Privacy and data protection
Last updated 24 August 2026.
This notice describes what iTRUSH stores about you, how it is protected, and what we can and cannot do when you ask us to remove it.
What we collect
To operate the service we hold:
- Identity — your name, username, phone number and, if you give one, an e-mail address.
- Location — the coordinates and description of your pickup point.
- Transactions — the collections you booked, what you paid, and the mobile-money number used.
- Activity — sign-in times, the device and browser you used, and the IP address you connected from.
- For collectors — national ID and driving-permit numbers, and position while actively working a job.
How it is protected
Names, usernames, phone numbers, e-mail addresses, physical addresses, national ID numbers and payer details are encrypted at rest using AES-256-CBC with an authentication tag. They are not stored as readable text. Someone who obtains a copy of the database — a stolen backup, a mis-configured admin tool — does not get a usable list of names and addresses.
Because encrypted values cannot be searched directly, we store an additional irreversible keyed hash of each searchable field. That lets the system find your account when you sign in without ever holding your phone number in the clear.
Passwords are hashed, not encrypted. That distinction matters: encryption is reversible, hashing is not. Nobody at iTRUSH can read your password, and nobody can recover it for you — we can only help you set a new one.
What is not encrypted, and why
We are specific about this rather than implying everything is protected equally. The coordinates of a pickup point are stored in readable form, because the platform has to calculate distances to find the nearest collector, and that arithmetic happens inside the database. The address text beside those coordinates is encrypted. A leak would therefore reveal points on a map, not households with names attached — a meaningful reduction in harm, but not zero.
Location tracking
A collector's position is shared with the resident only while they are actively travelling to that job. It stops when the collection closes, and the position trail is deleted after a short retention period. We do not track collectors when they are off duty. Continuously logging a worker's whereabouts would be surveillance rather than operations, and we do not do it.
Who can see your data
- The collector assigned to your job sees your pickup location, your first name and a contact number — for as long as the job is live.
- The collection company sees the collections its staff performed.
- Administrators can see what they need to operate the platform. Every time an administrator views or changes a record, it is written to a tamper-evident audit trail.
- Exports of user data are masked even for administrators, because a spreadsheet of names and phone numbers on a laptop is exactly the leak the encryption exists to prevent.
We do not sell your data. We do not share it with advertisers. We share it with a payment aggregator only to the extent needed to process a payment you initiated.
Messages we send
SMS and e-mail notifications carry operational information: a collector's name and number, a confirmation code, a receipt. The message body is stored encrypted, because those messages contain exactly the details this notice is about. You can turn off SMS or e-mail notifications in your account settings; messages that are essential to a transaction you started will still be sent.
Deleting your account
If you have never made a transaction, closing your account removes it.
If you have — this is the part most privacy notices avoid — we cannot simply delete the record. A completed collection has a payment attached, that payment was settled to a company, and those books have to remain reconcilable. What we do instead is anonymise: your name, contact details, address and ID numbers are irreversibly destroyed and replaced with a tombstone, while the financial and audit records remain, linked to an account that no longer identifies anyone. We would rather describe that accurately than promise an erasure we cannot perform.
Retention
- Collection and payment records — retained while needed for reconciliation and any statutory accounting period.
- Audit trail — retained permanently and append-only. It cannot be edited or deleted, by anyone, including us. That is the point of it.
- Collector position history — deleted shortly after the job it belongs to closes.
- Sign-in attempt logs — 30 days.
- Read notifications — 90 days.
Your rights
Under the Data Protection and Privacy Act, 2019 you may ask to see the personal data we hold about you, correct it, or ask us to stop processing it. Most of it you can already see and edit yourself in your account. For anything else, contact us at support@itrush.ug.
Contact
iTRUSH Waste Solutions
Plot 12, Kyambogo Road, Kampala, Uganda
support@itrush.ug · 0800 100 200