Privacy Policy
What Wicker uses, who receives it, and the choices available to you.
This notice covers the Wicker app and usewicker.com. Wicker operates from Accra, Ghana. Contact support@usewicker.com about your personal data. Our first Ghana release is for adults aged 18 and over.
1. Account and age information
We use your email address, username, account identifiers, and sign-in information to create and secure your account. Passwords are stored as password hashes. If you choose Google Sign-In or a passkey, we process the identifiers and credentials needed to verify that sign-in. Profile photos, bios, and business details are optional information you add.
We collect your date of birth privately to determine whether you meet the 18+ requirement. We keep the birth date separately from public profile information, with an eligibility result and check record. It is not displayed on your profile. Contact support if the recorded date is incorrect.
Accounts that do not meet the age requirement are restricted from normal app access. Restricting access does not itself delete the account. An account holder or someone concerned about an under-18 account can contact support about correction or removal.
2. Content, conversations, and app activity
- Content you provide: photos, videos, captions, comments, reviews, places, events, products, services, and other listing details you submit.
- Social and discovery activity: follows, reactions, saved items, lists, queues, searches, place views, check-ins, and related activity records used to organize the app and make recommendations.
- Messages and calls: message text and shared files, conversation participants, delivery/read state, and call connection information. Microphone and camera access support voice/video calls and the content you choose to create.
- Service and security information: authentication/session identifiers, notification tokens, network and request details such as IP address, and operational/error logs needed to deliver, protect, and troubleshoot the service.
Posts, comments, reviews, listings, and content you share with an audience can be seen by that audience. Direct conversations are not a public feed, but their participants can read or save what you send. Notification previews may show message excerpts on a recipient’s device. Do not include information in a public post or shared message that you do not want its recipients to retain.
3. Location and selected contacts
With the relevant device permission, Wicker uses foreground location for nearby discovery, maps, check-ins, choosing delivery locations, placing listings/events, and recording a road report while you use that feature. A road recording can include a series of precise coordinates. Locations you select manually are also processed.
Location is not always private. A place, event, check-in, road report, or other location you choose to publish can reveal its coordinates to other users. A delivery address or pin is shared with the participants who need it for that delivery. Map and route services receive the map areas or coordinates requested from them.
If you pick someone from your phone’s contact picker, Wicker receives the selected name and phone number. You can edit them before adding the person to a group or recording an invitation. Wicker also uses existing chat contacts, followers, and following lists where those choices are shown. This contact-picker flow does not upload your entire address book. An invitation or share action you choose may pass its content to your selected messaging app.
4. Orders, groups, and private proofs
If you use the relevant features, we process order items, bookings, delivery details, amounts, currency, transaction references and status, account or mobile-money details you provide, group membership, expenses, contributions, splits, confirmations, and related notes. These records let the people involved understand the activity and its status.
Relevant order or group records are visible to their participants as the feature requires. Buyer and seller proof images uploaded for an order are stored in private storage and accessed through an authenticated order route. Both the order’s buyer and seller can view those proofs; they are not published as public photo links.
Where a provider checkout is enabled and you use it, the checkout provider receives the details needed for that transaction, such as an amount, reference, customer email where required, and the information you enter into its own checkout. Wicker receives status and reference information. The provider also handles data under its own terms and privacy notice.
5. Support and safety reports
If you contact support, we receive your sender details, subject, message, and any attachments you include. Support email is routed through Cloudflare to our forwarded support inbox hosted by Google Gmail, where the full original remains available to the support operator.
When support monitoring is connected, a signed integration also delivers a bounded plain-text preview and attachment details to an admin inbox. Attachment contents are not copied into that monitoring inbox, and oversized or unreadable messages are marked incomplete. Monitoring queue entries have a 24-hour retention window per queue; that window does not delete the original email in the forwarded inbox.
In-app reports include the reported content identifier, reason, and reporting account. Authorized administrators can review reports, support previews, account-cleanup status, and internal follow-up notes. Admin updates are recorded in an audit history. Monitoring does not send automatic replies or make autonomous moderation decisions.
6. Service providers and other recipients
We use the following services for the functions described here. The data sent depends on which features you use and which integrations are enabled:
- MongoDB Atlas: storage and retrieval of account, content, activity, transaction, and support records.
- Google Cloud: app hosting, uploaded media, private proof storage, and associated operational infrastructure.
- Google Sign-In and Firebase Cloud Messaging: optional Google authentication, notification tokens, notification content, and delivery metadata.
- Agora: voice/video call connections, including the media streams and channel/device/network information required to connect a call.
- Mailgun: account emails such as verification, recovery, and deletion-confirmation messages, including their destination address and content.
- Google Gmail: the forwarded support mailbox, including original email messages and attachments.
- Cloudflare: support email routing and, when connected, the bounded support monitoring and queue service described above.
- Vercel: hosting usewicker.com and processing website requests and delivery/security logs.
- OpenStreetMap and the OSRM route service: map tile requests and route coordinates for map and planning features.
- Payment providers where enabled: Paystack or Orchard, according to the checkout used, for transaction processing and status verification.
- Google Gemini or OpenAI, with your permission: the optional AI assistance described below. AI assistance is off unless you explicitly enable it for your account.
Providers may process data on infrastructure outside Ghana. Providers process information under their applicable privacy notices and our service arrangements. We can also disclose information where a valid legal requirement applies or when necessary to investigate a security or safety issue.
Wicker does not sell personal data or use it for third-party advertising. Public sharing you choose and the service-provider processing described above are separate from selling data.
7. Optional AI assistance
AI assistance is off by default. In Wicker 1.2.8, open Hub → Settings → AI privacy to review the information involved and choose whether to enable it. If you enable it, the relevant feature can send the following information to Google Gemini or OpenAI:
- Comment analysis: up to 1,000 characters of a comment you write, to classify its sentiment.
- Recommendations: names of places you liked, your list and queue names, recent searches, and public place/product descriptions.
- AI search: the search query you enter.
- Queue planning: places in your queue, their categories and opening hours, and your chosen start date and time.
- Business schedule summaries: appointment counts and times. Customer names and identifiers are excluded from the AI summary request.
- Shelf scanning: the image you select and product names in your business inventory. Avoid including people or private documents in that image.
You can turn AI assistance off in the same setting. This stops future AI requests, including queued comment analysis. It cannot recall information already sent or cancel a request already in progress; the provider’s terms and privacy policy govern its retention. Ordinary search and non-AI recommendations remain available without enabling AI.
8. Your choices and security
You can change optional profile information, choose what to post or share, use the app’s content/reporting controls, and change camera, microphone, location, or notification permissions in your device settings. Declining a permission limits the feature that needs it; it does not remove information you already submitted.
Production connections use HTTPS. Account and private-proof routes require authentication and access checks, and support administration requires an active admin role. These controls reduce unauthorized access; they are not a promise that no security incident can occur. Do not send passwords or login/recovery codes to support.
9. Retention and account deletion
We retain account information and content to provide the features you use. Operational, security, and support records are kept as needed for their purpose, resolving issues, and applicable legal requirements. Retention can differ by record and provider; there is no single retention period covering every log, backup, and support email. Ask support about particular data if you need more detail.
In Wicker 1.2.8, open Hub’s settings menu and choose Delete account. You can also request deletion without signing in by emailing support@usewicker.com. We verify ownership before acting. The account deletion page explains the confirmation and status steps.
Once an in-app deletion starts, account access is revoked and cleanup processes the account’s personal data and uploads that can be reliably attributed to it. Cleanup retries when a required service is unavailable. Some completed shared records remain with account references anonymized for the other participants.
Active removal is different from expiry of storage recovery copies. Storage for private order proofs currently has a seven-day recovery window, so recoverable object copies can remain after active cleanup. This does not keep the account open. Older uploads without reliable account ownership records may need an ownership review before removal. Contact support about specific files or retained records.
Original support emails in the forwarded mailbox are reviewed separately when you request their deletion; removing an app account does not automatically erase that mailbox copy. We can explain any record-specific retention that applies to your request.
10. Data requests and contact
You can ask what personal data we hold about you, request a correction, or request deletion where applicable. Email support@usewicker.com with the subject “Data request”. We may ask you to verify identity before discussing account-specific information. You can also contact Ghana’s Data Protection Commission about your data rights or a complaint.
Privacy contact: support@usewicker.com, +233 24 961 7491. Postal contact: 20 Woody Street, Teshie Rasta Road, Accra, Ghana.
We will publish policy updates on this page and change the date shown above. A material change to processing may also require notice or a choice in the app.