Legal

Privacy policy

Version 1.0 · Effective 17 September 2026

Sabi is a private, invite-only network where members date, connect, hire and trade with escrow protection. That means we handle unusually sensitive information: who you are attracted to, who you talk to, where you are, what you buy and sell, and the identity documents that let us keep the network vetted. This policy explains, in plain language and in full detail, what we collect, why, who sees it, how long we keep it, and how you control it. We do not sell your personal data.

1. Who we are

Sabi ("Sabi", "we", "us") operates the Sabi members' network — the mobile and web applications, the marketplace and storefronts, the escrow service, messaging, Flips, Discover and all related services (together, the "Services"). Panaga Holdings, a company registered in France (registration no. 109 765 073), is the data controller for members worldwide unless a regional disclosure in section 17 says otherwise. For members in the European Economic Area and the United Kingdom, our appointed representatives and Data Protection Officer are reachable through the contact details in section 24. In Nigeria, our launch market, we process personal data in accordance with the Nigeria Data Protection Act 2023 and register with the Nigeria Data Protection Commission as required.

2. Scope of this policy

This policy applies to every member, applicant, visitor, buyer, seller and business account that interacts with the Services, including people who apply for membership and are not approved. It also covers non-members whose data reaches us — for example, someone a member refers by invite, a person named in a dispute, or a recipient of an order.

It does not cover third-party services you reach through Sabi (a seller's external website, a payment provider's own account portal, or a social platform you link). Those operate under their own policies.

3. Data we collect

3.1 Information you give us

3.2 Information we collect automatically

3.3 Information from third parties

4. Where the data comes from

Every field above comes from one of four sources: you provide it; your device generates it as you use Sabi; another member or a counterparty provides it; or a verification, payment, safety or infrastructure partner returns it to us. We do not buy personal data from data brokers to build member profiles.

5. How we use your data

PurposeWhat it means in Sabi
Provide the ServicesCreate and run your account, render your feed, matches, inbox, storefront and orders, sync your settings and presence status.
Vet the networkReview applications, verify identity and liveness, detect duplicate or fake accounts, and decide admission to an invite-only community.
Match and recommendRank Discover profiles, feed posts, Flips, search results, marketplace listings and suggested members using your intents, location, activity and connection graph.
Enable commerce and escrowTake payment into escrow, hold funds, release or refund them, calculate fees, handle disputes and pay out sellers.
Safety, integrity and moderationDetect harassment, scams, spam, CSAM, fraud and prohibited goods; review reports; enforce our rules; support law enforcement where legally required.
ComplianceMeet KYC, anti-money-laundering, sanctions, consumer-protection, tax and record-keeping obligations in every market where we operate.
CommunicationsSend transactional messages (order, escrow, security, application status) and, where permitted, product news and marketing you can opt out of.
Improve and measureDiagnose crashes, run A/B tests, measure feature performance and produce aggregated analytics that do not identify you.

Where the GDPR, UK GDPR, the Nigeria Data Protection Act or a comparable law applies, we rely on the following legal bases:

Legal basisUsed for
ContractCreating your account, delivering the feed and messaging, processing orders, operating escrow, paying out sellers.
Legitimate interestsSecurity and fraud prevention, network integrity, product improvement, recommendation quality, and direct marketing to existing members — balanced against your rights.
ConsentPrecise location, optional marketing, non-essential cookies, linking social accounts, and any processing of sensitive data such as dating preferences or biometric face-match.
Legal obligationIdentity and AML checks, tax and transaction records, responses to lawful requests, and mandated reporting.
Vital interestsRare cases involving a credible risk to someone's life or physical safety.

Where we rely on consent, you can withdraw it at any time in Settings or by contacting us; withdrawal does not affect processing already carried out.

7. Sensitive and special category data

Because Sabi includes dating, some of what you share can reveal sensitive information — for example your sexual orientation implied by who you choose to see or match with, or health, religion or ethnicity if you mention them in a profile, post or message. The face-match step in verification uses biometric data.

8. Identity verification and vetting

Membership is reviewed. When you apply, we collect your application answers, an identity document and a live holding photo, and we send them to a specialist verification provider that checks the document's authenticity, matches the face to the document, screens against sanctions and politically-exposed-person lists where required, and returns a result. Our reviewers see the result, your application answers and, where a manual review is needed, the submitted images.

9. Payments, escrow and financial data

Payments are handled by regulated payment processors and escrow partners. Sabi does not store full card numbers or bank credentials; our processors do, under PCI DSS. We receive and store transaction metadata: amount, currency, item, timestamps, escrow state, fee breakdown, partial card identifiers, payout status and dispute outcomes.

10. Messaging, calls and content moderation

Messages between members are transmitted over encrypted connections and stored encrypted at rest. They are not end-to-end encrypted today, which means we can access message content in narrow, controlled circumstances: to respond to a report, to investigate fraud or a safety threat, to operate automated detection of prohibited content, or to comply with a valid legal demand. Access by staff is role-restricted, logged and audited.

11. Location, the globe and discovery

Sabi shows where members are active — cities on the globe, distance context in Discover, and place filters. By default we use city-level location taken from your profile or inferred from your IP address. We only collect precise device location if you explicitly grant permission, and you can revoke it in your device settings at any time.

12. How we share data

We share personal data only in the situations below. We do not sell personal data.

RecipientWhat they receive and why
Other membersYour public profile, posts, Flips, statuses, storefront, reviews and presence status; and, to a trading counterparty, the order details needed to fulfil it. Matches and messages are private to the participants.
Service providersCloud hosting, storage and CDN, analytics, crash reporting, email/SMS/push delivery, customer support tooling, content moderation and media scanning — each under contract, limited to what the service requires.
Verification and screening partnersIdentity documents, selfie, name and date of birth, to run the checks described in section 8.
Payment and escrow partnersTransaction, payout and dispute data needed to move and hold funds and to meet financial regulation.
Legal and safety recipientsLaw enforcement, regulators or courts where we receive a valid legal request, and anyone whose safety is at credible risk. We assess each request, push back on overbroad ones, and notify affected members unless legally prohibited.
Corporate transactionsA buyer, investor or successor in a merger, acquisition or financing — under confidentiality, and with notice to you if the handling of your data would change.
Aggregated or de-identified dataStatistics and insights that cannot reasonably be used to identify you, shared for research, reporting or investor updates.

13. International data transfers

Sabi operates globally and uses infrastructure in multiple regions, so your data may be processed outside your country — including in the European Union, the United Kingdom, the United States and Nigeria. Where we transfer data out of the EEA, the UK, Nigeria or another jurisdiction with transfer rules, we rely on an adequacy decision where one exists, and otherwise on Standard Contractual Clauses (with the UK Addendum where applicable) plus a transfer impact assessment and technical measures such as encryption in transit and at rest. You can request a copy of the safeguards we use.

14. How long we keep data

DataRetention
Account and profileWhile your account is active; deleted within 30 days of deletion request, subject to the exceptions below.
Posts, Flips, comments, reviewsUntil you delete them or the account is deleted; backups purge within 90 days.
Statuses and ephemeral notes6 or 24 hours as chosen, then deleted from live systems; backups purge within 30 days.
MessagesWhile the conversation exists; deleted with the account, except items preserved for an open report or legal hold.
Identity verification recordsResult and metadata for 5 years after account closure where AML rules apply; document images deleted after the check.
Transactions, escrow and payouts6–7 years, as required by tax and financial regulation.
Safety, moderation and enforcement recordsUp to 5 years, or longer for repeat or severe violations, to prevent re-entry to an invite-only network.
Declined applicationsMinimal decision record for 2 years.
Device, log and analytics dataTypically 13 months, or shorter where aggregated sooner.

15. How we protect data

No system is perfectly secure. Use a strong unique password, enable two-factor authentication, and tell us immediately if you suspect unauthorised access.

16. Your rights and controls

Depending on where you live, you have some or all of these rights:

In-app controls: Settings covers profile visibility, who can see you, discretion mode, blocked members, notification preferences, linked accounts, location permission, data download and account deletion. We respond to rights requests within 30 days, extendable by a further 60 days for complex requests, and we may ask you to verify your identity before we act.

17. Regional disclosures

Nigeria (NDPA 2023)

We process personal data lawfully, fairly and transparently, maintain a data protection compliance record, engage a licensed Data Protection Compliance Organisation for our annual audit where thresholds apply, and appoint a Data Protection Officer. You may complain to the Nigeria Data Protection Commission.

European Economic Area and United Kingdom

You hold the GDPR/UK GDPR rights listed in section 16 and may lodge a complaint with your supervisory authority. Our Article 27 representative details are available on request.

California (CCPA/CPRA)

In the preceding 12 months we collected the categories of personal information described in section 3 for the purposes in section 5, and disclosed them to the recipients in section 12. We do not sell or share personal information for cross-context behavioural advertising, and we do not knowingly collect data from anyone under 18. You may exercise the rights to know, delete, correct and limit the use of sensitive personal information, and may use an authorised agent.

Other jurisdictions

Members in Brazil (LGPD), South Africa (POPIA), Canada (PIPEDA), Kenya, Ghana, India (DPDP Act) and other markets hold equivalent rights under local law; contact us and we will honour them.

18. Children and age assurance

Sabi is strictly for adults aged 18 and over. We verify age through the identity check at application. If we learn that someone under 18 has gained access, we terminate the account immediately and delete the data, retaining only the minimum needed to prevent re-registration and to meet any legal reporting duty.

19. Automated decisions and profiling

We use automated systems to rank content and profiles, to score fraud and safety risk, and to triage applications. Automated screening can flag or provisionally restrict an account, but decisions with a significant effect — rejecting an application, permanently banning a member, withholding escrowed funds — get human review. You can ask for that review, state your case and appeal the outcome by contacting support.

20. Advertising and analytics

Sabi is subscription-funded. We do not run third-party ad networks inside the app and we do not sell or share your data for cross-context behavioural advertising. We may promote Sabi on external platforms using our own member lists in hashed form, and you can opt out of that at any time. Analytics are limited to first-party and contracted processors, used for product measurement rather than ad targeting.

21. Cookies and similar technologies

On the web we use strictly necessary cookies (session, authentication, security, load balancing), preference cookies (theme, language) and, with your consent where required, analytics cookies. In the apps we use equivalent SDKs and local storage. You can manage non-essential cookies through the consent banner or your browser; blocking strictly necessary cookies will break sign-in and checkout.

22. Deactivation and deletion

23. Changes to this policy

We update this policy as the product and the law change. For material changes we give at least 30 days' notice in the app and by email before they take effect, and where the law requires it we ask for fresh consent. The version and date at the top always reflect the current policy, and previous versions are available on request.

24. Contact us

Privacy teamprivacy@sabiofficial.com
Data Protection Officerprivacy@sabiofficial.com
Safety and reportssafety@sabiofficial.com
Legal requestslegal@sabiofficial.com

You can also reach us through Settings → Support → Contact concierge. We acknowledge privacy requests within 72 hours.