Privacy policy
In effect from 31 July 2026.
This describes what Uniland collects, why, who else sees it and how to get rid of it. It is written to be read rather than to be defensible, so where something is uncomfortable (we ask for a photograph of your student ID; we keep payment records after you leave), it says so plainly.
Uniland is operated by WIRED INTELLIGENCE LTD, company number CS171992020, of Dansoman Sahara Down, Accra, Ghana. We are the data controller for the information described here, and we process it under the Data Protection Act, 2012 (Act 843).
What we collect
Your account
Your name, username, email address and password. The password is stored only as an Argon2 hash. We cannot read it, and neither can anyone who obtains the database. Optionally: a profile photo, a cover image, a short bio and a phone number.
Your campus
Your university, and if you tell us: faculty, department, hall of residence, level of study and interests. This is what puts you in the right communities and the right feed; a Uniland account with no campus attached shows you nothing useful.
Student verification
To sell on the marketplace, host an event or upload notes, you have to be a verified student. There are two ways to prove it, and they collect different things:
- A university email address. We send a link to it and record that it was confirmed. This is the route we prefer, because it collects the least.
- A photograph of your student ID. If your university does not issue student addresses, we accept a photo of your ID card and your student ID number. A moderator looks at it, approves or rejects it, and the image is stored in our object storage. It is deleted along with everything else when you delete your account, including if you started verification and never finished.
What you post
Posts, comments, reactions, poll votes, marketplace listings, hostel adverts, roommate requests, job posts and applications, lecture notes, and ratings and reviews of businesses, food vendors and accommodation. Also who you follow and who you have blocked.
If you attach a location to a post, an event or a listing, we store the coordinates you chose. We do not read your device’s location in the background, and the apps do not request location permission at all.
Tickets and payments
Orders, tickets, amounts and a reference from our payment provider. We never see your card number or your mobile money PIN. Payment details are entered on Paystack’s own hosted page and never reach our servers.
How the app is used
We record what parts of Uniland get used, so we can tell what is worth building and what is quietly broken. This is ours, it stays on our servers, and you can turn it off in Settings → Privacy. The switch is enforced on our side, not just in the app, so nothing is written for an account that has turned it off.
- Which screens you open, and roughly how long you spend on one.
- Which post, event, listing, note, community, business, hostel or food vendor you opened, and what you did with it: liking, saving, sharing, commenting, RSVPing, downloading, following, or starting a message.
- How far you get through a document in the reader, rounded to the nearest tenth so it is “how far people get” rather than a trace of your reading.
- Where people give up on signing up, getting verified, buying a ticket or writing a first post, which is the only way we find out that a step is broken.
- What you search for, with how many results came back, so we can see what students look for and do not find. Lower-cased and kept short so it groups together rather than identifies you.
Some of this is recorded before you have an account, because the sign-up itself is the part we most need to see failing. Those events are grouped by a random identifier that changes when you close the app and after half an hour of not using it; it is not a device id and it is not used to recognise you later. Everything here is deleted after a year, and everything attached to your account goes when your account does.
Technical information
- The IP address and browser or device description of each sign-in, kept with the session so you can see where you are signed in and end sessions you do not recognise.
- A push notification token per device, if you allow notifications.
- Search terms you type, so your recent searches are there next time.
- Error reports when something breaks, with identifying fields (authorisation headers, email addresses, phone numbers, ticket QR payloads) stripped before they leave our servers.
What we don’t do
Stated as plainly as the rest, because these are the questions people actually have.
- We do not sell your data. There is no arrangement under which anyone pays us for it.
- We do not run advertising, and there is no third-party tracking in the site or the apps. No Google Analytics, no Meta pixel, no attribution SDK. The usage data described above is our own, goes nowhere else, and can be switched off.
- We do not track you across other apps or websites, and we never ask permission to.
- We do not use tracking cookies. The website keeps your sign-in token in your browser’s local storage, which is what keeps you signed in and nothing else. That is why there is no cookie banner: there is nothing to consent to.
- Your university does not get an account, a dashboard, or a report on what you post.
Who else sees it
Other students see what you choose to publish: your profile, your posts, your listings, and your name on a guest list if the host has made it public. Everything else goes only to the companies below, each of which does one job and is contractually limited to it.
- Paystack: card and mobile money payments. They receive your email address and the amount. Ghana and Nigeria.
- Expo, Apple and Google: delivering push notifications to your device. They receive the notification text and your device token.
- Our object storage and hosting providers: where uploads and the database physically live.
- Our email provider: sending you sign-in links, ticket confirmations and refund notices.
- Sentry: error reports, with personal fields redacted before sending.
We will also disclose information where the law requires it, or where it is necessary to investigate a credible threat to someone’s safety. If we ever receive a request from a university or a law enforcement body, we will tell you unless we are legally prohibited from doing so.
Where it is kept
Our servers and object storage may be located outside Ghana. Where information leaves the country we rely on contractual safeguards with the provider concerned, as the Data Protection Act, 2012 (Act 843) requires.
How long we keep it
- Your account and content: until you delete your account.
- Sessions: until they expire or you end them.
- Ticket and payment records: retained after account deletion, because tax and accounting law requires records of money changing hands. They are detached from your name.
- Moderation records: retained after account deletion, so that a ban cannot be undone by deleting the account and signing up again.
- Usage data: one year, deleted automatically. Anything recorded while you were signed in goes when your account does, and does not wait for the year.
- Your recent searches: ninety days, or until you clear them.
- Posts, comments and messages other people took part in: the row survives so the conversation keeps its shape, but your words are erased and replaced with “[deleted]” and your name is removed.
Your rights
Under the Data Protection Act, 2012 (Act 843) you have the right to know what we hold, to correct it, to have it deleted, to object to how we use it, and to complain.
- See and correct it: most of it is on your profile and settings screens, editable directly.
- Delete it: Settings → Account, in the app or on the web. It is immediate and permanent. Full details of what deletion does.
- Get a copy: email privacy@blacheinc.com and we will send you your data within 30 days.
- Complain: to us at privacy@blacheinc.com, or directly to the Data Protection Commission, Ghana, which you can do without going through us first.
Security
Passwords are hashed with Argon2id. Traffic is encrypted in transit. Sessions can be revoked individually or everywhere at once, and changing your password ends every other session automatically. Content is partitioned by campus, and a request for another university’s data is refused rather than filtered. Ticket QR codes are signed so a screenshot of one cannot be altered.
No system is perfect. If we discover a breach affecting your data we will tell you and the Data Protection Commission, Ghana, and we will tell you what actually happened rather than the smallest true thing we can say.
Age
You must be at least 16 to hold a Uniland account. Uniland is built for university students, and we do not knowingly collect information from children. If you believe a child has an account, email privacy@blacheinc.com and we will remove it.
Changes
If we change this policy in a way that affects you, we will tell you in the app before it takes effect, not by quietly updating a date at the top of this page. Past versions are available on request.
Contact
Privacy questions and requests: privacy@blacheinc.com. Anything else: support@blacheinc.com.