Skip to content
Zoe
Zoe
hello@qcodelabs.comAccra · Ghana — for the world
← Back home

Legal

Privacy Policy

How Zoe Community collects, uses, shares, and protects your personal data.

Last updated 2026-06-27 · Version 1.0

Introduction

Quabynah Codelabs LLC ("Zoe", "we", "our", or "us") operates Zoe Community ("the App"), a multi-tenant social platform that connects churches ("communities" or "tenants") and their members. Zoe is built Ghana-first and offers devotionals, events and RSVPs, a prayer wall, groups and chat, fasting challenges, podcasts and sermons, live services, and giving.

This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and the rights you have over it. Quabynah Codelabs LLC is the data controller responsible for your personal data under the Republic of Ghana's Data Protection Act, 2012 (Act 843) and, where it applies to users in the European Union, the EU General Data Protection Regulation (GDPR).

This notice covers both the Zoe Community mobile app and our marketing website. By using the App, you acknowledge the practices described here. Where we rely on your consent, we ask for it separately and you may withdraw it at any time.

This document is a draft prepared for legal review. It describes our intended data practices in plain language and is not a representation of certified legal compliance.

Information We Collect

We collect the following categories of personal data:

  • Account information. Your name, email address, and profile photo, provided through Google or Apple sign-in. We do not receive or store your Google or Apple password.
  • Church membership data. The communities (tenants) you belong to, your membership status, and your roles within each community (for example, member, leader, or administrator).
  • Content you create. Prayer requests, posts, comments, chat and group messages, event RSVPs, and other content you submit through the App.
  • Device information. Push notification device tokens, device type, and operating system version, used to deliver notifications and keep the App working reliably.
  • Giving and transaction metadata. Records of giving you make through the App, including amounts, dates, the community you gave to, and a payment reference. We do not collect or store your card number, PIN, or other payment-card credentials — these are handled directly by our payment processor (see "How We Disclose Your Data").
  • Usage data. Anonymized information about how you interact with the App, such as features used and content viewed, used to understand and improve the product.

We do not intentionally collect special-category data (such as health, political, or biometric data). Note that content you choose to share — for example a prayer request — may reveal religious belief by its nature; you control what you post.

Cookies and Tracking Technologies

We use a limited set of cookies and similar technologies across our marketing website and within the App.

  • Marketing website. We use strictly necessary cookies to make the site function and may use limited analytics to understand aggregate traffic. We do not use third-party advertising or cross-site tracking cookies. Where required, we ask for your consent to non-essential cookies and let you manage your preferences.
  • Mobile app. The App does not use browser cookies for advertising. It stores local identifiers and authentication tokens on your device to keep you signed in and to deliver push notifications. We do not operate third-party ad-tracking SDKs.

You can control cookies through your browser settings and control notification permissions through your device settings. Disabling some technologies may affect how the site or App works.

Lawful Bases for Processing

For users to whom the GDPR applies, and as a matter of good practice for all users, we rely on the following lawful bases to process your personal data:

  • Performance of a contract — to provide the App and the features you ask for, such as your account, community membership, content, and giving.
  • Consent — for optional processing such as non-essential marketing communications and certain cookies. You may withdraw consent at any time without affecting processing already carried out.
  • Legitimate interests — to keep the App secure, prevent abuse, understand usage through anonymized analytics, and improve our product, balanced against your rights and freedoms.
  • Legal obligation — to comply with applicable laws, lawful requests from authorities, and record-keeping duties.

How We Use Your Data

We use your data for the purposes below, each tied to a lawful basis:

PurposeWhat it involvesLawful basis
Provide the AppCreate and maintain your account, communities, devotionals, events, prayers, groups, chat, podcasts, and live servicesContract
Process givingRecord and reconcile tithes, offerings, and other giving you makeContract; Legal obligation
Deliver notificationsSend push notifications about your community's announcements, events, and devotionalsContract; Consent (where required)
Personalize your experienceTailor content to your community membership and preferencesLegitimate interests
Maintain security and prevent abuseDetect and prevent fraud, abuse, and unauthorized access; enforce our TermsLegitimate interests; Legal obligation
Improve the productAnalyze anonymized usage to fix problems and improve featuresLegitimate interests
Support youRespond to your questions, requests, and rights requestsContract; Legal obligation
Marketing communicationsSend optional product updates and announcementsConsent

How We Disclose Your Data

We do not sell your personal data. We share it only as described here.

Subprocessors. We use trusted service providers to operate the App. Each is bound by contractual confidentiality and data-protection obligations and may only process data on our instructions.

SubprocessorPurposeData sharedPolicy
PaystackPayment processing for giving, including Mobile Money (MTN MoMo, Vodafone Cash, AirtelTigo) and card paymentsGiving amount, transaction metadata, and the payment details you enter directly with Paystack. We do not receive or store your card credentials.https://paystack.com/terms/privacy
Firebase Cloud Messaging / GoogleDelivery of push notificationsDevice push tokens and notification payloadshttps://firebase.google.com/support/privacy
Hetzner CloudPrimary hosting and storage (servers in the EU/Germany)All App data we store, including account, content, and membership datahttps://www.hetzner.com/legal/privacy-policy
imgproxyOn-the-fly image resizing and deliveryImages you upload or view, processed in transithttps://imgproxy.net/
Google (Sign-In)Authentication via Google accountYour name, email, and profile photo from your Google accounthttps://policies.google.com/privacy
Apple (Sign in with Apple)Authentication via Apple IDYour name and email (or relay email) from your Apple IDhttps://www.apple.com/legal/privacy

Church administrators. Administrators and leaders of a community you join can see information relevant to their community — your name, profile photo, membership role, and your activity and content within that community (for example, your event RSVPs and posts). Administrators of one community cannot see your data in another community; tenant isolation is enforced at the database level.

Legal requirements. We may disclose personal data when required by law, court order, or a valid request from a public authority, or where disclosure is necessary to protect the rights, safety, or property of our users, the public, or Zoe.

In the event of a merger, acquisition, or asset sale, personal data may be transferred to the successor entity, subject to this notice and applicable law.

Aggregated / De-Identified Data

We may aggregate or de-identify personal data so it can no longer reasonably be linked to you — for example, counts of attendees at an event or overall feature-usage statistics. We may retain and use this aggregated or de-identified data indefinitely for analytics, reporting, and product improvement. We do not attempt to re-identify de-identified data, and we do not treat it as personal data.

Retention of Your Data

We keep personal data only for as long as we need it for the purposes described in this notice, then delete or anonymize it.

  • Account and profile data. Retained while your account is active. Deleted within the deletion process below after you close your account.
  • Community membership and roles. Retained while you are a member and through the deletion grace period.
  • Content you create (prayers, posts, comments, chat and group messages). Retained until you delete it or until your account is permanently deleted; you can remove your own content at any time.
  • Device tokens. Retained while valid; removed when you sign out, uninstall, or revoke notification permission.
  • Giving and transaction metadata. Retained as needed to provide receipts and reconciliation and to meet financial and legal record-keeping obligations, which may extend beyond account deletion.
  • Anonymized usage and aggregated data. May be retained indefinitely as it cannot be linked back to you.

Account deletion and the 30-day grace period. You can request deletion at any time from the account settings in the App. When you do:

  • Your account is immediately deactivated and you are signed out; it becomes inaccessible to others.
  • A 30-day grace period begins, during which you can cancel deletion and reactivate your account simply by signing back in.
  • After 30 days, your personal data — profile, community memberships, prayer requests, posts, messages, and activity history — is permanently and irreversibly deleted, except records we must retain by law (such as certain giving records) and anonymized data that cannot be linked to you.

Security of Your Data

We apply technical and organizational measures designed to protect your personal data:

  • Encryption in transit using TLS for all communication between the App and our servers.
  • Tenant isolation using PostgreSQL Row-Level Security (RLS), so each community's data is strictly separated from every other community's.
  • Encrypted local storage on your device (via isar) for sensitive data such as authentication tokens.
  • Least-privilege access, so staff and systems can only access the data they need.

No method of electronic transmission or storage is completely secure. While we work to protect your data, we cannot guarantee absolute security. If we become aware of a personal-data breach that affects you, we will act in line with our legal obligations, including notifying the relevant authority and affected users where required.

Your Rights as a Data Subject

Under the Ghana Data Protection Act, 2012 (Act 843), and the GDPR where it applies to you, you have the following rights over your personal data:

  • Access — request a copy of the personal data we hold about you. You can also view much of it directly in your profile.
  • Rectification — correct inaccurate or incomplete data. You can update most profile details in the App at any time.
  • Erasure — request deletion of your account and associated data (see the account-deletion process above), subject to data we must keep by law.
  • Restriction — ask us to limit how we process your data in certain circumstances.
  • Portability — request a copy of your personal data in a structured, commonly used, machine-readable format.
  • Objection — object to processing based on our legitimate interests, including profiling.
  • Withdraw consent — withdraw any consent you have given, at any time, without affecting prior processing.

To exercise any of these rights, contact us at privacy@qcodelabs.com. We will respond within the time limits set by applicable law and may need to verify your identity first. Exercising your rights is free unless a request is manifestly unfounded or excessive.

Children's Privacy

Zoe is intended for churchgoers and is not directed at young children. You must be at least 18 years old, or have the consent and supervision of a parent or guardian if you are a minor under the laws of your country, to use the App. We do not knowingly collect personal data from a child without the appropriate parental or guardian consent.

If you are a parent or guardian and believe a child has provided us with personal data without your consent, please contact us at privacy@qcodelabs.com and we will take steps to delete that data promptly.

International Transfer of Data

Zoe primarily serves users in Ghana, but our hosting infrastructure (Hetzner Cloud) is located in the European Union (Germany). This means your personal data is transferred to and stored in the EU, and certain subprocessors (such as Google and Apple) may process data in other countries.

We rely on appropriate safeguards for these transfers, including the protections offered by hosting within the EU/EEA, our contractual data-protection commitments with subprocessors, and recognized transfer mechanisms such as standard contractual clauses where applicable. By using the App, you understand that your data will be processed in these locations. If you have questions about a specific transfer or its safeguards, contact us at privacy@qcodelabs.com.

Marketing and Communications

We send two kinds of messages:

  • Service messages that are part of using the App — for example, notifications about your community's events, devotionals, and announcements, and account or security notices. These are necessary to provide the service.
  • Marketing messages about new features, updates, or offers. We send these only where you have opted in or where permitted by law.

You can control notifications in your device settings and within the App, and you can opt out of marketing communications at any time using the unsubscribe link or by contacting us. Opting out of marketing does not stop essential service messages.

Complaints

If you have a concern about how we handle your personal data, please contact us first at privacy@qcodelabs.com so we can try to resolve it.

You also have the right to lodge a complaint with a supervisory authority. In Ghana, the relevant authority is the Data Protection Commission (Ghana) (https://www.dataprotection.org.gh). If you are in the European Union, you may complain to the supervisory authority in your country of residence, place of work, or where the issue occurred.

Changes to This Notice

We may update this Privacy Policy from time to time. When we make material changes, we will notify you through an in-app notification and update the "Last updated" date at the top of this document. Where required by law, we will seek your consent before applying changes that affect how we process your data.

Your continued use of the App after an update takes effect indicates your acknowledgment of the revised notice.

Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us:

Quabynah Codelabs LLC (operator of Zoe Community) Data controller — Republic of Ghana

Supervisory authority: Data Protection Commission (Ghana) — https://www.dataprotection.org.gh