The Movement
Entertainment Platform
Privacy Policy
Effective Date
7 June 2026
Document
Privacy Policy

THE MOVEMENT

PRIVACY POLICY

Last Updated: [INSERT DATE]

The Movement (Private) Limited

Registration Number: XXXXXXXX

Republic of Zimbabwe

INTRODUCTION

The Movement (Private) Limited (Registration Number: XXXXXXXX), a company registered in the Republic of Zimbabwe (“The Movement”, “we”, “us”, or “our”), is committed to protecting your privacy and personal information.

This Privacy Policy describes how we collect, use, store, share, and protect your personal information when you use The Movement platform, including our mobile application, website, and related services (collectively, the “Platform”).

By using the Platform, you consent to the collection and use of your information as described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the Platform.

TABLE OF CONTENTS

1. INFORMATION WE COLLECT

2. HOW WE COLLECT INFORMATION

3. HOW WE USE YOUR INFORMATION

4. LEGAL BASIS FOR PROCESSING (GDPR)

5. HOW WE SHARE YOUR INFORMATION

6. DATA RETENTION

7. DATA SECURITY

8. YOUR RIGHTS AND CHOICES

9. INTERNATIONAL DATA TRANSFERS

10. COOKIES AND TRACKING TECHNOLOGIES

11. CHILDREN’S PRIVACY

12. THIRD-PARTY LINKS AND SERVICES

13. ROLE-SPECIFIC DATA COLLECTION

14. PAYMENT AND FINANCIAL INFORMATION

15. LOCATION DATA

16. COMMUNICATIONS

17. CHANGES TO THIS PRIVACY POLICY

18. CONTACT INFORMATION AND COMPLAINTS

1. INFORMATION WE COLLECT

We collect several types of information from and about users of our Platform:

1.1 Personal Information You Provide

Account Information:

• Full name

• Email address

• Phone number

• Date of birth

• Password (encrypted)

• Profile photograph

• User role selection (Artist, Venue Owner, Event Organizer, Attendee)

Identity Verification Information (KYC):

• Government-issued identification documents (passport, driver’s license, national ID)

• Proof of address (utility bills, bank statements)

• Tax identification number (TIN) or ZIMRA registration number

• Business registration documents (for businesses)

• Facial verification photographs

• Signatures

Payment and Financial Information:

• Bank account details (for payouts)

• Mobile money wallet information

• Payment card information (processed by Payment Gateways, not stored by us)

• Transaction history

• Billing address

• Tax information

Artist-Specific Information:

• Artist biography and description

• Performance genre and categories

• Portfolio materials (photos, videos, audio samples)

• Pricing information

• Availability calendar

• Performance history and credentials

• Equipment and technical requirements

• Social media links

Venue-Specific Information:

• Venue name and description

• Venue capacity and specifications

• Facility details and amenities

• Photos and videos of the venue

• Pricing and rental terms

• Business licenses and permits

• Insurance information

Event Information:

• Event title and description

• Event date, time, and location

• Ticket pricing and availability

• Event type and category

• Age restrictions

• Expected attendance

• Special requirements

Communication Data:

• Messages sent through the Platform

• Customer support inquiries

• Feedback and survey responses

• Email correspondence

• SMS messages

1.2 Information Collected Automatically

Device Information:

• Device type and model

• Operating system and version

• Unique device identifiers

• Mobile network information

• Device settings

Usage Information:

• Pages or features accessed

• Time spent on pages

• Search queries

• Booking history

• Click patterns and navigation paths

• Feature usage statistics

Location Information:

• IP address-based location

• GPS location (when you grant permission)

• Location entered manually for searches

• Event check-in locations

Technical Information:

• Browser type and version

• Internet service provider

• Referring/exit pages

• Date and time stamps

• Clickstream data

Cookies and Similar Technologies:

• Session cookies

• Persistent cookies

• Web beacons

• Analytics identifiers

• Advertising identifiers

1.3 Information from Third Parties

KYC Verification Partners:

• Identity verification results

• Document authenticity checks

• Fraud risk assessments

• Watchlist screening results

Payment Gateways:

• Payment confirmation

• Transaction status

• Refund information

• Payment method details

Social Media (if you connect accounts):

• Public profile information

• Friends lists

• Photos and posts you authorize us to access

Other Users:

• Reviews and ratings

• Reports of prohibited conduct

• Messages and communications

2. HOW WE COLLECT INFORMATION

We collect information through:

2.1 Direct Collection

• When you create an Account

• When you complete your profile

• When you make Bookings or purchase tickets

• When you upload content

• When you communicate with us or other Users

• When you contact customer support

• When you participate in surveys or promotions

2.2 Automatic Collection

• Through cookies and similar technologies

• Through your device when you use our mobile app

• Through analytics services

• Through your interactions with the Platform

2.3 Third-Party Collection

• From KYC verification partners

• From Payment Gateways

• From social media platforms (with your permission)

• From publicly available sources (business registries, etc.)

3. HOW WE USE YOUR INFORMATION

We use your information for the following purposes:

3.1 Providing Platform Services

• Creating and managing your Account

• Processing Bookings and transactions

• Facilitating communication between Users

• Processing payments and payouts

• Verifying your identity (KYC)

• Displaying your profile to other Users (as applicable)

• Matching Artists with Clients and Events

• Enabling event discovery and attendance

• Providing location-based services

• Sending transactional notifications (booking confirmations, payment receipts, etc.)

3.2 Platform Improvement and Development

• Analyzing usage patterns and trends

• Testing new features

• Improving user experience

• Optimizing search and recommendation algorithms

• Conducting research and analytics

• Developing new services

3.3 Safety and Security

• Detecting and preventing fraud

• Enforcing our Terms of Service

• Investigating violations and prohibited conduct

• Protecting against unauthorized access

• Resolving disputes

• Complying with legal obligations

• Protecting our rights and property

3.4 Marketing and Communications

• Sending promotional emails (with your consent)

• Displaying personalized content and recommendations

• Informing you about new features or services

• Conducting surveys and requesting feedback

• Sending SMS notifications about Events and Bookings

• Push notifications through the mobile app

3.5 Legal and Compliance

• Complying with tax reporting requirements (ZIMRA)

• Responding to legal requests and court orders

• Enforcing our agreements

• Protecting legal rights

• Complying with Zimbabwe and international laws

3.6 Business Operations

• Processing payments and commissions

• Managing Escrow arrangements

• Calculating and distributing payouts

• Generating invoices and receipts

• Maintaining business records

• Conducting internal audits

4. LEGAL BASIS FOR PROCESSING (GDPR)

For users in jurisdictions covered by the General Data Protection Regulation (GDPR), including the European Union, we process your personal data on the following legal bases:

4.1 Contract Performance

Processing necessary to fulfill our Terms of Service and provide Platform services, including:

• Account creation and management

• Booking processing

• Payment processing

• Communication facilitation

4.2 Legitimate Interests

Processing necessary for our legitimate business interests, including:

• Platform improvement and development

• Fraud prevention and security

• Analytics and research

• Direct marketing (where not requiring consent)

• Network and information security

4.3 Legal Obligation

Processing required to comply with legal obligations, including:

• Tax reporting and compliance

• Response to legal process

• KYC and anti-money laundering requirements

• Regulatory compliance

4.4 Consent

Processing based on your explicit consent, including:

• Marketing communications (where required)

• Location tracking (precise GPS data)

• Sharing with third parties beyond service provision

• Optional data processing activities

You may withdraw consent at any time through your Account settings or by contacting us.

5. HOW WE SHARE YOUR INFORMATION

5.1 Public Information

The following information is publicly visible on the Platform:

For Artists:

• Name and profile photograph

• Artist biography and description

• Performance genres and categories

• Portfolio materials (photos, videos, audio)

• Pricing (or “pricing on request”)

• Availability calendar

• Reviews and ratings

• Performance history (number of Events)

For Venues:

• Venue name and photographs

• Venue description and capacity

• Location and address

• Amenities and specifications

• Pricing information

• Reviews and ratings

For Events:

• Event title and description

• Date, time, and location

• Ticket prices and availability

• Featured Artists

• Event photographs

• Organizer information (name and profile)

For All Users:

• Reviews and ratings you leave

• Public comments or posts

• Display name and profile picture (in communications)

5.2 Sharing with Other Users

When you engage in transactions on the Platform, we share information necessary to facilitate the Booking:

Artists receive:

• Client name and contact information

• Event details and location

• Booking specifications and requirements

• Payment confirmation

Clients receive:

• Artist name and contact information

• Artist portfolio and credentials

• Availability information

• Booking confirmation

Event Organizers share with Attendees:

• Event details and location

• Organizer contact information

• Featured Artists

• Venue information

5.3 Sharing with Service Providers

We share information with trusted third-party service providers who assist us in operating the Platform:

Payment Gateways (Paynow, etc.):

• Payment information

• Transaction details

• User identification information

KYC Verification Partners:

• Identity documents

• Verification photographs

• Personal identification information

Cloud Service Providers:

• Platform data and backups

• User-generated content

• Transaction records

Mapping Services (Google Maps, etc.):

• Location data

• Search queries

• Navigation requests

Push Notification Services (Firebase, etc.):

• Device tokens

• Notification preferences

• User identifiers

Communication Service Providers:

• Email addresses

• Phone numbers

• Message content (for delivery)

Analytics Providers:

• Usage data (anonymized where possible)

• Device information

• Interaction patterns

All service providers are contractually obligated to protect your information and use it only for the purposes we specify.

5.4 Legal and Regulatory Sharing

We may disclose your information:

To Government Authorities:

• ZIMRA (Zimbabwe Revenue Authority) for tax reporting

• Law enforcement in response to valid legal requests

• Regulatory bodies as required by law

• Courts in response to subpoenas or court orders

For Legal Protection:

• To enforce our Terms of Service

• To protect our rights and property

• To protect the safety of Users or the public

• To defend against legal claims

5.5 Business Transfers

If The Movement is involved in a merger, acquisition, sale of assets, or bankruptcy, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on the Platform before your information is transferred and becomes subject to a different privacy policy.

5.6 With Your Consent

We may share your information with third parties when you explicitly consent to such sharing.

5.7 Aggregated and Anonymized Data

We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you, including:

• Platform usage statistics

• Market trends and insights

• Research findings

• Public reports and presentations

6. DATA RETENTION

6.1 Active Accounts

We retain your information for as long as your Account is active and as necessary to provide Platform services.

6.2 Inactive Accounts

If your Account is inactive for 2 years or more, we may:

• Send reminders to reactivate

• Delete non-essential data

• Archive your Account

• Eventually delete your Account entirely

6.3 After Account Deletion

When you delete your Account, we:

• Immediately remove public-facing information

• Retain transaction records for 7 years (legal/tax requirements)

• Retain KYC data for 5 years (regulatory requirements)

• Retain backup copies for 90 days

• Anonymize data used for analytics

6.4 Legal Holds

We may retain information longer if required by law, legal proceedings, or to protect our legal rights.

6.5 Specific Retention Periods

• Transaction records: 7 years (ZIMRA requirements)

• KYC documents: 5 years from last transaction

• Communication records: 3 years

• Support tickets: 2 years

• Analytics data: 2 years (anonymized thereafter)

• Marketing consent records: 3 years after withdrawal

• Deleted Account backups: 90 days

7. DATA SECURITY

7.1 Security Measures

We implement technical and organizational measures to protect your information:

Technical Measures:

• Encryption of data in transit (TLS/SSL)

• Encryption of sensitive data at rest

• Secure data centers with physical security

• Regular security audits and penetration testing

• Firewall and intrusion detection systems

• Secure authentication mechanisms

• Regular software updates and patches

Organizational Measures:

• Employee training on data protection

• Access controls and least-privilege principles

• Background checks for employees with data access

• Data protection policies and procedures

• Incident response plans

• Third-party security assessments

Payment Security:

• PCI-DSS compliant Payment Gateways

• Tokenization of payment information

• No storage of complete payment card data on our servers

7.2 Your Responsibilities

You are responsible for:

• Maintaining confidentiality of your password

• Using strong, unique passwords

• Enabling two-factor authentication (if available)

• Logging out of shared devices

• Reporting suspected security breaches immediately

7.3 Security Limitations

While we implement robust security measures, no system is completely secure. We cannot guarantee absolute security of your information. You acknowledge and accept the inherent risks of internet-based data transmission and storage.

7.4 Data Breach Notification

In the event of a data breach that affects your personal information, we will:

• Notify you within 72 hours of becoming aware

• Describe the nature of the breach

• Provide guidance on protective measures

• Report to relevant authorities as required by law

8. YOUR RIGHTS AND CHOICES

8.1 Access Rights

You have the right to:

• Access your personal information

• Request a copy of your data in portable format

• Review what information we hold about you

To exercise: Contact us at [PRIVACY EMAIL] or use Account settings.

8.2 Correction Rights

You have the right to:

• Correct inaccurate information

• Update outdated information

• Complete incomplete information

To exercise: Update directly in your Account settings or contact us.

8.3 Deletion Rights

You have the right to:

• Request deletion of your Account

• Request deletion of specific information

Limitations: We may retain information required by law or for legitimate business purposes.

To exercise: Use Account deletion feature or contact us at [PRIVACY EMAIL].

8.4 Objection and Restriction Rights

You have the right to:

• Object to processing based on legitimate interests

• Request restriction of processing in certain circumstances

• Object to direct marketing (opt-out anytime)

To exercise: Contact us at [PRIVACY EMAIL] or adjust Account settings.

8.5 Data Portability

You have the right to:

• Receive your data in machine-readable format

• Transfer your data to another service

To exercise: Contact us at [PRIVACY EMAIL].

8.6 Withdrawal of Consent

Where processing is based on consent, you may withdraw consent at any time. This does not affect the lawfulness of processing before withdrawal.

To exercise: Adjust consent settings in your Account or contact us.

8.7 Marketing Preferences

You can opt out of marketing communications:

• Click “unsubscribe” in marketing emails

• Adjust notification settings in your Account

• Reply “STOP” to marketing SMS

• Disable push notifications in device settings

• Contact us at [PRIVACY EMAIL]

Note: You cannot opt out of transactional communications (booking confirmations, payment receipts, etc.).

8.8 Cookie Preferences

You can control cookies through:

• Browser settings (block or delete cookies)

• Mobile app settings

• Cookie preference center (if provided)

Note: Disabling cookies may limit Platform functionality.

9. INTERNATIONAL DATA TRANSFERS

9.1 Primary Data Location

Our primary data servers are located in [SPECIFY COUNTRY/REGION]. Your information may be stored and processed in Zimbabwe or other jurisdictions where our service providers operate.

9.2 Cross-Border Transfers

When we transfer data across borders, we ensure adequate protection through:

• Standard contractual clauses

• Service provider commitments to data protection

• Compliance with applicable data transfer regulations

9.3 International Users

If you access the Platform from outside Zimbabwe:

• You consent to transfer of your data to Zimbabwe

• Your data will be subject to Zimbabwean law

• We will respect your rights under local data protection laws to the extent practicable

9.4 GDPR Compliance

For users in the European Union, we:

• Implement appropriate safeguards for data transfers

• Provide mechanisms for exercising GDPR rights

• Maintain records of processing activities

• Appoint data protection contacts as required

10. COOKIES AND TRACKING TECHNOLOGIES

10.1 What Are Cookies

Cookies are small text files stored on your device that help us provide and improve our services.

10.2 Types of Cookies We Use

Essential Cookies:

• Required for Platform functionality

• Enable Account authentication

• Remember your preferences

• Maintain session state

Analytics Cookies:

• Track usage patterns

• Measure Platform performance

• Identify popular features

• Understand user behavior

Advertising Cookies:

• Deliver relevant advertisements

• Measure ad effectiveness

• Limit ad frequency

Third-Party Cookies:

• Google Analytics

• Payment Gateway providers

• Social media platforms

• Advertising networks

10.3 Similar Technologies

We also use:

• Web beacons: Track email opens and clicks

• Local storage: Store data locally on your device

• SDK identifiers: Track mobile app usage

• Device fingerprinting: Detect fraudulent activity

10.4 Managing Cookies

You can control cookies through:

• Browser settings

• Mobile device settings

• Third-party opt-out tools

• Cookie preference tools (if provided)

Effect of disabling cookies: Some Platform features may not function properly.

10.5 Do Not Track Signals

Some browsers have “Do Not Track” features. Currently, there is no industry standard for responding to these signals. We do not alter our data collection practices in response to Do Not Track signals.

11. CHILDREN’S PRIVACY

11.1 Age Restriction

The Platform is not intended for individuals under 18 years of age. We do not knowingly collect information from children under 18.

11.2 Parental Responsibility

If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at [PRIVACY EMAIL].

11.3 Deletion of Children’s Data

If we learn that we have collected information from a child under 18, we will:

• Delete the information immediately

• Terminate the Account

• Notify the parent/guardian if possible

12. THIRD-PARTY LINKS AND SERVICES

12.1 External Links

The Platform may contain links to third-party websites, services, or applications. We are not responsible for the privacy practices of these third parties.

12.2 Third-Party Privacy Policies

When you access third-party services, their privacy policies apply. We encourage you to review their policies before providing information.

12.3 Social Media Features

The Platform may include social media features (sharing buttons, widgets). These features may collect information about you and are governed by the privacy policies of the respective social media companies.

12.4 Third-Party Integrations

When you connect third-party accounts (social media, payment methods), you authorize data sharing between The Movement and those services as described in their privacy policies.

13. ROLE-SPECIFIC DATA COLLECTION

Different user roles involve different data collection practices:

13.1 Artists

Additional Data Collected:

• Portfolio materials (extensive photos, videos, audio)

• Performance credentials and history

• Specialized equipment requirements

• Technical rider information

• Travel preferences

• Insurance information

Public Visibility:

• Most Artist profile information is publicly visible

• Portfolio materials are public

• Reviews and ratings are public

• Performance history summary is public

Privacy Controls:

• Set availability hours

• Choose pricing display (show or “on request”)

• Control social media link visibility

13.2 Venue Owners

Additional Data Collected:

• Business registration documents

• Property ownership or lease agreements

• Venue capacity and safety certifications

• Insurance certificates

• Facility specifications

• Licensing information

Public Visibility:

• Venue details and photos are public

• Location and contact information are public

• Pricing and availability are public

Business Information:

• May be verified against public business registries

• Business licenses may be confirmed with authorities

13.3 Event Organizers

Additional Data Collected:

• Event history and reputation

• Permit applications

• Attendee lists (for private Events)

• Payment processing for ticket sales

• Communication with Attendees

Public Visibility:

• Public Events are fully visible

• Private Events show limited information

• Organizer reputation and history visible

13.4 Attendees

Data Collection:

• Minimal personal information

• Ticket purchases and attendance history

• Check-in data

• Reviews left

Privacy:

• Attendance at public Events may be visible to Event Organizers

• Reviews you leave are public

• Personal information not shared publicly

14. PAYMENT AND FINANCIAL INFORMATION

14.1 Payment Processing

Payment information is processed by our Payment Gateway partners (Paynow, etc.). We do not store complete payment card numbers on our servers.

What We Store:

• Last 4 digits of card number (for identification)

• Card type (Visa, Mastercard, etc.)

• Expiration date

• Billing address

• Payment method tokens (from Payment Gateway)

14.2 Payout Information

For Artists and Venue Owners receiving payouts:

• Bank account numbers

• Bank name and branch

• Account holder name

• Mobile money wallet numbers

• Tax identification numbers

This information is encrypted and access is restricted to authorized personnel only.

14.3 Transaction Records

We maintain records of all transactions for:

• Escrow management

• Dispute resolution

• Tax compliance (ZIMRA reporting)

• Financial audits

• Legal compliance

Transaction records are retained for 7 years.

14.4 Tax Reporting

We may report income paid to Artists and Venue Owners to ZIMRA as required by Zimbabwean law. This includes:

• Total income earned

• Tax identification numbers

• Payment dates and amounts

15. LOCATION DATA

15.1 Types of Location Data

IP Address Location:

• Approximate location based on IP address

• Used for regional content and fraud prevention

• Collected automatically

GPS Location:

• Precise location from your device

• Collected only with your permission

• Used for location-based features

Manual Location:

• City, region, or address you enter

• Used for search and discovery

15.2 How We Use Location Data

• Show nearby Events, Artists, and Venues

• Verify Event check-ins

• Provide directions to Events

• Analyze geographic trends (aggregated)

• Prevent fraud

• Comply with legal requirements

15.3 Location Permissions

Mobile App:

• Request permission to access device location

• Can be granted or denied in device settings

• Can be changed at any time

Location Features Without GPS:

• Enter location manually

• Search by city or region

• Access Platform with reduced location features

15.4 Location Privacy

• We do not continuously track your location

• GPS is accessed only when using location-based features

• Precise location is not shared publicly

• Location data is encrypted in transmission

16. COMMUNICATIONS

16.1 Transactional Communications

We send communications necessary for Platform operation:

• Account verification and confirmations

• Booking confirmations and reminders

• Payment receipts and payout notifications

• Security alerts and password resets

• Platform updates affecting your Account

• Legal notices and policy changes

You cannot opt out of transactional communications as they are essential for Platform services.

16.2 Marketing Communications

With your consent, we send:

• Promotional emails about Events

• Featured Artist announcements

• Platform updates and new features

• Surveys and feedback requests

• Special offers and discounts

You can opt out anytime through unsubscribe links, Account settings, or by contacting us.

16.3 Push Notifications

The mobile app may send push notifications:

• Booking reminders

• Event updates

• New messages

• Special promotions

You can disable push notifications in your device settings or app settings.

16.4 SMS Notifications

We may send SMS messages for:

• Booking confirmations

• Event reminders

• Security verification codes

• Critical Account alerts

You can opt out of promotional SMS by replying “STOP” but may still receive transactional SMS.

16.5 In-App Messaging

Communications between Users through the Platform are:

• Monitored for prohibited content

• Retained for dispute resolution

• Subject to these privacy practices

17. CHANGES TO THIS PRIVACY POLICY

17.1 Right to Modify

We may update this Privacy Policy from time to time to reflect:

• Changes in our practices

• Legal or regulatory requirements

• New features or services

• User feedback

17.2 Notice of Changes

We will notify you of material changes by:

• Email to your registered address

• Prominent notice on the Platform

• Push notification through the mobile app

• Update to the “Last Updated” date

17.3 Effective Date

Changes become effective 30 days after notice, except:

• Changes required by law (effective immediately)

• Changes that enhance privacy protections (effective immediately)

• You may need to accept changes before continuing to use the Platform

17.4 Reviewing Changes

We encourage you to review this Privacy Policy periodically. Continued use of the Platform after changes become effective constitutes acceptance.

18. CONTACT INFORMATION AND COMPLAINTS

18.1 Contact Us

For privacy-related questions, concerns, or requests:

The Movement (Private) Limited

Registration Number: XXXXXXXX

Physical Address: [INSERT ADDRESS]

Privacy Email: [INSERT PRIVACY EMAIL]

Phone: [INSERT PHONE NUMBER]

Website: [INSERT WEBSITE]

Specific Inquiries:

• Data Access/Deletion Requests: [PRIVACY EMAIL]

• Security Concerns: [SECURITY EMAIL]

• General Privacy Questions: [PRIVACY EMAIL]

18.2 Response Time

We aim to respond to privacy requests within:

• 14 days for routine inquiries

• 30 days for complex requests

• 72 hours for security breaches

18.3 Complaints

If you believe we have not handled your personal information properly, you may:

Step 1: Contact Us

• Email [PRIVACY EMAIL] with details of your complaint

• We will investigate and respond within 30 days

Step 2: Regulatory Authority

If you are not satisfied with our response, you may lodge a complaint with:

• Zimbabwe: [INSERT RELEVANT DATA PROTECTION AUTHORITY IF ESTABLISHED]

• For EU Residents: Your local data protection authority

• For Other Jurisdictions: Your local privacy regulator

18.4 Dispute Resolution

Privacy disputes are subject to the dispute resolution provisions in our Terms of Service, including arbitration in Zimbabwe under the Arbitration Act (Chapter 7:15).

END OF PRIVACY POLICY