Enehid Privacy Policy
Last updated: 2026-08-02
Policy owner: Enehid Product and Engineering
Contact: privacy@enehid.com
Review cadence: Quarterly or after material data-flow changes
This Privacy Policy explains how Enehid ("Enehid", "we", "us", "our") collects, uses, stores, and shares information when you use the Enehid mobile application, public websites (including enehid.com and enehid.com/pitch), wallet web pages, and related services (the "Service").
Enehid is built to help people discover places in Addis Ababa, contribute to an accurate city map, and stay active through gamified rewards. We process data primarily to operate and improve the Service, reward health and fitness, and understand—at an aggregated level—how the city is used so we can improve maps, listings, and features.
If you do not agree with this Policy, please do not use the Service.
1. Scope
This Policy applies to personal data processed through the Enehid Service, including account and profile features, maps and navigation, place submissions and moderation, reviews and favorites, points and credits economy, optional step-based fitness rewards, notifications, advertising (where shown), analytics, and support.
On our public marketing sites we use Google Analytics 4 to measure aggregate traffic (for example page views and referrers on enehid.com and the pitch deck). Google may set cookies or similar identifiers as described in Google’s policies. We configure IP anonymization where available. This website analytics is separate from in-app Firebase Analytics.
2. Data We Collect
2.1 Data you provide directly
- Account information: email address and authentication identifiers when you sign in (including Google or Apple Sign-In); optional display name and profile photo;
- Profile and gamification: badge and title preferences, joke display name shown on reviews (we do not require your legal name on public reviews), leaderboard-visible totals such as lifetime points earned and level;
- User-generated content: place submissions, photos, videos, descriptions, operating hours, reviews, star ratings, comments, and favorites;
- Support: messages and optional screenshots you send through Help Center or support channels;
- Payments (optional): if you buy credits or redeem value through supported payment flows (for example Telebirr), we process order references, credit-pack selections, and phone numbers you provide for payout—payment partners handle card/wallet processing under their own policies.
2.2 Data collected automatically with your permission or as part of using the Service
- Location (optional): precise or approximate GPS location when you grant permission—used to show nearby places, power the map, calculate routes and walking/driving navigation, estimate travel distance for movement-based rewards, and attribute activity to places and sub-city areas;
- Motion / step data (optional): if you enable Walk Rewards, we read your daily step total to award fitness points. On iPhone we prefer Apple Health (HealthKit) when you grant access; on Android we prefer Health Connect when installed and permitted. If those are unavailable, we fall back to device motion sensors (Activity Recognition on Android, Core Motion on iOS). Step totals are synced to our servers to calculate rewards and prevent abuse; continuous GPS is not required for this feature;
- Background step sync (Android, optional): when Walk Rewards is enabled on Android, a low-priority foreground notification may appear while the app keeps syncing your daily step total for points. You can turn off Walk Rewards in Profile to stop this;
- Device and app information: device model, operating system, app version, language, and similar technical metadata;
- Diagnostics: crash reports and performance logs (for example Firebase Crashlytics) to fix bugs and improve stability;
- Usage and engagement: in-app events such as searches, filters applied, navigation starts, route outcomes, shares, and screen views (for example Firebase Analytics) to understand feature use and improve the product;
- Camera, microphone, and photo library (when you use those features): to capture or upload place media and support attachments.
2.3 Data generated by your use of gamification and economy features
- Points balance, lifetime points earned, credits balance, level, and transaction history (earns and spends);
- Records of point spends on actions such as new reviews, review edits, and photo uploads, including daily review limits per place;
- Step sync records (calendar day and steps synced that day) for Walk Rewards;
- Travel and movement reward metadata (distance and transport mode such as walk or drive when navigation completes);
- Achievement and activity logs tied to your account.
2.4 Data from third parties
If you use third-party login providers (such as Google or Apple), we receive account identifiers and basic profile information they share according to your provider settings. Map, ads, analytics, and payment partners may also process limited data as described in Sections 5 and 6.
3. How We Use Data
We use personal and usage data for the following purposes:
3.1 Core app functionality
- Authenticate you and maintain your account;
- Display maps, places, events, reviews, favorites, and search results;
- Provide navigation, directions, and place detail experiences;
- Operate submissions, moderation, and support workflows.
3.2 Gamification, health, and fitness rewards
- Operate the points and credits economy (earning, spending, converting, and redeeming where enabled);
- Reward engagement such as reviews, favorites, submissions, daily check-in, and navigation;
- Walk Rewards: convert your optional daily step count—read from Apple Health, Health Connect, or device sensors—into in-app points to encourage walking and exploration. A step counter may also appear on the home map while you browse;
- Movement rewards: award points based on verified travel distance when you complete walking or driving navigation to a destination;
- Display leaderboards, levels, badges, and profile stats.
3.3 Growing and improving Enehid (including Addis Ababa map development)
- Improve place data quality, search relevance, and map accuracy for Addis Ababa and surrounding areas;
- Understand aggregated patterns—such as which places, categories, and sub-city areas receive more interest, reviews, favorites, navigation, and open-venue activity—to prioritize map coverage, clustering, and product decisions;
- We do not sell your personal identity or precise real-time location to third parties for advertising. City-level and venue-level insights are used internally to improve the Service and grow the platform.
3.4 Safety, integrity, and legal compliance
- Detect abuse, fraud, and policy violations (including duplicate point claims and profanity moderation);
- Enforce rate limits and economy rules;
- Meet legal, regulatory, and contractual obligations.
4. Aggregated and Pseudonymous Data
Many features use aggregated or pseudonymous data so we can improve the city map without exposing private details unnecessarily:
- Public reviews show a generated joke display name, not your email or legal name;
- Place-level statistics (review counts, average ratings, weekly activity) are computed from many users;
- Sub-city and map overlays may reflect combined venue density and open-status signals—not your individual real-time location on a public map;
- Analytics reports typically summarize events (for example “navigation started”) without publishing your identity to other users.
We may retain aggregated statistics after account deletion where they no longer identify you.
5. Permissions You Control
The app requests optional permissions only when needed:
- Location: map, nearby discovery, and navigation;
- Apple Health / Health Connect / Motion: Walk Rewards daily step totals (read-only on health platforms);
- Notifications (Android): optional foreground notification while Walk Rewards background sync is active;
- Camera / microphone / photos: submissions and support attachments;
- Notifications: alerts you opt into.
You can decline or revoke permissions in device settings. Some features will not work without the relevant permission (for example step rewards without motion access).
6. Legal Bases (where required)
Depending on jurisdiction, we process data based on consent (optional permissions and step tracking), contract performance (providing the Service), legitimate interests (security, fraud prevention, aggregated product improvement, city map development), and legal obligations.
7. Data Sharing
We do not sell personal data.
We may share data with:
- Infrastructure providers (for example Google Firebase for auth, database, functions, storage, analytics, crash reporting);
- Health platforms (read-only, optional): Apple HealthKit on iOS and Google Health Connect on Android process step-count permission requests on-device; we receive only the daily step totals you authorize;
- Map providers (for example Google Maps, Mapbox) when you use map and routing features;
- Authentication providers (Google, Apple) when you choose those sign-in methods;
- Advertising partners (for example Google AdMob) where ads are shown;
- Payment partners (for example Telebirr) when you initiate purchases or redemptions;
- Legal authorities when required by law or to protect rights and safety;
- Professional advisors or acquirers in a merger, acquisition, or similar transaction.
Service providers process data under contractual obligations appropriate to their role.
8. Advertising
If ads are shown, ad partners may process device and ad-related identifiers for delivery, frequency control, and measurement according to their policies and your platform settings. Premium or configured ad-free periods may reduce ad exposure.
9. International Transfers
Your data may be processed in countries other than Ethiopia, including where our cloud providers operate. Where required, we use appropriate safeguards for cross-border transfers.
10. Data Retention
We keep data only as long as necessary for service operation, economy and fraud records, security, legal compliance, and backup cycles. When data is no longer needed, we delete or anonymize it. Some aggregated map and analytics statistics may be retained in non-identifying form.
11. Security
We use reasonable safeguards, including encrypted transport (HTTPS/TLS), access controls, server-side validation for points and economy actions, and platform security features. No method of storage or transmission is completely secure.
12. Your Rights and Choices
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or object to certain processing, and withdraw consent where processing is consent-based.
You can:
- Manage location, motion, camera, and notification permissions in device settings;
- Disable Walk Rewards in the app Profile section;
- Sign out to stop account-linked syncing;
- Request account deletion (see Section 13).
Contact privacy@enehid.com for privacy requests.
13. Account Deletion
You may request account deletion from the app or by contacting us. We will delete or de-identify personal data associated with your account, subject to lawful retention (for example payment dispute records) and aggregated non-identifying statistics.
See Delete Account for process details.
14. Children
The Service is not directed to children under the minimum age required by applicable law. If we learn that data was collected in violation of this requirement, we will take appropriate deletion and account measures.
15. Changes to this Policy
We may update this Policy to reflect legal, technical, or product changes. Material updates may be communicated in-app or by other appropriate channels. The “Last updated” date above shows the latest revision.
16. Contact
For privacy questions, requests, or complaints:
Email: privacy@enehid.com
In-app: Profile → Privacy & security, or Help Center / Support