Privacy Policy

Closed Beta • Last Updated: 15 September 2026

The short version. To make Relay work, we verify who you really are — which means we collect your government ID and a selfie, which we delete once it has been checked. We record what happens on every job, and we keep those records permanently, even if you delete your account. If someone commits fraud or theft, we can hand that record to the police. That permanence is the entire point of Relay: it is what makes cheating expensive. If you are not comfortable with it, please do not use Relay.

1. Who we are

Relay is a marketplace that connects customers with verified independent runners for errands, deliveries and cross-border collections, operating primarily in Zimbabwe with supported corridors to South Africa. In this policy, "Relay", "we" and "us" mean the operators of the Relay platform; "you" means anyone who uses the Relay app or this website.

Relay does not hold, move or process the money you pay a runner. Payments happen directly between you and the other person. Because of that, we never collect or store your card numbers or bank details.

2. What we collect

Account details. Your name, email address, phone number, date of birth and gender, as you enter them at sign-up.

Identity verification. If you register as a runner — or as a customer who wants to post higher-value jobs — we collect a photograph of your government-issued ID document (national ID or passport), the document number, and a selfie used to check it matches the document. This is mandatory for runners before accepting any job.

Phone and email verification. We send a one-time code by SMS to confirm your number belongs to you, and a link or code by email to confirm your address belongs to you. Each is used only to prove the contact detail is yours.

Location. Runners' GPS location is recorded only while a job is actively accepted and in progress. Relay does not track your location in the background, when you are offline, or between jobs.

Places you choose. When posting a job you can search for an address or drop a pin on a map, and you can ask the app to centre that map on where you are. Your device asks your permission first, the position is used at that moment to fill in the job's address, and it is not recorded as a separate trace of where you have been. Declining leaves the map fully usable — you can search or scroll to the right place instead.

Job records. For each job: the title and description, what kind of errand it is, the agreed price and currency, how you agreed to pay, roughly how much the runner is expected to spend on your behalf, when it is needed by, the addresses, timestamps for each stage, and which parties were involved.

Who is receiving it. If somebody other than you is receiving the delivery, you can give us their name, a contact number and a note for the runner on arrival. Giving a number is optional, and section 2a explains what we expect of you before you share someone else's.

Messages and evidence. Chat messages exchanged in a job, and photographs attached to it. We ask for photographs at the points where a job changes hands — when a runner collects, when they hand over, and when a customer receives — as well as any you upload when raising or responding to a dispute. These prompts are requests, never requirements: you can decline every one of them and still complete the job.

Technical information. App version, and standard server logs (including IP address) generated when your device contacts our servers.

2a. Information about people who are not Relay users

This one deserves its own heading, because most privacy policies quietly skip it.

Errands involve other people. To get a job done you will often tell us about someone who has no Relay account and has never read this policy — the relative receiving a parcel and their address, the shopkeeper to collect from, a contact number to call on arrival.

Photographs deserve their own warning here, because we now ask for them at collection and handover on ordinary jobs rather than only when something has gone wrong. A picture taken at somebody's gate can capture their home, their vehicle, or them. Point the camera at the parcel, not at the person or their doorway, and if somebody asks you not to photograph them, do not — every one of these prompts can be declined and the job still completes.

What we remove from a photograph before storing it. Phones record more than the picture: almost every camera writes the exact coordinates the photograph was taken at, the time, and the device into the file, where no viewer shows it and any program can read it. A photograph taken at a customer's door therefore carries that door's location. We strip that out on arrival, before the file is stored, so what is kept is the picture and not the place — for job photographs and for identity documents alike. This happens on our servers rather than on your phone, so it holds however old your app is.

We receive that information from you, and we hold it as part of the job record. Specifically:

  • Most of it is simply what you typed — the job description, an address, something said in a message. Where a job names the person receiving the delivery, we keep their name, number and arrival note against that job on their own, so a runner standing at the right gate can find them without reading back through a conversation. Either way it belongs to that one job and nowhere else. We do not build a record of people who are not Relay users, we do not link their details from one job to another, and we do not use them to market anything to anyone.
  • It is visible to the Runner or Client on that job, because they need it to complete it, and to our Trust & Safety staff if the job is disputed.
  • It is subject to the same permanent retention as the rest of the job record, described in section 7.
  • It may appear in an incident packet provided to police, described in section 4.

If you are entering someone else's details: share only what the job actually needs, and tell them you have done so. Do not enter another person's ID number, financial details or health information. Our Terms make this your responsibility, and we mean it.

If you are that person — someone whose details ended up in a Relay job without you signing up — you can contact us at [email protected] to ask what we hold about you and to object to it. We will be straightforward with you, including about the limits: where your details form part of the evidence record of a disputed job, we may be unable to remove them, and we will explain why rather than pretend otherwise.

3. Why we collect it

  • To verify real identities. Reputation is worthless if identities are fake. ID and selfie checks are what make a Relay runner different from an anonymous stranger.
  • To run the marketplace. Matching jobs to runners, showing a job's progress, and letting both sides communicate.
  • To resolve disputes. When something goes wrong, timestamps, GPS check-ins, chat history and uploaded evidence are what let a human review what actually happened.
  • To deter and act on fraud. Permanent records, and the ability to produce them, are the consequence that makes dishonesty costly.
  • To meet legal obligations where we are required to retain or produce information.

4. Who can see it

Other users see very little. The other party to a job sees your display name, your reputation, your verification badge and the messages you send them — plus whatever you put in the job description, which is why section 2a matters. They never see your ID document, your selfie, your document number, or your date of birth.

People at the door. While a job is under way, either of you can show a screen that displays your first name, whether Relay has checked your identity, and a code that both of you see. It exists so the person at the gate and the person on the bike can each tell the other is who they claim to be. Anyone you show it to — a security guard, a receptionist — sees that first name and nothing else. Your surname, contact details, documents and job history are not on it.

Relay's Trust & Safety staff can access verification documents and job records, but only to review a verification submission or investigate a dispute. Every such access is logged against the staff member who made it.

Law enforcement. Where our Trust & Safety team substantiates fraud, theft or a serious safety incident, we compile an "incident packet" — the verified identity details of the account holders involved, the full job record, timestamps, GPS check-ins, chat history and any photographic evidence — and this may be provided to the police, either at your request as a victim, or on our own initiative in serious or repeated cases. We keep a log of every such referral.

Because a packet reproduces the job record as it stands, details of third parties named in that record — a recipient, a pickup contact, someone visible in an evidence photo — will appear in it too. We verify account holders only, so anything in a packet about a non-user is unverified information supplied by a user, and is labelled that way rather than presented as fact we have confirmed.

5. Who processes it for us

  • Google Cloud — hosts our servers, our database and our files. Where each of those sits is worth being exact about, so: your job and account records are stored in Google Cloud Firestore in africa-south1 (Johannesburg); the servers that process them run on Google Cloud Run in europe-west1 (Belgium); and identity documents, selfies and the photographs attached to jobs are stored encrypted in Google Cloud Storage in us-central1 (Iowa, United States). Your records therefore sit in South Africa, are processed in Europe, and your documents and photographs are held in the United States.
  • ESMS Africa — delivers the one-time SMS codes used for phone verification. They receive your phone number for that purpose.
  • Resend — delivers the emails we send to verify your address. They receive your email address and the contents of that message. Resend processes this outside Zimbabwe and South Africa, in the United States and the European Union, under their own data protection commitments.
  • OpenStreetMap — provides the map you see when choosing a place, and turns addresses into map positions and back again. When you use the map, your device requests map images from them, which necessarily tells them roughly which area you are looking at. Address lookups are sent through our servers rather than from your device. We send no name, account or job details with either.
  • Netlify and Cloudflare — host and serve this website, and process standard request logs and IP addresses. Cloudflare may set a __cf_bm cookie for bot management.

About your information leaving the region. Zimbabwe's Data Protection Act and South Africa's POPIA both allow personal information to be sent abroad, but they expect us to say so plainly rather than bury it, and to be satisfied it stays protected. So, plainly: some of your information is held and processed outside Zimbabwe and South Africa, as set out above. It sits with established providers under their own contractual data protection commitments, it is encrypted, and we send them only what each one needs to do its job — an email address to the company that sends email, a phone number to the company that sends messages. We are reviewing whether the files currently held in the United States should be moved closer to home, and if we move them we will say so here.

We do not sell your personal information, and we do not share it with advertisers. There are none.

6. How we protect it

ID documents and selfies are encrypted at rest using AES-256-GCM before being stored, and are never displayed to other users. Access to our systems is authenticated, sessions can be revoked, and administrative actions are recorded in an audit log.

No system is perfectly secure, and we will not pretend otherwise. If a breach affects your personal information, we will tell you.

7. How long we keep it — please read this

Job records are permanent and cannot be deleted — not by you, and not by us. A completed, cancelled or disputed job stays on file indefinitely. This is deliberate. Those records are the evidence trail that makes Relay's disputes and police referrals possible, and a platform where bad actors could erase their history would offer no protection at all.

If you close your account, your profile is deactivated and you can no longer sign in, but your job history, disputes and verification record remain.

If you are permanently banned for substantiated fraud, we keep a one-way cryptographic hash of your ID document so the same document cannot be used to open a new account. We keep the hash, not a readable copy of the document number.

Your ID photograph and selfie are different, and we delete them. They exist so a person can check that your document is real and that it is you. Once that check is done, keeping the pictures protects nobody and puts you at risk if we are ever breached.

  • If you are approved, the photograph of your ID and your selfie are destroyed immediately.
  • If you are rejected, they are kept for seven days so you can challenge the decision while the evidence still exists, then destroyed.
  • If nobody ever reviews your submission, they are destroyed after thirty days.

After that we keep only what the record needs: the type of document and the country that issued it, the last few digits of the number, a one-way hash of it, who reviewed it and when, and a fingerprint of each image. That fingerprint lets us prove what was checked without holding the thing that was checked.

This means we cannot give you back a copy of your own ID photograph, because we no longer have one. It also means a breach of Relay cannot expose it.

8. Your rights

Relay operates under the Zimbabwe Data Protection Act [Chapter 11:12], and where users or data are in South Africa, the Protection of Personal Information Act (POPIA). Subject to those laws, you may ask us to:

  • tell you what personal information we hold about you;
  • correct information that is wrong — particularly your account details;
  • explain why a decision about your account or a dispute was made;
  • close your account.

We will be straight with you about the limit here: we cannot delete job records, dispute records or verification history on request, because they are retained to protect other users, to resolve disputes, and to meet legal and evidential obligations. If you object to that retention, tell us and we will consider it, but in most cases we will decline and explain why.

9. What stays on your device

The Relay app keeps a few things on your phone and nowhere else: a draft of a job you have started writing, so that taking a call does not lose it; which finished jobs you have cleared from your home screen; and your sign-in. Drafts are discarded after a week. None of it is sent to us, none of it is visible to anyone else, and clearing the app's data removes all of it.

10. This website specifically

This website runs no analytics, no advertising pixels and no tracking scripts. It sets no cookies of its own, and stores nothing in your browser. Fonts and icons are served from our own servers rather than a third-party CDN, so simply visiting this page does not report your visit to anyone else. The exceptions are the hosting-level logs and Cloudflare bot-management cookie described in section 5, and the waitlist form, which collects the email address you type into it so we can contact you about the beta.

See our Data & Cookie Policy for the detail.

11. Children

Relay is not for anyone under 18. We collect date of birth at sign-up and will close any account we find belongs to a minor.

12. Changes

We will update this policy as Relay changes, and the "Last Updated" date above will change with it. During the closed beta, expect it to change reasonably often.

13. Contact

Questions about this policy, or a request under section 8, can be sent to [email protected].

Related: Terms of Service · Data & Cookie Policy · End User Licence Agreement

Portions adapted from the Basecamp open-source policies, used under CC BY 4.0.