CaafiHub
CaafiHub trust centre

Privacy Policy

This policy explains how CaafiHub handles account, verification, transaction, device, and support information across its website, dashboards, APIs, and mobile applications.

Effective 31 July 2026 · Version 2026-07-31

1. Scope and responsibility

This Privacy Policy applies to CaafiHub’s websites, admin and wholesaler dashboards, retailer mobile applications, APIs, emails, support channels, and related marketplace services. “CaafiHub,” “we,” and “our” refer to the operator of the CaafiHub platform. Retailers and wholesalers are independent businesses and may have their own privacy duties when they process information received through a transaction.

2. Information we collect

Account and contact information

Names, business names, phone numbers, email addresses, password hashes, roles, account status, and authentication records.

Business and verification information

Business and warehouse addresses, region, district, city, optional GPS coordinates, licence and registration numbers, tax identifiers, establishment year, pharmacy type, branch and order estimates, product categories, and document expiry information.

Identity and verification documents

Pharmacy or wholesale licences, business registration certificates, government-issued national ID or passport files, and optional verification selfies. These are sensitive materials used for verification, fraud prevention, safety, and legal compliance.

Marketplace and financial records

Product listings, images, inventory, batches, expiry information, carts, orders, delivery details, payment and escrow statuses, commissions, refund requests, decisions, and transaction communications.

Technical and usage information

IP address, device or browser information, API tokens, login activity, timestamps, security events, audit logs, notification activity, and diagnostic data. Precise GPS is collected only when a user chooses to submit it.

Support communications

Messages, attachments, complaint details, and other information supplied when contacting support or responding to a review.

3. How we use information

  • create, authenticate, secure, and administer accounts;
  • verify businesses, licences, identity, authority, and eligibility;
  • operate product, inventory, ordering, payment-status, refund, reporting, and notification functions;
  • connect relevant retailer and wholesaler transaction information;
  • prevent fraud, misuse, counterfeit trade, security incidents, and regulatory harm;
  • provide support, investigate disputes, maintain audit trails, and enforce platform terms;
  • comply with lawful requests, tax, accounting, healthcare, trade, and other legal obligations;
  • measure performance and improve reliability, accessibility, and user experience.

Depending on applicable law and context, processing may be based on contract performance, consent, legal obligations, legitimate interests in operating and securing a B2B marketplace, or protection of users and the public.

4. When information may be shared

We do not sell personal information. We may disclose limited information:

  • Between transaction parties: business, contact, delivery, product, and order information needed to fulfil and support an order.
  • To service providers: infrastructure, database, storage, email, security, analytics, and professional advisers operating under appropriate obligations.
  • For legal and safety reasons: regulators, courts, law enforcement, rights holders, or other parties where reasonably necessary to comply with law, protect safety, investigate fraud, or enforce rights.
  • During a business change: to a successor or adviser involved in a merger, financing, restructuring, or transfer, subject to confidentiality and applicable law.
  • With direction or consent: where a user requests or clearly authorises disclosure.

Verification documents are not publicly displayed and are limited to authorised review, security, support, and legal personnel with a legitimate need.

5. Retention and deletion

We keep information only as long as reasonably necessary for the purposes described above. Account and verification records generally remain while an account is active and for an appropriate period afterward. Transaction, audit, consent, tax, fraud, dispute, and regulatory records may be retained longer where required or reasonably necessary.

When information is no longer required, we take reasonable steps to delete, anonymise, or securely isolate it. Backup copies may remain until ordinary backup rotation completes. Account closure does not require deletion of records that must lawfully be retained.

6. Security

CaafiHub uses administrative, technical, and organisational safeguards appropriate to the nature of the information. Measures include encrypted network transport, hashed passwords, restricted private-document storage, role-based access, token controls, validation, rate limiting, audit logging, backups, and monitored server access.

No system is perfectly secure. Users must keep credentials confidential, secure their devices, verify unusual messages, and report suspected compromise promptly to support.

7. Your rights and privacy choices

Subject to applicable law and necessary identity verification, users may request access, correction, export, objection, restriction, withdrawal of optional consent, or deletion of eligible information. Requests can be sent from the registered email address to support@caafihub.com.

Include the registered business name and phone number. Do not attach identity documents unless support securely requests them. We may need to retain transaction, consent, security, fraud, tax, legal, and regulatory records despite a deletion request.

Essential account, security, verification, and transaction messages cannot be disabled while using the relevant service. Optional marketing communication, if introduced, will include an appropriate choice mechanism.

8. International processing

CaafiHub, its users, and service providers may operate in different countries. Information may therefore be processed outside the place where it was collected. Where required, we use contractual, organisational, or other lawful safeguards and assess service providers’ security and confidentiality practices.

9. Children

CaafiHub is a B2B service and is not directed to children. Account holders and authorised users must be at least 18 years old or the legal age required to bind their business. If we learn that a child supplied personal information without lawful authorisation, we will take appropriate steps to remove it.

10. Policy updates and contact

We may update this policy as the platform, service providers, or legal requirements change. The effective date and version identify the current policy. Material updates will be communicated through reasonable channels.

Privacy and support contact
support@caafihub.com

Contact us with privacy questions, rights requests, security concerns, or complaints. We will review verified requests and respond within the period required by applicable law.