1. Introduction
ZivaPay+ ("the App", "we", "us") is a personal finance tool that helps you track your mobile money transactions automatically. This Privacy Policy explains what the App accesses, what it keeps on your device, what you can choose to share, and the limited diagnostics linked to an app installation that are used to keep the App working well. We are committed to protecting your privacy — by design, not just by policy.
The App is operated by Neyoni Technologies (Pvt) Ltd, Zimbabwe.
2. Information the App Accesses on Your Device
The App requests the following so it can do its job:
- SMS messages — the App reads mobile money confirmation messages (e.g. EcoCash, InnBucks) on your phone to display your transaction history, balances, and spending summaries. It looks only for these financial messages; ordinary personal texts are ignored.
- Notifications — to show spending alerts and reminders you choose to enable in the App.
The content of these messages and the detailed transaction values extracted from them are processed on your device and are not uploaded automatically. Section 5 describes the limited activity and diagnostic signals sent to Firebase.
3. How Your Transaction Information Is Used
- Your mobile money messages are read and analysed on your device only.
- The resulting transaction data is used to display your history, balances, analytics, and money-tracking features inside the App.
- Exported reports (PDF / Excel) are generated on your device and are shared only when you choose to export and share them.
- If the App cannot read a supported wallet message, you may choose to preview and send an automatically masked copy to the developer. Section 6 explains this voluntary path.
- Notifications and reminders are generated locally based on settings you choose.
4. Where Your Data Is Stored
Your messages and transaction records are stored in a private database on your device. We do not automatically upload, back up, or store your transactions, balances, or message content on any ZivaPay+ server or in the cloud. Information can leave through a share action that you deliberately start, as described in Section 6.
You stay in control: clearing the App's data or uninstalling the App permanently removes all of this on-device information.
5. Analytics & Crash Reporting (Google Firebase)
To keep the App stable and understand whether features work, the App uses Google Firebase Analytics and Firebase Crashlytics. These collect limited information linked to an app installation:
- App-interaction events — for example which features are opened, whether a transaction scan ingested new records, which supported wallets are present, balance-data age ranges, and money-request lifecycle steps. These carry no amount, balance, name, phone number, or message content.
- Unread-format diagnostics — a known wallet-service label, wallet type, and a shape-only fingerprint in which letter runs and digit runs are replaced before hashing. The SMS body itself is not sent through automatic analytics.
- Crash logs & diagnostics — technical details about errors and your device (such as device model and Android version) that help us fix problems.
- A device identifier used by Firebase to group events from the same installation.
This information does not include the content of your messages, your contacts, your balances, your transaction amounts, counterparty names, or wallet phone numbers. Financial-health scores, bands, coaching factors, savings-rate bands, runway bands, and spending-direction signals are not sent. Firebase uses an installation identifier, so these diagnostics can be linked to the same app installation over time. The App does not use an advertising ID, does not show ads, and does not work with any ad networks. Firebase data is processed by Google as our service provider, in line with Google's privacy terms.
6. Data Sharing
We do not sell, rent, or trade your personal data. Your detailed money history is not transmitted automatically.
Information leaves the device in two circumstances:
- Automatic diagnostics — the limited Firebase information linked to an app installation described in Section 5.
- Actions you deliberately start — sharing a money request, exporting a PDF or Excel statement, sharing a Financial Health report, inviting someone to the App, or sending an unreadable-message report to the developer.
An unreadable-message report is voluntary and per-message. Before anything opens in WhatsApp, email, or another share destination, the App shows the exact outgoing payload. Every digit is replaced, likely identity words are masked on a best-effort basis, and unknown or personal senders become a constant label. Masking is not guaranteed to identify every possible name, so you should cancel if anything in the preview looks personal. The preview is deliberately not editable because hiding individual words previously removed the transaction-direction clues needed to support new formats. Your choice is to send the exact preview or cancel.
We may also disclose information if required to do so by law.
7. Third-Party Services
The App uses Google Firebase Analytics, Crashlytics, and Remote Config for usage statistics and crash reporting linked to an app installation, and for feature configuration. It does not integrate any advertising networks or ad-tracking services, and there are no ads in ZivaPay+.
8. Permissions Explained
- READ_SMS — required to read mobile money confirmation messages. Without it, the App cannot track your transactions.
- POST_NOTIFICATIONS — to deliver the spending alerts and reminders you enable. You can turn these off any time in your device settings.
- RECEIVE_BOOT_COMPLETED — to restore your scheduled reminders after your phone restarts.
- VIBRATE — for notification feedback only.
- INTERNET — used for Firebase diagnostics and Remote Config. It is not used to upload your detailed transaction history.
The App does not request permission to send SMS and does not request exact-alarm permission.
9. Your Data Protection Rights (Zimbabwe)
We process personal information in line with Zimbabwe's Cyber and Data Protection Act [Chapter 12:07], which is overseen by the data protection authority, the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ).
Because your messages and transactions are kept on your own device, you remain in direct control of that information. In particular, you can:
- Access and review your transaction data at any time within the App.
- Correct or remove records, or delete everything, by clearing the App's data or uninstalling it.
- Choose what to share by cancelling any request, export, report, or developer-message preview before it is handed to another App.
For any data-protection question or request, contact us using the details in Section 12. The data controller is Neyoni Technologies (Pvt) Ltd, Zimbabwe.
10. Children's Privacy
ZivaPay+ is not directed at children under the age of 13, and we do not knowingly collect information from children.
11. Security
Your messages and transactions are kept on your device and protected by your device's own security (PIN, fingerprint, etc.). The analytics and crash data linked to an app installation and sent to Firebase is transmitted over encrypted connections. We recommend keeping your device locked and your software up to date.
12. Contact Us
If you have any questions about this Privacy Policy or the App, contact us at: hello@zivapayplus.com
13. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be shown on this page with an updated date. Please review this policy periodically.