1. Introduction
NuuniHub is a digital services platform that provides:
- an in-app wallet funded by Somali mobile-money and bank transfer methods;
- game top-ups and related digital products, including PUBG UC, PUBG Korean UC, Free Fire Diamonds, eFootball Coins (iOS and Android), Mobile Legends Diamonds, FC Mobile Points, and other packages made available in the app;
- a marketplace where users can buy and sell game and social-media accounts (including eFootball, PUBG, Free Fire, TikTok, Instagram, Facebook, and other categories listed in the app);
- player / pack products (for example eFootball player packs) where offered;
- customer support by in-app chat, WhatsApp, and phone;
- optional paid “blue tick” / verified-badge subscriptions.
This policy applies to the NuuniHub Android/iOS app identified as NuuniHub (Android application ID com.nuunihub.app) and to this public website. It is written from the current NuuniHub source code. It does not describe practices the app does not implement.
By creating an account or using NuuniHub, you agree to this Privacy Policy. If you do not agree, please do not use the app.
2. Information we collect
We collect information in three ways:
- Information you provide when you register, update your profile, deposit or withdraw funds, place orders, list or buy accounts, contact support, or upload photos.
- Information collected to fulfil a service you request, such as a game Player ID, region/server, or login details needed to deliver a top-up or marketplace order.
- Information created by the app or our infrastructure, such as Firebase user IDs, wallet IDs, timestamps, language and theme preferences stored on your device, and technical data processed by Google Firebase and other providers listed below.
The current NuuniHub mobile app does not include advertising SDKs, Firebase Analytics, or Firebase Crashlytics. In-app notifications are stored in our database; the app does not currently include a Firebase Cloud Messaging (push notification) SDK.
3. Information you provide
Account registration and profile
When you create an account, NuuniHub uses Firebase Authentication (email and password) and stores a user profile in Cloud Firestore. The registration flow collects:
- full name (display name);
- email address;
- password (used to create the Firebase Authentication account; we do not store your NuuniHub login password in Firestore);
- phone number (optional at registration, can be added later);
- city (required in the current registration form);
- country (optional);
- profile photo, if you choose to upload one (camera or photo library).
We also create and store:
- a Firebase user ID;
- a short public NuuniHub wallet / user ID used for sending money to other users;
- role (user or admin), account status (including banned/active flags);
- account creation time and last login time;
- blue-tick / verification badge status, plan, and expiry if you purchase that feature.
You can later update phone, city, country, and profile photo from the Profile screen.
Wallet, deposits, and withdrawals
NuuniHub operates an in-app USD wallet. To add funds you send money using a selected payment method and then confirm the deposit in the app. We store:
- deposit amount, selected method, your name, user ID, status, timestamps, and the phone number you enter as the deposit reference;
- withdrawal amount, selected method, destination account details (mobile-money number or bank account number), status, timestamps, and any admin notes;
- wallet balance, locked balance, and currency;
- ledger records of purchases, refunds, transfers, deposits, withdrawals, and similar transactions (amount, type, description, reference, balance after the event).
Supported payment method types in the app currently include EVC Plus, Zaad, Sahal, eDahab, Jeeb, Waafi, Premier Bank, and Salam Bank. Deposits are completed by you sending funds to NuuniHub’s published receive numbers or bank details, then submitting a deposit request. NuuniHub does not collect or store card numbers, mobile-money PINs, bank passwords, or OTP codes.
Game top-ups and digital products
Depending on the product, we may collect:
- Player ID / UID for games such as PUBG, Free Fire, and FC Mobile, solely to credit the requested account;
- region, server, zone, or similar fields when a product requires them (for example some Mobile Legends or regional packages);
- Konami / eFootball account email and password for manual eFootball coin top-ups, because those products are fulfilled by logging into the game account you provide;
- order identifiers, product name, quantity, price, status, and related notes.
Automatic catalogue top-ups are sent to our fulfilment partner FazerCards with the player ID and any required extra fields so the order can be delivered. Gift-card style products may not require a player ID.
Marketplace listings (selling accounts)
If you list a game or social-media account for sale, the app collects:
- listing title, description, category, and price;
- at least two screenshots or photos of the account;
- the login email, password, and optional recovery email for the listed account, so the account can be transferred after purchase;
- seller identity documents: ID card / NIRA front, back (for ID cards), and a face photo, or passport front and a face photo;
- precise device location (latitude and longitude) at the time you enable location to list on the market.
Listing login credentials are hidden from other users until a purchase is completed. Authorized NuuniHub operators can access them to review and deliver orders.
Buying marketplace accounts and player packs
When you buy a listed account or a player pack, we store the order, the buyer and seller identifiers, amount, status, and — after delivery — the account login details needed for you to receive the product. Some player-pack checkouts collect a Gmail address and password that you type in, so the pack can be applied to that account.
Customer support
If you use in-app support, we store your user ID, display name, subject, messages, replies, and timestamps in support tickets. If you contact us on WhatsApp or by phone, that conversation is handled on those services under their own policies. The in-app support number is 619556051 / +252619556051.
Photos, camera, and files
With your permission, the app accesses the camera and photo library to:
- set a profile photo;
- upload marketplace screenshots;
- capture seller ID / face photos;
- let administrators upload product images.
Images are uploaded to Cloudinary (and the app also contains Firebase Storage upload code for stored files). We do not use the camera or photos for advertising.
4. Automatically collected information
The NuuniHub app and its backends may process the following technical information:
- Firebase identifiers created by Firebase Authentication and Firestore (user UID, authentication tokens).
- On-device preferences stored with SharedPreferences: language (English or Somali), light/dark theme, and IDs of in-app notifications you have already seen.
- Location only when you list an account for sale and tap to enable location. The app requests fine and coarse location permission. Location is not collected for browsing the marketplace, top-ups, or ordinary profile use.
- Cached images stored locally by the image cache so pictures load faster.
- Google Fonts: the app uses the Plus Jakarta Sans font via Google Fonts, which may receive a network request from your device when fonts are fetched.
- Infrastructure logs. Google Firebase, Cloud Functions, Cloudinary, and (if used) our API servers process IP addresses, user-agent strings, and similar request metadata as part of providing hosting, authentication, and security. A separate NuuniHub API in the project can store IP address and user-agent on authentication refresh tokens. The current mobile app fulfils automatic top-ups through Firebase Cloud Functions rather than that API client.
We do not currently collect advertising IDs, contacts, SMS, microphone audio, or precise location in the background.
5. How we use your information
We use the information described above to:
- create and authenticate your account;
- operate the wallet, deposits, withdrawals, and peer-to-peer transfers via public NuuniHub IDs;
- display catalogues and process game top-up, gift-card, marketplace, and player-pack orders;
- validate a game Player ID with our fulfilment partner when you request validation;
- review seller identity documents and listing location before publishing marketplace listings;
- deliver purchased account credentials to the buyer;
- provide in-app notifications and support;
- apply coupons, feature products, and operate admin tools;
- prevent fraud, abuse, chargebacks, and unauthorised access;
- keep transaction and order records for accounting, dispute handling, and legal obligations;
- improve reliability and customer service.
We do not sell personal information. We do not use advertising SDKs in the current app.
6. Game top-up services
NuuniHub may offer digital game products such as:
- eFootball Coins (iOS and Android);
- PUBG UC (Global) and PUBG Korean UC;
- Free Fire Diamonds;
- Mobile Legends Diamonds;
- FC Mobile Points;
- other packages, passes, draws, or gift-card products shown in the catalogue.
There are two fulfilment paths in the current app:
- Automatic top-ups (FazerCards). After your wallet is charged, Firebase Cloud Functions send the order to FazerCards (
api.fzr.cards), including the product identifiers and the Player ID / region fields required by that product. FazerCards may return a player nickname during ID validation. Order status is stored in Firestore (game_orders). - Manual top-ups. Some products (notably eFootball / Konami coin packages) are submitted as wallet-paid requests stored in Firestore (
topup_orders), including Player ID where relevant, or the game-account email and password you typed so staff can complete delivery.
Player IDs, regions, and any game-account credentials you submit are used solely to fulfil the requested service, to handle refunds or failed deliveries, and to keep a record of the order. Providing an incorrect Player ID or login may result in a failed or misdirected delivery.
7. Social media account marketplace
NuuniHub includes a marketplace for buying and selling digital accounts in categories such as eFootball, PUBG, Free Fire, TikTok, Instagram, Facebook, and others listed in the app.
Sellers must complete an identity step before a listing is sent for review. That step uploads ID images to Cloudinary (folder used in code: seller_ids) and saves location coordinates and document type in Firestore (seller_kyc). Listings stay inactive until an administrator publishes them.
Buyers receive the listed account’s login email, password, and recovery email after a successful purchase. Those secrets are operational data for the marketplace. Do not list an account you are not entitled to sell. NuuniHub may refuse, delay, or remove listings for fraud, policy, or safety reasons.
8. Payments and transactions
NuuniHub does not process card payments inside the app. You fund your wallet by sending money through the mobile-money or bank method you select, using the receive numbers or account details shown in the app, then confirming the deposit. Withdrawals send wallet value back to the mobile-money number or bank account you specify.
Payment credentials such as PINs, OTPs, and card numbers are entered only in your own mobile-money or banking app, not in NuuniHub, and are not stored by NuuniHub.
Wallet charges for catalogue purchases, marketplace orders, player packs, and blue-tick subscriptions are recorded in Firestore. Automatic top-up charges happen in a server-side Firebase transaction before FazerCards is called. Failed automatic deliveries may be refunded to the wallet.
Peer-to-peer transfers use the recipient’s public NuuniHub ID, display name, and optional photo to confirm the destination.
9. Third-party services
The following third-party services were identified in the NuuniHub application, package files, and configuration. Each processes data according to its own privacy policy as well as this one.
- Google Firebase (project ID
nuunihub): Firebase Authentication, Cloud Firestore, Firebase Storage, Cloud Functions (regionus-central1), and Firebase Core. Used for accounts, database, file storage, and automatic top-up fulfilment. Google may process IP addresses and device/technical data as part of providing these services. The web Firebase configuration includes a Google Analytics measurement ID; the mobile app’s current package list does not include the Firebase Analytics or Crashlytics SDKs. - Cloudinary: unsigned image uploads for profile photos, listing screenshots, seller ID images, and admin product images.
- FazerCards (
https://api.fzr.cards/api/v2): wholesale fulfilment of automatic game top-ups and related digital products. Receives product identifiers and the player/account fields required to deliver the order. NuuniHub’s FazerCards API key is stored only on the server. - Google Fonts: font files used by the app (and this website).
- WhatsApp: if you choose “WhatsApp” in support, the app opens WhatsApp with a pre-filled message to NuuniHub’s support number. WhatsApp is operated by Meta.
- Device phone dialer: if you tap to call support.
- Google Play / Apple: if you install NuuniHub from an app store, that store processes install and account data under its own policy.
The repository also contains a NestJS API (with Redis, JWT, Helmet, and Prisma) intended for production top-up processing. If that API is deployed and used, it may additionally process authentication tokens, IP address, user-agent, and order records. The current Flutter client calls Firebase Cloud Functions for automatic top-ups.
Relevant provider policies include:
- Google Privacy Policy (Firebase and Google Fonts)
- Cloudinary Privacy Policy
- WhatsApp Privacy Policy
FazerCards is a fulfilment supplier. Review any privacy terms they publish for their API and dashboard when those are made available to you.
10. Data sharing and disclosure
We share personal information only as needed to operate NuuniHub:
- Fulfilment partners: FazerCards receives player IDs and related game fields to deliver automatic top-ups.
- Infrastructure providers: Google Firebase and Cloudinary host accounts, database records, functions, and images.
- Other users: public profile name, public NuuniHub ID, optional photo, city/country if shown, listing photos/titles/prices, and (after a marketplace purchase) the delivered account credentials to the buyer. Seller names may appear on listings.
- Administrators / operators: staff using the admin panel can view users, wallets, orders, support tickets, KYC images, listing credentials, and transaction history in order to run the service.
- Legal and safety: we may disclose information if required by law, to prevent fraud or harm, or to protect NuuniHub, users, or the public.
We do not share data with advertising networks. There is no advertising SDK in the current app.
11. Data security
We use reasonable technical and organizational measures appropriate to a marketplace and wallet app, including:
- Firebase Authentication for account sign-in;
- Firestore security rules and Storage rules in the project;
- HTTPS for network traffic to Firebase, Cloudinary, and FazerCards;
- server-only storage of the FazerCards API key;
- wallet deductions for automatic top-ups performed in server-side transactions;
- admin-only tools for user and order management;
- marketplace listing secrets withheld from the public catalogue until purchase.
No method of transmission or storage is completely secure. We cannot guarantee that unauthorized third parties will never defeat our measures. You should use a strong unique password for NuuniHub, and you should understand that game/social login details you submit for top-ups or listings are highly sensitive.
12. Data retention
We keep information for as long as needed to provide the service and for legitimate business, security, and legal reasons:
- Account profile and wallet: until you successfully delete your account, unless we must keep a record (for example a ban related to fraud).
- Orders, deposits, withdrawals, and transactions: retained as commercial and anti-fraud records even after an account deletion request, for as long as reasonably necessary for accounting, dispute resolution, tax, and security. We may anonymize or detach these records from your profile where feasible.
- Marketplace credentials, seller ID images, and location: retained while the listing or related orders are active and thereafter as needed to handle disputes or fraud. ID images are sensitive; we do not use them for marketing.
- Support tickets: retained to continue customer service and quality review.
- On-device preferences: remain on your device until you clear app data or uninstall the app.
The current in-app admin deletion tool removes the Firestore user document and wallet document. It does not automatically erase every related order, KYC file, or the Firebase Authentication account. Deletion requests submitted through this website are processed manually as described below.
13. Your privacy rights
Depending on where you live, you may have rights to access, correct, or delete personal information, or to object to certain processing. You can:
- view and update name-related profile fields, phone, city, country, and photo in the app;
- reset your password with Firebase’s email password-reset function;
- request a copy of the personal information we hold, or correction of inaccurate data, by contacting us;
- request deletion of your account and associated personal information as described in the next section.
We may need to verify that the request comes from the account holder.
14. Account and data deletion
Google Play requires apps that offer account creation to provide a way to delete the account and associated data.
The current NuuniHub app does not yet include a self-service “Delete account” button for users. Administrators can delete a user’s Firestore profile and wallet from the admin users screen. That in-app admin action is not a complete erasure of all related records.
To request deletion of your NuuniHub account and personal information:
- Open the public deletion page: Delete my NuuniHub account.
- Send the request via WhatsApp or in-app support, using the email address on the account.
- You may also call +252 619556051.
After we verify the request, we will delete or de-identify personal information associated with the account, including the Firebase Authentication user where technically possible, the Firestore user profile, wallet, support tickets we can locate, seller KYC images we can locate, and profile/listing images we control, subject to the retention limits below.
We may retain information when we have a legitimate need, including:
- completed payment, top-up, marketplace, and wallet transaction records required for accounting, audits, chargebacks, or fraud prevention;
- information we must keep to comply with law;
- records needed to resolve an existing dispute or investigate abuse.
Temporary deactivation or “freezing” an account is not treated as deletion. When we complete a verified deletion request, the account is removed rather than merely disabled, except for the retained records described above.
We aim to complete verified deletion requests within a reasonable period, typically within 30 days, unless a lawful investigation requires more time.
15. Children’s privacy
NuuniHub is a digital marketplace and wallet for game top-ups and account trading. It is not directed at children and is not designed as a children’s app.
The current application source code does not define a numeric minimum age. You must be old enough under the laws of your country to use an online wallet and digital-goods marketplace, and you must not use NuuniHub if you are a child. We do not knowingly collect personal information from children. If you believe a child has created an account or given us personal information, contact us and we will take steps to delete that information.
You must be at least years old to create a NuuniHub account or use the services. We do not knowingly collect personal information from anyone under that age. If you believe we have collected such information, contact us and we will take steps to delete it.
16. Cookies and similar technologies
The NuuniHub mobile app does not use web cookies. It stores a small amount of data on your device with SharedPreferences (language, theme, and seen in-app notification IDs) so the app remembers your settings.
This Privacy Policy website does not set advertising cookies. If you load Google Fonts, Google may process technical data as described in Google’s privacy policy. Hosting providers (for example Firebase Hosting, Vercel, or Netlify, depending on where this page is deployed) may set strictly necessary cookies or logs for security and delivery.
17. International data transfers
NuuniHub is used primarily by customers in Somalia and nearby regions, but our processors operate globally. Firebase Cloud Functions for automatic top-ups are configured in us-central1 (United States). Google Firebase, Cloudinary, and FazerCards may store or process data in other countries. Where data is transferred internationally, it is transferred in order to provide the service you requested.
18. Changes to this Privacy Policy
We may update this policy when the app’s data practices change. The “Last updated” date at the top will change when we do. Continued use of NuuniHub after an update means you accept the revised policy. Material changes should be reviewed on this page before you keep using the app.
19. Contact us
For privacy questions, access requests, or deletion requests, contact NuuniHub using the channels that already exist in the app:
- In-app: Profile → Support chat
- WhatsApp: +252 619556051
- Phone: +252 619556051
- Account deletion form: Delete account
No official support email is stored in the NuuniHub source code. When you have one, add it in site-config.js (supportEmail) so it appears here and on the Contact page.
Please do not send game-account passwords or ID photos over untrusted public channels unless a NuuniHub operator has asked you to do so for a specific, verified request.