Legal
Privacy Policy
Last updated 29 September 2026 · Version 2026-09-29
We collect only what is needed to run paid Wi-Fi, keep it for limited periods, and never sell it.
1. Who this covers
This policy explains how ZFINET handles personal data in ZFINET. It covers two groups of people:
- Operators and their staff, who have ZFINET accounts. For their data, we are the controller.
- Wi-Fi customers, who buy access on an operator's hotspot. The operator is the controller of their data and we process it on the operator's behalf. Questions about a hotspot's use of your data should go to that operator first.
2. What we collect
Operators and staff: name, email address, phone number if given, password (stored hashed), two-factor and passkey settings, organization details, invoices and billing contacts, and a log of important actions for the audit trail.
Wi-Fi customers: phone number (to send the access code and receipts), optional name and email, the packages bought, payment references and status, the device's MAC address and IP address while connected, session times and data used, and SMS messages sent to them.
We do not receive or store full card numbers or mobile money PINs; our payment partner handles those.
3. How and why we use it
- To provide the service: sell and activate Wi-Fi access, enforce data and time limits, send access codes, and run reports (performing our contract with the operator).
- To bill operators and prevent fraud and abuse (contract and legitimate interests).
- To keep the service secure and reliable, investigate problems and keep audit records (legitimate interests and legal obligations).
- To tell operators about their account, invoices and important changes. We do not sell personal data or use it for advertising.
5. How long we keep it
We keep data only as long as needed. By default:
| Data usage records | 90 days |
| Wi-Fi session history (device and IP addresses) | 180 days |
| Router health and command logs | 30 days |
| SMS delivery records | 1 year |
| Payment gateway call details | 1 year (payments themselves are kept as financial records) |
| Audit log | 400 days |
| Wi-Fi customers inactive for | 2 years, then anonymized |
Payments and access passes are kept as financial records for as long as the law requires; a customer's details can be anonymized on request. Operator account data is kept while the account is open and deleted or anonymized after it closes, except where we must keep it by law.
6. Security
Data is encrypted in transit. Secrets such as router credentials, payment keys and access codes are encrypted at rest. Access is limited by role, privileged staff must use two-factor authentication, and important actions are logged. No system is perfectly secure; we will notify affected operators and authorities of a breach as the law requires.
7. International transfers
ZFINET is used in many countries, and our providers may process data outside yours. Where that happens we rely on appropriate safeguards required by the applicable law.
8. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your data, or object to some uses. Operators can do most of this themselves in the app, including exporting and anonymizing a customer's data.
Wi-Fi customers should contact the operator of the hotspot; we will help the operator respond. You can also email us at billing@rcodez.com or complain to your data protection authority.
10. Children
ZFINET accounts are for businesses and adults. We do not knowingly collect data from children for our own purposes.
11. Changes and contact
We will post changes here and tell operators about material ones. See also our Terms of Service. Contact: billing@rcodez.com, Accra, Ghana.