Minzani

Privacy Policy

Effective 13-08-2026

1. Who we are

Minzani is operated by Prolearnerz Solutions. This policy explains what we collect when you or your business uses Minzani, why, and what rights you have over it.

2. Information we collect

Account information

Your name, username, and — where you provide them — your email and phone number. Email is optional for a teammate someone else invites, but required for whoever creates a business account, since it's how we send verification links, password resets, and account notices.

Business information

Your business's name, phone number, and address, plus who's on your team and in what role.

Financial and ledger data

Every receipt and expenditure you or your team record — amount, date, description, category, payment method — plus your budget figures. This is the core of what Minzani exists to store, so we treat it as sensitive by default.

Uploaded documents

Receipt photos or documents you choose to attach to a ledger entry. These are only ever served to people who actually belong to your business, through an access-checked link — never a plain, guessable file URL.

Payment information

When you pay for a Pro subscription, Pesapal handles your card or mobile money details directly — we only receive a transaction reference and status back, never your card number or mobile money PIN.

Activity and usage

A record of significant actions in your business's account (who added or edited an entry, confirmed a deposit, invited a teammate, and so on) — this is the audit trail the product is built around, viewable by your business's Owner/Admin in the Activity Log, and scoped to your business the same as everything else.

Cookies

We use only two cookies, both strictly necessary: one to keep you logged in (your session) and one to protect forms from cross-site attacks (CSRF). We don't use advertising or analytics tracking cookies.

3. How we use your information

To provide the service itself (your ledger, budget, exports, and reports), to authenticate you and enforce who can see and do what within your business, to send account-related email (verification links, subscription reminders, notices you'd reasonably expect), and to maintain the audit trail the product promises. We don't use your data to train external models, sell it, or share it for advertising.

4. Data protection and security

Every view and query in Minzani explicitly scopes to your business — there's no shared query path that could accidentally return another business's rows. Passwords are stored hashed, never in plain text. Uploaded files are served only through an authenticated, access-checked view. Production traffic runs over HTTPS. No system is perfectly secure, but tenant isolation specifically is treated as a non-negotiable architectural rule, not a best-effort feature.

5. Who we share data with

We don't sell your data. We share the minimum necessary with the service providers that make Minzani work: Brevo (sends account and notification emails on our behalf), Pesapal (processes subscription payments — see Section 2), and our cloud infrastructure provider (hosts the application and database). Each of these only sees what it needs to do its job, not your full ledger.

6. Platform administrator access

Minzani's own platform administrators can see aggregate statistics for a business — counts and totals, like how many entries exist or how close a business is to its budget — for support and platform-health purposes. They cannot see individual ledger entries, budget line items, categorized amounts, uploaded documents, or team member identities for any business, and cannot create, edit, or delete anything on a business's behalf through the app. The one narrow exception is Django's built-in administrative tool, used only for genuine data-correction emergencies and automatically logged when used.

7. Data retention

We keep your business's data for as long as the account is active. A ledger entry can never be deleted, even on request — it can be corrected while its month is still open, with every correction kept in the Activity Log (see our Terms of Service), so the history of a change is itself part of the record we retain. If you close your account, we retain records for a reasonable period afterward to meet ordinary financial record-keeping obligations, then delete what we're not required to keep.

8. Your rights under Ugandan law

As a data subject under Uganda's Data Protection and Privacy Act, 2019, you have the right to be informed of what we collect and why, to access a copy of your data, to have inaccurate data corrected, to object to or request erasure of data (subject to the record-keeping limits in Section 7), to receive your data in a portable format, and to withdraw consent where processing depends on it. You can lodge a complaint with the Personal Data Protection Office (PDPO), the supervisory authority operating within Uganda's National Information Technology Authority (NITA-U), if you believe your data has been mishandled. To exercise any of these rights, contact us using the details in Section 12.

9. Children's privacy

Minzani is a business tool, not directed at children, and we don't knowingly collect information from anyone under 18.

10. International data transfers

Our infrastructure providers may process or store data outside Uganda. Where that happens, we expect our providers to apply reasonable technical and organizational safeguards to protect it, consistent with this policy.

11. Changes to this policy

We may update this policy as Minzani changes. Material changes will be announced in-app or by email where we have one on file.

12. Contact us

For privacy questions or to exercise any of the rights in Section 8, email support@prolearnerz.com — our parent company's support address (see Section 1).

Minzani is a product of Prolearnerz Solutions. We built the platform's tenant isolation and platform-administrator limits described above as hard architectural rules, not policy promises alone — see Section 6.