Back to PaneMba

Privacy Policy

Last updated: 31 July 2026

1. Overview

PaneMba (Pvt) Ltd operates the PaneMba property marketplace for Zimbabwe. This policy describes how we handle personal information under the Cyber and Data Protection Act [Chapter 12:07] (Zimbabwe Data Protection Act).

2. Information We Collect

We collect only the minimum data needed to operate the marketplace:

Landlord contact details on gated listings are not shown publicly until a seeker unlocks contact via PaneMba Pass or is accepted through the rental application flow.

We do NOT collect: precise GPS location tracking, contacts/address book, biometric templates (face embeddings are computed on-device and never uploaded), financial account credentials, or advertising identifiers.

3. How We Use Your Information

4. Third-Party Services and Cross-Border Transfer

We use Firebase (Google) for authentication, database, hosting, analytics, and push notifications. Your data is stored on Google Cloud servers in the United States (us-central1 region). By using PaneMba, you consent to this cross-border transfer of your personal data to the United States. Google complies with industry-standard security certifications (ISO 27001, SOC 2) and encrypts data at rest (AES-256) and in transit (TLS 1.2+).

Payment processing is handled by Pesepay. PaneMba does not store card numbers or mobile-money PINs.

We do not sell personal data to any third party.

5. Identity Verification and Biometric Data

If you choose to verify your identity (optional, not required to use the marketplace), the following processing occurs:

6. Data Retention

7. Your Rights

Under the Zimbabwe Data Protection Act, you have the right to:

8. Children's Privacy

PaneMba is for users 18 and older. We do not intentionally collect data from minors. Contact us if you believe a minor created an account.

9. Cookies and Tracking

We use essential cookies for authentication and session management. Firebase Analytics uses cookies to understand how users interact with the platform in aggregate. No advertising cookies are used. You can control cookies through your browser settings.

10. Security

Data is encrypted at rest (AES-256) and in transit (TLS 1.2+). Access is enforced through Firestore security rules (owner-scoped access). Sensitive operations require App Check verification. No raw passwords or payment credentials are stored.

11. Changes to This Policy

We may update this privacy policy from time to time. Changes will be posted on this page with an updated revision date.

Questions or complaints:

Email: support@panemba.com

Data controller: PaneMba (Pvt) Ltd, Harare, Zimbabwe