Draft last updated: 28 September 2026
Status: Prepared for owner and Ghana-qualified legal counsel review. Not yet approved.
This Privacy Policy explains how SOMAME APP LTD, trading as SomaMe ("SomaMe", "we", "us"), handles personal data through somameapp.com (the Website) and the Asori and Asori Admin applications (together, Asori).
Mcket, Mcket Errander and Mcket Vendor are covered by the Mcket Privacy Policy, not this policy. A separate notice shown with a SomaMe Lab may also apply when that Lab uses a third-party service.
1. Who is responsible for your data?
SomaMe is the data controller when it decides why and how personal data is used, including Website inquiries, SomaMe business contacts and the administration of Asori user accounts.
A church or other organisation using Asori decides why its member, visitor, attendance, pastoral and ministry records are collected and used. For that organisation-managed data, the organisation is the data controller and SomaMe processes the data to provide Asori on its instructions. Contact the organisation first about its records; we will assist it where required.
This role split depends on the context. Calling data "church data" does not remove the rights of the people the data identifies.
2. Data covered by this policy
Depending on the features you use, we may process:
- Website inquiries: name, email address, optional phone number, country, organisation, product of interest, inquiry type and message.
- Account and profile data: name, email address, phone number, profile image, authentication identifiers, church association, role and permissions.
- Church-managed records: membership and visitor information, family relationships, age band or date of birth, gender, marital status, address, ministry involvement, attendance, follow-up, pastoral or operational notes, prayer or testimony submissions, event participation and communication history.
- Special personal data: information that may reveal religious belief, and any health or other specially protected information an organisation chooses to record using an available field. Asori also supports records relating to children under parental control.
- Attendance and location data: attendance events and, when you choose location-aware self check-in and grant device permission, location information needed to assess whether you are at the relevant church. QR and manual check-in options may also be available.
- Face Attendance pilot data: participation and consent status, a face template created from guided live captures, liveness and match results, attendance decisions and audit records. Camera frames used during recognition are processed on the device and are not uploaded, stored or logged by Asori. The template is separate from the profile picture and is available only to authorised roles for this feature.
- Photo Discovery data: opt-in status, event photos supplied by the church, possible matches, reviewer decisions and a member's "Not me" feedback. A church reviewer must confirm a match before a photo is made available to the member.
- Communications data: app-message and SMS recipients, message content, delivery status, notification tokens and communication preferences.
- Payment and transaction data: amounts, dates, status and transaction references for enabled payment or SMS-wallet features. Payment credentials are handled by the payment provider; SomaMe does not intend to store full payment-card details.
- Technical and security data: IP address, device and app information, authentication events, diagnostics, security signals, audit logs and records of feature use needed to operate and protect the service.
- Support and rights-request data: correspondence and information needed to verify and fulfil a request.
Please do not send confidential member information through the Website contact form.
3. How we collect data
We collect data:
- directly from you when you create an account, complete a profile, use a feature or contact us;
- from a church or an authorised user who creates or manages organisation records;
- from your device when you grant a permission or use a technical feature;
- from service providers that support authentication, hosting, messaging, payments or diagnostics; and
- automatically through essential service logs and security records.
An organisation that adds information about another person is responsible for providing the required notice and having a lawful basis to do so.
4. Why we use data
We process personal data as necessary to:
- provide, authenticate, maintain and support the Website and Asori;
- place users in the correct organisation, role and permission scope;
- deliver the attendance, directory, follow-up, service-planning, reporting, messaging, payment and optional face or photo features selected by the user or organisation;
- respond to inquiries and support requests;
- secure accounts, prevent misuse, diagnose faults, keep audit records and recover the service;
- administer transactions and maintain records required by law; and
- improve reliability and understand aggregate service use.
We rely on consent where the law or the feature requires it, including device permissions and the optional Face Attendance and Photo Discovery features. In other contexts, processing may be necessary to provide the requested service, comply with law, protect legitimate interests without overriding individual rights, or carry out an organisation's lawful instructions.
We do not sell personal data or use Asori member records for third-party advertising.
5. Churches and authorised users
An organisation using Asori must:
- collect and use personal data lawfully, fairly and for stated purposes;
- give members, visitors, staff and volunteers an appropriate privacy notice;
- obtain valid consent where required, especially for optional face and photo features and data about children;
- give access only to people whose roles require it and keep their access details secure;
- keep records accurate and avoid collecting more than is needed; and
- respond to requests about organisation-controlled records, with SomaMe's assistance where applicable.
Role-based access reduces visibility, but the organisation remains responsible for assigning roles and deciding what its authorised users may enter, view, export or communicate.
6. When data is disclosed
We may disclose personal data:
- to the church or organisation you join and its authorised users, in line with the feature and permission scope;
- to infrastructure and service providers that process data for hosting, authentication, storage, notifications, SMS, email, support, payments, monitoring or analytics;
- to professional advisers, auditors or a successor in a genuine corporate transaction, subject to appropriate confidentiality; or
- where disclosure is required by law, legal process or a competent authority, or is reasonably necessary to protect people, rights, systems or the service.
Current Asori infrastructure includes Firebase and Google Cloud. Enabled features may also use providers such as Paystack for payment processing, mNotify for SMS, Apple or Google for sign-in and push services, and Huawei push services on supported devices. The Website loads no analytics provider unless SomaMe configures the documented cookieless Vercel or Plausible option.
Service providers may use data only for the contracted service and their own legally required purposes. Their separate notices may also apply when you deal with them directly.
7. International processing
Some providers may store or process data outside Ghana. Where personal data is transferred internationally, SomaMe will use the contractual, organisational or other safeguards required by applicable law and will consider the destination and the sensitivity of the data. Ask us for information about safeguards relevant to your data.
8. Retention and deletion
We keep personal data only as long as reasonably needed for the purpose described in this policy, an organisation's documented instructions, security and continuity needs, or legal, accounting and dispute requirements. Retention varies by record and feature.
Deleting an Asori account removes or schedules removal of data controlled only through that account, subject to verification, technical processing time, backups and records that must lawfully be retained. It may not delete records that a church controls independently, such as membership, attendance, transaction or audit history. Ask the church about those records. Backup copies are isolated from ordinary use and are removed or overwritten through the applicable backup cycle.
Instructions for starting account deletion are on the account-deletion page. Unfollowing or leaving a church changes the relationship but should not be assumed to erase every historical record.
9. Security
We use technical and organisational measures appropriate to the nature of the service and data. Verified measures include encrypted network connections, server-side checks for sensitive operations, role- and scope-based access, audit trails for sensitive actions, device-integrity checks in release apps, managed backups and keeping service secrets off client devices.
No system is completely secure. Users and organisations must protect their credentials, devices and exports and must notify us promptly of suspected unauthorised access.
If we have reasonable grounds to believe personal data has been accessed or acquired by an unauthorised person, we will investigate, take appropriate remedial steps and make notifications as soon as reasonably practicable where required by applicable law.
10. Cookies and similar technologies
The Website does not use advertising cookies. It may use essential technical data and, only if configured, cookieless aggregate analytics. Asori uses local storage, tokens and similar device technologies for sign-in, security, preferences, offline operation and synchronisation. Device settings and operating-system permissions give you controls over items such as notifications, camera, photos and location.
11. Your rights
Subject to applicable law and relevant exemptions, you may ask to:
- be informed whether and how your personal data is processed;
- access your personal data and information about its source, purpose and recipients;
- correct inaccurate, incomplete, excessive, out-of-date or misleading data;
- delete data that is unlawfully held or no longer authorised for retention;
- object to or require the cessation of processing likely to cause unwarranted damage or distress; and
- withdraw consent for future processing where consent is the basis, without affecting earlier lawful processing.
We may need to verify your identity and determine whether SomaMe or your church controls the record. Send requests to kessben@somameapp.com. You may also complain to Ghana's Data Protection Commission.
12. Children and special personal data
Asori is not intended for children to create and administer church accounts independently. Churches may use Asori to manage authorised ministry and membership records concerning children. The church must involve a parent or guardian and obtain any consent or other authority required by law.
Religious-belief information, data about children under parental control, and optional face data require particular care under Ghana's Data Protection Act, 2012 (Act 843). Organisations must use these features only for legitimate church activities, limit access and avoid unrelated disclosure. A parent, guardian or eligible individual may contact the relevant church or SomaMe about such data.
13. Changes to this policy
We may update this policy when our products, providers or legal obligations change. We will post the revised date and give additional notice of material changes where appropriate. A change will apply from its stated effective date; it will not create consent where the law requires consent to be obtained separately.
14. Contact
Questions, privacy requests and complaints may be sent to:
SOMAME APP LTD (SomaMe)
Opoku Ware II Museum Africa Hall Road, Kumasi, Ghana
kessben@somameapp.com · +233 20 633 2524
This draft is designed around Ghana's Data Protection Act, 2012 (Act 843). Rights or obligations under another applicable law may also apply. Publication of this draft does not by itself represent legal approval or regulatory registration.