Privacy Policy — RentPilot Kenya

Effective date: October 25, 2025 · Last updated: October 25, 2025

Scope: This Privacy Policy describes how RentPilot Kenya (“RentPilot”, “we”, “us”, or “our”) collects, processes, stores, discloses and protects personal data when you use our website, progressive web app (PWA), mobile application, APIs, or related services (collectively, the “Platform”). It also explains your rights and choices and how to contact us.

1. Definitions

Personal data any information relating to an identified or identifiable individual. Processing any operation performed on personal data (collection, storage, use, disclosure, deletion). Controller RentPilot Kenya, which determines the purposes and means of processing. Processor third party acting on our instruction (e.g., hosting, analytics).

2. Data Controller & Contact

Controller: RentPilot Kenya Limited

Contact: rentpilotkenya@gmail.com

Postal address: Nairobi, Kenya (address on request)

3. Categories of Personal Data We Collect

We collect the following categories of data where necessary and lawful:

4. Sources of Personal Data

We obtain personal data directly from you when you register, use the Platform, contact support, or provide information in onboarding calls. We may also collect data automatically (analytics) and from third parties such as payment providers (M-Pesa/Daraja API), identity verification providers, or public registers.

5. Purposes of Processing & Legal Bases

We process personal data for the following specific purposes and legal bases:

  1. Providing the Service (Contractual performance): registration, authentication, account management, payment processing, rent collection, issuing receipts and statements.
  2. Verification & Onboarding (Legitimate interest / Contract): screening users via short calls and verification checks to maintain trust and safety of the platform.
  3. Platform security (Legitimate interest): fraud prevention, monitoring, enforcement of terms, and abuse detection.
  4. Analytics & product improvement (Legitimate interest / Consent): aggregated analytics to improve the Platform; we use anonymised data where possible.
  5. Communications (Contract / Consent): service messages, notifications, emails or SMS about transactions, policy updates, or support requests.
  6. Legal & compliance (Legal obligation): retention and disclosure to meet tax, accounting, audit or regulator requests and to comply with law.

6. User Access, Verification & Approvals

Access to the Platform is restricted to approved, registered users only. Registration is subject to a verification and screening process that includes a short onboarding call with RentPilot staff. Users must provide accurate information and supporting documentation on request. We reserve the right to refuse or suspend accounts that fail verification, violate terms, or pose risk to the community.

7. Cookies, Sessions & Tracking

We use cookies and similar technologies only as necessary to operate the Platform securely and to provide core functionality:

No non-essential cookies are collected by default. You may control cookie settings through your browser or device; however disabling essential cookies may prevent access to the Platform.

8. Data Sharing & Third-Party Processors

We do not sell personal data. We share personal data only with:

All processors are required by contract to implement appropriate technical and organisational measures and act only on our instruction.

9. International Data Transfers

Where we transfer personal data outside Kenya (e.g., cloud providers, analytics), we ensure adequate safeguards are in place such as standard contractual clauses, binding corporate rules, or ensuring the destination country provides adequate protection. If you would like specific details of the safeguards used for a transfer, contact us at rentpilotkenya@gmail.com.

10. Data Retention & Retention Schedule

We retain personal data only as long as necessary for the purpose collected, to comply with legal obligations, resolve disputes, and enforce agreements. Typical retention periods:

Data categoryRetention period (typical)
Account & profile dataRetained while account active + 2 years after deletion
Transaction records (payments)7 years (to meet financial/tax regulations)
Verification records / onboarding call notes5 years
Analytics & logs (aggregated)Up to 2 years (pseudonymised where possible)
Support communications3 years

We securely dispose of or anonymise data once retention periods expire.

11. Security Measures

We apply technical and organisational security measures, including but not limited to:

If you suspect a security incident involving your data, notify us immediately at rentpilotkenya@gmail.com.

12. Data Subject Rights & How to Exercise Them

You have rights under Kenya's Data Protection Act and applicable global privacy laws, including:

To exercise any rights, contact us at rentpilotkenya@gmail.com. We will respond within the statutory timeframe (typically 30 days) or notify you if an extension is necessary.

13. Children & Minors

The Platform is intended for users aged 18 and above. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected information about a child, please contact us to request deletion.

14. Automated Decision-Making & Profiling

We may use automated systems to support verification, risk assessment, and fraud detection. These processes do not make final legal or similarly significant decisions without human review. If you would like information about the logic involved and the measures used to protect your rights, contact us.

15. Breach Notification

In the event of a personal data breach that is likely to result in a risk to individuals' rights and freedoms, we will notify affected individuals and the relevant supervisory authority in accordance with applicable law as soon as practicable and with required information about the breach and mitigation steps.

16. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. We will post the revised policy with a revised “Last updated” date and, where appropriate, notify registered users by email or in-app messages.

17. Complaints & Supervisory Authority

If you are not satisfied with our response to a privacy request, you may lodge a complaint with the Office of the Data Protection Commissioner (ODPC) in Kenya or the relevant supervisory authority in your jurisdiction.

18. Contact Information

For privacy enquiries, data subject requests, or to request copies of the safeguards for international transfers, contact:

RentPilot Kenya
Email: rentpilotkenya@gmail.com
Website: www.rentpilotkenya.com
Phone: +254 710 897 101

Annex A — Technical & Organisational Measures (summary)

Annex B — Retention Summary

Record typeRetentionReason
Account dataAccount active + 2 yearsService, support and fraud prevention
Payment transactions7 yearsFinancial regulation and audit
Verification records5 yearsCompliance and dispute resolution
Support logs3 yearsCustomer support and quality
System logs (access, error)12–24 monthsSecurity and incident investigation
Note: This policy is intended to be comprehensive and to reflect industry best practice. It does not, and cannot, replace legal advice tailored to your organisation’s exact circumstances. If you require a tailored data protection compliance assessment, consider consulting a legal professional.