Your data
BetaFund publishes contribution lists — that is the product. So this policy leads with the question that actually matters: what of yours becomes readable by other people, and what never does. Everything else here supports those two answers.
No analytics, no advertising, no trackers — see section 8.
BetaFund — Privacy Policy
Version: 1.0
Effective date: 27 August 2026
Applies to: the BetaFund website, the public event pages, the organizer dashboard, the account settings, the BetaFund WhatsApp bot accounts, and the SMS and email we send.
1. What this policy is
BetaFund is a way for a family, a committee, or a group of friends to collect mobile-money contributions for an event — a wedding, a funeral, school fees, a medical emergency — and to have the running list of who has contributed posted automatically into their WhatsApp group.
That product only works because it publishes things. A contribution list that nobody can see is not a contribution list. So this document is written to answer one question before any other: what of yours becomes readable by other people, and what never does. Sections 5 and 6 answer it directly, and everything else here supports them.
This policy explains what we collect, why we hold it, who else it reaches, how long we keep it, and what you can ask us to do about it. It adds detail to section 13 of our Terms and Conditions and takes nothing away from it: §13 is the binding promise, and nothing in this document reduces it.
Words in bold — Organizer, Contributor, Event, Participant, Group, Bot Account, Contribution — carry the meanings given in section 2 of the Terms.
2. Who is responsible for your data
BetaFund is operated by Beta TQ Company Limited, a company registered in the United Republic of Tanzania (registration 171304350, TIN 171304350), of Mikocheni, Kinondoni, Dar es Salaam, Tanzania.
We are the data controller for account data, payment data, the public record of an Event, and the technical records our servers keep. Write to tech@betatq.com about anything in this document; the full contact details are in section 16.
One thing we are not the controller of. When an Organizer types or pastes a list of names into their Event, those names are theirs, not ours — they decided to collect them and they decided to publish them. The Organizer is the controller of that list and is responsible for what those people have been told (Terms §13.6). We hold and publish it on their instruction. If your name is on an Event's list and you want it off, section 13 explains what we can and cannot do, and why asking the Organizer is usually faster.
3. What we collect, and where it comes from
Nearly all of it you type yourself. Almost none of it is collected in the background.
If you organise a collection
- Your mobile number, which is the account. There is no password anywhere in BetaFund, so this number and the one-time code sent to it are how you sign in every time.
- Your name and email address, given once when you finish signing up. The email is where receipts, security notices, and a second copy of every sign-in code go — SMS in Tanzania is dropped often enough that one channel regularly locks people out of their own money.
- The record that you accepted the Terms — the version number and the moment. Nothing else: no IP address and no browser fingerprint is stored against an acceptance, because a phone number already proved by SMS is the stronger evidence and the rest would be collected for no reason.
- Everything you put into an Event — title, description, image, type, target, visibility, participant names, pledged amounts, and any contribution you record by hand together with the note you file it under.
- Your payout destination — the mobile network and number, or the bank, account number and account name, that an Event's balance is paid to.
- A record of changes worth answering for — each change to an Event's title, description, target, payout destination, or status, with who made it and how it was authorised. It is written once and never rewritten, because a Contributor who gave money on a Monday is entitled to know what the page said on the Monday.
- Your connected Groups — each Group's WhatsApp identifier and name, the claim code it was connected with, and the text of every summary the Bot posted into it. Section 7 is about this in full.
If you contribute to a collection
- The name you give — either a name you picked from the Event's list or one you typed yourself. This is the name that appears in public, so it is worth choosing deliberately: a first name and an initial is a complete answer if you would rather not be fully named.
- The mobile number you pay from, and the network it belongs to. Never public. It is what the payment prompt goes to, and what lets an Organizer find your payment when you say it did not appear.
- An email address, if you give one — optional, and used for your receipt.
- The amount, the time, the status, and the reference our payment provider returns.
- Two technical values that stop a double tap becoming two payments: an idempotency key, and a fingerprint of the request. The fingerprint is a hash — it identifies a repeated submission, not a person, and cannot be turned back into who you are.
If you ask an Organizer to add you to their list
Your name, your mobile number, the amount you are offering to pledge, and the Organizer's decision. The number is how the Organizer tells two people with the same name apart, and how a duplicate request is recognised as the same person asking twice. It is never published.
From everybody who uses the site
Ordinary technical records of requests made to our servers, and short-lived counters used to enforce rate limits — a count of how many sign-in codes or payment attempts have come from one address in the last hour. The counters expire on their own within the hour and are never joined to an account.
What we deliberately do not collect
No passwords, ever — there is none in the system to leak, reuse, or reset. No identity documents at sign-up. No location. No access to your contacts. No tracking of you across other websites. No advertising profile, because BetaFund carries no advertising. We run no analytics product of any kind: there is no Google Analytics, no Meta pixel, and no third-party script measuring you on this site.
What we hold only as a hash, and cannot read back
Sign-in codes are stored as a keyed hash and are never written to a log; nobody at BetaFund can read a code out of the database or the server logs. Session tokens are stored the same way. The Bot Accounts' WhatsApp credentials are encrypted at rest.
4. Why we hold each thing
| What | Why we hold it | On what basis |
|---|---|---|
| Mobile number, name, email | To open and secure the account, to send sign-in codes, receipts, and notices about your own Events | Performance of our agreement with you |
| Terms acceptance record | To be able to show which version of the Terms an account is operating under, and when it agreed | Performance of our agreement; our legitimate interest in an account we can hold to its terms |
| Event content, participant list, pledges | To run the Event and publish its record — this is the Service | Performance of our agreement; the Organizer's own basis for the names they upload |
| Contribution details and payment references | To take the payment, confirm it, reconcile it, and answer a dispute about it | Performance of our agreement; legal obligation |
| Payout destination and payout history | To pay an Event's balance out, and to prove where it went | Performance of our agreement; legal obligation |
| Financial records generally | Tanzanian financial-record, tax, and anti-money-laundering obligations | Legal obligation |
| Sign-in codes, session records, the change log | To keep accounts and other people's money secure | Legitimate interest in a secure service |
| Request records and rate-limit counters | To stop abuse — a script cycling through numbers to make our SMS bill somebody else's problem | Legitimate interest in a service that stays available |
| Service SMS and email | Sign-in codes, payout receipts, and notices about your own Events | Performance of our agreement |
We send no marketing. Every message BetaFund sends is about something you are already doing: a code you asked for, a payment that arrived, a payout that left. There is no mailing list to leave, which is why there is no unsubscribe link — and it is also why service messages cannot be switched off while your account is open (Terms §13.7).
5. What is public by design
Anyone holding an Event's link, or its Public ID, can open its page and read all of this:
- the Event's title, description, image, type, and Public ID;
- its target, and the history of every change to that target;
- every Participant's name, and the amount they pledged;
- every Contributor's name, the amount they gave, and when it arrived;
- the running total, and how far it is towards the target.
The same list is posted into every WhatsApp Group connected to the Event.
Link-only Events are not private Events. Choosing Link-only limits who can find the Event — it will not be listed on BetaFund's public listing and search engines are told not to index it — and hides nothing at all from anyone holding the link. Links get forwarded. That is what they are for.
A Listed Event is additionally offered to anyone searching BetaFund, and its page may be indexed by search engines.
So: do not put anything on an event page that you would not want publicly readable — not in the title, not in the description, and not in a participant's name. A funeral collection is a public document about a private grief, and that is a choice worth making deliberately rather than discovering afterwards.
6. What is never public
None of the following ever appears on a public page or in a WhatsApp message:
- phone numbers — the Organizer's, a Contributor's, a Participant's, or a pledge requester's;
- email addresses;
- payout destinations — the network and number, or the bank details, an Event pays out to;
- payment references and payment provider identifiers;
- anything about a payout at all — that a withdrawal happened, when, for how much, or where it went.
Payout information is visible to that Event's Organizer and to nobody else. Not to Contributors, not to Participants, not on the public page. This is deliberate: what an Event has collected is the group's business, and where the money then goes is the Organizer's.
What the Organizer of an Event you contributed to can see. In their own dashboard — never in public — the Organizer sees the mobile number you paid from, the email address you gave if you gave one, and the payment reference, alongside your name and amount. They need it: the single most common thing that happens on this platform is somebody saying "I paid and my name is not on the list", and without the number there is no way to find the payment. Treat it as you would treat paying that person by mobile money directly, because in substance that is what you are doing.
What our own staff can see. Enough to run the platform and answer a support request — which includes the data above. Nobody at BetaFund will ever ask you for a sign-in code, by any channel, for any reason.
7. WhatsApp, and what the Bot can see
The account that joins your Group is ours, drawn from a small pool we operate. Your personal WhatsApp account is never connected to BetaFund, never asked for, and never at risk from it.
What the Bot receives. Once it has been added to a Group it receives every message posted in that Group, exactly as any other member does — that is simply what being in a WhatsApp group means, and there is no way to be a member and not receive them.
What it does with them. It looks at each message for one thing: an Event's claim code. Anything that is not a claim code is discarded immediately, before it is stored, examined, or sent anywhere. We do not keep your group's conversation. We do not build a record of who is in the group; the only membership event the Bot acts on is its own removal, so it can tell the Organizer the connection has stopped.
What we do store about a Group: its WhatsApp identifier and its name, which Event it is connected to, which of our Bot Accounts serves it, the claim code and when it was used, and the text of every summary the Bot posted with whether that post was delivered.
What we cannot control. Once the Bot posts a summary into your Group, that message is in WhatsApp — on Meta's systems and on every member's handset — and is subject to WhatsApp's own terms and privacy policy, not ours. We cannot unsend it, and deleting an Event on BetaFund does not remove messages already delivered.
Ending it is one action: remove the Bot from the Group. Nothing further is posted, and the Event's page carries on as the authoritative record.
8. Cookies, and what we do not use
BetaFund sets two cookies. Both are necessary for the site to work, and neither tracks you.
| Cookie | What it is for | Lifetime |
|---|---|---|
betafund_session |
Keeps an Organizer signed in. Holds a random token; our database stores only its hash. HttpOnly, SameSite=Lax, and Secure in production, so it cannot be read by scripts and is not sent from other sites. |
14 days, refreshed while you are active; ends immediately when you sign out |
betafund-locale |
Remembers whether you are reading in Swahili or English. | 1 year |
That is the whole list. There are no analytics cookies, no advertising cookies, no third-party trackers, and no pixels on this site — which is also why you are not asked to dismiss a cookie banner. There is nothing here to consent to beyond the two cookies that make signing in and reading in your own language work at all.
Cloudflare sits in front of the site to serve it quickly and to absorb attacks, and may set its own security cookie as part of that. It is a security measure, not a tracker, and is described in Cloudflare's own privacy documentation.
9. Who else your data reaches
The providers listed in Schedule A, each only so far as their part of the job requires, and each under a contract that permits them to use it for that job and nothing else.
Beyond them:
- Law enforcement, regulators, and courts, where we are legally required to hand something over, or where it is necessary to investigate fraud.
- Our professional advisers — lawyers, accountants, auditors — under a duty of confidence.
- A successor, if the business or part of it is ever transferred. You would be told, and this policy would continue to apply to what was transferred until a replacement was published.
We do not sell personal data. We do not share it for anybody else's marketing. There is no advertising on BetaFund and no data broker in this list.
10. Where your data is held
| What | Where |
|---|---|
| The database, the application servers, and the queue that drives WhatsApp posting | Servers we operate and control |
| Event images | Object storage operated by Wasabi, in the United States |
| Site delivery and protection | Cloudflare's global network |
| Payments, SMS, email | Our providers' own systems — see Schedule A |
Some of this is outside Tanzania. Where personal data leaves Tanzania we require by contract that it is protected to the standard this policy describes, and we use providers who commit to that in writing.
11. How long we keep it
| What | How long |
|---|---|
| Sign-in codes | 10 minutes, or until used — whichever comes first. Then only a spent record that the code existed |
| Sessions | 14 days, or until you sign out; immediately ended everywhere when you use "sign out of all devices" |
| Rate-limit counters | Under an hour, then discarded |
| Pending pledge requests | Until the Organizer accepts or declines them, and then as part of that Event's record |
| Account, Event, contribution, and payout records | While the account is open, and afterwards for as long as Tanzanian financial-record law requires — which is longer than the life of your account |
| WhatsApp summaries the Bot posted | With the Event they belong to |
The public record of a finished collection stays. We will not retrospectively rewrite a contribution list that other people gave money against (Terms §13.8). It is a record of something that actually happened, and a name comes off it only where the law requires. Closing an Event stops it collecting; it does not erase what it collected.
12. How we protect it
- There is no password in the system. Nothing to guess, reuse across sites, phish, or leak in somebody else's breach.
- Sign-in codes and session tokens are stored only as hashes, and codes are never written to a log.
- Changing where an Event's money goes needs two codes — one to the current destination and one to the new one — so a stolen session cannot quietly redirect a payout, and the rightful owner is warned that someone tried.
- The Bot Accounts' WhatsApp credentials are encrypted at rest with a key held outside the database.
- You can end every session on every device at once from your account settings. It is the first thing to do if you lose your handset.
- Traffic is encrypted in transit throughout, and every public write is rate-limited.
The honest limit. Your account is your SIM card, and once your account has an email address, that inbox is a second way in. Anyone who controls either can access your account. Keep control of both, and tell us at once if you lose your number.
13. Your rights, and how to use them
You may ask us to:
- Give you a copy of the personal data we hold about you.
- Correct anything inaccurate. Most of it you can correct yourself in the dashboard.
- Delete your data and close your account. We delete what we are free to delete.
- Stop or limit a particular use, where you object to it.
- Explain anything in this document that affects you.
How to ask. Write to tech@betatq.com, or to support@betafund.co.tz, from the email address or the phone number the account uses. Where we cannot tell that a request comes from the right person, we will send a one-time code to the account's number to check — handing somebody's contribution history to whoever asks for it would be the very failure this section exists to prevent. We aim to answer within 30 days.
Two limits, better said here than discovered later.
- We cannot delete what the law requires us to keep. Financial records outlive accounts.
- We will not rewrite a public contribution list. See section 11.
If your name is on somebody's Event. The Organizer put it there and can take it down themselves in seconds, which is nearly always the faster route. If they will not, write to us and we will deal with it — including with the Organizer — subject to the second limit above.
If you are unhappy with how we have handled it, tell us first so we have the chance to fix it. You also have the right to complain to Tanzania's Personal Data Protection Commission.
14. Children
You must be at least the Minimum Age in Schedule A of the Terms to hold an Organizer account. We do not knowingly collect personal data from anyone below it. If you believe a child's data has reached us — including as a name on a participant list — write to tech@betatq.com and we will remove what we are able to remove.
15. Changes to this policy
This policy is versioned, and every version is listed in Schedule B. When we change it in a way that materially affects you, we will say so on the site and, for Organizers, by email — not by quietly swapping the date at the top.
The canonical address of this policy is https://betafund.co.tz/privacy, and of the Terms it sits under, https://betafund.co.tz/terms.
16. How to reach us, and how to complain
| Data protection contact | tech@betatq.com |
| Support email | support@betafund.co.tz |
| Support phone / WhatsApp | +255 750 362 989 |
| Registered address | Mikocheni, Kinondoni, Dar es Salaam, Tanzania |
| Legal entity | Beta TQ Company Limited, registration 171304350, TIN 171304350 |
A person answers both addresses. If your money is involved, say so in the first line and we will treat it that way.
Schedule A — Who processes what
| Provider | What they do for us | What reaches them |
|---|---|---|
| Snippe | Takes mobile-money and card payments, and sends payouts | The Contributor's mobile number and name, the amount, an email address if given, and the Event's payout destination |
| Beem Africa | Sends our SMS | The recipient's mobile number and the text of the message, including sign-in codes |
| Resend | Sends our email | The recipient's email address and the text of the message |
| Wasabi | Stores Event images | The images an Organizer uploads |
| Cloudflare | Serves the site and absorbs attacks | Requests to the site pass through it, including their source addresses |
| WhatsApp (Meta) | Carries what the Bot posts into a Group | The summary message itself — Participant and Contributor names, amounts, and the running total |
Each processes on our instructions, for that purpose only, and none of them is permitted to use what reaches them for their own ends.
Schedule B — Change log
| Version | Date | What changed |
|---|---|---|
| 1.0 | 27 August 2026 |
First published version. Sets out in full what §13 of the Terms promises in summary: what is collected from an Organizer, a Contributor, and a pledge requester; the purposes and bases for each; what is public by design and what is never public, including that payout information is the Organizer's alone and that an Organizer can see the number a Contributor paid from; what the WhatsApp Bot receives and what it discards; the two cookies and the absence of any analytics or advertising; the processors and where the data sits; retention periods; and how to exercise a right. Nothing in §13 was narrowed. |
Want a copy of your data, or a name taken down?
Write from the number or the email address the account uses and say what you want. A person reads it. If a name on somebody else’s collection is the problem, the organizer can usually take it down faster than we can — but tell us either way.
support@betafund.co.tzRead the Terms and Conditions →