BoldTech AI logo

Susu Cocktail

Privacy Policy

Susu Cocktail Privacy Policy

Effective date: 30 September 2026
Operator: Bold Technology and AI, Ghana
Policy URL: https://boldtechai.com/susucocktail/privacy
Privacy contacts: info@boldtechai.com and support@boldtechai.com

About this policy

This policy explains how Susu Cocktail handles information when you create an account, participate in an association, record contributions and payouts, receive notifications, or use account-verification and recovery features. Bold Technology and AI operates the service in Ghana.

Susu Cocktail is an association record-keeping app. Members make mobile money payments outside the app through their network provider's payment interface. The app records information submitted by members and decisions made by chairmen. It does not hold members' funds, collect MoMo PINs, read payment-confirmation SMS messages, or automatically verify transfers with a mobile money provider.

Information handled by the service

Account and verification information

We receive the display name, phone number, password and any email address you provide through supported account features. The backend stores a password hash rather than your readable account password. It also stores account identifiers, verification status and account timestamps.

An optional recovery email must be verified while you are signed in before it can be used to reset your password. Verification and recovery involve temporary codes, challenge identifiers, expiry times, attempt counts and, when supplied, messaging-provider reference identifiers. Locally checked recovery codes are stored as hashes; messaging providers necessarily receive the codes contained in messages they deliver.

Sign-in tokens keep you signed in. If you enable “Remember me,” the app saves your selected country and phone number on your device to fill in the sign-in form.

Association and financial records

We store association names and settings, memberships, member roles, membership status, joining and leaving dates, member order, contribution schedules, contribution amounts, payment methods, submitted transaction IDs, confirmation or rejection status, confirmation timestamps, payout records and ledger entries. These records are linked to the relevant association and member identifiers.

Chairmen can provide a receiving wallet's account name, MoMo number and network. The backend also supports association payment-account details such as purpose, contact phone, address, start date and member count when supplied. Receiving-wallet details are visible to association members so they can check the intended recipient before paying.

Chairmen can look up registered members using a phone number they already have and add them to an association. They can also submit a phone number to invite someone who has not registered. Invitation records include the phone number, association, inviting chairman and invitation status. Consequently, we may receive your phone number from a chairman before you create an account.

Notifications and device information

For push notifications, the app and backend handle an app-installation identifier, a notification token, the device platform, the associated account and reminder preferences. The service also stores in-app notification records, including their recipients, association, category, message and creation time. Read status and related notification preferences are stored on the device.

Messages can contain personal and financial information. For example, a chairman's payment-review alert includes the submitting member's name, contribution amount, payment method and transaction ID. Firebase processes that notification content to deliver the alert. Depending on your phone settings, it may be visible on the lock screen.

Security, connection and support information

Account-verification audit records can include a phone number or email address, the action attempted, its outcome, IP address, user-agent information and security metadata. The backend also maintains operational and error logs. Hosting and messaging services process connection and delivery information as part of providing their services.

When you email us, we receive your email address and the information you include. Do not send your account password, verification code or MoMo PIN in a support message.

How the information is used

The app uses information to:

  • Create accounts, authenticate members, verify contact details and support password recovery.
  • Manage associations, memberships, receiving-wallet details and contribution schedules.
  • Record submitted payments, enable chairman review, calculate balances and maintain contribution and payout history.
  • Deliver association updates, payment-review alerts and contribution reminders.
  • Produce the exports and local backups that you enable or request.
  • Apply access controls, limit repeated verification attempts and diagnose service problems.

We do not sell member data, use it for marketing, or share it with other businesses for purposes outside the association features and service providers described in this policy. The reviewed app does not contain advertising, behavioural-analytics or crash-reporting SDK integrations. Firebase is integrated for cloud messaging.

Who can see information

Association members and chairmen

Members of an association can see its member names, group activity, contribution progress, financial history and receiving-wallet details. Chairmen administer memberships and review payment submissions. The contribution API discloses a submitted transaction reference to its submitting member and the association's active chairmen, rather than to every member.

Other members' profile phone numbers and email addresses are withheld from the member-directory responses. This does not hide a receiving-wallet number that a chairman deliberately publishes to the association. A chairman who supplies a phone number for member lookup can receive a matching registered member's display name.

Information already shared through an association, a notification or an export may also be held by its recipients. Deleting an account cannot recall those copies.

Service providers

The reviewed service uses the following providers:

Provider Purpose and information involved
Hostinger Hosts the backend and its stored account, association and financial records. Hostinger SMTP is configured for verification and recovery email; when mail is sent, the email service receives the recipient address, message contents and delivery information.
Google Firebase Cloud Messaging Delivers push alerts using installation and notification identifiers. It receives notification titles, message bodies and routing identifiers, which can include account, association and event identifiers. Google also processes technical service information, including IP-related information, as described in its Firebase privacy documentation.
Arkesel The configured SMS and phone-verification integration. It receives destination phone numbers, verification or invitation message contents, and related request and delivery information.

Provider information is available in Hostinger's privacy policy, Google's Firebase privacy documentation and Arkesel's privacy policy.

Hosting and messaging providers may process information outside Ghana. This policy does not promise that all information stays within Ghana or identify an unverified storage location.

Mobile money providers and apps you choose

Opening the payment menu passes a dialling request to your phone's external interface. You complete the transaction through your network or mobile money provider. Susu Cocktail then receives only the payment information submitted to it by members or chairmen; it does not receive your MoMo PIN or read the provider's confirmation SMS.

When you export or share records, the destination you select receives the exported information. That destination and your mobile money provider handle their own services under their own privacy terms.

Permissions and local storage

The Android release uses internet and network-state permissions to communicate with the backend and messaging services. It requests notification permission on Android versions that require it. Its included libraries also declare permissions for receiving push messages, waking the device for background work, vibration, boot-related scheduling and exact-alarm scheduling on supported older Android versions.

The reviewed Android release does not request access to your contacts, location, camera, microphone, SMS inbox or call logs. Verification fields can accept an operating-system-suggested one-time code; this does not grant the app general access to your SMS messages. The app opens the phone's external payment or dialling interface rather than making payments itself.

On supported Apple builds, the app uses notification permission and background notification or fetch capabilities; push delivery also involves Apple's notification service.

The app stores cached association records in a local database, sign-in credentials such as tokens in platform secure storage, and preferences in local settings. Optional automatic exports create dated JSON backup files in the app's documents directory. Exports may include association details, member records, contributions and ledger history.

Android's automatic app backup is disabled in the reviewed release. The app's own export feature is separate from Android backup. Local database and export files are not separately encrypted by the app, so protect your phone and any files you copy or share.

The account-recovery and deletion webpages use session and request-security mechanisms, including cookies, to process forms. This app policy does not describe unrelated browsing or tracking features that may be present elsewhere on the BoldTech AI website.

Retention and deletion

Account details remain in the active service while the account exists, subject to the deletion process below. Shared association records are kept while the association operates and for 12 calendar months after it closes. A daily cleanup then deletes the association and its related membership, contribution, payout, ledger, receiving-wallet, invitation and notification records. Removing one member does not start the association's retention period. For associations already closed when closure-date tracking was introduced on 30 September 2026, the 12-month period starts on that introduction date because their original closure dates were not recorded.

Application log files and failed background-job records are scheduled for deletion after 30 days. Daily log rotation means deletion occurs at file boundaries rather than at the exact moment each entry reaches 30 days. The legacy application log kept before rotation was introduced has a 30-day transition period from its archival date. These controls do not govern Hostinger's separate webserver or hosting control-panel logs.

Specific association records or security records may be retained longer where necessary for a documented unresolved dispute, legal requirement or security incident. Such holds have a recorded reason and expiry date and must be renewed explicitly if still necessary. Normal deletion rules apply when a hold ends.

The backend has a daily verification-cleanup task. Its current configuration selects verification audit records older than 30 days for deletion. It also removes expired recovery-email challenges, phone-verification records more than a day past expiry, expired email-verification records and expired verification locks. These are scheduled cleanup rules, not guarantees of deletion at the exact expiry time, and they do not set the retention period for hosting backups or providers' own records.

Deleting your account

Use Settings → Delete account in the app, or the Susu Cocktail account-deletion page. The deletion flow requires your current password and confirmation. Contact us if you cannot access your account.

Account deletion removes your profile name, phone number, email, recovery email and password from the active account record; the retained record is labelled “Deleted member.” It disables memberships and removes sign-in tokens, push registrations and the related verification and invitation records addressed by the deletion process.

Shared membership, contribution, payout and ledger history remains linked to retained identifiers so the association keeps its records. Transaction references, receiving-wallet names and numbers, and information embedded in shared records or messages may remain identifiable. This is not complete anonymisation of every record about you. If you are an association's last active chairman, deletion closes that association.

The app attempts to clear its active local database and remembered sign-in details after successful in-app deletion. This does not erase copies held by other members, previously exported files or app-generated backup files. Deleting through the website does not remotely erase cached files on every device. Uninstalling the app or clearing its local storage does not, by itself, delete the server account.

Deleted information may still exist in hosting backup copies for some time. Our hosting company, Hostinger, controls when those copies and its own technical server logs are removed. We have not confirmed their exact retention periods. The app's cleanup rules described above do not control those copies or logs. Deleting information from the app also does not remove copies in other providers' systems or previously downloaded exports. Contact us if you have questions about information that remains after an account-deletion request.

Security and your choices

The production app communicates with its backend over HTTPS, and the Android release disables cleartext network traffic. The backend uses password hashing, authenticated API requests, role-based access checks and verification-attempt limits. These measures reduce risk but do not make storage, transmission or shared exports risk-free.

You can decline or disable phone notifications, control lock-screen previews, change reminder preferences, turn optional automatic exports off, and clear remembered phone details. Disabling notifications does not delete your account or in-app financial records. Notification permission controls alert display; it is not a promise that all messaging-library network activity stops.

You can contact us to request access to or correction of information, ask about its use or retention, or seek help with deletion. We may need information sufficient to verify that a request concerns your account. Do not provide your password, verification code or payment PIN for that purpose.

Age eligibility

Susu Cocktail is intended only for people aged 18 or older. People under 18 must not create an account or use the service. If you believe an account belongs to someone under 18, contact us using the details below.

Contact

For privacy questions or requests concerning Susu Cocktail, contact Bold Technology and AI, Ghana:

Identify Susu Cocktail in your message and describe your request. Include only the information needed to help us locate the relevant account or record.

WhatsApp