KaziGo Legal

Trust Center

Effective date: 20 June 2026

This page is maintained by KaziGo to answer common security and privacy questions about our marketplace. It describes the controls we have enabled today and how responsibility is shared between KaziGo, our hosting platform, and you. It is not an independent certification or audit report.

1. Shared Responsibility

KaziGo operates the marketplace application and is responsible for the security of the code we ship, the configuration of our database, and how we handle your data. Our hosting platform (Lovable Cloud, built on Supabase and edge infrastructure) is responsible for the underlying servers, network, and managed services. You are responsible for keeping your account credentials safe and for the content and contracts you create on the platform.

2. Access & Authentication

  • Email/password and Google sign-in for end users.
  • Separate admin authentication with role-based access control across eight admin areas (marketplace, provider operations, dispatch, support, finance, trust & safety, insights, and super admin).
  • Server-side authorization on every privileged action — client-side role claims are never trusted.
  • Session management and password reset flows handled by our managed auth provider.

3. Data Protection

  • HTTPS for all traffic in transit.
  • Encrypted storage for data at rest, managed by our hosting platform.
  • Row-level security policies on every user-facing database table, so users can only read and write their own records.
  • Sensitive fields (phone numbers, ID documents, ID verification artefacts) are gated behind server functions that check owner-or-admin access — they are never readable directly from the browser.
  • Wallet credits and provider fees are charged through privileged server functions that are not callable from the browser.

4. Verification & Trust & Safety

  • Provider identity verification with ID document and selfie checks, plus AI-assisted screening reviewed by our trust & safety team.
  • Profile edits to risky fields (bio, services, phone, display name) are screened by AI and reviewed by admins before going live; the previously approved version stays visible during review.
  • In-platform messaging, dispute resolution, and a safety button for urgent issues.
  • Audit logs for sensitive administrative actions.

See our Trust & Safety page for user-facing safety guidance.

5. Privacy

We collect only what we need to operate the marketplace: account details, profile information, job and booking data, payment metadata, and basic usage information. We do not sell your personal data. Full details — including how to request access, correction, or deletion — are in our Privacy Policy.

6. Subprocessors & Integrations

KaziGo relies on a small set of vetted providers to deliver the service, including our hosting platform, our payment gateway (Paynow and supported mobile money operators), transactional email delivery, and push notification services. We share only the data each provider needs to perform its function.

7. Retention & Deletion

Account and transactional data is retained while your account is active and for as long as we are legally required to keep it (for example, financial records). You can request deletion of your account from the app; some records may be retained in anonymised or aggregated form for legal, security, or analytics purposes.

8. Incident Response & Vulnerability Reporting

If we become aware of a personal data breach that is likely to affect you, we will notify affected users and the relevant authority as required by Zimbabwean law and any other applicable African data protection frameworks.

If you believe you have found a security vulnerability, please report it confidentially to info@kazi-go.com. Please do not publicly disclose the issue until we have had a reasonable opportunity to investigate and fix it.

9. Compliance

We align our practices with the Zimbabwe Data Protection Act [Chapter 11:12] and aim to meet accepted industry practice for marketplace platforms. We do not currently hold independent certifications such as SOC 2 or ISO 27001 and do not claim compliance with any framework we have not been audited against.

10. Related Policies


Questions about this policy? Contact us at info@kazi-go.com.