Legal
Privacy Policy
This policy explains what personal data Imani handles, why, and what rights you have over it. It covers this website and the wallet at app.imani.casa.
The short version, which is not the legal one. Your account is a key on your phone, encrypted with a passphrase we never receive. Your vouchers and your sales history are yours, held and rebuilt on your own device. What passes through our infrastructure is encrypted and we cannot read it. A shop's public name and profile are public by design, because customers need to recognise it. We do not sell anything about you and we do not track you around the web.
1. Who is responsible
Imani is the data controller for the limited personal data described below. Contact us at hello@imani.casa.
To complete before publication: registered company name, company number, registered office address, ICO registration number, and a named contact for data protection queries. Replace this paragraph with those details.
Where you use the wallet as a shop, the shop is the controller of its own customer records and correspondence, and we are not.
2. How the design shapes this policy
Most privacy policies describe a database of users. Imani does not have one. Accounts are cryptographic keys generated on your device. The passphrase that encrypts a key is never transmitted. Vouchers are bearer credentials held on the device that owns them. A shop's sales history is reconstructed from its own key and encrypted to it.
The practical effect is that for most of what you do in Imani we hold either nothing at all or ciphertext we cannot decrypt. We have written the rest of this policy around what we do actually touch.
3. What we handle
Data that never reaches us
- Your private key and your passphrase.
- Your backup key.
- The plaintext contents of vouchers you hold and of messages between wallets.
- A shop's reconstructed sales history and dashboard figures.
Data that passes through our infrastructure
- Encrypted events. Our relay and gateway carry encrypted, wrapped messages between wallets so that a voucher issued on one device arrives on another. We can see that an encrypted item exists, its size and its arrival time, and the ephemeral identifiers used for delivery. We cannot see its contents.
- Connection metadata. Like any internet service, our servers process IP addresses, timestamps, user agent strings and error information in order to run and secure the service. This is used for operation, abuse prevention and diagnosis, and is retained for a short period.
Data that is public by design
- Public profiles. A handle, display name, description, avatar and banner are published so that customers can recognise a shop and so that vouchers show who issued them. Anything you put in a public profile is public, permanently and to anyone, and can be copied by others. Do not put anything in it you would not put on your shop window.
- Public keys. Your public key identifies your account to others and appears on the network.
Data you give us directly
- Correspondence. If you email us, we hold your email address and whatever you write, so we can reply and keep a record of the exchange.
- Onboarding details. If we take a shop on personally, we may hold a business name, address, contact name, phone number and notes about the conversation.
4. Why we handle it, and on what legal basis
| What | Why | Lawful basis |
|---|---|---|
| Encrypted events on the relay | To deliver vouchers and messages between wallets | Performance of a contract with you |
| Connection metadata and logs | To run the service, prevent abuse and diagnose faults | Legitimate interests, in keeping the service available and secure |
| Public profile data | So customers can identify shops and vouchers | Performance of a contract with you |
| Email and onboarding notes | To answer you and to set shops up | Legitimate interests, or performance of a contract |
| Aggregate website statistics | To understand what the site needs to say | Legitimate interests, where no cookie or identifier is used |
5. Cookies and analytics
This website sets no advertising or tracking cookies and runs no third-party advertising trackers. Fonts are loaded from Google Fonts, which means your browser makes a request to Google's servers and Google receives your IP address as part of serving that request; see Google's own privacy notice for what they do with it.
The wallet uses local storage on your own device to hold your encrypted key and your vouchers. That is not a cookie and it is not sent to us; it is what makes the wallet work offline and across sessions. Clearing your browser storage without your backup key will lose the account.
6. Who else sees anything
We do not sell personal data and we do not share it for advertising. We use a small number of processors to run the service:
- Hosting and infrastructure providers for the website, relay and gateway.
- A media host for avatar and banner images you upload for a public profile.
- An email provider, for correspondence with us.
Each is bound to process data only on our instructions. We may disclose data if required by law, but we can only ever disclose what we hold, which for your key, your vouchers and your records is nothing.
7. International transfers
Our infrastructure is operated in the UK and the European Economic Area where possible. Where a provider processes data outside the UK, we rely on UK adequacy regulations or the International Data Transfer Addendum to the standard contractual clauses.
8. How long we keep things
- Encrypted events — retained on the relay only as long as needed for delivery and resynchronisation, then subject to routine expiry.
- Server logs and connection metadata — typically 30 days, longer only where needed to investigate an incident.
- Email and onboarding records — for the life of the relationship and then up to six years, where needed for our own legal and accounting records.
- Public profile data — published on the network and, being public and replicated, not something we can guarantee to delete everywhere.
9. Your rights
Under UK GDPR you may ask for access to your personal data, correction of it, erasure, restriction of processing, portability, and you may object to processing based on our legitimate interests. Where we rely on consent you may withdraw it at any time.
Write to hello@imani.casa and we will respond within one month. Be aware of two real limits:
- We cannot give you data we do not have. We cannot produce your vouchers, your history or your key, because we never held them.
- Data published to a public network, such as a shop profile, is copied by others. We can stop publishing it from our infrastructure but cannot recall it from everywhere.
You can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you came to us first.
10. Children
Imani is not intended for children under 16. We do not knowingly handle their data. If you believe a child has registered, tell us and we will act.
11. Security
Encryption is done on your device with keys you hold. Traffic to our servers uses TLS. Access to our infrastructure is limited to those who need it. The strongest security property here is structural rather than procedural: there is no central store of who holds what, so there is no single database worth breaching.
The counterpart is your responsibility. Keep your backup key and passphrase private and offline. We will never ask you for either, and any message that does is not from us.
12. Changes to this policy
We will update this policy as the service changes. The version and date at the top will change, and we will notify material changes in the wallet or by email.