Tisewere Limited (Company No. COY-66QTY5J), a private company incorporated in Malawi and registered in Blantyre, is the data controller responsible for your personal data on tisewere.com and our related apps (the "Service"). This policy is written to meet the requirements of Malawi's Data Protection Act, 2024, which is regulated and enforced by the Malawi Communications Regulatory Authority (MACRA) as the designated Data Protection Authority.
Contact us about any privacy question at hello@tisewere.com.
Account data: name, username, email, password (stored only as a salted hash), phone number, date of birth (used solely to confirm your age bracket — see our Terms of Service), and — if you choose to add them — bio, location, website, and social media links on your profile.
Sign-in data: if you use Google or Facebook to sign in, we receive your name, email, and profile picture from that provider, plus a stable provider account id (used only to recognize your account on return visits and, for Facebook, to support the friend-matching feature below).
Facebook friends matching: if you use "Find Facebook friends," Facebook's own login screen asks your permission directly. We receive only the list of Facebook ids from your friends list, which we match against existing Tisewere accounts server-side. We never receive or store your Facebook access token, and we don't retain Facebook ids for accounts that don't match an existing Tisewere user.
Contacts matching: if you use "Find contacts on Tisewere" (where supported by your browser), the phone numbers/emails you select are sent to us once to check for a match against existing accounts and are not stored afterward — we keep the match result (i.e., which of your contacts are already on Tisewere), not your contact list itself.
Payment data: real-money payments are handled by Paychangu, our licensed payment processor. We receive a transaction reference, amount, and status — never your full card number or mobile-money PIN.
Gameplay and usage data: games played, results, wagers, wallet transactions, ad views, device type, browser, IP address, and general usage patterns (pages visited, features used).
Support and content data: anything you send us directly, such as bug reports, support emails, or content you submit as an advertiser.
Some of our service providers (hosting, email, analytics, payment processing) operate infrastructure outside Malawi. Where we transfer personal data outside Malawi, we do so only to providers that maintain appropriate contractual and technical safeguards, in line with the Data Protection Act, 2024's requirements for cross-border transfers.
We keep account and transaction data for as long as your account is active and for a reasonable period after closure to meet legal, tax, dispute-resolution, and fraud- prevention obligations. Guest accounts that are never converted to a full account and never return may be purged after a period of inactivity. You can ask us to delete your data sooner under Section 7, subject to records we're legally required to keep.
Under the Data Protection Act, 2024, you have the right to:
The Service is restricted to users aged 13 and over (see our Terms of Service). We do not knowingly collect personal data from anyone under 13. If we learn that we have, we will delete it and close the associated account.
Accounts aged 13 to 17 are further restricted: real-money purchases, wagering, cash-out, and peer Zude transfers are unavailable, and chat with other players is limited to a fixed set of preset messages rather than free text. We rely on the date of birth you provide at signup to apply these restrictions — we do not independently verify age. If you are a parent or guardian and believe your child has provided us with personal data without your consent, or has misrepresented their age, contact us at hello@tisewere.com and we will investigate and remove it.
We use industry-standard measures to protect your data, including encrypted connections (HTTPS) everywhere, salted password hashing, validated file uploads, and per-IP rate limiting and captcha checks on sensitive endpoints. No system is perfectly secure; if a breach occurs that poses a risk to your rights, we will notify MACRA and, where required, you, within 72 hours of becoming aware of it, as required by the Data Protection Act, 2024.
We may update this policy from time to time. We'll notify you of material changes (for example, by email or an in-app notice) before they take effect. The version number and effective date at the top of this page always reflect the current version.
Tisewere Limited (Company No. COY-66QTY5J), Blantyre, Malawi. Email hello@tisewere.com for any question about this policy or to exercise any of the rights in Section 7.