Privacy Policy
Last updated: [Effective date — insert on publish]
1. Who we are
This Policy is issued by [Company Legal Name] (“Magariyetu”, “we”, “us”), registered in Kenya at [Registered Address], acting as the data controller for personal data processed through the Magariyetu platform. Our Data Protection Officer / privacy contact can be reached at [DPO Contact Email].
2. Scope
This Policy explains how we handle personal data of Buyers, Sellers, Dealers, and site visitors under the Data Protection Act, 2019 (Kenya) and its implementing regulations. It should be read alongside our Terms of Service.
3. Personal data we collect
We collect the following categories of personal data, listed here as they actually exist in our systems:
- Account data: name, phone number, email address (a placeholder address is generated automatically for accounts created via phone-only sign-in), and a securely hashed password. We never store your password in readable form.
- Identity and business verification documents: where you apply for ID verification or a Dealer account, the documents you upload for that purpose (for example, national ID or KRA PIN certificate), reviewed by staff and then retained for audit purposes.
- Listing content: vehicle or item details, description, price, location, and photographs you upload. Uploaded photographs are watermarked before storage.
- Transaction and payment metadata: records of Featured Placement or subscription payments, including amount, plan, and status. We do not receive or store your M-Pesa PIN or full card number — those are handled directly by our payment processor.
- Enquiry data: when you contact a Seller through the Platform (WhatsApp click, phone reveal, or contact form), we record that this occurred, together with any message and contact details you choose to provide, so the Seller can follow up and so we can show Sellers basic performance analytics.
- Login codes: if you sign in by phone, a short-lived, hashed one-time code and its expiry time — deleted from active use once verified or expired, subject to routine database retention described in Section 8.
- Technical data: the session cookie that keeps you signed in, and standard web server logs. We do not currently use separate marketing or analytics cookies — if that changes, this Policy will be updated first.
4. How we collect it
Most data is provided directly by you — at registration, when posting a Listing, or when contacting a Seller. Some is generated automatically by the Platform (listing views, enquiry records). Payment status is received from our payment processor once a payment succeeds or fails; it does not include your underlying M-Pesa or card credentials.
5. Why we process your data
We rely on the following lawful bases, matched to the Data Protection Act, 2019:
- Performance of a contract — creating your account, publishing your Listings, processing Featured Placement and subscription payments, and enabling Buyer–Seller contact.
- Legitimate interests — fraud and price-outlier checks, platform security, and seller-facing analytics, balanced against your rights and always limited to what is necessary for those purposes.
- Consent — marketing communications, which you may withdraw at any time.
- Legal obligation — retaining verification documents and transaction records where required by applicable law or regulator request.
6. Who we share data with
- Other users: your name, and phone or WhatsApp number if you have chosen to display it, are shown on your own Listings so interested Buyers can contact you. Dealer verification status is shown publicly; the documents behind it are not.
- Payment processor: your phone number and payment amount are shared with our M-Pesa payment processor (IntaSend) solely to process Featured Placement and subscription payments.
- Phone-verification provider: your phone number is shared with Phone.Email to verify your number when you choose phone sign-in. We may use an SMS provider for seller lead notifications.
- Email provider: your email address is shared with our transactional email provider (Brevo) to deliver account and lead-notification emails.
- Hosting and storage providers: uploaded photographs and platform data are stored with our cloud hosting and file storage providers, who process it only on our instructions.
- Regulators and law enforcement: where we are legally required to disclose data, including to the ODPC or law enforcement under a lawful request.
We do not sell your personal data.
7. International data transfers
Some of the service providers listed in Section 6 may process or store data outside Kenya. Where this occurs, we take steps intended to meet the Data Protection Act's cross-border transfer requirements — such as relying on a provider's adequate safeguards or contractual protections. [Confirm and list each provider's actual data-hosting region here, and the specific safeguard relied on for each, before publishing — this cannot be accurately completed without checking each vendor's current hosting location.]
8. How long we keep your data
- Account data is retained while your account is active, and for a limited period after closure for legal, tax, and dispute-resolution purposes.
- Identity and business verification documents are retained for as long as your verified status is active, and for a defined period afterward for audit purposes.
- One-time login codes are short-lived by design and are not retained beyond routine database backups once expired or used.
- Listing content is retained for as long as the Listing is active and for a limited period after removal, for dispute and record-keeping purposes.
[Insert specific retention periods for each category once decided — a Policy that says data is kept “as long as necessary” without a defined period is weaker evidence of compliance than one with actual numbers.]
9. How we protect your data
Passwords are stored using one-way hashing, never in plain text. One-time login codes are hashed before storage. Access to identity verification documents is restricted to staff performing verification. Data in transit between your device and our servers is encrypted (HTTPS). No system is completely secure, and we cannot guarantee absolute security of information transmitted over the internet.
10. Your rights
Under the Data Protection Act, 2019, you have the right to:
- be informed of how your data is used (this Policy is part of that);
- access the personal data we hold about you;
- request correction of inaccurate or outdated data;
- request deletion of your data, subject to legal retention requirements;
- object to processing based on legitimate interests;
- request a portable copy of data you provided to us; and
- lodge a complaint with the Office of the Data Protection Commissioner (Britam Tower, Upper Hill, Nairobi; www.odpc.go.ke) if you believe we have mishandled your data.
To exercise any of these rights, contact us at [DPO Contact Email].
11. Children
The Platform is not directed at, and is not intended for use by, anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us so we can remove it.
12. Cookies
We use a single essential cookie to keep you signed in. We do not currently use advertising or analytics cookies. If that changes, we will update this Policy and, where required, seek your consent first.
13. Third-party links
The Platform may link to third-party sites, including WhatsApp and payment provider pages. We are not responsible for the privacy practices of sites we do not operate.
14. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified through the Platform or by email before they take effect.
15. Contact us
For any question about this Policy or your data, contact [DPO Contact Email] or write to us at [Registered Address].