Information we handle
- Account and profile information. Firebase Authentication identifies your account. Your profile may include your name, phone number and account identifier.
- Group membership and activity. We store the chamas you create, join or ask to join, member roles, meetings, votes and other group activity.
- Financial records. The app records contributions, M-Pesa references and parsed confirmation details, loans, repayments, investments, penalties, balances and related approvals. ChamaClub records activity but does not move money through M-Pesa.
- Join application details. A public chama application can include your workplace, residence, planned contribution, national ID number, reason for joining and an uploaded ID photo. ID photos are kept in protected Firebase Storage and are available only to you and members authorized to review the application.
- Support information. We receive the information you include when you contact us for help or make an account deletion request.
Optional SMS access on Android
You may allow ChamaClub to read SMS messages on Android so it can find your own M-Pesa confirmation and prefill the payment confirmation form. The app uses confirmation details such as the M-Pesa reference, amount and date to match a contribution or repayment.
On a device with SMS permission, ChamaClub can also ingest messages it recognizes as incoming M-Pesa confirmations. The app parses the sender name, phone number, amount, reference and payment date. For each chama where the device owner has an authorized Treasurer or Chairperson role, ChamaClub may place those parsed details in that chama's deposit inbox in Firestore to match a pending contribution. This is role-scoped processing within those chamas, not public sharing.
SMS access is optional. If you deny permission, you can paste the M-Pesa confirmation into the app instead. The contribution flow remains available without SMS permission.
App lock and device security
You can turn on a biometric or device-credential app lock that uses the fingerprint, PIN, pattern or password already configured on your device. ChamaClub does not receive your fingerprint or device credential. The app lock setting is stored locally in secure device storage and is used to protect the app when it opens.
How we use and share information
We use this information to provide sign-in, maintain your profile, manage group membership, show group records, match payment confirmations, support governance decisions, secure the app and answer support requests.
Group records are shared with chama members or authorized leaders according to their role and the action involved. Join application details are limited to the applicant and the people authorized by that chama's approval policy. Firebase processes hosted account, database and file data for ChamaClub.
Retention and account deletion
We keep information while your account is active and for as long as needed to operate the service. You can make an account deletion request by following the steps on our Delete account page.
After a verified request, we delete or detach personal account data that is no longer needed. Transaction and audit records may be retained where required for legal obligations, fraud prevention, dispute resolution or financial accountability. Access to retained records is limited to the purpose for which they are kept.
Contact
Questions about this policy or your information can be sent to support@chamaclub.com.