← Back to Howziiit
Privacy Policy
Last updated: 22 May 2026
Howziiit ("we", "us", "our") respects your privacy and is committed to protecting your personal data. This policy explains what data we collect, how we use it, and your rights under the UK GDPR.
1. Who we are
Howziiit is a dating app for South Africans living abroad, currently operating in the United Kingdom. If you have questions about this policy, contact us at [email protected].
2. Data we collect
Account data
- Email address or phone number (used for sign-in via OTP)
- Display name, date of birth, gender
- City, province of origin, rugby team, years abroad, bio, height
- Lifestyle and preference fields you provide (drinking, smoking, religion, cultural background, etc.)
Content you provide
- Photos you upload
- Profile prompt answers
- Messages you send to matches
- Reports you submit about other users
Technical data
- GPS location (used to verify you are in the UK)
- Device type and platform
- Push notification token
- App usage and error logs
3. How we use your data
- To operate the app, match you with other users, and deliver messages
- To enforce our community guidelines (anti-bot, anti-fraud, abuse prevention)
- To process subscriptions and one-time purchases via Stripe
- To send push notifications you opt in to receive
- To comply with legal obligations
4. Legal basis for processing
We process your data based on:
- Contract — to provide the service you signed up for
- Consent — for optional features like push notifications and marketing emails
- Legitimate interest — fraud prevention, security, abuse moderation
- Legal obligation — when required by law
5. Who we share data with
- Stripe — for payment processing (we never see your card details)
- Resend — for sending OTP and account emails
- Expo — for push notification delivery
- Cloudflare — DNS, CDN, and DDoS protection for our website
- Hetzner Online GmbH — hosts our database and application (located in Germany)
We do not sell your data. We do not share your profile with advertisers.
6. Data retention
We keep your data for as long as your account is active. When you delete your account, we erase your personal data within 30 days, except where we are legally required to retain certain records (e.g. financial records for HMRC).
7. Your rights under UK GDPR
- Access your data (in-app: Settings → Export my data)
- Correct your data (Edit Profile)
- Delete your data (Settings → Delete account)
- Restrict or object to processing
- Data portability
- Lodge a complaint with the Information Commissioner's Office (ico.org.uk)
8. Children's data
Howziiit is strictly for users aged 18 and over. If we learn we have collected data from anyone under 18, we will delete it immediately.
9. International transfers
Our servers are in the EU. Some service providers (Stripe, Expo) may transfer data to the US under Standard Contractual Clauses or the EU-US Data Privacy Framework.
10. Security
We use industry-standard security: HTTPS everywhere, hashed passwords (where applicable), encrypted secrets, rate limiting, JWT-based session tokens, and security headers (HSTS, X-Frame-Options, etc.). No system is 100% secure, but we work hard to protect you.
11. Cookies
The Howziiit website uses essential cookies for security and session management. The mobile app does not use cookies.
12. Changes to this policy
We may update this policy from time to time. We will notify you of material changes via the app or email.
13. Contact
For any privacy questions, email [email protected].