Privacy Policy

Effective date: 15 June 2026  •  Version 2026-06-15

Data Protection Act, 2012 (Act 843), Republic of Ghana

1. Who We Are

Data Controller: Yorm ("we", "us", "our"), operator of the Yorm marketplace at yorm.app.

Data Protection Commission, Application ID: QXI4OQHCD129

Contact for privacy queries: privacy@yorm.app

This Policy explains what personal data we collect from you, how we use and share it, your rights as a data subject under the Data Protection Act, 2012 (Act 843), and how to exercise those rights.

2. Scope & Children's Data

This Policy applies to all personal data we process about Customers, Service Providers, Administrators, and visitors to the Yorm application and website.

We do not knowingly collect personal data from children under 18. If we discover that we have inadvertently collected data from a person below the age of majority recognised by the Children's Act, 1998 (Act 560), we will delete that data without undue delay. Parents and guardians who become aware of such collection should contact us at privacy@yorm.app.

3. Lawful Bases for Processing (sec. 20, Act 843)

We process your personal data only where one or more of the following lawful bases apply:

  • Consent: for non-essential processing such as marketing, the optional Yorm Ai features, and access to your precise GPS location;
  • Contract: to perform the contract evidenced by these Terms (e.g., creating your account, displaying you on the map, processing bookings);
  • Legal obligation: to comply with the Anti-Money Laundering Act, 2020 (Act 1044), tax legislation, and lawful requests from competent authorities;
  • Vital interests: to protect the life or safety of a data subject (e.g., on receipt of a credible safety report);
  • Legitimate interests: to keep the Platform secure, prevent fraud, improve services, and conduct internal analytics, balanced against your rights.

4. Categories of Personal Data We Collect

4.1 Information you provide:

  • Identity & contact: full name, e-mail, mobile phone number, address (city/region), profile photo.
  • Identity verification (KYC): Ghana Card or passport number and image.
  • Service Provider profile: trade categories, specialisations, business name, work photographs, pricing.
  • Communications: in-app chat messages, support enquiries, voice notes you record.
  • Reviews & ratings.
  • Payment data: the parts of your mobile-money or card details required to process a transaction (full card numbers are tokenised by our PSP and never touch our servers).
  • AI prompts: any text, photo, or audio you submit to Yorm Ai or the Job Helper.

4.2 Information collected automatically:

  • Device identifiers, IP address, operating system, app version, time-zone.
  • Approximate location derived from your IP address; precise GPS coordinates only when you grant permission.
  • Usage logs (pages visited, features used, search terms, error reports), cookies, and similar tracking technologies.
  • Heartbeat & presence signals (used to show Service Providers as "online").

4.3 Information from third parties: payment-service providers (transaction status), SMS gateways (delivery status), and identity-verification partners (Ghana Card validation, where used).

5. How We Use Your Data

  • Create and administer your account and verify your identity.
  • Match Customers with Service Providers and display Service Providers on the live map.
  • Facilitate communication (chat, push notifications, branded e-mail, SMS through Africa's Talking).
  • Process payments via licensed PSPs under the Payment Systems and Services Act, 2019 (Act 987).
  • Provide Yorm Ai features (search-intent extraction, voice transcription, image generation, document drafting).
  • Maintain security, prevent fraud, debug, and improve the Platform.
  • Send service messages and, with your consent, marketing communications (you may opt out at any time).
  • Comply with legal obligations, court orders, and lawful requests from regulators or law-enforcement bodies (including the Bank of Ghana, GRA, CSA, and DPC).

6. Yorm Ai, AI Subprocessors

Yorm uses third-party AI services to power text, voice, and image features. Inputs you provide to these features (text prompts, voice samples, photos you upload) are transmitted to the relevant provider strictly to generate a response, and are not used by Yorm to train models.

Current AI subprocessors:

  • Google LLC (Google Generative-AI / Gemini family): natural-language understanding, search-intent extraction, image generation and editing (including the Yorm-Uniform feature), and vision analysis. Provider privacy notice: policies.google.com/privacy.
  • OpenAI, L.L.C.: voice transcription (Whisper), text-to-speech (TTS). Provider privacy notice: openai.com/policies/privacy-policy.

Where we change AI providers we will update this list and, if the change is material, notify you in advance.

7. Other Data Recipients

We may share personal data with the following categories of recipients, each under appropriate contractual and technical safeguards:

  • Other users of the Platform (e.g., your name, photo, trade, ratings, approximate location), only to the extent necessary to deliver the service you have requested.
  • Payment-service providers: Paystack and the mobile-money operators, regulated under Act 987.
  • Communication providers: SendGrid (Twilio Inc.) for branded e-mail; Africa's Talking for SMS and one-time passwords.
  • Cloud-hosting and storage providers for the application infrastructure and image storage.
  • Analytics and crash-reporting tools used solely in aggregate / pseudonymised form.
  • Regulators, courts, and law-enforcement in response to a lawful request or where reasonably necessary to defend our legal rights.
  • Successors in the event of a merger, acquisition, or sale of assets, under equivalent privacy protections.

8. Cross-Border Transfers (sec. 18, Act 843)

We want you to know exactly where your data is processed. Because Yorm is a cloud-hosted platform, certain personal data leaves Ghana for the purposes set out in this Policy. Specifically:

  • Database (account profile, bookings, messages, invoices, ID numbers): hosted on cloud infrastructure operated by our hosting provider in the United States.
  • File storage (Ghana Card / passport images, profile photos, work photos, AI-generated images, invoice PDFs): stored in our hosting provider's object storage and, as a fallback, in Google Cloud Storage (Firebase). Primary region: United States.
  • AI subprocessors (Section 6): Google LLC and OpenAI L.L.C. process AI prompts and attached media on data centres located primarily in the United States and the European Union.
  • Email delivery: SendGrid (Twilio Inc.), United States.
  • SMS & one-time-passwords: Africa's Talking, data centres in Kenya and South Africa.
  • Payments & mobile-money transactions: Paystack, data centres in Nigeria and South Africa (PCI-DSS certified).
  • Push notifications: Firebase Cloud Messaging (Google LLC), globally distributed.

We rely on the conditions in section 18 of Act 843 for each of these transfers:

  • made to a recipient subject to a law providing an adequate level of protection, or
  • governed by a written agreement (standard contractual clauses) that imposes data-protection obligations substantially equivalent to those under Act 843, or
  • necessary for the performance of the contract you have entered into with us, or
  • made with your explicit consent.

A copy of our standard contractual clauses with any of these providers is available on request from privacy@yorm.app.

9. Data Retention

We keep personal data only for as long as necessary for the purposes described above and, in any event, no longer than:

  • Active accounts: for the lifetime of the account.
  • Closed accounts: up to 24 months after closure for fraud-prevention and audit, then deleted or anonymised.
  • Transaction & financial records: at least 5 years from the date of the transaction, in line with the Anti-Money Laundering Act, 2020 (Act 1044) and tax law.
  • Identity-verification documents (Ghana Card / Passport images): retained for the longer of the period the account is active or as required by Act 1044.
  • Chat & AI prompts: up to 12 months unless required longer for safety or legal reasons.
  • System logs: typically 90 days.

10. Your Rights as a Data Subject

Under Part V of the Data Protection Act, 2012 (Act 843) you have the right to:

  • Be informed about how your personal data is processed (this Policy).
  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Block further processing where the data is contested or unlawfully processed.
  • Erase personal data we no longer need or that has been unlawfully processed.
  • Object to processing based on legitimate interests or direct marketing.
  • Withdraw consent at any time, where processing is based on consent.
  • Data portability: receive a copy of data you provided in a structured, commonly used format.
  • Complain to the Data Protection Commission if you believe your rights have been breached.

To exercise any of these rights, please contact privacy@yorm.app. We will respond within thirty (30) days, in line with section 35 of Act 843. We may need to verify your identity before fulfilling a request.

11. Security

We implement reasonable technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, and destruction, consistent with section 28 of Act 843 and the duties of a data controller under the Cybersecurity Act, 2020 (Act 1038). These include encryption in transit (TLS 1.2 or higher), hashed passwords using bcrypt with per-account salts, role-based access control, object-storage isolation using unguessable UUID paths, audit logging of admin actions, regular reviews of administrative privileges, and documented incident-response procedures. No security measure is, however, infallible; we cannot guarantee absolute security and rely on you to keep your password and one-time codes confidential.

12. Data-Breach Notification

In the event of a personal-data breach that is likely to result in significant harm to data subjects, we will, without undue delay and consistent with directions issued by the Data Protection Commission and the Cyber Security Authority, notify the relevant authorities and affected data subjects. We will provide information about the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to address it.

13. Cookies & Similar Technologies

The Platform uses essential cookies and local-storage entries to keep you signed in, remember preferences, and secure the application. We also use limited analytics tooling to measure aggregate usage. You can control or clear cookies through your browser settings; doing so may affect functionality.

14. Changes to This Policy

We may amend this Policy from time to time. Material changes will be notified in-app or by e-mail at least seven (7) days before they take effect. The current version is identified at the top of this page (effective date and version stamp).

15. Contact & Complaints

For privacy queries, requests to exercise data-subject rights, or to report a concern, please contact:

Yorm, Privacy Office
E-mail: privacy@yorm.app

If you are not satisfied with our response, you have the right to lodge a complaint with the Data Protection Commission of Ghana:

Data Protection Commission: Republic of Ghana
Website: dataprotection.org.gh