Last updated 8 October 2026
privacy policy
What personal information ZimFun collects, why, who sees it, and the choices you have.
1. Who is responsible
Bh3 Techs is responsible for the personal information processed by the ZimFun platform. Organisers who receive your booking details are separately responsible for how they use them to run your Event. We process personal information in line with the Cyber and Data Protection Act [Chapter 12:07].
2. What we collect
- Account and contact details: name, email, phone number, and a password (stored only as a one-way hash) — or your Google account name and email if you sign in with Google.
- Bookings: the Event, seats, package, extras, notes you add (such as dietary or medical needs you choose to share), booking status and check-in time.
- Payments: amounts, method, transaction or slip references, and proofs of payment you upload. For online payments, Paynow processes your mobile money or card details — we don't see or store card numbers or PINs.
- Reviews you write, shown with your first name only.
- Technical data: sign-in sessions and security logs (for example rate-limit counters, which store a one-way hash of IP addresses, not the address itself). Cookies: ones needed for sign-in and remembering guest bookings, plus one first-party analytics cookie holding a random id (no name or contact details) so we can count visits, searches and bookings. We don't use advertising cookies or share this with ad networks.
- Usage data: which events and locations were viewed, what was searched for (including search words) and how bookings progress — linked to your account only if you're signed in. We use it in aggregate to decide which trips, places and payment options to offer.
3. Why we use it
- To make, manage and confirm bookings, issue tickets and let Organisers check you in — this is necessary to provide the service you ask for.
- To process and record payments, prevent fraud (including fake proofs of payment) and keep the platform secure — our legitimate interest and legal obligations.
- To answer support requests and resolve disputes between guests and Organisers.
- To send booking messages. We'll only send marketing if you opt in, and you can opt out at any time.
5. Storage outside Zimbabwe
Our database and files are hosted in the European Union, which has data-protection law at least as protective as Zimbabwe's. Data is encrypted in transit, and payment-provider keys are additionally encrypted at rest.
6. How long we keep it
- Booking and payment records: 6 years after the Event, for accounting, tax and dispute purposes.
- Proofs of payment: 2 years after the Event, unless needed for an open dispute or fraud case.
- Accounts: until you ask us to close yours; we then delete or anonymise what we don't need to keep by law.
- Security logs: up to 12 months.
- Usage (analytics) data: 13 months, then deleted automatically.
7. Your rights
You can ask to see the personal information we hold about you, correct it, have it deleted where we don't need to keep it, object to or restrict certain uses, and withdraw consent you gave. Contact us using the details below; we'll respond within 30 days. You may also complain to the Data Protection Authority (POTRAZ).
8. Security
We use access controls so Organisers only see their own guests, encrypted connections, hashed passwords, signed tickets, private storage for proofs of payment, and audit logs of sensitive actions. No system is perfectly secure; if a breach affects you, we'll tell you and the Authority as the law requires.
9. Children
Accounts are for people aged 18 and over. A parent or guardian can book for children and provide the details needed for the Event.
10. Changes
We'll update this policy when our practices change and show the new date at the top. Significant changes will be highlighted to account holders.
Contact
Bh3 Techs, 3266 A Murisa Seke. Email hello@bh3techs.co.zw.