Last updated: August 2026
When you register we collect your full name and your Ethiopian mobile number. Your phone number is your login — you do not sign in with an email address; instead we build an internal sign-in identifier from your phone number. Your password is handled by Firebase Authentication and stored only as a hash — Gebeya never sees it.
You may optionally add a recovery email address so you can reset your password if you ever forget it. This is not required to use Gebeya. If you add one, we store it and use it only to send you account-recovery and password-reset messages, as described in "Who Else Handles Your Data". You can add or remove it at any time in the app.
You may also add a profile photo, a short bio and a list of skills. If you sell on Gebeya and set up payouts, we collect your payout account details — the bank or mobile-money provider, the account holder name and the account number.
As you use the app we record your orders, payments and withdrawals, the messages you send, and the reviews you write. If you allow notifications, we store a device token that identifies the device or browser to send them to. We also keep automated counters of how often you use certain features, to stop the app being abused.
Your information is used to provide the Gebeya service, process payments, resolve disputes and improve the platform. We do not sell your personal data to third parties.
Payments are processed by Chapa, our payment provider. You choose how to pay on Chapa's own secure page — telebirr, CBE Birr, M-Pesa, a card or a bank transfer. That page belongs to Chapa, not to us: your PIN, card number and banking passwords are entered there and are never seen or stored by Gebeya. What we store is the record of the transaction — the amount, the date, the status and Chapa's reference for it.
If you sell on Gebeya and set up payouts, we also store the bank or mobile-money provider you chose, the account holder name and the account number, because we have to give them to Chapa to send your money. Deleting your account removes these from your profile.
Messages between users are stored so the chat works and so we can settle disputes. They are visible to the person you are talking to, and to Gebeya staff reviewing a dispute or investigating a report.
An automated system checks messages, service listings and reviews for phone numbers, social handles and other contact details, which are not allowed on the platform. If content is refused it is not delivered or published.
You should know that we keep a record of refused content. When something is blocked we store what you tried to send, along with the reason and the time, in a log that only Gebeya administrators can read. We keep it so we can review your appeal if you think the block was wrong, and so we can correct the system when it makes mistakes. Content that passes the check is not logged this way.
Your data is encrypted in transit and at rest. Access rules on our database restrict each record to the people involved in it — your orders, payments and messages are not readable by other users of the app. Passwords are handled by Firebase Authentication and are never visible to us.
We take these measures seriously, but no online service can promise perfect security, and we do not.
Gebeya does not run its own servers. Your data is held on Google Cloud infrastructure through Firebase, and it is stored outside Ethiopia.
Our database and the code that runs the app are located in Google's europe-west1 region, in Belgium. Uploaded images — profile photos and service pictures — are currently held in a Google data centre in the United States. Payment processing is carried out by Chapa, in Ethiopia.
We do not sell your personal data, and we do not share it for advertising. A few companies process data on our behalf so that Gebeya can work:
Google (Firebase) provides our database, sign-in, file storage and push notifications. Most of the information described in this policy is held on their infrastructure.
Chapa processes payments. When you pay, we send Chapa the amount, our reference for the order, your name, your phone number and your sign-in identifier. When a freelancer withdraws, we send Chapa the bank code, account number and account holder name needed to make the transfer. Anything you enter on Chapa's own payment page is handled by Chapa under their terms, not ours.
AfroMessage delivers the SMS verification codes that confirm your phone number when you register. To send the code, we share your phone number with AfroMessage; it is used only to deliver that message.
Resend delivers our account emails. If you add a recovery email address, we share that address with Resend so it can send you the verification message and any password-reset links you request. Resend is not used unless you choose to add a recovery email.
Beyond these, we share data only when the law requires it — for example a lawful request from a regulator, tax authority or court.
You can update your profile information at any time. You can delete your account yourself from Profile → Delete Account; no request to support is needed and deletion takes effect immediately. Because deletion is permanent, we will not let you delete an account that still has an order in progress, an open dispute, or earnings you have not yet withdrawn. The app tells you which of these apply and you can delete once they are settled.
Deleting your account removes your profile, photo, phone number, recovery email (if you added one) and payout account details, and takes your listings off the marketplace. It also deletes your notifications, your registered devices, your usage counters, and the moderation log of any content of yours that was refused. Your sign-in is destroyed and you are signed out everywhere. On records that other people can still see — past orders, chats and reviews — your name is replaced with "Deleted user".
We cannot delete everything immediately. We keep certain business and financial records after an account is closed in order to meet our legal, accounting and tax obligations, to complete and evidence past transactions, and to resolve any later claims or disputes. When an account is deleted, the underlying transaction, payment and log data — order amounts and dates, our commission, payment and refund references, withdrawal records including the bank or mobile-money provider name, account holder name and the last four digits of the account number — is moved into a restricted financial archive. That archive is not part of the app. It is not visible to other users, and access is limited to authorised staff and to lawful requests from a regulator, tax authority or court. We retain it for as long as we are required to keep it under applicable Ethiopian law and for the accounting and tax purposes described above, and delete it once it is no longer needed for them. Where the exact retention period required by law is not yet certain, we keep the record until we can confirm the requirement rather than delete it prematurely.
For privacy related questions contact us at privacy@gebeyaet.com