LW LoanWise Hub Your account and your data

Privacy notice

How LoanWise Hub handles your personal data. Last changed 27 August 2026.

Who holds your data

LoanWise Hub is the data controller for the information described here, and is responsible to you for it under the Data Protection and Privacy Act 2019. Lending activity is conducted under the Tier 4 Microfinance Institutions and Money Lenders Act 2016 and is supervised by the Uganda Microfinance Regulatory Authority.

What we never collect

A commitment, not a preference

We do not read, upload, store, infer from or score any of the following, and the app never asks your handset for permission to reach them:

  • Your contact list, or anybody in it.
  • Your call log.
  • The content of your text messages.
  • Your photo gallery or the media on your device.

This is not a setting that can be turned on later. Collecting any of it to pursue a debt is forbidden by the Uganda Microfinance Regulatory Authority's digital lending guidelines (s.9.3), by the Data Protection and Privacy Act 2019, and by Google Play's Personal Loans policy. If we ever ask you for one of these permissions, something has gone wrong and you should refuse it and tell us.

What we do collect, and why

  • Who you are. Your name, date of birth, national identification number, address, district, occupation and income band. We are required to establish this before lending to you, and the identification number is held encrypted; no member of staff sees more than its last four digits without a specific, recorded reason.
  • How to reach you. Your mobile number and e-mail address, for the loan itself and for the notices the law requires us to send.
  • Your guarantors. The people you name and the contact details you give for them — supplied by you, one at a time, with their knowledge. We do not obtain them any other way.
  • Your borrowing. Applications, decisions, the reasons for them, the loan, its schedule, and every payment. This is the record of the agreement between us and it is also what a regulator inspects.
  • Your device and your sessions. The make of handset, the app version, the network address a request came from and when you signed in. This is how account takeover is detected, and it is kept for that reason and no other.
  • What you say to us. Support conversations, complaints, and the notices we sent you.

Who we share it with

  • Licensed credit reference bureaux, as the law requires of a regulated lender.
  • Mobile money operators, to the extent needed to move a payment.
  • The Uganda Microfinance Regulatory Authority, the Bank of Uganda and the Financial Intelligence Authority, where they require it.
  • A court or law enforcement agency, where compelled.

We do not sell your data, we do not share it for anybody else's advertising, and we do not pass your details to a debt collector who is not bound by this notice.

How long we keep it

These are the periods the platform actually enforces — the table below is read from the rules the disposal process runs on, not written out separately. A period runs from the point the record is closed, not from the day it was created.

What Kept for Then Because
Applications, scores, inputs and decision records seven years moved to a sealed archive that only a compliance officer can open, and deleted from there FR-SCR-110; ability to reconstruct any decision on regulatory request
Complaints register seven years moved to a sealed archive that only a compliance officer can open, and deleted from there UMRA DLG s.17.2
Consent grants and withdrawals seven years moved to a sealed archive that only a compliance officer can open, and deleted from there Data Protection and Privacy Act 2019; evidence of lawful basis
Credit reference bureau enquiries and submissions seven years moved to a sealed archive that only a compliance officer can open, and deleted from there Financial Institutions (Credit Reference Bureau) Regulations 2022
Customer profile seven years stripped of everything that identifies you, leaving figures that cannot be traced back to a person Retained while any financial record subsists, then anonymised
Identity document and biometric images seven years deleted outright AML/CFT record keeping; NFR-PRV-020 data minimisation on expiry
Identity verification results seven years moved to a sealed archive that only a compliance officer can open, and deleted from there AML/CFT record keeping
Key Facts statements and acknowledgements seven years moved to a sealed archive that only a compliance officer can open, and deleted from there FR-PRC-030/040; UMRA DLG s.12.4
Loans, ledger entries, transactions and payment attempts seven years moved to a sealed archive that only a compliance officer can open, and deleted from there NFR-MNT-080; tax and UMRA books-and-records obligations
Staff and agent accounts seven years moved to a sealed archive that only a compliance officer can open, and deleted from there Employment and audit obligations
Cases, contact attempts, promises and field visits five years moved to a sealed archive that only a compliance officer can open, and deleted from there UMRA DLG s.15 conduct evidence
Guarantor particulars three years deleted outright Retained three years after the last loan closes
Opt-out and unsubscribe records three years kept, because deleting it would mean losing the record that you asked not to be contacted FR-MKT-140: not less than twelve months; held longer to honour the opt-out
Support tickets three years moved to a sealed archive that only a compliance officer can open, and deleted from there Service evidence
Raw operator callbacks and third-party payloads two years deleted outright Dispute evidence window
Sent and suppressed messages with rendered content two years deleted outright Uganda Communications (Text and Multimedia Messaging) Regulations 2019
Leads and incomplete registration attempts two years deleted outright NFR-PRV-020 data minimisation
USSD sessions and channel telemetry one year deleted outright Operational troubleshooting only

What you can ask us to do

Under the Data Protection and Privacy Act 2019 you may ask for a copy of what we hold, ask us to correct it, ask us to delete it, object to a decision made about you by a machine, or withdraw a consent you gave. We must answer within the statutory period, and we answer free of charge.

Where a request would destroy a record we are legally required to keep, we will tell you which part we cannot delete and why, rather than refusing the whole request or quietly doing less than we said.

Decisions made automatically

Your application is scored. The score uses the information you gave us, your history with us, and bureau data — and nothing taken from your handset. You are entitled to be told the main reasons for a decline, to ask for it to be looked at by a person, and to have that reconsideration recorded.

Complaints

Complain to us first — every complaint is registered and answered. If you are not satisfied, you may complain to the Personal Data Protection Office, and to the Uganda Microfinance Regulatory Authority about the conduct of the lending itself.

Where this notice describes a retention period, that period is generated from the platform's live configuration at the moment you loaded this page.

Privacy notice  ·  Delete your account and data