Draft pending legal review. This text may change before launch.
Privacy Policy
This policy explains what personal data Abuna handles, why, who helps us, how long we keep it, and the rights you have under Cameroon’s Law No. 2024/017 of 23 December 2024 on personal data protection.
1. Who is responsible
Abuna is run by Desgn Space. We handle personal data in two roles:
- For businesses that use Abuna and their team members, we decide how their data is used. We are the data controller.
- For those businesses’ customers, we handle data on the business’s behalf, to run its billing. We are its processor, and the business is the controller. If you subscribe to something billed through Abuna, the business you bought from is your first contact.
For any privacy question, write to support@abuna.app.
2. What we collect
Businesses and team members
- Name, email address, and password. We store only a secure hash of the password, never the password itself.
- Your teams, your role in each, and who invited you.
- Your apps, products, prices, settings, and API keys.
- When you signed in, and your IP address in our server logs.
- What you write to us when you ask for help.
Customers of those businesses
- Name, email address, and phone number, given at checkout.
- Telegram chat ID, only if the customer chooses to connect Telegram.
- Subscriptions, invoices, amounts, and payment status and references.
- The private pay and portal links we send them.
Visitors to this website
This website has no analytics or advertising trackers. It saves your light or dark theme choice in your own browser. Cloudflare sees your IP address when it delivers the pages.
What we don’t collect
We never see or store card numbers or mobile money PINs. The payment provider handles those details directly.
3. Why we use it
- To provide Abuna, as our contract with the business requires: create accounts, run checkout and renewals, send pay links and receipts, and deliver webhooks.
- To keep Abuna secure, which is our legitimate interest: prevent fraud and abuse, and fix problems.
- To meet our legal duties, such as keeping accounting records and answering lawful requests from authorities.
- With consent, for Telegram messages. A customer connects Telegram only if they choose to. To stop, they can write to the business or to us at any time.
We don’t sell personal data, and we don’t use it for advertising.
4. Who helps us
These providers process personal data for us. Each gets only what it needs to do its job, and must keep it safe.
- Desgn Space (our own mail server)
- Sends every email: password resets, and each customer’s pay links, receipts, and notices.
- Data: Email address, name, and the email’s content.
- Cloudflare, Inc.
- Hosts this website and the dashboard, and protects them from attacks.
- Data: IP address, browser details, and the pages requested.
- Our server host
- Runs the servers that hold our database and API.
- Data: All account and billing data described above.
- Telegram
- Delivers pay and portal links to customers who choose to connect Telegram.
- Data: Telegram chat ID and the message content, such as an amount and a link.
- Our payment provider
- Processes payments in Live mode.
- Data: Customer name, phone number, amount, and payment reference.
We may also share data when the law requires it, for example with a court or a regulator, and only as much as the request requires.
5. Data sent outside Cameroon
Some of these providers store or process data outside Cameroon, including Cloudflare, in the United States. Law No. 2024/017 limits such transfers. We send data abroad only to providers that commit to protecting it at the level the law requires, and only what they need.
6. How long we keep it
- Account data: while the account is open. We delete it within 90 days after the account closes, except what we must keep by law.
- Invoices and payment records: 10 years, as OHADA accounting rules require.
- Customer details: as long as the business keeps its account, or until it asks us to delete them. Their invoices and payment records follow the 10-year rule above.
- Security logs: up to 90 days.
- Backups: overwritten within 30 days.
- Sign-in sessions: they end after 60 minutes of inactivity.
7. How we protect it
All traffic is encrypted with HTTPS. Passwords are stored as secure hashes. Only members of a team can see its apps and billing data. Webhooks are signed so your server can check they came from us. If a breach puts personal data at risk, we tell the data protection authority and the people affected, as the law requires.
8. Your rights
Under Law No. 2024/017, you have the right to:
- know what data we hold about you and how we use it;
- get a copy of it;
- have it corrected if it is wrong or incomplete;
- have it deleted, unless we must keep it by law;
- object to how we use it, or ask us to limit it;
- withdraw your consent at any time, for anything that relies on consent.
To use a right, write to support@abuna.app from the email address we have for you. We reply within 30 days. If you are a customer of a business that uses Abuna, you can also ask that business, and we help it answer.
If you think we have mishandled your data, you can complain to the personal data protection authority set up by Law No. 2024/017. We would like the chance to fix it first, so please write to us too.
If you or your customers are elsewhere in the CEMAC or UEMOA region, the data protection law of that country may also apply and give you further rights. We respect those rights too.
9. Cookies
The dashboard uses only the cookies it needs to keep you signed in and protect your account. It uses no advertising or analytics cookies. This website sets no cookies of its own.
10. Changes to this policy
If we change this policy in a way that matters to you, we update the effective date above and email businesses with an account at least 30 days before the change takes effect.