Privacy Policy
Last updated: 26 August 2026 · Effective: 26 August 2026
1. Who we are
ASH Glo REFER (“ASH Glo”, “we”, “us”) operates a digital marketplace and referral platform available at https://growrefer.app and as the mobile app “ASH Glo” (bundle ID app.growrefer.ashglo).
- Data controller: ASH Glo REFER, Douala, Cameroon.
- Privacy contact: privacy@growrefer.app
- Support: https://growrefer.app
This policy explains what personal data we collect, why, who we share it with, how long we keep it and what rights you have.
2. Scope
This policy covers:
- the ASH Glo web app and the iOS and Android apps;
- account creation, marketplace browsing, bookings, messaging and reviews;
- the referral programme and commission ledger;
- wallet balances, payment collection and payouts.
It does not cover third-party sites or services you reach from ASH Glo (for example a provider’s own social media), or how a service provider you book handles information you give them offline.
3. Data we collect
3.1 Data you give us
| Category | Examples | Why |
|---|---|---|
| Account identity | Full name, email address, phone number, password (hashed, never stored in plain text) | Create and secure your account |
| Profile | Display name, business name, avatar, bio, city/region, categories | Show your profile and match you to nearby users |
| Provider content | Service listings, prices, availability slots, portfolio photos, storefront details | Publish your storefront |
| Referral data | Referral code you enter at sign-up, referral link you share | Attribute referrals and calculate commissions |
| Bookings | Service requested, date/time, notes, status history | Deliver and support bookings |
| Messages | Text and attachments you send in booking conversations | Enable communication between client and provider |
| Reviews | Rating, review text, whether it is tied to a completed booking | Community trust |
| Payout details | Mobile Money number (MTN MoMo / Orange Money), bank or Stripe Connect account identifiers | Pay you |
| Support | Anything you send us by email or in-app | Answer you |
3.2 Collected automatically
| Category | Examples |
|---|---|
| Device and app | Device model, OS version, app version, language, time zone, crash diagnostics, push notification token |
| Usage | Screens viewed, features used, search terms, timestamps |
| Approximate location | City/region derived from your device or IP — only if you grant location permission, used to rank nearby providers. You can decline and still use the app. |
| Network | IP address, request logs, rate-limit counters (abuse prevention) |
| Security | Sign-in events, session tokens, audit records of privileged actions |
3.3 From third parties
- Social sign-in (Google, Apple): your name, email and a provider user ID, if you sign in that way. Apple’s “Hide My Email” relay is supported.
- Payment processors: transaction status, reference, amount, currency, masked payment identifiers, payout status.
- No data brokers. We do not buy personal data, and we do not run third-party advertising SDKs.
3.4 What we never store
We never receive or store your Mobile Money PIN, your full card number, CVV or your bank login. Card details are entered directly with our payment processor. We only receive a reference and a status.
3.5 Children
ASH Glo is not intended for anyone under 18. We do not knowingly collect data from children. If we learn we have, we delete it — contact privacy@growrefer.app.
4. Why we use your data, and our legal basis
| Purpose | Legal basis |
|---|---|
| Create your account, authenticate you, keep sessions secure | Performance of a contract |
| Show listings, rank nearby providers, run search and discovery | Contract / legitimate interests |
| Process bookings and the messages attached to them | Contract |
| Collect the one-time activation payment and booking payments | Contract |
| Verify payments and reconcile them against your account | Contract / legal obligation |
| Calculate, record and pay referral commissions across three levels | Contract |
| Review and execute withdrawals to Mobile Money or bank | Contract / legal obligation (AML, fraud prevention) |
| Detect fraud, self-referral, abuse and duplicate accounts; rate limiting | Legitimate interests / legal obligation |
| Keep financial and security audit logs | Legal obligation |
| Send transactional notifications (booking accepted, payment confirmed, payout sent) | Contract |
| Send marketing messages | Consent — withdrawable at any time |
| Improve the product and fix crashes | Legitimate interests |
| Comply with tax, accounting and lawful requests | Legal obligation |
We do not use your data for automated decisions that produce legal effects on you. Commission calculation is a deterministic rule (level 1 / 2 / 3 amounts), not profiling.
5. Payment verification and the referral ledger
Because ASH Glo moves money, some processing is unavoidable and is described here explicitly:
- Activation. A one-time activation fee unlocks earning. We create a payment reference and pass your phone number and amount to our Mobile Money processor.
- Verification. The processor confirms the payment through a signed server-to-server callback. We verify that signature before crediting anything. Unverified callbacks are rejected and logged.
- Ledger entry. Each verified payment writes an immutable ledger record: amount, currency, reference, status, timestamp and the account it belongs to.
- Commission attribution. When your account activates, the system walks up to three levels of the referral chain and writes a commission entry for each eligible upline member. Referrers must themselves be active to earn.
- Payout review. Withdrawal requests are reviewed by an authorised administrator before payment. Reviewers see the amount, destination and account history — enough to detect fraud, and no more.
- Retention. Financial records are retained for the statutory accounting period even after you close your account (see section 9).
Your network is not public. Members see aggregate counts and earnings for their own branches; member identities below level 1 are not exposed.
7. International transfers
Our processors operate outside Cameroon. Where data leaves Cameroon or the EEA we rely on the processor’s contractual safeguards (including Standard Contractual Clauses where applicable) and on their published security certifications. Contact us for details on a specific transfer.
8. How we protect your data
- Encryption in transit (TLS) and at rest.
- Row-level security on every database table: policies restrict each record to its owner, the counterparty in a booking, or an authorised administrator. Privileged database functions are restricted to service roles.
- Passwords are hashed by our authentication provider; we never see them.
- Private storage buckets for avatars and portfolio media, served through short-lived signed URLs with per-object visibility checks.
- Signature verification on every payment webhook; replayed or unsigned callbacks are rejected.
- Rate limiting on public endpoints and storefronts.
- A security audit log for privileged and financial actions, plus automated regression tests confirming anonymous users cannot read protected tables.
- Role-based admin access; administrative roles are stored separately from user profiles to prevent privilege escalation.
No system is perfectly secure. If a breach affects your rights we will notify you and the competent authority without undue delay.
9. How long we keep data
| Data | Retention |
|---|---|
| Account and profile | While your account is open |
| Bookings, reviews, messages | While your account is open, then 12 months |
| Financial records (payments, commissions, withdrawals, ledger) | 10 years from the transaction, as required by accounting and tax law — retained even after account deletion |
| Security and audit logs | 24 months |
| Marketing consent records | Until withdrawn, plus 3 years |
| Backups | Rolling, deleted within 90 days |
10. Your rights
You can:
- Access the data we hold about you;
- Correct inaccurate data (most fields are editable in Settings);
- Delete your account — Settings → Delete account. This removes your profile, listings, media and messages. Financial ledger entries are retained in pseudonymised form for the statutory period, and pending withdrawals must be settled first;
- Export your data in a portable format;
- Object to or restrict processing based on legitimate interests;
- Withdraw consent at any time (location and notification permissions in your device settings; marketing via the unsubscribe link);
- Complain to the competent Cameroonian authority (the data protection authority designated under Law No. 2024/017) or, for EEA/UK users, your local supervisory authority.
Requests: privacy@growrefer.app. We respond within 30 days and may ask you to verify your identity.
12. Store privacy disclosures
For Apple’s App Privacy and Google Play’s Data Safety forms, ASH Glo declares:
- Linked to you: contact info (name, email, phone), user content (photos, messages, reviews), identifiers (account ID), financial info (transaction history, payout destination), coarse location (optional), usage data, diagnostics.
- Used for tracking across apps or sites: none.
- Purposes: app functionality, analytics, and fraud prevention/security only.
- Data deletion: in-app account deletion is provided, plus a web request path at privacy@growrefer.app.
- Data encrypted in transit: yes.
13. Changes to this policy
We will post any change here and update the “Last updated” date. For material changes we will notify you in the app or by email before they take effect.
14. Contact
- ASH Glo REFER, Douala, Cameroon
- Email: privacy@growrefer.app
- Support: https://growrefer.app
