Skip to main content

Legal

Privacy Policy

What Kompound records about you, why we hold it, who else receives it — and, where the honest answer is uncomfortable, that answer rather than a comfortable one.

Last updated

A note on this document. This policy describes what Kompound really does with your information today, in plain language — including the parts that are less flattering than a template would be. Nothing here is legal advice; for your own situation, please consult a lawyer.

1. What this policy covers

This policy explains what Kompound records about you when you browse the platform, create an account, publish a listing or contact someone about a property — why we hold it, who else sees it, and what you can do about it.

It describes the personal data we handle as the party deciding how and why it is used. Ghana’s Data Protection Act 2012 (Act 843) calls that role the data controller, and the Data Protection Commission oversees it.

It does not cover what another user does with information you send them. When you contact an agent, a landlord or an agency through the platform, they receive your message and your contact details and handle them under their own arrangements, not ours.

2. Information you give us

When you create an account we ask for your name, your email address and your phone number, and you choose a password. We store phone numbers in the full international format, beginning with the country code, so that calls, SMS and WhatsApp messages reach you wherever you are — including from outside Ghana.

We never store your password itself. It is put through a one-way hashing function, and what we keep cannot be turned back into the password you typed.

After that, you give us information as you use the platform:

  • listings you publish — the property’s address and location, price, description, photographs and documents
  • enquiries, messages and viewing requests you send, including whatever you write in them
  • searches you run and the filters you set, properties you save, and agents you contact
  • profile details you choose to add — a photograph, a biography, service areas, business and social links
  • for agents and agencies, your business details and, where you have one, your Real Estate Agency Council (REAC) licence number

3. Identity and licence documents

Some parts of the platform ask you to prove who you are, or that you hold a licence, before they open up. Where you submit a verification request we collect the documents it needs — a national identity document or passport, a REAC licence for an agent, and registration documents for an agency — and our team reviews them.

Identity documents are held in private storage, separate from anything the platform serves publicly. A listing photograph is published to anyone who opens the listing. An identity document is not: it is kept in a private area, and is reachable only through a short-lived link issued to a reviewer who is entitled to see it.

Alongside the document we keep a record of the review — its status, who handled it, any note or reason they recorded, and, where the credential has one, its expiry date. We re-check those expiry dates daily so that a badge does not outlive the licence behind it.

We record the IP address the upload came from with every file you submit, including these.

4. What we record automatically

Some information is recorded by the platform itself, whether or not you are signed in and without you entering anything.

Your IP address is stored exactly as we receive it. We do not shorten it, mask it or replace it with a code. An IP address can point to roughly where you are and, with help from your internet provider, can sometimes be traced back to a person, so we treat it as information about you rather than as a technical detail.

We record the following when you:

  • open a property page — with the property, your browser’s user-agent string, the page you arrived from, and the time. Your IP address is used at the moment you open the page, to stop the same visitor inflating a property’s view count, but it is not kept with the record
  • run a search — with your search text, the filters you applied, how many results came back, and the time
  • sign in, or stay signed in — with the IP address and device the session was opened from
  • ask to reset a password, recover a username or change your email — with the IP address the request came from
  • upload a file, or change a privacy or profile setting — with the IP address, and, for settings, what the value was before and after

We also count failed sign-in attempts against an IP address so that nobody can sit and guess their way into other people’s accounts.

5. What we store in your browser

Kompound sets no cookies of its own. We write none for analytics, none for advertising and none for signing you in. Instead the platform uses your browser’s own storage, which stays on your device and is never attached automatically to requests the way a cookie is.

The network that delivers this site sits in front of it and may set a strictly necessary cookie of its own — the kind used to tell a real visitor from automated traffic. That is a security measure, it builds no profile of you, and we neither read it nor use it to study how you behave.

One of those entries is a visitor identifier that lasts between visits. The first time you open the platform, your browser generates a random identifier and keeps it. It is sent with property views and contact events so that we can tell that the same browser looked at a property and then enquired about it, rather than counting them as two unrelated strangers. It holds no name, email or phone number, it is never sold, and no advertiser or data broker receives it — though it does reach the providers in section 8 that host and monitor the platform for us. And it does link your activity across separate visits, which is tracking whichever technology carries it.

The rest of what we keep in your browser is:

  • your sign-in token and basic account details, so you are not signed out on every page
  • a second identifier that lasts only until you close the tab, used to group one visit’s activity
  • activity events waiting to be sent to us, held briefly if the network drops so they can be retried
  • conveniences you would notice the loss of — recent searches, unsent listing drafts, and which notices you have dismissed

Clearing your browser’s site data for Kompound removes all of it, including the visitor identifier, and a fresh one is generated on your next visit. Reload the page afterwards: until you do, the tab you already have open keeps using the old identifier it is holding in memory.

Two honest limits on that. Identifiers we have already received stay on the records they were attached to — we do not go back and erase them. And if you were signed in when you sent an enquiry, that enquiry carries your account alongside the identifier of the day, so an old and a new identifier belonging to the same signed-in person can still be matched up through the account. Clearing site data gives you a new identifier going forward; it does not unpick the history.

6. How we use your information

We use what we hold to:

  • run the platform — show listings, run searches, deliver enquiries, arrange viewings and keep you signed in
  • verify identities and licences, and decide whether to grant or withdraw a verification badge
  • send you what you have asked for or need — enquiry alerts, viewing confirmations, password resets, security notices and account updates
  • tell owners and agents how their own listings are doing, as counts and trends over time rather than as a list of who looked
  • keep the platform safe — spotting duplicate or fraudulent listings, limiting abuse, and investigating reports
  • understand which parts of the platform work, so we can improve them
  • meet our legal obligations, and deal with disputes and claims

We do not sell your personal data, and we do not share it with advertising networks or data brokers.

7. What other people can see

Anything you publish is public. A listing — its photographs, description, price and location — can be seen by anyone, signed in or not, and may be picked up by search engines.

Your profile is more restrained. By default your phone number is hidden, your social links are hidden, and your profile is shown to other signed-in agents rather than to the open web. Contacting you by WhatsApp is allowed by default; contacting you by phone or by direct email is not. You can change any of this in your privacy settings.

When you send an enquiry or request a viewing, the person on the other side sees your name and the contact details needed to reply to you, whatever your profile shows to everyone else. That is the point of sending it — but it does mean an enquiry is a decision to share.

Administrators can see account records, verification cases and reports where their role requires it, and those views are logged.

8. Who else receives your information

We use outside services to run the platform. They act on our instructions and only get what their job needs:

  • Email delivery — an email provider receives your email address and the contents of the message we are sending you
  • SMS delivery — an SMS gateway receives your phone number and the text of the message
  • WhatsApp — messages we send over WhatsApp pass through the WhatsApp Business platform, which is run by Meta and governed by its own terms
  • Browser notifications — if you turn them on, your browser’s own push service delivers them, which means Google, Apple, Mozilla or Microsoft depending on the browser you use
  • Hosting, storage and error reporting — the platform, its database, uploaded files and our diagnostic logs sit with infrastructure providers

Some of these providers operate outside Ghana, so running the platform means your information is processed abroad. We choose established providers and use them under their standard data-protection terms.

We will also disclose information where the law requires it, where a court or regulator properly demands it, or where it is needed to investigate fraud or protect someone’s safety. If the business is ever sold or reorganised, account records would transfer with it.

9. Your choices and controls

Signed in, you can edit or remove most of what you have given us, use your privacy settings to control what other users see, and choose which notifications reach you by email, SMS, WhatsApp or in the app. Browser notifications can be switched off in your browser at any time.

There is no working analytics opt-out today — not for visitors, and not for account holders either. An analytics preference exists in our data model, it defaults to on, and it is attached to an account — so a visitor who is not signed in could never have one. But we will not dress that up: no screen currently lets you change it, and nothing in the recording path consults it, so switching it off would not stop the collection described in sections 4 and 5. Offering you a control that does nothing would be worse than admitting there isn’t one. Making it real, and adding a consent surface that can cover visitors, is outstanding work — not a promise this page is entitled to make on the platform’s behalf.

So the recording in sections 4 and 5 happens for everyone. Separately, the records the platform needs in order to run and to stay secure — sign-in sessions, uploads, settings changes, failed sign-in attempts — would be kept in any case.

You can also clear your browser’s site data at any time, which removes the visitor identifier described above.

10. How long we keep it, and what closing your account does

We keep information for as long as your account is open and the purpose it was collected for still applies, and after that for as long as we need it to meet a legal obligation or to deal with a dispute or claim. Short-lived security records — password reset links, username recovery requests, expired sessions — stop being usable well before they stop being stored.

Closing your account anonymises it. It does not erase everything we hold. When you close your account we confirm your password, then mark the account closed, replace your name with a placeholder, remove your phone number and profile photographs, replace your email address with one that cannot receive mail, invalidate your password and sign out every device. What remains — listing records, enquiries, viewing history, verification decisions and the activity logs described above — stays. Some of it still carries your contact details. In particular, an enquiry you sent keeps the phone number and email address you supplied with it, because they were saved onto the enquiry itself and the agent who received it still holds their copy. Closing your account clears the details on your profile; it does not reach back into messages you already sent. Please read this as the plain description of what happens, not as a promise of full erasure — and if you want those records dealt with too, ask us and we will handle it individually.

If you want more than that, or want to know exactly what is held about you, ask us through the contact form and we will deal with it individually.

11. How we protect it

Passwords are stored only as one-way hashes. Traffic between your device and the platform is encrypted. Identity documents are kept in private storage and reached only through short-lived links issued to reviewers. Sensitive actions — changing your email address, upgrading your account — ask you to confirm your password again, and you can end any signed-in session.

No platform can promise perfect security, and we do not. If something goes wrong that affects your information, we will act on it and tell the people who need to know.

12. Your rights, and how to complain

Under the Data Protection Act 2012 (Act 843) you can ask what personal data we hold about you, ask us to correct it if it is wrong, object to how we are using it, and ask us to stop or to delete it. Where the law allows us to keep something despite your request, we will tell you what and why rather than simply refusing.

Ask through the contact form. We may need to confirm who you are first, so that nobody can obtain your data by pretending to be you.

If you are not satisfied with how we have handled it, you can complain to Ghana’s Data Protection Commission, which supervises compliance with Act 843.

The platform is not intended for anyone under 18, and we do not knowingly collect information from children. If you believe a child has created an account, please tell us and we will remove it.

13. Changes to this policy

We will update this policy as the platform changes or as the law requires. The revision date at the top of this page always tells you when the current version took effect. Where a change materially affects what we collect or why, we will do more than change the date.

This policy sits alongside our Terms of Service, which you also accept when you create an account.