Privacy Policy
Last updated: 18 May 2026
ZimLayby is a layby (lay-by) platform operating in Zimbabwe. We're owned and operated by Layby Africa. This policy explains what information we collect from you, how we use it, who we share it with, and the rights you have over your data. We've tried to write it in plain English instead of legalese.
1. Who runs this
ZimLayby is operated by Layby Africa. Individual shops on our platform (for example, Appliance & Home and Sofa & Couch Centre) are independent retailers ("tenants") who use our platform to run their layby operations. When you apply for a layby at one of these shops, both the shop and ZimLayby process your information together. The shop is the seller; ZimLayby provides the technology, accounts, and messaging infrastructure.
2. Information we collect
We only collect what's necessary to run a layby agreement and stay in touch with you about it.
You give us directly
- Identity: your full name and Zimbabwean National ID number (for verification)
- Contact: your phone number (WhatsApp), email address, and residential address
- Next of kin (optional): name, phone, and relationship of someone we can contact if we can't reach you
- Order details: the items you've selected, the payment plan you've chosen, and any notes you send us
- Payments: proof of payment you send us (e.g. EcoCash transaction references, bank transfer screenshots)
- Signature: your typed signature on the layby agreement
We collect automatically
- Usage data: when you log into your customer portal, when you view your layby balance, when you click payment links
- Device info: your IP address, browser type, and operating system (used for security)
- Cookies: a session cookie that keeps you logged into your portal. We don't use third-party tracking or advertising cookies on our customer-facing pages.
3. How we use your information
- To run your layby: processing your application, sending you reminders, recording payments, generating receipts and statements, holding inventory aside in your name
- To verify you: matching your ID against your details, contacting your next of kin if we can't reach you
- To communicate with you: WhatsApp and SMS messages about your layby (due dates, payment confirmations, status changes). These are transactional messages, not marketing.
- To improve the service: understanding which products customers layby, which payment schedules they choose, where they get stuck
- To meet legal obligations: tax records, anti-money-laundering checks, fraud prevention
4. Who we share with
We don't sell your data to anyone. We share it only with parties that help us run the service:
- The shop you've laybyed with (e.g. Appliance & Home). They need to know your details to reserve your items, process payments, and contact you.
- Meta / WhatsApp Business Cloud API — to send you WhatsApp messages. Meta processes your phone number and message content as a data processor on our behalf.
- Twilio — to send you SMS messages when WhatsApp isn't available.
- Email providers — to deliver receipt and statement emails to your inbox.
- Cloud hosting (Fly.io, Cloudflare) — our servers are operated by these providers under standard data-processing agreements.
- Zimbabwean authorities — if compelled by law (e.g. court order, ZIMRA request, police investigation).
We never share your information with advertisers or data brokers.
5. How long we keep it
- Active layby data: for the lifetime of your layby plus the receipt period
- Financial records (payments, agreements, receipts): 7 years, as required by Zimbabwe's Income Tax Act for businesses
- Account data (name, phone, email, address): as long as you have an active account with us, plus 7 years after your last layby
- Logs (login attempts, IP addresses): typically 90 days unless flagged for security review
6. Your rights
You have the right to:
- Access the information we hold about you
- Correct any inaccurate information (you can update most details from your customer portal at zimlayby.com/me)
- Delete your account data — see our Data Deletion page for how to request this. Note: financial records that we're legally required to keep cannot be deleted before the 7-year retention period.
- Object to specific uses of your data
- Receive a copy of your data in a portable format
To exercise any of these rights, email us at privacy@zimlayby.com. We aim to respond within 30 days.
7. Security
We protect your information with HTTPS encryption in transit, hashed PINs (we never store your PIN in plain text), brute-force protection on login, and access controls so only the staff of your specific shop can see your details. No system is 100% secure, but we take reasonable steps and respond promptly to any security incident.
8. Children
Our service is for people aged 18 and over. We don't knowingly collect information from anyone under 18. If you believe we have, contact us and we'll delete it.
9. Changes to this policy
If we make significant changes to this policy, we'll let you know through your customer portal or by message before the change takes effect. The "Last updated" date at the top will always reflect the current version.
10. Cross-border data transfers
Some of our service providers (Meta, Twilio, Cloudflare, Fly.io) process data outside Zimbabwe — primarily in the United States and Europe. These providers have their own privacy commitments and are bound by data-processing agreements with us.
Contact us about your privacy
Email: privacy@zimlayby.com
WhatsApp: +263 78 499 9995
Post: Layby Africa, Harare, Zimbabwe