain SHIDA services may not be appropriate for minors or may require specific rules.
Exact minimum-age requirements and rules for use by minors must be determined before final commercial launch according to relevant services and jurisdictions.
23. Changes to This Policy
NIHILOBA may update this Policy as SHIDA evolves or where legal, technical or operational developments require changes.
Where a new version requires renewed acknowledgement or acceptance within SHIDA, the system may require users to review the new version.
Previous versions may be retained for historical and evidentiary purposes.
24. Contact
For questions regarding privacy or personal data, use the official contact methods provided by SHIDA.
Status: Working draft — subject to legal review before final commercial launch.
