Privacy policy

In effect from 31 July 2026.

This describes what Uniland collects, why, who else sees it and how to get rid of it. It is written to be read rather than to be defensible, so where something is uncomfortable (we ask for a photograph of your student ID; we keep payment records after you leave), it says so plainly.

Uniland is operated by WIRED INTELLIGENCE LTD, company number CS171992020, of Dansoman Sahara Down, Accra, Ghana. We are the data controller for the information described here, and we process it under the Data Protection Act, 2012 (Act 843).

What we collect

Your account

Your name, username, email address and password. The password is stored only as an Argon2 hash. We cannot read it, and neither can anyone who obtains the database. Optionally: a profile photo, a cover image, a short bio and a phone number.

Your campus

Your university, and if you tell us: faculty, department, hall of residence, level of study and interests. This is what puts you in the right communities and the right feed; a Uniland account with no campus attached shows you nothing useful.

Student verification

To sell on the marketplace, host an event or upload notes, you have to be a verified student. There are two ways to prove it, and they collect different things:

  • A university email address. We send a link to it and record that it was confirmed. This is the route we prefer, because it collects the least.
  • A photograph of your student ID. If your university does not issue student addresses, we accept a photo of your ID card and your student ID number. A moderator looks at it, approves or rejects it, and the image is stored in our object storage. It is deleted along with everything else when you delete your account, including if you started verification and never finished.

What you post

Posts, comments, reactions, poll votes, marketplace listings, hostel adverts, roommate requests, job posts and applications, lecture notes, and ratings and reviews of businesses, food vendors and accommodation. Also who you follow and who you have blocked.

If you attach a location to a post, an event or a listing, we store the coordinates you chose. We do not read your device’s location in the background, and the apps do not request location permission at all.

Tickets and payments

Orders, tickets, amounts and a reference from our payment provider. We never see your card number or your mobile money PIN. Payment details are entered on Paystack’s own hosted page and never reach our servers.

Technical information

  • The IP address and browser or device description of each sign-in, kept with the session so you can see where you are signed in and end sessions you do not recognise.
  • A push notification token per device, if you allow notifications.
  • Search terms you type, so your recent searches are there next time.
  • Error reports when something breaks, with identifying fields (authorisation headers, email addresses, phone numbers, ticket QR payloads) stripped before they leave our servers.

What we don’t do

Stated as plainly as the rest, because these are the questions people actually have.

  • We do not sell your data. There is no arrangement under which anyone pays us for it.
  • We do not run advertising, and there are no advertising or analytics trackers in the site or the apps. No Google Analytics, no Meta pixel, no attribution SDK.
  • We do not track you across other apps or websites, and we never ask permission to.
  • We do not use tracking cookies. The website keeps your sign-in token in your browser’s local storage, which is what keeps you signed in and nothing else. That is why there is no cookie banner: there is nothing to consent to.
  • Your university does not get an account, a dashboard, or a report on what you post.

Who else sees it

Other students see what you choose to publish: your profile, your posts, your listings, and your name on a guest list if the host has made it public. Everything else goes only to the companies below, each of which does one job and is contractually limited to it.

  • Paystack: card and mobile money payments. They receive your email address and the amount. Ghana and Nigeria.
  • Expo, Apple and Google: delivering push notifications to your device. They receive the notification text and your device token.
  • Our object storage and hosting providers: where uploads and the database physically live.
  • Our email provider: sending you sign-in links, ticket confirmations and refund notices.
  • Sentry: error reports, with personal fields redacted before sending.

We will also disclose information where the law requires it, or where it is necessary to investigate a credible threat to someone’s safety. If we ever receive a request from a university or a law enforcement body, we will tell you unless we are legally prohibited from doing so.

Where it is kept

Our servers and object storage may be located outside Ghana. Where information leaves the country we rely on contractual safeguards with the provider concerned, as the Data Protection Act, 2012 (Act 843) requires.

How long we keep it

  • Your account and content: until you delete your account.
  • Sessions: until they expire or you end them.
  • Ticket and payment records: retained after account deletion, because tax and accounting law requires records of money changing hands. They are detached from your name.
  • Moderation records: retained after account deletion, so that a ban cannot be undone by deleting the account and signing up again.
  • Posts and comments other people replied to: the row survives so the conversation keeps its shape, but your words are erased and replaced with “[deleted]” and your name is removed.

Your rights

Under the Data Protection Act, 2012 (Act 843) you have the right to know what we hold, to correct it, to have it deleted, to object to how we use it, and to complain.

  • See and correct it: most of it is on your profile and settings screens, editable directly.
  • Delete it: Settings → Account, in the app or on the web. It is immediate and permanent. Full details of what deletion does.
  • Get a copy: email privacy@blacheinc.com and we will send you your data within 30 days.
  • Complain: to us at privacy@blacheinc.com, or directly to the Data Protection Commission, Ghana, which you can do without going through us first.

Security

Passwords are hashed with Argon2id. Traffic is encrypted in transit. Sessions can be revoked individually or everywhere at once, and changing your password ends every other session automatically. Content is partitioned by campus, and a request for another university’s data is refused rather than filtered. Ticket QR codes are signed so a screenshot of one cannot be altered.

No system is perfect. If we discover a breach affecting your data we will tell you and the Data Protection Commission, Ghana, and we will tell you what actually happened rather than the smallest true thing we can say.

Age

You must be at least 16 to hold a Uniland account. Uniland is built for university students, and we do not knowingly collect information from children. If you believe a child has an account, email privacy@blacheinc.com and we will remove it.

Changes

If we change this policy in a way that affects you, we will tell you in the app before it takes effect, not by quietly updating a date at the top of this page. Past versions are available on request.

Contact

Privacy questions and requests: privacy@blacheinc.com. Anything else: support@blacheinc.com.