Privacy
Your information deserves care.
This policy explains what UmojaMatch collects, why we use it, who receives it, and the choices available to every member.
Last updated 6 August 2026
Who is responsible for your information
UmojaMatch is operated by MASED INC LTD, company number 15390144. We are the controller of the personal information described in this policy. Our registered address is Dalton House, 60 Windsor Road, Merton Abbey, London SW19 2RR, United Kingdom.
Privacy questions and rights requests may be sent to emeceo@masedinc.com.
Who may use UmojaMatch
UmojaMatch is for adults aged 18 and over. We do not knowingly permit children to create accounts. Please report an underage concern through the in-app reporting flow or our Safety page.
Information we collect
- Account information: email address, username, name, surname, age, authentication records, and account status.
- Profile and connection information: photos, city, country, heritage or community, languages, profession, education, family context, values, lifestyle, relationship intentions, sex, and connection preferences.
- Special category information you choose to provide: profile details may reveal racial or ethnic origin, religious or philosophical beliefs, or sexual orientation. We ask for explicit consent where required and use this information only for the member-facing purposes described when it is collected.
- Location information: device coordinates and related signals used privately to verify current location and reduce misrepresentation. Other members are shown a city or country, not precise coordinates.
- Member content and activity: interests, introductions, messages, reports, blocks, moderation decisions, and support communications.
- Photos and safety information: uploaded images, review status, and signals needed to detect unsafe, fraudulent, or prohibited activity.
- Device and network information: device integrity proofs, IP address, approximate network location, session information, and risk signals including possible proxy, VPN, Tor, hosting, or automated activity.
- Purchase information: product identifiers, store transaction identifiers, subscription status, Connection Credit grants and use, refunds, and revocations. We do not receive full payment-card details from Apple or Google.
- Website information: essential cookie, security, device, and request data when you visit our website.
Why we use information
- To create and secure accounts and provide the service requested by members.
- To curate introductions using member-selected preferences, values, culture, and relationship intentions.
- To display the public parts of a profile to eligible members.
- To verify age declarations, location, device integrity, purchases, and entitlement status.
- To review photos and messages, prevent abuse and fraud, investigate reports, enforce our Terms, and protect members.
- To respond to support, privacy, safety, legal, and regulatory requests.
- To operate, troubleshoot, and improve reliability without selling member information.
Our legal bases
Depending on the activity, we rely on performance of our contract with you, compliance with legal obligations, our legitimate interests in operating a safe and reliable service, and consent. Where UK or European law treats information as special category data, we rely on an applicable Article 9 condition, normally your explicit consent for the optional profile and connection purposes you select.
You may withdraw consent for future processing. Withdrawal does not affect processing already carried out lawfully and may make features that depend on that information unavailable.
Automated processing and curation
UmojaMatch uses rules and scoring to order potential connections based on profile readiness, mutual preferences, shared signals, safety boundaries, and compatibility factors. This curation helps members explore a considered set; it does not make a legal or similarly significant decision about you. Safety systems may automatically refuse a protected action when required identity, device, network, location, moderation, or payment-risk checks do not return a clear approval.
Who receives information
We disclose information only as needed to operate the service, comply with law, protect members, or complete a transaction. Recipients may include:
- Cloud hosting, database, file-storage, authentication, email, and security providers.
- Photo, text, bot, device-integrity, location, network-risk, and fraud-prevention providers.
- Apple and Google for app distribution, in-app purchases, transaction validation, refunds, and subscription management.
- Professional advisers, courts, regulators, or law enforcement when disclosure is legally required or necessary to protect people and the service.
- A buyer or successor if the business is reorganised, subject to appropriate confidentiality and data-protection safeguards.
We do not sell personal information. We do not permit service providers to use member information for their own advertising.
International transfers
Some providers may process information outside the United Kingdom. Where required, we use an adequacy regulation, approved contractual safeguards, or another lawful transfer mechanism, together with proportionate technical and organisational protections.
Retention and deletion
We keep information while an account is active and for as long as it is needed for the purposes above. Retention depends on the data type, safety need, transaction lifecycle, limitation period, and legal obligation. When an account is deleted, we delete or anonymise the profile, photos, conversations, and associated member data, except limited records that must be retained for legal obligations, financial accounting, dispute resolution, store transaction reconciliation, or proportionate fraud and safety protection.
You can delete your account from Settings in the app. You can also use our account deletion page if you no longer have access to the app.
Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, and to withdraw consent. Contact us using the email above. We may need to verify your identity before completing a request.
UK members may complain to the Information Commissioner's Office at ico.org.uk. You may also contact the data-protection authority where you live.
Security
We use access controls, encryption in transit, server-side transaction validation, device-integrity checks, moderation, logging, and other safeguards designed for the sensitivity of member information. No system can guarantee absolute security, so please use a unique password and report suspected account misuse promptly.
Changes to this policy
We may update this policy as the service, law, or providers change. We will publish the new date here and provide additional notice when a material change requires it.