At a glance
Iwange is a tool you use to run your business. Your shop’s data — items, sales, debts, customers — belongs to you. We collect what we need to make the product work, and we never sell it.
This policy explains, in plain language, what we collect, why we collect it, and the rights you have over it. It applies to anyone using Iwange (the web app, the installable PWA, and any companion product we publish).
1. What we collect
Account information
- Your name, email, phone number, shop name and location.
- Your role and the role you assign to your team members.
Business data you enter
- Items, categories, stock movements, sales, purchases, expenses, damaged stock, suppliers, clients and debt records.
- Receipts and notes you attach to those records.
Technical data
- Device type and browser, IP address (for security and abuse prevention), session identifiers and crash reports.
- Connection state and sync status, so offline-first works reliably.
We do not collect biometric data, government IDs, or your customers’ government IDs. If you store such data inside Iwange, please don’t.
2. Why we collect it
- To provide the service you signed up for — running your shop.
- To keep your account secure and detect abuse.
- To support you when you contact us with a question or issue.
- To improve the product, using aggregated, anonymised usage signals (e.g. “how often does Quick Sell crash on Android 8?”).
- To bill you correctly, only after a payment is made.
3. Where your data lives
Operational data is stored in MongoDB Atlas clusters located in the EU region. Daily encrypted backups are retained for 30 days. Each shop’s data is scoped by a unique tenant identifier — no other shop can access your records, ever.
On the device, Iwange keeps a local mirror of the data you have access to (IndexedDB) so the app works offline. That mirror is cleared on logout.
4. Security
- All traffic to and from the app is encrypted using HTTPS (TLS 1.2+).
- Passwords are hashed with bcrypt; we never store them in plain text and cannot recover them.
- Sign-in tokens expire after seven days and are tied to a single user.
- We log access events to a tamper-evident audit trail. Suspicious activity triggers automatic session invalidation.
- Production access is limited to a small number of engineers, all using multi-factor authentication.
6. Your rights
- Access: see everything we hold about your account from the Settings → Data export screen.
- Export: download all your business data as CSV at any time, for free.
- Correction: fix any record directly in the product or by emailing us.
- Deletion: request full account deletion. Data is held for 5 days as a safety window, then permanently destroyed.
- Portability: the export format is open and reusable in spreadsheets or another accounting tool.
Ufite uburenganzira bwo kureba, gukosora cyangwa gusiba amakuru yawe igihe icyo ari cyo cyose. Twandikire kuri support@iwange.com.
8. Children
Iwange is intended for businesses and adults responsible for them. We do not knowingly collect data from anyone under 16. If you believe a child has signed up, contact us and we will remove the account.
9. Changes to this policy
We may update this policy as the product evolves. Material changes are announced in the app and via email at least 14 days before they take effect. The “last updated” date at the top of this page always reflects the current version.
10. Contact us
- Email: support@iwange.com
- WhatsApp: +250 798 734 900
- Postal: Iwange Ltd, KG 9 Avenue, Kigali, Rwanda.
Version 1.0 — last updated January 1, 2025.