Hapo
How it works Pricing FAQ Blog
Log in Sign up

Legal

Privacy Policy

Last updated 26 June 2026

Introduction and scope

Hapo Technologies Limited ("Hapo", "we", "us", "our") operates the booking and advance-deposit platform at gethapo.com and associated sub-domains (the "Platform"). This Privacy Policy explains how we collect, use, store, share, and protect personal data when you use the Platform, and what rights you have in relation to that data.

This Policy is written to comply with the Ghana Data Protection Act, 2012 (Act 843) and the regulations issued under it by the Data Protection Commission of Ghana. Because the Platform is accessible globally via the web, we also align our practices with internationally recognised standards, including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), where applicable to users in those jurisdictions.

By accessing or using the Platform, you acknowledge that you have read this Policy. If you do not agree, you should stop using the Platform.

Data we collect

Data you provide directly

Service professionals (account holders):

  • Full name, business or trading name, and professional category.
  • Email address and phone number.
  • Profile content you upload: biography, service descriptions, portfolio photos.
  • Payout account details collected and held by our payment partner, Paystack Inc. — we receive only a tokenised reference, not raw bank or card numbers.
  • Subscription and billing information (processed by Paystack; we hold the plan tier and subscription status, not card data).

Clients booking an appointment:

  • Full name, email address, and phone number.
  • Appointment details: service type, date, time, and the professional being booked.
  • Deposit amount and Paystack transaction reference (not card numbers; PCI-DSS scope is handled entirely by Paystack).

Data collected automatically

  • IP address — captured in server access logs for security and abuse prevention.
  • Browser and device information — browser type, operating system, screen resolution; used to ensure the Platform displays correctly.
  • Session data — an encrypted session cookie is set when a professional logs in to authenticate subsequent requests.
  • Usage data — pages visited, actions taken on the dashboard, and timestamps; used in aggregate to understand how the Platform is used and to improve it.

Lawful basis and how we use your data

We process personal data only where we have a lawful basis. The bases we rely on are:

  • Performance of a contract — processing your account data and booking records to fulfil the service you have requested: account creation, scheduling, deposit collection and disbursement, sending booking confirmations and reminders.
  • Legitimate interests — operating and improving the Platform, detecting and preventing fraud and abuse, maintaining security logs, and communicating service-related updates. We balance these interests against your rights before relying on this basis.
  • Legal obligation — retaining financial transaction records as required by Ghanaian tax and financial law, and complying with valid orders from competent authorities.
  • Consent — where we send optional marketing communications. You may withdraw consent at any time.

Specifically, we use your data to:

  • Create and manage your professional account or booking record.
  • Process and track advance deposits via Paystack and disburse net amounts to professionals.
  • Send transactional emails and SMS messages: booking confirmations, appointment reminders, deposit receipts, and payout notifications.
  • Detect fraudulent bookings, chargebacks, and misuse of the Platform.
  • Comply with financial record-keeping obligations under Ghanaian law.
  • Respond to support requests and resolve disputes between professionals and clients.
  • Improve Platform features through aggregate, de-identified usage analysis.

Data retention and storage

The Platform is hosted on cloud infrastructure operated by third-party providers. Data may be stored and processed on servers located outside Ghana. Where personal data is transferred internationally, we take steps to ensure appropriate safeguards are in place consistent with Act 843 and applicable international standards.

We retain personal data for the following periods:

  • Account data (professionals): for the lifetime of the account and for 7 years after closure, to comply with Ghanaian tax and financial record-keeping obligations.
  • Booking and payment records: 7 years from the date of the transaction, consistent with the requirements under the Revenue Administration Act, 2016 (Act 915).
  • Client booking data: 2 years from the appointment date, after which it is deleted or anonymised unless a longer retention period is required by law or an ongoing dispute.
  • Server access logs (IP addresses): 90 days, then automatically deleted.
  • Marketing consent records: until you withdraw consent, plus 1 year thereafter as evidence of the consent.

When a retention period expires and no legal hold applies, we securely delete or anonymise the data so that it can no longer be attributed to an individual.

Third-party sharing

We do not sell your personal data. We share it only with the following categories of recipient and only to the extent necessary:

  • Paystack Inc. — our payment processor. Paystack handles all payment card data, deposit collection, and disbursements. Paystack's own privacy policy is available at paystack.com/gh/privacy/merchant.
  • Cloud infrastructure providers — for hosting, database storage, and content delivery. These providers act as data processors under our instruction and are contractually bound to protect your data.
  • Email and SMS delivery providers — to send transactional messages. Only the minimum data necessary (recipient address or phone number, message content) is shared.
  • Competent authorities — where required by Ghanaian law, a valid court order, or a directive from a regulatory body.

Where we share data with sub-processors, we require them to maintain appropriate technical and organisational security measures and to process data only on our documented instructions.

Your rights under Act 843 and GDPR

Under the Ghana Data Protection Act, 2012 (Act 843) and, where applicable, the GDPR, you have the following rights in relation to your personal data:

  • Right of access — you may request a copy of the personal data we hold about you.
  • Right to rectification — you may ask us to correct inaccurate or incomplete data.
  • Right to erasure — you may ask us to delete your data where it is no longer necessary for the purpose it was collected, where you withdraw consent (and we have no other lawful basis), or where you have objected to processing and we have no overriding legitimate interest. This right does not apply where retention is required by law.
  • Right to object — you may object to processing based on legitimate interests or for direct marketing. We will stop unless we have compelling grounds that override your interests or a legal obligation to continue.
  • Right to restriction — you may request that we restrict processing while a dispute about accuracy or our lawful basis is resolved.
  • Right to data portability — where processing is based on consent or contract and is carried out by automated means, you may request your data in a structured, commonly used, machine-readable format.
  • Right to withdraw consent — where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

To exercise any of these rights, contact us at hello@gethapo.com. We will respond within 30 days. We may ask you to verify your identity before processing your request.

If you are not satisfied with our response, you have the right to lodge a complaint with the Data Protection Commission of Ghana at dataprotection.gov.gh. EU-based users may also lodge a complaint with their local supervisory authority.

Security measures

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. These include:

  • TLS encryption for all data in transit between your browser and our servers.
  • Encryption of sensitive data at rest in our databases.
  • Role-based access controls — only authorised staff and systems can access personal data, and only to the extent required for their function.
  • Secure session management — session tokens are cryptographically signed and expire automatically.
  • Payment card data is never stored on our servers; PCI-DSS compliance is fully delegated to Paystack.
  • Regular security reviews of our infrastructure and dependencies.

No system can be guaranteed to be entirely secure. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the Data Protection Commission as required by Act 843.

Cookies and tracking

We use a small number of first-party cookies. We do not use third-party advertising cookies or cross-site tracking technologies.

  • Session cookie — set when a professional logs in. Contains an encrypted session token used to authenticate subsequent requests. This cookie is essential for the Platform to function and is deleted when you log out or close your browser.
  • Cookie consent flag — a persistent cookie that records your cookie preference so you are not shown the consent prompt on every visit. Expires after 12 months.

You can configure your browser to refuse or delete cookies, but disabling the session cookie will prevent you from logging in to your dashboard.

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or in applicable law. When we make material changes, we will notify registered professionals by email and update the "Last updated" date at the top of this page. We will provide at least 14 days' notice of material changes before they take effect.

Your continued use of the Platform after the effective date of a revised Policy constitutes your acceptance of the changes.

Contact and data requests

For questions about this Policy, to exercise your data rights, or to serve legal notices relating to data protection, contact us at:

  • Email: hello@gethapo.com

To submit a formal data access, rectification, or erasure request, email hello@gethapo.com with the subject line "Data Rights Request" and include your name and the email address associated with your account. We will acknowledge your request within 5 business days and respond in full within 30 days.

To lodge a complaint with the Data Protection Commission of Ghana: dataprotection.gov.gh.

Hapo

Ghana's booking platform for service professionals. Collect advance deposits and stop losing money to no-shows.

Get started free

Product

  • Booking platform
  • How it works
  • Pricing
  • FAQ

For you

  • Service providers
  • Makeup artists
  • Photographers
  • Event planners

By profession

  • Tattoo artists
  • Lash techs
  • Braiders
  • Nail techs
  • Massage therapists
  • Private chefs

Company

  • About
  • Blog
  • Contact

Legal

  • Privacy
  • Terms

© 2026 Hapo. All rights reserved.

A quick note on cookies

We use essential cookies to keep Hapo working. We'd also like a couple to see what's actually helping people, but only if you're okay with it.