In short
- We collect operator account details: name, email, phone number, city.
- Passwords are one-way hashed and cannot be read, including by us.
- MAC and IP addresses of people connected to hotspots are never stored in plain text: they pass through memory for a few seconds to display live sessions, then disappear. Only a non-reversible hash (fingerprint) of the MAC address is kept, to detect abusive sharing of a single voucher across several devices.
- The phone number is verified at sign-up with a code sent by WhatsApp or SMS.
- If a technical error occurs, a report is sent to our incident-tracking tool (Sentry, hosted in the European Union), without any password, token or phone number.
- No advertising, tracking or third-party analytics tools are installed on the platform.
- We do not sell or rent any data.
1Who processes your data
Processing is subject to Ivorian law no. 2013-450 of 19 June 2013 on the protection of personal data.
2Two levels of responsibility
The platform serves two distinct audiences, and our role differs for each.
For operators (our customers)
We are the data controller for account data: we decide what is collected and why.
For WiFi end customers
When someone buys a voucher or connects to a hotspot, the operator is the data controller. We act as data processor: we process this data on the operator's behalf, following their instructions, and we do not use it for our own purposes.
In practice: if you are a WiFi customer and wish to exercise your rights over your data, contact the operator of the hotspot you use first. We will assist them in handling your request.
3Data we collect
Operator account
| Data | Purpose | Protection |
|---|---|---|
| Name | Account identification | Plain text |
| Login, notifications, support | Plain text | |
| Phone number | Contact, Mobile Money payouts | Plain text |
| City, country | Business location | Plain text |
| Password | Authentication | Hashed (bcrypt) |
Passwords are transformed by a one-way function: they cannot be recovered, including by us. If forgotten, a password is reset, never resent.
Phone number verification
If sign-up is done with a phone number (signing up by email is also possible and is not affected), a 6-digit verification code is sent to confirm it is a real, reachable number.
| Data | Purpose | Protection / Retention |
|---|---|---|
| Verification code | Confirm the number belongs to the operator | Hashed (bcrypt), expires after 10 minutes |
| Phone number | Delivery of the code | Sent to the delivery provider (WhatsApp or, as a fallback, SMS) |
The code is sent primarily via WhatsApp (Meta API). If delivery fails, a fallback SMS is sent via Africa's Talking. The phone number is shared with either provider solely to deliver the code, never for any other purpose.
Voucher purchase by an end customer
| Data | Purpose | Retention |
|---|---|---|
| Phone number | Mobile Money collection | Erased if payment fails or expires |
| Name (optional) | Sales tracking by the operator | Per operator settings |
| Payment method | Transaction routing | With the transaction |
| Transaction reference | Accounting reconciliation | With the transaction |
No banking or card data is stored by CodeWifi. Payments are handled by a specialised provider.
People connected to a hotspot
| Data | Purpose | Retention |
|---|---|---|
| MAC address | Live display of active sessions | In memory, ~17 seconds |
| Local IP address | Live display of active sessions | In memory, ~17 seconds |
| Session duration and data volume | Usage monitoring by the operator | In memory, ~17 seconds |
This data is never written to our database. It is read directly from the router at the moment the operator views their screen, held in memory for a few seconds, then automatically discarded. It also disappears whenever the server restarts.
Voucher-sharing detection (anti-fraud)
To spot a WiFi voucher being shared abusively across several devices, we count the number of distinct devices that have used the same voucher.
| Data | Purpose | Protection |
|---|---|---|
| Hashed MAC fingerprint | Count distinct devices using the same voucher | One-way HMAC-SHA256 hash, dedicated key |
The real MAC address is never stored and cannot be reconstructed from this fingerprint. It cannot identify a device outside the voucher it is tied to: it is only used to count, never to track a person. It is automatically deleted 60 days after the voucher's last use (automatic purge, no human action required).
Equipment and transactions
| Data | Purpose | Protection |
|---|---|---|
| VPN public key, internal tunnel address | Secure router connection | Technical, not personal |
| Router API password | Remote management | AES-256-GCM encrypted |
| Mobile Money payout number | Revenue payout | Plain text |
4Logs and tracking
We keep no persistent browsing logs: visitor IP addresses are not written to disk. A login attempt counter is held in memory for fifteen minutes to limit brute-force attacks, then cleared.
The platform includes no analytics, advertising or third-party tracking tools: no Google Analytics, no advertising pixel, no behavioural tracking service.
The only cookies used are strictly necessary for operation: maintaining the login session and security. No advertising cookies are set.
If a server-side technical error occurs, a diagnostic report is automatically sent to Sentry (Functional Software, Inc.), our incident-tracking tool, hosted in the European Union (Germany). This report contains the error message and its technical context — never a password, authentication token or phone number: this information is automatically stripped before sending.
6Retention periods
| Data | Period |
|---|---|
| Active operator account | For the duration of the contractual relationship |
| Closed account | 30 days for export, then deletion |
| Sold vouchers and transactions | Statutory accounting retention (10 years) |
| Reserved unpaid vouchers | Phone number erased after 3 minutes |
| Live WiFi sessions | A few seconds, in memory |
| Device fingerprint (MAC hash) | Rolling 60 days from last use, then automatic deletion |
| Phone verification code | 10 minutes, then automatically invalidated |
7Security
We apply the following measures:
- HTTPS encryption across the entire platform;
- encrypted VPN tunnel (WireGuard) for all communication with routers;
- passwords hashed with bcrypt, never stored in plain text;
- AES-256-GCM encryption of sensitive technical credentials;
- strict separation between operators: every request is filtered on account identity;
- single-use, short-lived access tokens for opening the management interface;
- rate limiting on login attempts;
- one-way hashing (HMAC-SHA256) of MAC addresses used for anti-fraud detection, with a dedicated key distinct from the one protecting technical credentials;
- automatic stripping of passwords, tokens and phone numbers before any technical error report is sent.
No system is infallible. In the event of a data breach likely to harm you, we will inform you as soon as possible and make the required notifications.
8Your rights
Under law no. 2013-450, you have the following rights:
- Access — obtain a copy of the data concerning you;
- Rectification — correct inaccurate information;
- Erasure — request deletion, subject to statutory retention obligations;
- Objection — object to processing on legitimate grounds;
- Portability — retrieve your data in a usable format.
To exercise these rights, write to partnership@oziproholding.com. We respond within thirty (30) days. Proof of identity may be requested to prevent disclosure to a third party.
You may also refer the matter to ARTCI, the data protection authority in Côte d'Ivoire.
9Minors
The platform is intended for adult professionals. We do not knowingly collect data concerning minors. Should such data be sent to us in error, it would be deleted upon notification.
10Changes to this policy
This policy may be amended to reflect changes to the platform or to regulations. Substantial changes are notified by email. The last update date appears at the top of the page.