CropifycropfyInform • Connect • Grow
Cropify
Back to home

Privacy Policy

Last updated 13 August 2026

Cropify ("Cropify", "we", "us") operates a digital marketplace connecting farmers, buyers, transporters, agricultural input suppliers, crop-disease pathologists, offtakers, and farmer groups across Uganda. This policy explains what personal data we collect through the Cropify app and website, why we collect it, who we share it with, and the choices you have. It applies to every Cropify user regardless of role.

We handle personal data in line with Uganda's Data Protection and Privacy Act, 2019, and applicable guidance from the Personal Data Protection Office (PDPO), Uganda's independent data-protection authority.

By creating an Cropify account you agree to the collection and use of information as described here. If you do not agree, please do not use the app.

1. Information we collect

1.1 Information you give us directly

  • Account details: full name, phone number, email address, password, and your selected role(s).
  • Profile information: district/location, bio, farm size and crops, avatar photo.
  • Identity verification (KYC): depending on the trust tier you apply for — a national ID photo, a selfie, a driving permit, vehicle registration, business registration documents, or professional qualifications (for pathologists). These are stored in a private file store that only you and an Cropify administrator reviewing your application can access — never a public link.
  • Marketplace content: crop listings, prices, offers, orders, delivery requests, reviews, disputes, and messages you send to other users (e.g. farmer-to-buyer or farmer-to-pathologist chat).
  • Financial information: your in-app wallet balance and transaction history, and the mobile money phone number/provider you use to deposit or withdraw. We do not collect or store your mobile money PIN or card details — deposits and withdrawals are processed directly by our payment partner, PrimePay.
  • Photos you submit for crop disease diagnosis, and any notes describing the issue.

1.2 Phone and email verification

Signing up or changing your phone number/email requires verifying it with a one-time code (OTP). We process your phone number or email, the code's status (sent/verified), and the time it was requested and verified, to confirm you actually control that phone number or address and to prevent abuse of the verification system (e.g. someone flooding a number with codes). Codes are short-lived and are not usable once verified or expired. We will never ask you to read an OTP back to us over chat, call, or email.

1.3 Information collected automatically

  • Location data: if you grant permission, we use your device's GPS to help match nearby transporters and buyers, and — during an active delivery only — to let you and the other party (driver or requester) see each other's live position on a map so a pickup can actually happen. Live location sharing is per-delivery and stops when you end it or the delivery completes.
  • Device and usage data: app version, device type, IP address, and basic usage logs, used to diagnose bugs, secure accounts, and understand which features are actually used.
  • Cookies and local storage: used to keep you signed in, remember preferences (like your chosen theme), and support essential functionality. We don't use third-party advertising trackers.

2. How we use your information

  • To create and secure your account, and verify your identity for higher trust tiers.
  • To operate the marketplace — showing listings, matching buyers with farmers, matching delivery requests with available transporters, and connecting farmers with pathologists.
  • To process payments: funding and releasing escrow, wallet deposits/withdrawals, and paying commissions — via PrimePay, our licensed mobile-money payment processor.
  • To run AI-assisted crop disease detection on photos you submit.
  • To show relevant weather forecasts and market price data for your district.
  • To detect and prevent fraud, abuse, and violations of our Terms & Conditions.
  • To respond to support requests and resolve disputes between users.
  • To send you notifications about orders, payments, deliveries, and account activity.

We do not sell your personal data to anyone.

3. Who we share information with

We share the minimum data necessary with a small number of service providers that make Cropify work:

ProviderPurposeData involved
SupabaseDatabase, authentication, and file storage hostingAll account and marketplace data
PrimePayMobile money deposits, withdrawals, and payment processingPhone number, transaction amounts
Google Cloud (Vision API)Automated crop disease image analysisPhotos you submit for diagnosis
OpenWeatherMap / Open-MeteoWeather forecasts by districtDistrict/location only
UgSMSDelivering OTP and other essential SMS messagesPhone number
ResendDelivering account and transaction emailsEmail address, email content

Other users of the app see the information relevant to a transaction you're part of — e.g. a buyer sees a farmer's listing and, once an order is placed, the farmer's name and phone number; an assigned transporter can see pickup/dropoff details. We never expose your identity documents to other users — only to Cropify administrators reviewing a verification request.

We may also disclose information if required by Ugandan law, to enforce our Terms, or to protect the rights, property, or safety of Cropify, our users, or the public. We do not sell your personal data as a commodity to third parties.

Some of the providers above operate infrastructure outside Uganda (e.g. cloud hosting), meaning your data may be processed on servers outside the country. Where that happens, we rely on those providers' own security and contractual safeguards, and take steps required by applicable Ugandan data-protection law concerning such transfers.

4. How we protect your data

  • Database access is governed by row-level security — a user can only read or write data they actually own or are a party to, enforced at the database level, not just in the app.
  • Identity documents are stored in a private file store, never a public link, and can only be viewed by an administrator via a short-lived (5-minute) access link generated at the moment of review.
  • All traffic between your device and Cropify is encrypted (HTTPS).
  • Passwords are hashed and never stored or visible in plain text, including to Cropify staff.

No system is 100% secure, but we treat identity documents and financial data as our highest priority to protect, and we review our security posture on an ongoing basis.

5. Your rights and choices

Under Uganda's Data Protection and Privacy Act, 2019, you have rights over your personal data, including to:

  • Know how your information is collected and used (this policy).
  • Access & correct your data — most profile information can be viewed and edited directly in the app; for anything you can't self-serve, contact us.
  • Delete your account at any time from Settings. This removes your profile and personal data, subject to what Ugandan financial-recordkeeping law requires us to retain for completed transactions (see below).
  • Object to certain processing, and withdraw consent where processing is based on it.
  • Control location at the device level and turn it off at any time; some features (live delivery tracking, nearby matching) won't work without it.
  • Control notifications from within the app.
  • Complain — to us directly (see Section 10) or, if unresolved, to the Personal Data Protection Office.

We may need to verify your identity before acting on a request affecting your account.

6. Data retention

We keep your account data for as long as your account is active. After deletion, most personal data is removed promptly; transaction records tied to completed payments are retained for a period consistent with Uganda's financial and tax recordkeeping requirements, even after account deletion, because that data underlies a real money transaction between real parties. KYC/identity documents and security logs are retained only as long as reasonably necessary for verification, compliance, and fraud-prevention purposes.

7. Children

Cropify is intended for users aged 18 and older, consistent with our escrow and payment features. We do not knowingly collect data from children. If we learn that a child's data was collected without appropriate consent, we will take steps to delete it.

8. If something goes wrong

If a security incident compromises personal data, we will investigate, work to contain and fix it, and — where required by law or where it could meaningfully affect you — notify affected users and the relevant authority.

9. Changes to this policy

We'll update the date at the top of this page whenever this policy changes, and where a change is significant, we'll notify you in-app before it takes effect.

10. Contact us

Questions about this policy or your data can be sent to us via our Contact page.

© 2026 Cropify. All rights reserved.