Privacy policy
Sabi is a private, invite-only network where members date, connect, hire and trade with escrow protection. That means we handle unusually sensitive information: who you are attracted to, who you talk to, where you are, what you buy and sell, and the identity documents that let us keep the network vetted. This policy explains, in plain language and in full detail, what we collect, why, who sees it, how long we keep it, and how you control it. We do not sell your personal data.
1. Who we are
Sabi ("Sabi", "we", "us") operates the Sabi members' network — the mobile and web applications, the marketplace and storefronts, the escrow service, messaging, Flips, Discover and all related services (together, the "Services"). Panaga Holdings, a company registered in France (registration no. 109 765 073), is the data controller for members worldwide unless a regional disclosure in section 17 says otherwise. For members in the European Economic Area and the United Kingdom, our appointed representatives and Data Protection Officer are reachable through the contact details in section 24. In Nigeria, our launch market, we process personal data in accordance with the Nigeria Data Protection Act 2023 and register with the Nigeria Data Protection Commission as required.
2. Scope of this policy
This policy applies to every member, applicant, visitor, buyer, seller and business account that interacts with the Services, including people who apply for membership and are not approved. It also covers non-members whose data reaches us — for example, someone a member refers by invite, a person named in a dispute, or a recipient of an order.
It does not cover third-party services you reach through Sabi (a seller's external website, a payment provider's own account portal, or a social platform you link). Those operate under their own policies.
3. Data we collect
3.1 Information you give us
- Application and account data: name, date of birth, email address, phone number, password credentials, city and country, referral or invite code, and the answers you give in the membership application (profession, industry, intent modes, what brings you to Sabi).
- Identity and vetting data: a government identity document (passport, national ID, driver's licence, or NIN/BVN reference where applicable), a live selfie or holding photo used for liveness and face-match checks, and the result of that check.
- Profile content: photos, bio, headline, education, links in bio, portfolio work, intent modes (Date, Connect, Transact) and any tags or preferences you set.
- Content you create: posts, carousels, Flips, statuses, notes, comments, reviews, ratings, saved items and messages — including drafts held on our servers and media you upload.
- Commerce data: listings, storefront details, product and service descriptions, prices, inventory, orders, delivery addresses, fulfilment notes, payout details and business registration details (for example CAC number, tax identification number, trading name).
- Support and safety data: reports, blocks, appeals, dispute submissions, evidence you upload and your correspondence with our concierge or support team.
3.2 Information we collect automatically
- Device and technical data: device model, operating system, app version, browser type, language, screen and viewport, time zone, network carrier, IP address and coarse geolocation derived from it, and device identifiers including advertising identifiers where permitted.
- Usage data: screens viewed, sessions, taps, swipes (including passes and likes on Discover), searches, filters, dwell time on posts and Flips, referral paths, feature usage and crash logs.
- Location data: city-level location inferred from your profile, IP address or the place you select on the globe; precise device location only if you grant that permission, and only while you use distance-based features.
- Connection graph: who you follow, match with, message, save, buy from, review or block — and the strength and recency of those interactions.
- Integrity signals: login times, authentication events, repeated failed attempts, duplicate-account signals, device fingerprints and fraud-risk scores used to keep the network invite-only and safe.
3.3 Information from third parties
- Identity verification and sanctions/PEP screening providers, who return a pass/fail result and the underlying check data.
- Payment processors and escrow partners, who confirm transaction status, chargebacks, refunds and payout state.
- The member who invited you (your invite code and the fact that you joined through them).
- Social or authentication providers you choose to link, limited to the fields you authorise (for example your name, email and avatar).
- Other members, when they report you, tag you, name you in a dispute, or send an order to you.
- Public sources and vendors used for fraud prevention, safety and anti-money-laundering obligations.
4. Where the data comes from
Every field above comes from one of four sources: you provide it; your device generates it as you use Sabi; another member or a counterparty provides it; or a verification, payment, safety or infrastructure partner returns it to us. We do not buy personal data from data brokers to build member profiles.
5. How we use your data
| Purpose | What it means in Sabi |
|---|---|
| Provide the Services | Create and run your account, render your feed, matches, inbox, storefront and orders, sync your settings and presence status. |
| Vet the network | Review applications, verify identity and liveness, detect duplicate or fake accounts, and decide admission to an invite-only community. |
| Match and recommend | Rank Discover profiles, feed posts, Flips, search results, marketplace listings and suggested members using your intents, location, activity and connection graph. |
| Enable commerce and escrow | Take payment into escrow, hold funds, release or refund them, calculate fees, handle disputes and pay out sellers. |
| Safety, integrity and moderation | Detect harassment, scams, spam, CSAM, fraud and prohibited goods; review reports; enforce our rules; support law enforcement where legally required. |
| Compliance | Meet KYC, anti-money-laundering, sanctions, consumer-protection, tax and record-keeping obligations in every market where we operate. |
| Communications | Send transactional messages (order, escrow, security, application status) and, where permitted, product news and marketing you can opt out of. |
| Improve and measure | Diagnose crashes, run A/B tests, measure feature performance and produce aggregated analytics that do not identify you. |
6. Legal bases for processing
Where the GDPR, UK GDPR, the Nigeria Data Protection Act or a comparable law applies, we rely on the following legal bases:
| Legal basis | Used for |
|---|---|
| Contract | Creating your account, delivering the feed and messaging, processing orders, operating escrow, paying out sellers. |
| Legitimate interests | Security and fraud prevention, network integrity, product improvement, recommendation quality, and direct marketing to existing members — balanced against your rights. |
| Consent | Precise location, optional marketing, non-essential cookies, linking social accounts, and any processing of sensitive data such as dating preferences or biometric face-match. |
| Legal obligation | Identity and AML checks, tax and transaction records, responses to lawful requests, and mandated reporting. |
| Vital interests | Rare cases involving a credible risk to someone's life or physical safety. |
Where we rely on consent, you can withdraw it at any time in Settings or by contacting us; withdrawal does not affect processing already carried out.
7. Sensitive and special category data
Because Sabi includes dating, some of what you share can reveal sensitive information — for example your sexual orientation implied by who you choose to see or match with, or health, religion or ethnicity if you mention them in a profile, post or message. The face-match step in verification uses biometric data.
- We process dating-related preferences only to operate Discover and matching, on your explicit consent given during onboarding.
- Biometric templates generated during verification are used only for the one-time face-match, are not used to identify you elsewhere, and are deleted by our verification partner within 30 days of a completed check unless a fraud investigation requires a longer hold.
- We never use sensitive data for advertising or to infer categories for marketing.
- Anything sensitive you voluntarily publish in a public post, profile or Flip is visible to other members — please share deliberately.
8. Identity verification and vetting
Membership is reviewed. When you apply, we collect your application answers, an identity document and a live holding photo, and we send them to a specialist verification provider that checks the document's authenticity, matches the face to the document, screens against sanctions and politically-exposed-person lists where required, and returns a result. Our reviewers see the result, your application answers and, where a manual review is needed, the submitted images.
- Approved: we keep the verification result, document type, issuing country, document expiry and check reference. Full document images are deleted from our systems after the check completes, subject to regulatory retention where AML rules require the record.
- Declined or withdrawn: we retain a minimal record (hashed identifiers, decision, date, reason code) to prevent re-application abuse, and delete the rest.
- We do not publish your verification status as a badge, and we do not share your documents with other members — ever.
9. Payments, escrow and financial data
Payments are handled by regulated payment processors and escrow partners. Sabi does not store full card numbers or bank credentials; our processors do, under PCI DSS. We receive and store transaction metadata: amount, currency, item, timestamps, escrow state, fee breakdown, partial card identifiers, payout status and dispute outcomes.
- Escrow means the funds sit with our partner until you confirm delivery or a dispute is resolved. Both buyer and seller therefore see order and delivery information necessary to complete the trade — including the delivery address for physical goods.
- Sellers receive the buyer's name, delivery details and order contents; buyers receive the seller's trading identity and fulfilment information. Neither party receives the other's payment credentials.
- Where a dispute is raised, both parties' submitted evidence is reviewed by Sabi and, if escalated, by the payment partner.
- Financial and transaction records are kept for the period required by tax and AML law in the relevant market — commonly six to seven years — even after account deletion.
10. Messaging, calls and content moderation
Messages between members are transmitted over encrypted connections and stored encrypted at rest. They are not end-to-end encrypted today, which means we can access message content in narrow, controlled circumstances: to respond to a report, to investigate fraud or a safety threat, to operate automated detection of prohibited content, or to comply with a valid legal demand. Access by staff is role-restricted, logged and audited.
- Automated classifiers scan content and media for scams, harassment, sexual exploitation of minors, prohibited goods and spam; matches may be queued for human review.
- Confirmed CSAM is reported to the relevant authorities and hashed for future detection, as required by law.
- Reported conversations are retained for the length of the investigation and any appeal window.
- Deleting a message removes it from your view and, where the feature allows, from the recipient's; copies may persist in backups or moderation records for a limited period.
11. Location, the globe and discovery
Sabi shows where members are active — cities on the globe, distance context in Discover, and place filters. By default we use city-level location taken from your profile or inferred from your IP address. We only collect precise device location if you explicitly grant permission, and you can revoke it in your device settings at any time.
- Other members never see your precise coordinates, your home address or your live position — only the city you present and, where relevant, an approximate distance.
- Activity counts shown on the globe are aggregated and do not reveal any individual's exact whereabouts.
- You can hide yourself from Discover and from place-based browsing in Privacy settings.
12. How we share data
We share personal data only in the situations below. We do not sell personal data.
| Recipient | What they receive and why |
|---|---|
| Other members | Your public profile, posts, Flips, statuses, storefront, reviews and presence status; and, to a trading counterparty, the order details needed to fulfil it. Matches and messages are private to the participants. |
| Service providers | Cloud hosting, storage and CDN, analytics, crash reporting, email/SMS/push delivery, customer support tooling, content moderation and media scanning — each under contract, limited to what the service requires. |
| Verification and screening partners | Identity documents, selfie, name and date of birth, to run the checks described in section 8. |
| Payment and escrow partners | Transaction, payout and dispute data needed to move and hold funds and to meet financial regulation. |
| Legal and safety recipients | Law enforcement, regulators or courts where we receive a valid legal request, and anyone whose safety is at credible risk. We assess each request, push back on overbroad ones, and notify affected members unless legally prohibited. |
| Corporate transactions | A buyer, investor or successor in a merger, acquisition or financing — under confidentiality, and with notice to you if the handling of your data would change. |
| Aggregated or de-identified data | Statistics and insights that cannot reasonably be used to identify you, shared for research, reporting or investor updates. |
13. International data transfers
Sabi operates globally and uses infrastructure in multiple regions, so your data may be processed outside your country — including in the European Union, the United Kingdom, the United States and Nigeria. Where we transfer data out of the EEA, the UK, Nigeria or another jurisdiction with transfer rules, we rely on an adequacy decision where one exists, and otherwise on Standard Contractual Clauses (with the UK Addendum where applicable) plus a transfer impact assessment and technical measures such as encryption in transit and at rest. You can request a copy of the safeguards we use.
14. How long we keep data
| Data | Retention |
|---|---|
| Account and profile | While your account is active; deleted within 30 days of deletion request, subject to the exceptions below. |
| Posts, Flips, comments, reviews | Until you delete them or the account is deleted; backups purge within 90 days. |
| Statuses and ephemeral notes | 6 or 24 hours as chosen, then deleted from live systems; backups purge within 30 days. |
| Messages | While the conversation exists; deleted with the account, except items preserved for an open report or legal hold. |
| Identity verification records | Result and metadata for 5 years after account closure where AML rules apply; document images deleted after the check. |
| Transactions, escrow and payouts | 6–7 years, as required by tax and financial regulation. |
| Safety, moderation and enforcement records | Up to 5 years, or longer for repeat or severe violations, to prevent re-entry to an invite-only network. |
| Declined applications | Minimal decision record for 2 years. |
| Device, log and analytics data | Typically 13 months, or shorter where aggregated sooner. |
15. How we protect data
- TLS 1.2+ in transit and AES-256 encryption at rest for member data, media and backups.
- Row-level access control in our data layer so a member's records are only reachable by that member and authorised systems.
- Least-privilege staff access, single sign-on with mandatory multi-factor authentication, and logged, reviewable access to sensitive records.
- Secrets held in a managed vault, never in source code; separate production and development environments.
- Continuous dependency scanning, periodic penetration testing and an internal secure development review before release.
- An incident response plan with 72-hour regulator notification where required, and prompt notice to affected members when a breach is likely to result in high risk.
No system is perfectly secure. Use a strong unique password, enable two-factor authentication, and tell us immediately if you suspect unauthorised access.
16. Your rights and controls
Depending on where you live, you have some or all of these rights:
- Access — get a copy of the personal data we hold about you.
- Portability — receive your data in a structured, machine-readable format, or have it sent to another provider where technically feasible.
- Rectification — correct data that is wrong or incomplete.
- Erasure — have your data deleted, except where we must keep it for legal, financial or safety reasons.
- Restriction and objection — limit or object to processing based on legitimate interests, including profiling for recommendations.
- Withdraw consent — for precise location, marketing, linked accounts or sensitive-data processing.
- Opt out of marketing — through the unsubscribe link, notification settings, or by contacting us.
- Non-discrimination — we will not degrade your Sabi experience because you exercised a right.
- Complain — to your local supervisory authority, including the NDPC (Nigeria), the ICO (UK) or your EU data protection authority.
In-app controls: Settings covers profile visibility, who can see you, discretion mode, blocked members, notification preferences, linked accounts, location permission, data download and account deletion. We respond to rights requests within 30 days, extendable by a further 60 days for complex requests, and we may ask you to verify your identity before we act.
17. Regional disclosures
Nigeria (NDPA 2023)
We process personal data lawfully, fairly and transparently, maintain a data protection compliance record, engage a licensed Data Protection Compliance Organisation for our annual audit where thresholds apply, and appoint a Data Protection Officer. You may complain to the Nigeria Data Protection Commission.
European Economic Area and United Kingdom
You hold the GDPR/UK GDPR rights listed in section 16 and may lodge a complaint with your supervisory authority. Our Article 27 representative details are available on request.
California (CCPA/CPRA)
In the preceding 12 months we collected the categories of personal information described in section 3 for the purposes in section 5, and disclosed them to the recipients in section 12. We do not sell or share personal information for cross-context behavioural advertising, and we do not knowingly collect data from anyone under 18. You may exercise the rights to know, delete, correct and limit the use of sensitive personal information, and may use an authorised agent.
Other jurisdictions
Members in Brazil (LGPD), South Africa (POPIA), Canada (PIPEDA), Kenya, Ghana, India (DPDP Act) and other markets hold equivalent rights under local law; contact us and we will honour them.
18. Children and age assurance
Sabi is strictly for adults aged 18 and over. We verify age through the identity check at application. If we learn that someone under 18 has gained access, we terminate the account immediately and delete the data, retaining only the minimum needed to prevent re-registration and to meet any legal reporting duty.
19. Automated decisions and profiling
We use automated systems to rank content and profiles, to score fraud and safety risk, and to triage applications. Automated screening can flag or provisionally restrict an account, but decisions with a significant effect — rejecting an application, permanently banning a member, withholding escrowed funds — get human review. You can ask for that review, state your case and appeal the outcome by contacting support.
20. Advertising and analytics
Sabi is subscription-funded. We do not run third-party ad networks inside the app and we do not sell or share your data for cross-context behavioural advertising. We may promote Sabi on external platforms using our own member lists in hashed form, and you can opt out of that at any time. Analytics are limited to first-party and contracted processors, used for product measurement rather than ad targeting.
21. Cookies and similar technologies
On the web we use strictly necessary cookies (session, authentication, security, load balancing), preference cookies (theme, language) and, with your consent where required, analytics cookies. In the apps we use equivalent SDKs and local storage. You can manage non-essential cookies through the consent banner or your browser; blocking strictly necessary cookies will break sign-in and checkout.
22. Deactivation and deletion
- Deactivate — hides your profile, posts, listings and presence from other members while keeping your data so you can return.
- Delete — permanently removes your account. Live data is deleted within 30 days and backups within 90 days.
- What survives deletion — transaction and escrow records required by financial law, moderation records for serious violations, minimal identifiers preventing re-registration after a ban, anonymised analytics, and anything under a legal hold.
- Content others have copied, screenshotted or quoted, and messages already delivered to another member's inbox, may remain visible to them.
23. Changes to this policy
We update this policy as the product and the law change. For material changes we give at least 30 days' notice in the app and by email before they take effect, and where the law requires it we ask for fresh consent. The version and date at the top always reflect the current policy, and previous versions are available on request.
24. Contact us
You can also reach us through Settings → Support → Contact concierge. We acknowledge privacy requests within 72 hours.