POP Privacy Policy

Effective Date: 3rd Feb 2026 | Last Updated: 3rd Feb 2026

Tubayo (U) LTD ("POP", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you use the POP mobile application, website, and related services (collectively, the "Platform"). It also describes your rights and choices with respect to your personal information.

By accessing or using the Platform, you acknowledge that you have read and understood this Privacy Policy and agree to its terms. If you do not agree, please do not use the Platform.

This Policy applies to all users of the Platform operating in Uganda and any other jurisdiction in which POP operates. Where applicable, we comply with the Data Protection and Privacy Act, 2019 of Uganda ("DPPA") and any other relevant data protection laws.

Table of Contents

  1. Information We Collect
  2. How We Use Your Information
  3. How We Share Your Information
  4. Cookies and Tracking Technologies
  5. Data Retention
  6. Data Security
  7. Your Rights and Choices
  8. Children's Privacy
  9. Third-Party Links and Services
  10. AI-Powered Features
  11. Cross-Border Data Transfers
  12. Changes to This Privacy Policy
  13. Contact Us

1. Information We Collect

We collect information about you in connection with your use of the Platform. The categories of personal information we collect are described below.

A. Information You Provide to Us

Account Registration. When you create a POP account, we collect your full name, email address, phone number, password, and profile photo (optional).

Delivery Address. When you place an order, we collect the delivery address you provide, including any saved addresses stored on your account.

Payment Information. We collect payment details necessary to process transactions, including mobile money account numbers and card details. Full payment credentials are processed and stored by our third-party payment processors; POP only retains limited payment information such as the last four digits of a card and the payment method type.

Order and Transaction Information. When you place an order, we collect details about that order, including items purchased, order value, special instructions, date and time of order, and transaction history.

Communications. When you contact our customer support team or use our AI assistant, we collect and retain the content of those communications, including messages, queries, complaints, and feedback.

User-Generated Content. If you upload photos, leave reviews, or submit ratings for Sellers, products, or Riders, we collect and store that content.

Survey and Research Responses. If you participate in surveys, promotions, or research programmes offered by POP, we collect your responses and any other information you provide.

B. Information We Collect Automatically

When you access or use the Platform, we automatically collect certain information, including:

  • Device Information: device type, operating system, unique device identifiers, hardware model, and mobile network information.
  • Log Data: IP address, browser type, pages visited, time and date of visits, time spent on pages, links clicked, and referring URLs.
  • Location Information: with your permission, we may collect precise or approximate geolocation data from your device to enable delivery features, estimate delivery times, and show relevant nearby Sellers. You can disable location permissions at any time through your device settings, though some features may not function correctly without them.
  • Usage Data: how you interact with the Platform, including searches performed, products viewed, items added to cart, and orders placed.
  • App Performance Data: crash reports, diagnostic information, and performance analytics to help us identify and resolve issues.

C. Information We Collect from Third Parties

We may receive information about you from third parties in the following circumstances:

Payment Processors. Our payment partners may share transaction confirmation data and limited payment information with us to facilitate order processing.

Sellers. Sellers on the Platform may provide information relevant to your order, including order confirmation or fulfilment status updates.

Riders. Our Rider network may share delivery confirmation data, including delivery timestamps and proof of delivery.

Social Login Providers. If you choose to register or log in using a social media or third-party identity provider (e.g., Google), we receive profile information from that provider as authorised by your account settings.

2. How We Use Your Information

We use the information we collect for the following purposes:

A. Providing and Operating the Platform

  • Creating and managing your account.
  • Processing and fulfilling orders, including transmitting order details to Sellers and Riders.
  • Processing payments and managing refunds.
  • Coordinating deliveries between Sellers, Riders, and Consumers.
  • Providing order tracking and delivery status updates.
  • Responding to your queries and providing customer support through human agents and our AI assistant.

B. Improving and Personalising the Platform

  • Analysing how users interact with the Platform to improve features, content, and performance.
  • Personalising your feed, product recommendations, and promotional content based on your browsing and order history.
  • Conducting research and analytics to better understand user needs and behaviour.
  • Training and improving our AI customer service tools using anonymised or aggregated interaction data.

C. Safety, Security, and Fraud Prevention

  • Verifying your identity and authenticating your account.
  • Detecting, investigating, and preventing fraudulent transactions, abuse, and other illegal activity.
  • Enforcing our Terms of Service and other platform policies.
  • Protecting the rights, property, and safety of POP, our users, Sellers, and Riders.

D. Communications and Marketing

  • Sending transactional messages about your orders, account, and the Platform (e.g., order confirmations, delivery updates).
  • Sending promotional offers, discounts, and news about POP and Seller products, where you have given your consent or where permitted by law.
  • Conducting surveys and requesting feedback to improve our services.

You can opt out of marketing communications at any time by using the unsubscribe link in any marketing email, adjusting your notification preferences in the app, or contacting us at support@getpopafrica.com. Note that opting out of marketing communications will not affect transactional or service-related messages.

E. Legal and Compliance Purposes

  • Complying with applicable laws, regulations, and legal obligations in Uganda and other applicable jurisdictions.
  • Responding to lawful requests from government authorities, courts, or regulatory bodies.
  • Establishing, exercising, or defending legal claims.
  • Fulfilling our obligations under the Data Protection and Privacy Act, 2019.

3. How We Share Your Information

POP does not sell your personal information to third parties. We may share your information in the following limited circumstances:

A. With Sellers

When you place an order, we share relevant order information with the Seller who is fulfilling your order. This includes your name, delivery address, order details, and contact information necessary for the Seller to process and confirm your order. Sellers are contractually prohibited from using this information for any purpose other than fulfilling your order.

B. With Riders

We share your delivery address, first name, and contact phone number with the Rider assigned to your delivery. Riders only receive the minimum information necessary to complete the delivery. Riders do not have access to your full order history, payment information, or account details.

C. With Payment Processors

We share your payment information with our third-party payment processors (including mobile money providers and card payment gateways) for the purpose of processing transactions. These processors operate under their own privacy policies and are bound by applicable data protection obligations.

D. With Service Providers

We engage trusted third-party service providers who perform services on our behalf, including cloud hosting, data analytics, customer support tools, push notification services, and AI infrastructure. These providers access your information only as necessary to perform their services and are bound by confidentiality and data protection obligations.

E. For Legal and Safety Reasons

We may disclose your information if we believe in good faith that such disclosure is necessary to: (a) comply with applicable laws or respond to valid legal processes, including requests from law enforcement or regulatory authorities; (b) protect the rights, property, or safety of POP, our users, Sellers, Riders, or the public; or (c) detect or prevent fraud or security threats.

F. Business Transfers

In the event of a merger, acquisition, reorganisation, sale of assets, or bankruptcy involving POP, your personal information may be transferred as part of that transaction. We will notify you via the Platform or by email if such a transfer occurs and if it results in a material change to this Privacy Policy.

G. Aggregated and Anonymised Data

We may share aggregated or anonymised information that does not directly identify you with third parties, including for research, analytics, and business purposes. This data cannot reasonably be used to identify you.

4. Cookies and Tracking Technologies

We and our third-party partners use cookies, mobile SDKs, pixels, and similar tracking technologies to collect information about your use of the Platform. These technologies help us:

  • Keep you logged in to your account.
  • Remember your preferences and saved addresses.
  • Understand how users navigate and interact with the Platform.
  • Measure the effectiveness of our communications and promotions.
  • Deliver relevant content and personalised recommendations.

Types of Technologies We Use

Essential Cookies: Necessary for the Platform to function. These cannot be disabled as they enable core features such as secure login, cart functionality, and payment processing.

Analytical Cookies: Help us understand how users engage with the Platform, which pages are visited most, and where users encounter issues. We use this data to improve the user experience.

Functional Cookies: Allow us to remember your preferences, language settings, and saved locations.

Marketing and Advertising Cookies: Used to show you relevant promotions and measure advertising effectiveness. Where required by law, we obtain your consent before deploying these cookies.

You can manage your cookie preferences through your device or browser settings. Please note that disabling certain cookies may affect the functionality of some Platform features.

5. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Platform and related services. We also retain information as necessary to comply with our legal obligations, resolve disputes, prevent fraud, enforce our agreements, and for legitimate business purposes.

Specifically:

  • Account Information is retained for the duration of your account and for a period of up to 3 years after account deletion, unless a longer retention period is required by law.
  • Order and Transaction Records are retained for a minimum of 5 years in accordance with Ugandan tax and financial recordkeeping requirements.
  • Customer Support Communications are retained for up to 2 years from the date of the interaction.
  • AI Conversation Logs are retained in anonymised form for up to 12 months for the purpose of improving our AI systems.
  • Marketing Preferences and Consent Records are retained for as long as required to demonstrate compliance with applicable law.

When your information is no longer required for the purposes described above, we will securely delete or anonymise it in accordance with our data retention policies.

6. Data Security

POP takes the security of your personal information seriously. We implement reasonable administrative, technical, and physical safeguards designed to protect your information from unauthorised access, disclosure, alteration, and destruction. Our security measures include:

  • Encryption of data in transit using industry-standard TLS/SSL protocols.
  • Secure cloud infrastructure with access controls and role-based permissions.
  • Regular security assessments and penetration testing.
  • Two-factor authentication options for account access.
  • Internal data access policies that limit access to personal information to authorised personnel on a need-to-know basis.

While we work hard to protect your information, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security of your data. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant data protection authority as required by applicable law.

You are responsible for keeping your account credentials confidential. Please notify us immediately at security@getpopafrica.com if you suspect any unauthorised access to your account.

7. Your Rights and Choices

Subject to applicable law, you have the following rights with respect to your personal information held by POP:

A. Right of Access

You have the right to request a copy of the personal information we hold about you, including information about how it is used and with whom it is shared.

B. Right to Correction

You have the right to request that we correct any inaccurate or incomplete personal information we hold about you. You can update most account information directly within the app under Account Settings.

C. Right to Deletion

You have the right to request that we delete your personal information. To delete your account and associated data, go to Account Settings > Manage Account > Delete Account. Please note that we may retain certain information as required by law or for legitimate business purposes even after account deletion.

D. Right to Restrict Processing

In certain circumstances, you have the right to request that we limit the processing of your personal information, for example while a dispute about the accuracy of your data is being resolved.

E. Right to Object

You have the right to object to the processing of your personal information for direct marketing purposes. You can exercise this right by opting out of marketing communications as described in Section 2(D).

F. Right to Data Portability

Where technically feasible and where required by applicable law, you have the right to receive your personal information in a structured, commonly used, machine-readable format.

G. Right to Withdraw Consent

Where we rely on your consent to process your personal information (e.g., for location access or marketing communications), you may withdraw your consent at any time. Withdrawal of consent will not affect the lawfulness of processing that occurred before withdrawal.

How to Exercise Your Rights

To exercise any of the above rights, please submit a request to privacy@getpopafrica.com or through the in-app support feature. We will respond to your request within 30 days. We may need to verify your identity before processing your request. We will not discriminate against you for exercising any of your privacy rights.

8. Children's Privacy

The Platform is not directed at or intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have inadvertently collected personal information from a child under 18, we will take steps to delete that information as promptly as possible.

If you are a parent or guardian and believe that your child has provided personal information to POP without your consent, please contact us at privacy@getpopafrica.com and we will investigate and take appropriate action.

9. Third-Party Links and Services

The Platform may contain links to third-party websites, applications, or services, including Seller storefronts, payment provider portals, and social media platforms. This Privacy Policy does not apply to those third-party services. We encourage you to read the privacy policies of any third-party services you interact with. POP is not responsible for the privacy practices, content, or security of third-party services.

When you choose to register or log in using a third-party identity provider, that provider will share certain account information with POP as described in Section 1(C). Your use of such providers is governed by their own terms and privacy policies.

10. AI-Powered Features

POP uses artificial intelligence to power our customer service assistant and to personalise your experience on the Platform. The following describes how personal data is handled in connection with these AI features:

AI Customer Service. When you interact with our AI assistant, your messages and queries are processed to generate responses. These conversations may be stored and used in anonymised form to improve the AI system's accuracy and performance. Your conversations are not used to train publicly available AI models or shared with third-party AI providers beyond what is necessary to operate the service.

Personalised Feed and Recommendations. We use your browsing history, order history, and usage patterns to personalise the product feed and recommendations shown to you. This processing is automated. You can request that we limit personalisation by contacting us at privacy@getpopafrica.com.

Fraud Detection. We use automated systems to detect unusual activity, verify transactions, and flag potentially fraudulent behaviour. These systems analyse patterns in your usage data and transaction history. Where an automated decision may significantly affect you, you have the right to request human review by contacting us.

11. Cross-Border Data Transfers

POP operates primarily in Uganda. However, we use third-party service providers and cloud infrastructure that may process or store your data outside of Uganda, including in the European Union, the United States, or other jurisdictions.

Where we transfer personal information outside Uganda, we take steps to ensure that such transfers are subject to appropriate safeguards, including contractual clauses that provide a level of protection equivalent to that offered under the Data Protection and Privacy Act, 2019. By using the Platform, you acknowledge that your information may be transferred to and processed in countries outside Uganda.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other legitimate business reasons. When we make material changes, we will notify you through the Platform (e.g., via in-app notification or banner) or by email to the address associated with your account at least 14 days before the changes take effect.

The updated Policy will be posted on the Platform with a revised 'Last Updated' date. Your continued use of the Platform after the effective date of the updated Policy constitutes your acceptance of the changes. If you do not agree to the updated Policy, you must stop using the Platform and may request deletion of your account and associated data.

We encourage you to periodically review this Privacy Policy to stay informed about how we are protecting your information.

13. Contact Us

If you have any questions, concerns, or complaints about this Privacy Policy or our data practices, or if you wish to exercise any of your rights described in Section 7, please contact our Data Protection Officer:

Data Protection Officer: Tubayo (U) LTD

Email: privacy@getpopafrica.com

Support: support@getpopafrica.com

Address: Nakawa, Kampala, Uganda

We will respond to your request or complaint within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the National Information Technology Authority of Uganda (NITA-U) or the relevant supervisory authority in your jurisdiction.

This Privacy Policy is provided in accordance with the Data Protection and Privacy Act, 2019 (Uganda) and other applicable laws. It forms part of POP's overall legal framework governing use of the Platform.

© Tubayo (U) LTD. All rights reserved.