Privacy Policy
Last updated: 27 September 2026
This policy explains what information Gepa Birr collects, how we use it, and the choices you have. It applies to the Gepa Birr mobile app and to gepabirr.leseb.et. "We" and "us" refer to the operators of Gepa Birr, based in Addis Ababa, Ethiopia.
Gepa Birr is a business tool. It is used by shop owners, managers, and cashiers to verify that a customer's payment reference — from Telebirr, Commercial Bank of Ethiopia (CBE), Dashen Bank, or Bank of Abyssinia — has actually been received before a sale is completed. Everything below flows from that single purpose.
1. What we collect
- Phone numbers. Owners sign in by phone using a one-time SMS code. We store the phone number so we can recognise the account on the next sign-in.
- Business details you enter. Business name, business code, category, plan, branch names, and branch addresses.
- Staff records the owner or manager creates. Full name, username, role (owner, manager, waiter), and the branch a staff member is assigned to.
- Staff PINs. Staff sign in with a PIN they set themselves. PINs are hashed on our servers using an industry-standard one-way function; we never store them in plaintext and cannot recover a forgotten PIN — only reset it.
- Payment references submitted for verification. When a receipt is scanned, we transmit the reference (Telebirr transaction number, CBE token, Dashen or Abyssinia transaction number) to the corresponding bank's verification interface. We record the reference, the result, the timestamp, which user scanned it, and which branch they belong to.
- Subscription payment references and screenshots. When an owner pays for their Gepa Birr subscription, they submit the payment reference and may optionally attach a screenshot of the payment as supporting evidence. Screenshots are stored in Cloudflare R2 object storage.
- Approximate location. We derive an approximate location from the IP address a request came from, and record it against the audit log entry for a scan or a sensitive account change. We do not use device GPS.
- Diagnostic crash reports. If the app crashes, Google Firebase Crashlytics captures a non-fatal stack trace and basic device metadata (OS version, device model, app version). These reports do not include your phone number, receipts, or business data.
2. What we do with it
- Verify receipts against Telebirr, CBE, Dashen, and Bank of Abyssinia in real time.
- Detect and flag duplicates, tampered receipts, and payments to the wrong account.
- Show you a history of scans, filterable by branch and cashier, so you can audit what happened.
- Manage staff access — who can sign in, from where, with what role.
- Process subscription billing and confirm that a subscription payment reached our merchant accounts.
- Investigate abuse, disputes, and support requests you send us.
- Improve app stability using non-identifying crash reports.
3. What we do not do
- We do not run ad networks or advertising SDKs in the app.
- We do not sell, rent, or trade personal data to third parties.
- We do not use third-party analytics that build a profile on you across apps.
- We do not access your device's contacts, photos, files, or location beyond what is described above.
4. Third parties who process data on our behalf
- Cloudflare, Inc. — object storage (R2) for subscription payment screenshots and dispute attachments; edge networking for the API.
- Google LLC (Firebase) — push notifications delivery and Crashlytics crash reports.
- The banks and mobile-money operators we integrate with — Ethio Telecom (Telebirr), Commercial Bank of Ethiopia, Dashen Bank, and Bank of Abyssinia. We call their verification interfaces with only the transaction reference. We do not send them your business's other information.
- An SMS delivery provider — to deliver the one-time sign-in code to your phone.
Each of these processes data only to deliver its service to us. We do not authorise them to use it for any other purpose.
5. Where data is stored
The primary Gepa Birr database and API run on infrastructure operated by us in a Cloudflare-fronted environment. Object storage is Cloudflare R2. Crash reports live in Google Firebase. Data may be processed in data centres outside Ethiopia; we do not target a specific residency.
6. How long we keep it
- Session tokens — until you sign out or the token expires.
- Business, staff, branch, and receipt records — for as long as the business account is active. Business owners can access historical receipts through the app and can export them at any time.
- Deleted accounts — when you request account deletion, we remove personal identifiers and business content within 30 days. Aggregate, non-identifying counts of verification activity may be retained for fraud-prevention analysis.
- Crash reports — Firebase Crashlytics retention (90 days by default at Google).
7. Your rights
- Access. You can see your own account details in the app under Profile, and receipt history under Receipt history.
- Correction. Owners can edit business, branch, staff, and payment-account details directly in the app.
- Deletion. Owners can request full account and data deletion at gepabirr.leseb.et/delete-account. Staff members whose account was created by an owner should ask that owner to remove them; the owner can also reset their PIN or deactivate them from the Staff screen.
- Withdraw consent. Uninstalling the app stops any further data being sent from your device.
- Complaint. You can raise concerns with us at the contact addresses below.
8. Children
Gepa Birr is a tool for registered businesses. It is not directed at anyone under the age of 18, and we do not knowingly create accounts for minors.
9. Security
Traffic between the app and our servers is encrypted with TLS. Passwords and PINs are stored as one-way hashes, never in plaintext. Access to production data is limited to a small number of engineers and logged. Despite these controls, no system is perfectly secure; if we become aware of a breach that affects you, we will notify you through the app or by SMS.
10. Changes to this policy
If we make a material change, we will update the "last updated" date at the top and, for changes that expand what we collect or how we use it, notify owners inside the app before the change takes effect.
11. Contact us
Telegram support bot: @gepabirrbot
Email: support@leseb.et
Address: Gepa Birr, Addis Ababa, Ethiopia.