Privacy Policy

Last updated: 26 August 2026 · Effective: 26 August 2026

1. Who we are

ASH Glo REFER (“ASH Glo”, “we”, “us”) operates a digital marketplace and referral platform available at https://growrefer.app and as the mobile app “ASH Glo” (bundle ID app.growrefer.ashglo).

  • Data controller: ASH Glo REFER, Douala, Cameroon.
  • Privacy contact: privacy@growrefer.app
  • Support: https://growrefer.app

This policy explains what personal data we collect, why, who we share it with, how long we keep it and what rights you have.

2. Scope

This policy covers:

  • the ASH Glo web app and the iOS and Android apps;
  • account creation, marketplace browsing, bookings, messaging and reviews;
  • the referral programme and commission ledger;
  • wallet balances, payment collection and payouts.

It does not cover third-party sites or services you reach from ASH Glo (for example a provider’s own social media), or how a service provider you book handles information you give them offline.

3. Data we collect

3.1 Data you give us

CategoryExamplesWhy
Account identityFull name, email address, phone number, password (hashed, never stored in plain text)Create and secure your account
ProfileDisplay name, business name, avatar, bio, city/region, categoriesShow your profile and match you to nearby users
Provider contentService listings, prices, availability slots, portfolio photos, storefront detailsPublish your storefront
Referral dataReferral code you enter at sign-up, referral link you shareAttribute referrals and calculate commissions
BookingsService requested, date/time, notes, status historyDeliver and support bookings
MessagesText and attachments you send in booking conversationsEnable communication between client and provider
ReviewsRating, review text, whether it is tied to a completed bookingCommunity trust
Payout detailsMobile Money number (MTN MoMo / Orange Money), bank or Stripe Connect account identifiersPay you
SupportAnything you send us by email or in-appAnswer you

3.2 Collected automatically

CategoryExamples
Device and appDevice model, OS version, app version, language, time zone, crash diagnostics, push notification token
UsageScreens viewed, features used, search terms, timestamps
Approximate locationCity/region derived from your device or IP — only if you grant location permission, used to rank nearby providers. You can decline and still use the app.
NetworkIP address, request logs, rate-limit counters (abuse prevention)
SecuritySign-in events, session tokens, audit records of privileged actions

3.3 From third parties

  • Social sign-in (Google, Apple): your name, email and a provider user ID, if you sign in that way. Apple’s “Hide My Email” relay is supported.
  • Payment processors: transaction status, reference, amount, currency, masked payment identifiers, payout status.
  • No data brokers. We do not buy personal data, and we do not run third-party advertising SDKs.

3.4 What we never store

We never receive or store your Mobile Money PIN, your full card number, CVV or your bank login. Card details are entered directly with our payment processor. We only receive a reference and a status.

3.5 Children

ASH Glo is not intended for anyone under 18. We do not knowingly collect data from children. If we learn we have, we delete it — contact privacy@growrefer.app.

4. Why we use your data, and our legal basis

PurposeLegal basis
Create your account, authenticate you, keep sessions securePerformance of a contract
Show listings, rank nearby providers, run search and discoveryContract / legitimate interests
Process bookings and the messages attached to themContract
Collect the one-time activation payment and booking paymentsContract
Verify payments and reconcile them against your accountContract / legal obligation
Calculate, record and pay referral commissions across three levelsContract
Review and execute withdrawals to Mobile Money or bankContract / legal obligation (AML, fraud prevention)
Detect fraud, self-referral, abuse and duplicate accounts; rate limitingLegitimate interests / legal obligation
Keep financial and security audit logsLegal obligation
Send transactional notifications (booking accepted, payment confirmed, payout sent)Contract
Send marketing messagesConsent — withdrawable at any time
Improve the product and fix crashesLegitimate interests
Comply with tax, accounting and lawful requestsLegal obligation

We do not use your data for automated decisions that produce legal effects on you. Commission calculation is a deterministic rule (level 1 / 2 / 3 amounts), not profiling.

5. Payment verification and the referral ledger

Because ASH Glo moves money, some processing is unavoidable and is described here explicitly:

  1. Activation. A one-time activation fee unlocks earning. We create a payment reference and pass your phone number and amount to our Mobile Money processor.
  2. Verification. The processor confirms the payment through a signed server-to-server callback. We verify that signature before crediting anything. Unverified callbacks are rejected and logged.
  3. Ledger entry. Each verified payment writes an immutable ledger record: amount, currency, reference, status, timestamp and the account it belongs to.
  4. Commission attribution. When your account activates, the system walks up to three levels of the referral chain and writes a commission entry for each eligible upline member. Referrers must themselves be active to earn.
  5. Payout review. Withdrawal requests are reviewed by an authorised administrator before payment. Reviewers see the amount, destination and account history — enough to detect fraud, and no more.
  6. Retention. Financial records are retained for the statutory accounting period even after you close your account (see section 9).

Your network is not public. Members see aggregate counts and earnings for their own branches; member identities below level 1 are not exposed.

6. Who we share data with

We do not sell your personal data. We share it only with:

RecipientRoleData shared
SupabaseProcessor — database, authentication and storageAccount, booking, message and ledger data
TchokoPayProcessor — Mobile Money collection and payoutName, phone number, amount, reference
Stripe (incl. Stripe Connect)Card payments and international payoutsName, email, payout account details, transaction data
CloudflareProcessor — hosting, CDN, DDoS protectionIP address, request metadata
Google / AppleIndependent controllers — sign-in, app distribution, push deliverySign-in identifiers, device push tokens
AI assistant providerProcessor — powers the in-app Refer AssistantYour assistant messages and minimal account context. Do not paste sensitive data into the assistant.
Email delivery providerProcessor — transactional emailEmail address, message content
Advisers, auditors, law enforcementAs requiredOnly what is legally necessary

Between users: when you book a provider (or a client books you), the other party sees your display name, avatar, the booking details and your messages. Reviews you publish are visible to everyone, attributed to your display name.

7. International transfers

Our processors operate outside Cameroon. Where data leaves Cameroon or the EEA we rely on the processor’s contractual safeguards (including Standard Contractual Clauses where applicable) and on their published security certifications. Contact us for details on a specific transfer.

8. How we protect your data

  • Encryption in transit (TLS) and at rest.
  • Row-level security on every database table: policies restrict each record to its owner, the counterparty in a booking, or an authorised administrator. Privileged database functions are restricted to service roles.
  • Passwords are hashed by our authentication provider; we never see them.
  • Private storage buckets for avatars and portfolio media, served through short-lived signed URLs with per-object visibility checks.
  • Signature verification on every payment webhook; replayed or unsigned callbacks are rejected.
  • Rate limiting on public endpoints and storefronts.
  • A security audit log for privileged and financial actions, plus automated regression tests confirming anonymous users cannot read protected tables.
  • Role-based admin access; administrative roles are stored separately from user profiles to prevent privilege escalation.

No system is perfectly secure. If a breach affects your rights we will notify you and the competent authority without undue delay.

9. How long we keep data

DataRetention
Account and profileWhile your account is open
Bookings, reviews, messagesWhile your account is open, then 12 months
Financial records (payments, commissions, withdrawals, ledger)10 years from the transaction, as required by accounting and tax law — retained even after account deletion
Security and audit logs24 months
Marketing consent recordsUntil withdrawn, plus 3 years
BackupsRolling, deleted within 90 days

10. Your rights

You can:

  • Access the data we hold about you;
  • Correct inaccurate data (most fields are editable in Settings);
  • Delete your account — Settings → Delete account. This removes your profile, listings, media and messages. Financial ledger entries are retained in pseudonymised form for the statutory period, and pending withdrawals must be settled first;
  • Export your data in a portable format;
  • Object to or restrict processing based on legitimate interests;
  • Withdraw consent at any time (location and notification permissions in your device settings; marketing via the unsubscribe link);
  • Complain to the competent Cameroonian authority (the data protection authority designated under Law No. 2024/017) or, for EEA/UK users, your local supervisory authority.

Requests: privacy@growrefer.app. We respond within 30 days and may ask you to verify your identity.

11. Cookies and similar technologies

  • Strictly necessary storage: session tokens, your language (EN/FR) and theme (light/dark) preference. No consent required.
  • No advertising cookies. No cross-site tracking. No third-party ad SDKs.

The mobile app uses local storage for the same purposes and does not use the advertising identifier (IDFA/AAID).

12. Store privacy disclosures

For Apple’s App Privacy and Google Play’s Data Safety forms, ASH Glo declares:

  • Linked to you: contact info (name, email, phone), user content (photos, messages, reviews), identifiers (account ID), financial info (transaction history, payout destination), coarse location (optional), usage data, diagnostics.
  • Used for tracking across apps or sites: none.
  • Purposes: app functionality, analytics, and fraud prevention/security only.
  • Data deletion: in-app account deletion is provided, plus a web request path at privacy@growrefer.app.
  • Data encrypted in transit: yes.

13. Changes to this policy

We will post any change here and update the “Last updated” date. For material changes we will notify you in the app or by email before they take effect.

14. Contact

  • ASH Glo REFER, Douala, Cameroon
  • Email: privacy@growrefer.app
  • Support: https://growrefer.app