Who we are and what this policy covers
ToAba is a paid live audience-voting platform and a product of PKay Software Consultancy. This Privacy Policy explains how we handle personal information when you visit ToAba, create or manage an organization, participate in an event, vote through the public website or Arkesel USSD, make or receive a payment, contact support, or otherwise use our services.
This policy applies to ToAba's websites, dashboards, voting experiences, communications, and related services. It does not replace the privacy notices of event organizers, Paystack, Arkesel, mobile network operators, banks, or other third parties whose services you choose to use.
Our role and the organizer’s role
ToAba determines how account, platform-security, transaction, and service-operations data is handled. For event content and participant information submitted by an organizer, the organizer may also decide why that information is collected and used. Depending on the context, ToAba and the organizer may each have independent privacy obligations, or ToAba may process information on the organizer's instructions.
Organizers are responsible for providing any additional event-specific privacy notice and obtaining permissions required for candidate profiles, photographs, biographies, sponsor content, and participant information they upload.
Information we collect
The information we collect depends on how you use ToAba.
- Account information: name, email address, password credentials in protected form, email-verification status, account role, session data, and account-security activity.
- Organization information: organization name, contact details, website, team memberships, invitations, settlement setup information, onboarding-payment status, and configuration choices.
- Event and candidate information: event names, schedules, descriptions, branding, categories, candidates, photographs, biographies, codes, voting rules, result visibility, and organizer-supplied content.
- Voting and transaction information: selected candidate, vote quantity, amount, channel, payment reference, currency, transaction status, provider response, timestamps, payment reconciliation records, refund or dispute information, and a voter email address or phone number where required for the flow.
- USSD information: mobile number or masked identifier, session identifier, menu selections, carrier context, timestamps, and the event, candidate, quantity, and payment status associated with the session.
- Device and usage information: IP address, browser type, device and operating-system information, pages requested, referring page, timestamps, diagnostics, security events, and application logs.
- Communications: messages, attachments, identifiers, and other information you provide when contacting support or responding to a service communication.
Please do not provide card PINs, mobile-money PINs, passwords, or one-time verification codes to ToAba or an organizer. Card and mobile-money authentication is handled through the relevant payment provider flow; ToAba does not need those secrets.
Where information comes from
We receive information directly from account holders, organizers, team members, voters, candidates, and people who contact us. We also receive transaction confirmations and related details from Paystack; USSD session and delivery information from Arkesel and participating mobile networks; and technical information automatically from the device, browser, and systems used to access ToAba.
Organizers may provide candidate or team-member information. They must have the authority to give us that information and to instruct us to display or process it.
How we use information
- Create, verify, secure, and administer accounts and organizations.
- Publish organizer-approved events, candidates, schedules, and public voting experiences.
- Create vote orders, initialize payments, confirm transaction status, credit paid votes exactly once, issue receipts, and reconcile records.
- Deliver web and USSD voting, show permitted results, and generate organizer analytics and reports.
- Configure settlement accounts, calculate platform deductions and organizer shares, and support financial reporting.
- Send verification, password-reset, invitation, receipt, operational, security, and support communications.
- Detect, investigate, prevent, and respond to fraud, abuse, duplicate crediting, unauthorized access, security incidents, and disputes.
- Monitor reliability, diagnose errors, improve usability, plan capacity, and develop the service using aggregated or appropriately de-identified insights where practical.
- Enforce our agreements, protect users and the public, comply with legal obligations, and respond to valid regulatory or legal requests.
Why we are allowed to process information
Where a legal basis is required, we rely on one or more of the following: performing a contract or taking requested pre-contract steps; complying with a legal obligation; pursuing legitimate interests such as operating, securing, improving, and preventing abuse of ToAba; protecting a person's vital interests where necessary; and consent, where we specifically request it.
You may withdraw consent for future processing where consent is the basis, but this does not affect processing already carried out or information we must retain for another lawful reason.
Public event information and visibility
Public event pages may display organizer-selected event branding, candidate names, photographs, biographies, categories, sponsors, schedules, and voting status. Vote totals and rankings are shown only according to the organizer's configured result-visibility rules.
A voter's contact information, payment reference, payment method, and individual purchase history are not intended for public display. Organizers receive only the operational information permitted for managing their event, with voter contacts masked where appropriate.
How long we retain information
We keep personal information only for as long as reasonably necessary for the purposes described in this policy, including providing the service, maintaining accurate vote and financial records, resolving disputes, preventing fraud, enforcing agreements, and meeting legal, tax, accounting, audit, and regulatory requirements.
Retention periods vary by record type. Account information may be removed or de-identified after an account is closed when no continuing obligation applies. Transaction, settlement, audit, security, refund, and dispute records may be retained longer because they support financial integrity and legal compliance. Backups are deleted or overwritten on a controlled schedule.
How we protect information
We use administrative, technical, and organizational measures designed to protect personal information, including access controls, role-based authorization, protected password storage, session and request safeguards, encryption in transit, transaction idempotency, audit records, monitoring, backups, and restricted access to production systems.
No service can guarantee absolute security. You are responsible for using a strong, unique password, protecting your device and email account, signing out of shared devices, and promptly telling us about suspected unauthorized access.
International processing
Some providers or their systems may process information outside Ghana. Where this occurs, we take steps designed to ensure the transfer has an appropriate legal basis and that contractual, organizational, or other safeguards protect the information as required by applicable law. Payment and telecommunications providers may make their own transfer decisions under their respective privacy notices.
Your privacy rights and choices
Subject to applicable law and relevant exemptions, you may ask us to:
- confirm whether we process your personal information;
- provide access to, or a copy of, information about you;
- correct information that is inaccurate or incomplete;
- stop, restrict, or object to certain processing;
- delete information that no longer has to be retained;
- provide portable information where the right applies; or
- honour a withdrawal of consent for future consent-based use.
Email hello@toaba.com with the subject “Privacy request.” We may verify your identity and authority before responding. If an organizer controls the relevant information, we may direct the request to that organizer or assist them in responding.
You may also raise a concern with Ghana's Data Protection Commission or another competent privacy authority. Ghanaian data subject rights are addressed in the Data Protection Act, 2012 (Act 843).
Children and young participants
ToAba organization accounts are intended for adults and authorized representatives. Events may involve schools or young participants, but organizers must obtain any consent or authorization required before uploading a minor's name, image, biography, or other personal information.
A parent or guardian who believes a child's information was submitted improperly should contact us and identify the event so the request can be reviewed with the organizer.
Changes, questions, and complaints
We may update this policy when the service, our providers, or legal requirements change. We will publish the revised version here, update the date above, and provide additional notice when a change is significant and notice is required.
For privacy questions, requests, or complaints, email hello@toaba.com. Please do not include a password, PIN, or one-time verification code.
