Agrovio (“we”, “our”, or “us”) operates a digital marketplace connecting farmers, buyers, and logistics providers. This Privacy Policy explains how we collect, use, and protect your information when you use Agrovio.
1. Information We Collect
We may collect:
- Account information such as your name, email address, phone number, and login details
- Profile and location information including profile photo, role, approximate location and service area, and listings
- For logistics providers/drivers: where you enable delivery features, we process precise, real-time GPS location during active deliveries to provide tracking and coordination. This is collected only while a delivery is in progress.
- Marketplace activity such as orders, messages, delivery details, and uploaded images
- Technical information needed to secure and improve the platform
2. How We Use Information
We use your information to:
- Create and manage accounts
- Operate marketplace and delivery features
- Enable communication between users
- Process orders and logistics activities
- Improve platform security and performance
- Prevent fraud and abuse
- Comply with legal obligations
3. Sharing of Information
We may share information with trusted service providers that help operate Agrovio, including hosting, authentication, storage, messaging, and analytics services.
Certain marketplace information may be visible to other users where necessary, such as:
- listings
- delivery details
- seller profiles
- ratings and reviews
Some of these providers operate outside Zimbabwe, so certain data may be transferred across borders. In particular, document verification securely transmits your document to a third-party AI processor in the United States — see Section 5A. We do not sell personal information.
4. Data Retention
We retain information for as long as necessary to provide our services, comply with legal obligations, resolve disputes, and maintain platform security.
- Account and marketplace data: retained for the life of your account and deleted or anonymised within 30 days of a valid account-deletion request, except where an exception below applies.
- Order and transaction records: retained for up to 6 years to meet tax and legal record-keeping obligations.
- Verification documents: retained only while your verification/badge is active, and deleted within 90 days of account deletion, unless subject to a fraud hold below.
- Fraud-investigation records: where an account is flagged for fraud, a limited identity record may be retained for up to 24 months after account deletion (or as long as necessary to prevent repeat fraud and abuse), then deleted or anonymised.
Users may request account or data deletion, subject to the fraud-prevention and legal-retention exceptions above.
5. How We Protect Your Data
We use strong, industry-standard encryption and access controls:
- In transit: connections to Agrovio are encrypted using TLS (HTTPS).
- At rest: verification documents you upload are encrypted using AES-256 encryption. Each file is encrypted with its own key, and those keys are protected by a master key held securely on our servers.
- Access controls: stored data is access-restricted; in normal operation it is processed by automated systems and is not accessed manually in normal operation.
We use strong encryption, but Agrovio is not an “end-to-end encrypted” service. Because we operate document verification and must be able to investigate fraud, we can access your data for the limited, specific purposes described in this policy (verification, fraud prevention, and legal compliance). No online platform can guarantee complete security.
5A. Document Verification & Automated Processing
To earn certain trust badges or access certain features, you may upload identity or business documents (for example a national ID, passport, or business registration). These documents are checked by an automated AI verification system for authenticity, accuracy, and validity.
To perform this check, the contents of your document are transmitted securely (over TLS) to a third-party AI processor, Groq, Inc., which operates in the United States. This is a cross-border transfer of your personal and identity data outside Zimbabwe.
- What is shared: the document image and the details you declared (such as your name) for matching.
- Purpose: identity / business / trust verification.
- Lawful basis: your explicit consent, given when you submit documents for verification, together with the necessity of the transfer to provide the verification you requested. We notify Zimbabwe’s data-protection authority of cross-border transfers as required.
- Safeguard: secure (TLS) transmission; the document is never posted publicly or shown to other users. We maintain a data-processing agreement with our verification processor and use Zero Data Retention where available.
- Processor retention: Groq does not retain API inference data by default; limited operational logs may be held for a short period for error-troubleshooting or abuse-investigation only.
- Our retention: verification documents are retained as described in Section 4.
- Human review: verification is partly automated. If an automated check declines or affects your verification, you may request a manual review of that decision by contacting us at support@agrovio.online.
5B. When and How We May Access Your Data
- Normal operation: your data is encrypted and access is restricted to automated systems. It is not routinely browsed by our staff.
- Fraud, abuse, or policy violations: when fraud is reported or reasonably suspected, we may access relevant account data, verification documents, messages, and transaction records strictly to investigate, prevent, and act on the fraud.
- Limited and logged: such access is limited to what is necessary for the investigation, requires authorization, and is logged.
- Legal disclosure: we may disclose data to law enforcement or regulators where legally required, or to protect users and the platform from harm.
Lawful basis: we rely on fraud prevention and platform security as a legitimate interest, and on compliance with our legal obligations, under Zimbabwe’s Cyber and Data Protection Act.
5C. Data Breach Notification
If we become aware of a personal-data breach that affects your information, we will notify Zimbabwe’s data-protection authority (POTRAZ) within 24 hours of becoming aware of it, as required by law, and will inform affected users where the breach is likely to present a risk to their rights.
6. Your Rights
Depending on your location, you may have the right to:
- access your data
- correct inaccurate information
- request deletion (subject to fraud-prevention and legal-retention exceptions)
- restrict certain processing activities
- complain to Zimbabwe’s data-protection authority, the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ)
We aim to respond to verified data-subject requests within 30 days.
You may contact us regarding any privacy-related requests.
7. Children's Privacy
Agrovio is intended for users aged 18 and over. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected such information, we will delete it.
8. Facebook / Meta Data Deletion
If you signed in using Facebook Login, you may request deletion of your data by removing Agrovio from your Facebook Apps settings or by contacting us directly.
Agrovio supports Meta data deletion requirements and processes deletion requests securely. See Delete Your Data for step-by-step instructions.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Updated versions will be posted on this page with a revised “Last updated” date.
10. Contact
For privacy-related requests or questions, contact:
Email: support@agrovio.online
We currently accept privacy requests by email only.