Privacy Policy

Effective date: 24 July 2026

This Privacy Policy explains how GETO Space and MiMi Money (together, the “Services”, “GETO”, “we”, “us” or “our”) collect, use, disclose, retain and protect personal information. It applies when you use geto.space, the GETO Space social and business network, the MiMi Money wallet experience, our mobile applications, marketplace, messaging, advertising, escrow, support and other features that link to this Policy.

We designed this Policy for the realities of African digital markets, including mobile-first access, mobile money and wallet services, cross-border communities, shared devices, intermittent connectivity and different national privacy laws. We aim to use clear language and collect only what is reasonably needed. If a translated version conflicts with the English version, the English version controls to the extent permitted by law.

Privacy at a glance

  • We use information to operate GETO Space and MiMi Money, secure accounts and wallets, process transactions, provide social and marketplace features, prevent fraud and meet legal obligations.
  • We do not ask for or store your wallet private key or seed phrase. Never share either with us or with another user.
  • Wallet addresses and blockchain transactions may be publicly visible and generally cannot be changed or deleted from a blockchain.
  • You control what you post and many account, communication, cookie and marketing settings. Public posts can be copied or reshared by others.
  • We do not sell personal information for money. We do not use financial, identity-verification or precise-location information to target advertising.
  • You may have rights to access, correct, download, object to, restrict or delete personal information, subject to applicable law and legitimate retention duties.

1. Who is responsible for your information

GETO, a decentralized autonomous organization (DAO), provides the GETO Space ecosystem. GETO Space and MiMi Money determine how personal information is processed for the integrated Services and may act as controllers individually or jointly, depending on the feature you use. A separately identified merchant, payment provider, mobile-money operator, identity-verification provider, blockchain network, application or website may be an independent controller under its own privacy notice.

For privacy questions and rights requests, email info@geto.space or info@mimi.money. We will route your request to the team or service responsible for the relevant processing.

2. Information we collect

The information we collect depends on which Services you use, the choices you make and the law that applies to you.

Account and profile information

This may include your name, username, password in protected form, email address, telephone number, date of birth or age, gender, profile and cover photos, language, country, city, biography, education, employment, business details, interests, account preferences and verification status.

Content, social connections and communications

We process posts, stories, blogs, comments, reactions, groups, pages, events, listings, reviews, advertisements, photos, audio, video, live streams and other content you create or upload. We also process information about followers, people and businesses you interact with, message participants, call and message metadata, reports, moderation actions and support communications. Where necessary to provide the feature, enforce our rules or protect users, authorised systems or personnel may process message or content information, subject to applicable law.

Contacts and information about people who do not use the Services

If you choose to sync or invite contacts, we may receive names, telephone numbers or email addresses from your device. Only provide information you are authorised to share. We may use contact matching to help you find people or invite them, and we provide controls to stop future syncing where the feature is available. We may also receive information about non-users when other people mention, upload or transact with them.

MiMi Money, wallet and blockchain information

When you connect MiMi Money or another supported wallet, we may process your public wallet address, wallet provider identifier, connection and linking time, login time, authentication nonce, signed authentication message and signature, token or network information, transaction hash, public on-chain activity and related fraud or security signals. We use a signature to verify that you control a wallet address. We do not need and will not ask for your private key or seed phrase.

Blockchain networks are public systems operated independently of GETO. Information written to a blockchain may be visible worldwide, combined with other data, and impossible for us or anyone else to erase or change.

Payments, marketplace, business and escrow information

Depending on the feature, we may process order and listing details, amount, currency, payer and payee information, payment status, mobile-money or payment-channel references, transaction and withdrawal records, wallet balance records, bank-receipt information, shipping or delivery information, invoices, refunds, disputes, escrow status and dispute communications. Payment card, bank, mobile-money or crypto-payment providers may collect information directly; we normally receive a token, reference, status or limited account details rather than complete payment credentials.

Identity, compliance and sensitive information

Where required for account security, payments, withdrawals, regulated services, fraud prevention or legal compliance, we or an authorised provider may request proof of identity, date of birth, address, selfie or liveness result, tax information, source-of-funds information, sanctions or politically exposed person screening results and similar know-your-customer information. We treat identity, financial, biometric, precise-location and other legally sensitive information with additional safeguards. We process sensitive information only where permitted, such as with explicit consent, to comply with law or to protect vital interests.

Device, network, usage and location information

We may collect IP address, device and advertising identifiers, device type, operating system, browser, application version, language, time zone, mobile network or internet service provider, referral page, pages and features used, search and click activity, session dates and duration, crash and diagnostic data and security events. With your device permission, features such as nearby content, maps, marketplace delivery or check-ins may use approximate or precise location. You can manage location permission in your device settings, although some features may then be unavailable.

Cookies and similar technologies

We and our authorised partners use cookies, local storage, pixels, software development kits and similar technologies to keep you signed in, remember preferences, secure the Services, measure performance, understand usage and, where permitted, deliver or measure advertising. Required technologies operate because they are necessary for the Services. Where law requires, we request consent for analytics or advertising technologies. Browser blocking may affect functionality.

Information from partners and other sources

We may receive information from users, merchants, payment and mobile-money providers, wallet providers, identity and fraud-prevention providers, delivery partners, analytics and advertising partners, linked social-login services, public blockchain networks, public sources, regulators and law-enforcement bodies. We may combine it with information we already hold where lawful and reasonably necessary.

Support, surveys, promotions and employment

We collect information you provide when you contact support, appeal a decision, report content, answer a survey, enter a promotion, attend an event or apply to work with us. Employment information may include a CV, qualifications, references and interview notes.

3. How we use information

We use personal information to:

  • create, authenticate, maintain and recover accounts;
  • link and verify a MiMi Money wallet and enable wallet-based login;
  • provide feeds, profiles, messaging, calls, groups, pages, events, marketplace, advertising, payments, escrow, support and other requested features;
  • process orders, payments, wallet activity, commissions, withdrawals, refunds and disputes;
  • personalise content, language, connections, recommendations and non-sensitive advertising choices;
  • measure, troubleshoot, research, test and improve accessibility, reliability, performance and user experience;
  • detect spam, scams, account takeover, money laundering, prohibited transactions, harmful content and other misuse;
  • verify identity, enforce our terms, moderate content and protect users, the public and the integrity of the Services;
  • communicate about transactions, security, service changes, support and, with the required choice or consent, promotions;
  • meet accounting, tax, consumer-protection, anti-money-laundering, sanctions, recordkeeping and other legal duties;
  • respond to lawful requests and establish, exercise or defend legal claims; and
  • create aggregated or de-identified insights. We do not try to re-identify information that has been properly de-identified.

4. Our legal grounds for processing

Depending on your country and the activity, we rely on one or more recognised grounds:

  • Contract: processing needed to provide the Services you request or take steps at your request before a contract.
  • Consent: for optional activities such as certain marketing, contact syncing, precise location, sensitive information or non-essential cookies. You may withdraw consent for future processing.
  • Legal obligation: processing required by financial, tax, corporate, consumer, data-protection, court-order or other applicable law.
  • Legitimate interests: operating and improving the Services, securing users and systems, preventing fraud, understanding performance, communicating and protecting legal rights, after considering the impact on your rights.
  • Public or vital interests: where processing is necessary to protect life, safety or another interest recognised by law.

Where applicable law uses different legal grounds, we process information on the closest lawful basis available under that law. You may ask us about the ground used for a particular activity.

5. Public information and your audience

Your username, profile image and information you mark public may be visible to anyone, including people without an account and search engines. Posts and marketplace listings are shared with the audience you select, subject to feature settings. Other people may download, screenshot, translate, embed or reshare content beyond your chosen audience. Before posting, consider personal safety, shared-device access, location clues and the permanence of public information.

Deleting content removes it from normal display, but copies may remain in recipients’ accounts, backups, legal records, search caches or material reshared by others. Public blockchain records are not controlled by us and cannot generally be deleted.

6. When we disclose information

We disclose only information reasonably necessary for the relevant purpose:

  • People and businesses you choose: according to your audience, message, transaction, group, page or marketplace choices.
  • GETO Space and MiMi Money teams and infrastructure: to operate integrated accounts, wallet connections, security, support and shared features.
  • Service providers: hosting, storage, content delivery, communications, email, customer support, security, fraud detection, identity verification, analytics, maps, moderation, payments and professional services. They must process information under contractual and security obligations.
  • Payment, mobile-money, wallet and blockchain participants: to initiate, route, verify, settle, record, refund or investigate a transaction.
  • Merchants, buyers, sellers and delivery partners: to complete an order, delivery, refund, escrow or dispute.
  • Integrated applications and websites: when you choose to connect them. Their own terms and privacy policies apply.
  • Advertising and measurement partners: limited device, cookie, engagement or aggregated information where permitted. We do not disclose private messages, identity documents, complete payment credentials or seed phrases to advertisers.
  • Authorities and other parties for legal or safety reasons: where required by valid law or reasonably necessary to prevent fraud, serious harm, abuse or a security incident; enforce terms; or protect rights and property. We assess requests for legal validity and scope where we are allowed to do so.
  • Business or organisational change: in a merger, financing, restructuring, asset transfer or similar event, with confidentiality safeguards and notice where required.
  • With your direction or consent: for another purpose clearly explained to you.

We do not sell personal information for money. If a local law defines “sale” or “sharing” more broadly to include certain advertising technologies, we provide the choices required by that law.

7. International and cross-border transfers

Our users, service providers, counterparties and technical systems may be located in different African countries and elsewhere. Your information may therefore be processed outside the country where you live. This is sometimes necessary for cross-border communication, wallet or payment networks, fraud prevention, support and reliable hosting.

For a restricted transfer, we use safeguards appropriate to the relevant law, which may include an adequacy decision, contractual clauses, consent where valid, data-transfer agreements, security controls, risk assessments or another lawful mechanism. We consider local legal requirements and data-sovereignty risks when selecting providers. You may contact us for more information about safeguards relevant to your data.

8. How long we retain information

We retain personal information only for as long as reasonably necessary for the purposes in this Policy. The period varies according to the type of information, the feature, your choices and legal requirements. We consider:

  • whether your account is active and the information is needed to provide a feature;
  • transaction, anti-money-laundering, tax, accounting and consumer-protection retention duties;
  • security, fraud, abuse, dispute, chargeback and limitation periods;
  • whether you asked us to delete information and an exception applies;
  • backup cycles and technical restoration needs; and
  • whether the information has been aggregated or de-identified.

Account and content information is generally kept while your account is active. Some security logs are kept for a shorter operational period; transaction, identity-verification, escrow and legal records may be kept longer where law or risk requires. After the applicable period, we delete, anonymise or securely isolate information. A blockchain’s independent retention is not controlled by us.

9. Security and account safety

We use risk-based administrative, technical and physical safeguards, which may include encryption in transit, protected password hashing, access controls, authentication challenges, signature verification, monitoring, backups, staff confidentiality and vendor reviews. No service or transmission method is completely secure, especially on shared devices or public networks.

Protect your password, device, one-time codes and wallet. Use available two-factor authentication, check transaction details before signing and log out of shared devices. GETO Space and MiMi Money will never need your wallet seed phrase or private key. Report suspected account or wallet misuse promptly by emailing info@geto.space or info@mimi.money.

If a personal-data breach creates a risk requiring notice, we will notify the appropriate regulator and affected people as required by applicable law, taking account of law-enforcement restrictions and the information available to us.

10. Your rights and choices

Subject to your country’s law and relevant exceptions, you may have the right to:

  • be informed about processing and request access to your personal information;
  • correct inaccurate or incomplete information;
  • request deletion, anonymisation or restriction;
  • object to direct marketing or processing based on certain legitimate interests;
  • withdraw consent without affecting earlier lawful processing;
  • receive information you provided in a usable format and ask for portability where applicable;
  • ask for human review of a decision based solely on automated processing where it has a legal or similarly significant effect;
  • complain to us or your national data-protection authority; and
  • not be unlawfully discriminated against for exercising a privacy right.

You can use account and privacy settings to update profile information, choose audiences, manage notifications and marketing, control permissions, download available information or close your account. You can also email info@geto.space or info@mimi.money. Tell us the account and Service involved and the right you want to exercise.

To prevent unauthorised access, we may verify your identity or authority to act for another person. We respond within the period required by applicable law. We may deny or limit a request where the law allows—for example, to protect another person, preserve evidence, complete a transaction, comply with financial recordkeeping, secure the Services or exercise legal rights—and will explain when we are permitted to do so. We cannot alter or erase public blockchain records.

11. Automated systems, recommendations and fraud controls

We may use automated systems to rank content, recommend connections or products, detect fraud and spam, identify security risks, moderate content and apply transaction controls. These systems may use account activity, device signals, content interactions, transaction patterns and public blockchain data. We test and review systems proportionate to risk and provide appeal or human-review channels where required. We do not make a decision with a legal or similarly significant effect based solely on automated processing unless it is authorised by law and appropriate safeguards are available.

12. Marketing and advertising choices

We may send service and security communications even if you opt out of marketing. You can unsubscribe from promotional email through the message link, adjust notification settings or contact us. It can take a short time to apply a preference, and you may still see non-personalised advertisements.

Advertising may be selected using general information such as language, country, broad location, age range and activity on the Services, subject to law and your settings. We do not use identity documents, complete financial credentials, private messages, seed phrases or precise location to target ads. Where required, we obtain consent for personalised advertising or provide an objection or opt-out control.

13. Children and young people

The Services are not directed to children under 13, and a higher minimum age applies where local law requires it. A person aged 13 to the age of legal majority may use eligible social features only with any consent or supervision required by their country. Financial, wallet, marketplace, advertising or other restricted features may require the user to be 18 or older, pass age or identity checks, or act through a lawful guardian.

We do not knowingly collect information from a child contrary to law or knowingly use a child’s information for targeted advertising. A parent or guardian who believes a child provided information unlawfully should contact us so we can investigate and take appropriate action.

14. African privacy commitments and regional rights

We apply the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, security and accountability reflected in the African Union Convention on Cyber Security and Personal Data Protection and national laws. Depending on where you live or where processing occurs, applicable law may include Uganda’s Data Protection and Privacy Act, 2019; Kenya’s Data Protection Act, 2019; Nigeria’s Data Protection Act, 2023; South Africa’s Protection of Personal Information Act, 2013; Ghana’s Data Protection Act, 2012; Mauritius’s Data Protection Act, 2017; or another national framework.

This list does not limit rights available under another law. If a mandatory local rule provides stronger protection than this Policy, the local rule applies. You may complain to the data-protection authority in your country. We encourage you to contact us first so we can try to resolve the concern quickly.

15. Third-party services and external links

The Services may link to or integrate with merchants, mobile-money operators, wallet applications, blockchains, payment providers, social-login services, maps, websites and applications that we do not control. Their privacy practices apply to information they collect for their own purposes. Review their notices and permissions before connecting an account, signing a transaction or providing information. This Policy does not cover an independent third party’s processing.

16. Changes to this Policy

We may update this Policy as the Services, technologies or laws change. We will post the revised version here and update the effective date. If a change materially affects your rights or how we use information, we will provide additional notice through the Services, email or another appropriate channel before the change takes effect where required.

17. Contact and complaints

For a privacy question, rights request, complaint or security concern, email info@geto.space or info@mimi.money. Please do not include a password, private key, seed phrase, full payment credential or unnecessary identity document in your first message.

If you are not satisfied with our response, you may lodge a complaint with the data-protection authority in the country where you live, work or believe a violation occurred, where that right is available.