Daffaa App — Privacy Policy
Last updated: 2026-07-13
This policy explains how the Daffaa Android app ("the app") handles data. Daffaa helps merchants confirm e-wallet and InstaPay payments by reading the confirmation SMS on the merchant's own phone. The app is installed and operated by the merchant on their own device.
1. SMS permissions and how SMS is used
The app requests the READ_SMS, RECEIVE_SMS and SEND_SMS permissions. These are used solely to detect incoming payment-confirmation messages from mobile-wallet providers (e.g. Vodafone Cash, Etisalat Cash, Orange Cash, WE Pay, InstaPay) on the merchant's device.
- The app reads only wallet payment-confirmation messages. It matches the sender and message pattern of known payment providers.
- From a matching message, it extracts the amount, the sender number, the reference number and the receiving wallet number, and sends only these fields to the merchant's Daffaa account to record the payment.
- The app does not read, upload, store, or share personal SMS, one-time passwords, or messages unrelated to payments beyond what is needed to identify a payment.
- SMS content is not sold, shared with third parties, or used for advertising.
2. Other data the app sends
- Device status for reliability (battery level, connectivity, app version, SIM carrier names) so the merchant can see whether their device is online and receiving.
- The account credentials the merchant uses to sign in (or a paired-device token).
All data is transmitted over encrypted HTTPS to the merchant's own Daffaa server.
3. Data retention
Extracted payment records are kept in the merchant's account for their business records. The raw SMS text is not retained beyond what is required to create and audit a payment record. A merchant can delete their data by contacting support or removing it from their dashboard.
4. Data sharing
The app shares data only with the merchant's own Daffaa account. We do not sell personal data and do not share it with advertisers or unrelated third parties.
5. Security
Data in transit is encrypted with HTTPS. Access tokens are stored on the device using Android's app-private storage. Merchants can revoke a device at any time from their dashboard.
6. Children
The app is a business tool for merchants and is not directed at children.
7. Contact
For any privacy question or a data-deletion request, contact: support@smmtarget.net