What we collect
In plain English
We collect only what's needed for your order to reach you safely and for the food to be great.
| Information | Why we need it | How long we keep it |
|---|---|---|
| Phone number | OTP verification, order communication | Until you delete your account |
| Name | So your cook knows who they're cooking for | Until you delete your account |
| Delivery address | To bring food to your door | 90 days after your last order |
| Current location | Showing nearby cooks (only during ordering) | Not stored — used in the moment |
| Order history | Receipts, dispute resolution, recommendations | 2 years (tax compliance) |
| Device info | Crash diagnostics, app improvements | 30 days |
How we use your information
In plain English
We use your information for four things only — running orders well and improving the app.
- Fulfilling your orders and tracking deliveries.
- Showing you cooks nearby.
- Sending order-status notifications — when the cook accepts, when it's on the way, when it's delivered.
- Improving the app through anonymized analytics.
Cooks and your orders
The cook preparing your order sees your first name, delivery address, and any special notes you wrote (e.g. “no chili”).
They never see your phone number. All order communication happens inside the app — you and the cook chat through Mpishi only.
M-Pesa & Tigo Pesa payments
In plain English
We never hold your M-Pesa number. Licensed payment providers handle that.
We only see whether the payment succeeded or failed, the amount, and a transaction ID for your receipt. Financial details are held by the licensed providers: Vodacom M-Pesa, Mixx by Yas, and Airtel Money.
Your location
We ask for location permission only while you're ordering — to show cooks nearby and make delivery painless. Your location isn't stored on our servers.
You can revoke location permission anytime from your phone's settings. If you do, you'll just type the address yourself.
Children under 13
Mpishi is not a service for children. We don't intend to collect data from children under 13, and we won't knowingly let them sign up. If you discover a child has used an account, please write to us and we'll delete it.
Your rights
In plain English
You have full control over your information. Send us a message — we'll respond within 30 days.
- Get a copy of all the information we hold about you.
- Correct information that's wrong.
- Delete your account and all your data.
- Object to specific uses (e.g. marketing notifications).
- Export your data in JSON format.
How we keep it safe
Your data is stored on servers with encryption-at-rest, and travels over HTTPS only. We have access controls on staff — very few people can read personal data, and every access is logged.
If a security breach ever puts your data at risk, we'll notify you within 72 hours by email and in-app notification.
Changes to this policy
This policy may change as we build new things. For material changes, we'll notify you via in-app notification and email before they take effect.
The current version and date are always shown at the top of this page.
Contact us
For privacy questions, complaints, or data requests email privacy@mpishi.co.tz — that goes straight to our Data Protection Officer.
For general support, use hello@mpishi.co.tz.