Back to Tisewere

Privacy Policy

Version 2.1 — Effective 27 July 2026

1. Who We Are

Tisewere Limited (Company No. COY-66QTY5J), a private company incorporated in Malawi and registered in Blantyre, is the data controller responsible for your personal data on tisewere.com and our related apps (the "Service"). This policy is written to meet the requirements of Malawi's Data Protection Act, 2024, which is regulated and enforced by the Malawi Communications Regulatory Authority (MACRA) as the designated Data Protection Authority.

Contact us about any privacy question at hello@tisewere.com.

2. Data We Collect

Account data: name, username, email, password (stored only as a salted hash), phone number, date of birth (used solely to confirm your age bracket — see our Terms of Service), and — if you choose to add them — bio, location, website, and social media links on your profile.

Sign-in data: if you use Google or Facebook to sign in, we receive your name, email, and profile picture from that provider, plus a stable provider account id (used only to recognize your account on return visits and, for Facebook, to support the friend-matching feature below).

Facebook friends matching: if you use "Find Facebook friends," Facebook's own login screen asks your permission directly. We receive only the list of Facebook ids from your friends list, which we match against existing Tisewere accounts server-side. We never receive or store your Facebook access token, and we don't retain Facebook ids for accounts that don't match an existing Tisewere user.

Contacts matching: if you use "Find contacts on Tisewere" (where supported by your browser), the phone numbers/emails you select are sent to us once to check for a match against existing accounts and are not stored afterward — we keep the match result (i.e., which of your contacts are already on Tisewere), not your contact list itself.

Payment data: real-money payments are handled by Paychangu, our licensed payment processor. We receive a transaction reference, amount, and status — never your full card number or mobile-money PIN.

Gameplay and usage data: games played, results, wagers, wallet transactions, ad views, device type, browser, IP address, and general usage patterns (pages visited, features used).

Support and content data: anything you send us directly, such as bug reports, support emails, or content you submit as an advertiser.

4. Who We Share Data With

We share data only as needed to run the Service:

  • Paychangu — to process real-money payments.
  • Google / Facebook — for OAuth sign-in (they receive your login request, not your Tisewere gameplay data).
  • Cloudflare — for bot protection (Turnstile) on signup and guest-account creation.
  • Our hosting, storage, and email providers — to run and secure the Service and deliver transactional email (verification, password reset, receipts).
  • Analytics providers — Vercel Analytics (cookieless, aggregated) always; Google Analytics and/or Meta Pixel only if enabled and only after you accept the cookie banner (Section 8).
  • Authorities — where required by Malawian law or a valid order from MACRA or a court.

We do not sell your personal data to third parties.

5. International Data Transfers

Some of our service providers (hosting, email, analytics, payment processing) operate infrastructure outside Malawi. Where we transfer personal data outside Malawi, we do so only to providers that maintain appropriate contractual and technical safeguards, in line with the Data Protection Act, 2024's requirements for cross-border transfers.

6. How Long We Keep Data

We keep account and transaction data for as long as your account is active and for a reasonable period after closure to meet legal, tax, dispute-resolution, and fraud- prevention obligations. Guest accounts that are never converted to a full account and never return may be purged after a period of inactivity. You can ask us to delete your data sooner under Section 7, subject to records we're legally required to keep.

7. Your Rights

Under the Data Protection Act, 2024, you have the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate or incomplete data;
  • Request deletion of your data, subject to legal retention requirements;
  • Object to or restrict certain processing (for example, marketing analytics);
  • Receive a copy of your data in a portable format;
  • Withdraw consent at any time for anything based on consent (this won't affect processing carried out before you withdrew it);
  • Lodge a complaint with MACRA as Malawi's Data Protection Authority, or with us directly first at hello@tisewere.com.

8. Children

The Service is restricted to users aged 13 and over (see our Terms of Service). We do not knowingly collect personal data from anyone under 13. If we learn that we have, we will delete it and close the associated account.

Accounts aged 13 to 17 are further restricted: real-money purchases, wagering, cash-out, and peer Zude transfers are unavailable, and chat with other players is limited to a fixed set of preset messages rather than free text. We rely on the date of birth you provide at signup to apply these restrictions — we do not independently verify age. If you are a parent or guardian and believe your child has provided us with personal data without your consent, or has misrepresented their age, contact us at hello@tisewere.com and we will investigate and remove it.

9. Cookies and Similar Technologies

Essential: we use browser local storage (not a traditional cookie) to keep you signed in and remember your theme preference. This is necessary for the Service to function and isn't optional.

Analytics: we use Vercel Analytics by default, which is cookieless and reports only aggregated, non-identifying usage statistics. If we've enabled Google Analytics and/or the Meta Pixel, a cookie banner asks for your consent before either one loads — nothing from either loads until you click Accept, and you can decline and keep using the Service normally. You can change your choice at any time by clearing your browser's local storage for this site.

10. Security

We use industry-standard measures to protect your data, including encrypted connections (HTTPS) everywhere, salted password hashing, validated file uploads, and per-IP rate limiting and captcha checks on sensitive endpoints. No system is perfectly secure; if a breach occurs that poses a risk to your rights, we will notify MACRA and, where required, you, within 72 hours of becoming aware of it, as required by the Data Protection Act, 2024.

11. Changes to this Policy

We may update this policy from time to time. We'll notify you of material changes (for example, by email or an in-app notice) before they take effect. The version number and effective date at the top of this page always reflect the current version.

12. Contact Us

Tisewere Limited (Company No. COY-66QTY5J), Blantyre, Malawi. Email hello@tisewere.com for any question about this policy or to exercise any of the rights in Section 7.