1. Purpose And Scope
This Privacy Policy explains how ReturnHaven collects, uses, shares, protects, and retains personal data when you use the Service. It applies to account holders, people described in posts, claimants, finders, institution representatives, support contacts, and visitors to ReturnHaven services.
ReturnHaven is intended primarily to help people recover lost property and share legitimate missing-person information. Some content is public by design, while claims, evidence, contact details, chats, moderation records, and identity information have more restricted access.
2. Who Is Responsible
HINDA TECH LTD (RC 7924553) is the data controller for the processing described here unless a separate notice says otherwise. Institutions using ReturnHaven may also be independent controllers for information they collect or use for their own purposes.
Use hindatech01@gmail.com for questions about this Policy or a privacy request. The final notice must provide a channel that is monitored and usable without requiring access to a closed account.
3. Data We Collect
Depending on how you use ReturnHaven, we may process:
Account And Profile Data
- name, username, email address, password hash, and email-verification status
- phone number, country, state, local government area, address, and profile image
- account status, preferences, acceptance version, and acceptance timestamp
- provider identifier and provider email for enabled social sign-in services
We verify provider credentials during social login but do not intentionally store the Google, Apple, or Facebook sign-in token submitted for verification.
Posts And Recovery Data
- lost/found case type, category, name, description, dates, approximate location, images, and hidden proof guidance
- missing-person name, age group, last-seen information, image, and other details supplied by a poster
- claims, sightings, recovery leads, private messages, evidence, decisions, contact-release events, blocks, and handover confirmations
- institution or community-partner involvement
Trust, Safety, And Identity Data
- reports, reason codes, appeal information, moderation decisions, audit history, and account or capability restrictions
- KYC submission details and evidence only if a verification flow is enabled in a later release; KYC is not required in the current public flow
- records needed to investigate fraud, disputes, security issues, or misuse
Communications And Device Data
- chat messages and attachments
- support communications and service feedback
- notification preferences, in-app notifications, device identifier, platform, and Firebase Cloud Messaging token
- email and push delivery status or failure information
Technical Data
- request identifier, route template, method, response status, duration, and security or operational events
- IP address and similar connection information where captured by hosting, security, throttling, or infrastructure systems
- app version, device, crash, and diagnostic information when the applicable tooling is enabled and disclosed
Our application request logs do not intentionally record request bodies, query strings, authentication tokens, email addresses, phone numbers, or concrete URL parameters. Other infrastructure providers may maintain limited access and security logs under their configured policies.
4. Information About Other People
You may submit information about another person only when you have a lawful and legitimate reason. This is especially important for missing-person posts, children, vulnerable persons, identity documents, images, and contact details.
Use the minimum detail necessary for identification and safety. Where reasonably possible, tell the person, parent, guardian, family, or responsible authority about the post. Do not use ReturnHaven to expose, track, harass, or locate someone for an unlawful purpose.
If you are described in a ReturnHaven post and want it reviewed, contact hindatech01@gmail.com and provide enough information to locate the content and assess the request safely.
5. Why We Use Personal Data
We use personal data to:
- create, secure, and authenticate accounts
- provide posting, discovery, alert, claim, recovery, chat, institution, and handover functions
- deliver essential and optional communications according to applicable choices
- verify identities or organizations where the feature requires it
- prevent fraud, abuse, unsafe contact, unauthorized access, and service attacks
- moderate content, investigate reports, resolve disputes, and hear appeals
- maintain, troubleshoot, measure, and improve service reliability and relevance
- comply with law, legal process, and enforceable regulatory requests
- establish, exercise, or defend legal claims
Depending on the context, our lawful basis may include performing our contract with you, complying with a legal obligation, protecting vital interests, obtaining consent, or pursuing legitimate interests such as service security, fraud prevention, recovery coordination, and product improvement. We will use consent where applicable law requires it and allow withdrawal without affecting processing that was lawful before withdrawal.
6. Public And Restricted Information
Information shown on a public case may be available to anyone and may be copied or reshared outside ReturnHaven. Public visibility is limited by product rules but cannot prevent another person from taking a screenshot.
A limited profile summary may be shown to authenticated users through user-discovery features. This summary may include a username, display name, state, local government area, and profile image. It does not include the account email address, phone number, or street address.
The following should remain restricted to eligible users, participants, or authorized staff according to the relevant workflow:
- private proof answers and claim evidence
- recovery-lead evidence and private notes
- exact handover details released after acceptance
- chats and attachments
- KYC materials
- report identities and internal moderation notes
- raw storage identifiers, provider credentials, and authentication secrets
ReturnHaven may disclose restricted information where reasonably necessary for safety, fraud review, dispute handling, legal obligations, or protection of rights.
7. Automated Signals And Human Review
ReturnHaven may use search ranking, watch-alert rules, duplicate prevention, rate limits, report thresholds, and safety signals to recommend content or temporarily restrict activity or visibility. Reports are signals, not proof.
Important moderation, restriction, and appeal decisions may involve authorized human review. Contact hindatech01@gmail.com if you believe a decision was made incorrectly. ReturnHaven does not currently use biometric or facial-recognition processing. We will update this Policy and complete the required assessment and safeguards before introducing such processing.
8. Sharing And Service Providers
We may share the minimum necessary data with:
- other users and the public according to the visibility of the feature
- institutions or community partners involved in a case or handover
- cloud hosting, database, and storage providers
- email and push-notification providers
- an authentication provider when you choose social sign-in
- professional advisers, auditors, insurers, or security responders
- courts, regulators, law enforcement, emergency services, or other authorities when required by law or reasonably necessary to protect safety and rights
- a successor in a merger, financing, reorganization, or sale, subject to appropriate confidentiality and legal safeguards
We do not sell personal data. We do not enable third parties to use private claim, KYC, chat, or missing-person data for their independent advertising.
You may contact us for information about service providers involved in processing your personal data.
9. International Transfers
Some service providers may process data outside Nigeria. Where personal data is transferred internationally, we take steps required by applicable data-protection law to protect it.
10. Retention And Deletion
We retain data only as long as reasonably needed for the purposes described, subject to safety, dispute, legal, security, and backup requirements.
Our current retention approach includes:
| Data | Retention direction |
|---|---|
| Active item posts and images | While active and needed for discovery/recovery |
| User-deleted item images | Scheduled for purge after 30 days by default |
| Safety hold on deleted item images | May delay purge for an active claim, dispute, report, appeal, or moderation review; ordinary application holds are capped at 90 days by default |
| Deleted item text | Removed from normal reads immediately and scrubbed when the purge process completes |
| Claims and recovery evidence | Restricted and retained while needed for the workflow, dispute, safety, audit, or legal obligations |
| Chats and attachments | Retained while needed for participant communication, safety, support, disputes, or legal obligations |
| KYC data | Not collected by the current public flow |
| Account and acceptance records | While the account is active and for a limited closure, security, legal, and audit period |
| Moderation and appeal records | Restricted retention for safety, consistency, legal claims, and abuse prevention |
| Notification and device records | Until no longer needed for delivery, user history, security, or troubleshooting |
| Request and security logs | Retained for a limited period needed for operations, security, and incident investigation |
| Backups | Removed through the ordinary protected backup-expiry cycle |
Deleting a post removes it from public and normal account views immediately but does not always mean immediate physical deletion from primary storage or backups. Withdrawal is different: it hides a post but is intended to remain reversible.
Closing an account immediately deactivates authentication and push devices and removes the profile and personal posts from normal public APIs. Account closure does not itself cascade-delete chats, claims, recovery evidence, moderation records, legal acceptance history, or backups. Those records remain restricted and follow the applicable retention and privacy-request decision.
11. Your Rights And Choices
Subject to applicable law and permitted exceptions, you may have rights to:
- receive information about our processing
- access your personal data
- correct inaccurate or incomplete data
- request deletion
- restrict or object to certain processing
- withdraw consent where consent is the basis
- receive portable data where applicable
- complain to the Nigeria Data Protection Commission or another competent body
- seek review of certain decisions affecting you
You can manage available notification preferences in the Service. Essential security, account, moderation, and recovery messages may still be sent while needed to provide or protect the Service.
Submit a rights request to hindatech01@gmail.com. We may verify your identity and authority before acting, especially when a request concerns a missing person, child, claimant, institution, or disputed property. We may retain limited evidence that a request was completed.
12. Children And Vulnerable Persons
ReturnHaven may process information about a child or vulnerable person when a legitimate missing-person or safety notice is submitted. Such posts should use the minimum necessary data and receive heightened privacy and moderation care.
ReturnHaven does not currently provide biometric face matching. Accounts are available only to people aged 18 or older. An adult may submit a legitimate missing-person or safety notice concerning a child, subject to the safeguards in this Policy and the Community Guidelines.
13. Security And Breaches
We use organizational and technical measures intended to protect data, including access controls, authenticated private workflows, restricted evidence, signed storage access, password hashing, token validation, moderation records, and operational monitoring. No service can guarantee absolute security.
If a breach creates a legally reportable risk, we will follow applicable notification and remediation requirements. Report suspected unauthorized access to hindatech01@gmail.com.
14. Policy Changes
We may update this Policy as the Service, providers, law, or data practices change. We will publish the version and effective date and provide appropriate notice of material changes. If a new use requires consent, we will request it rather than relying only on an updated page.
15. Contact And Complaints
Controller: HINDA TECH LTD Privacy and safety contact: hindatech01@gmail.com
You may also contact the Nigeria Data Protection Commission through its official channels at https://ndpc.gov.ng/ if you believe your data-protection rights have been infringed.
