Legal
Privacy Policy
What PataSpace collects, why, who it goes to, how long it is kept, and how to get it out or get it deleted. Written to Kenya's Data Protection Act, 2019.
The short version
- Browsing is anonymous: you only need an account to unlock a contact, post a listing, or get paid.
- We never sell your personal data and we run no advertising or tracking SDKs.
- A listing shows an approximate map pin until someone pays to unlock it — the exact address and phone number are revealed only then.
- You can delete your account, and everything attached to it, from inside the app at any time.
The short version is a summary, not the policy. The sections below are what apply.
1. Who we are
PataSpace is a housing marketplace for Kenya. Outgoing tenants post the homes they are leaving, and incoming tenants pay to reveal the contact details once they decide to move. This policy explains what we do with your personal data when you use the PataSpace mobile app or the dalakenya.com website.
"We", "us" and "our" mean PataSpace, based in Nairobi, Kenya. We are the data controller for the personal data described here, which means we decide why and how it is processed. You can reach us about anything in this policy at info@dalakenya.com.
This policy is written to meet the Data Protection Act, 2019 of Kenya. Where the Act gives you a right, this policy tells you how to use it rather than only naming it.
2. What we collect
We collect only what a rental handover actually needs. Nothing below is optional-but-collected-anyway: if a section does not apply to how you use the app, that data is never created.
Account details, when you create an account: your first and last name, email address, phone number, and a password. We store the password only as a one-way hash, so nobody at PataSpace can read it. Your phone number is stored encrypted, plus a separate hash we use to look it up without decrypting it.
Listing content, when you post a home: the title, description, rent, deposit, county, neighbourhood, address, unit type, amenities, availability date, your reason for moving, and the landlord or caretaker contact you supply. You also confirm that the landlord or caretaker knows the unit is listed.
Photos, video, and precise location, when you capture a listing: the app uses your camera and microphone to take listing photos and record an optional walkthrough video with sound, and reads your device GPS at that moment so each photo carries the coordinates and time it was taken. That GPS proof is why a listing can be trusted; it is attached to the photo, not tracked over time. We never read your location in the background or when the app is closed.
Payment information, when you buy credits or receive a payout: the M-Pesa phone number you pay from, the amount, and the transaction reference and status that Safaricom returns. Card numbers, M-Pesa PINs, and bank credentials never reach us — you type your PIN into Safaricom's own prompt on your handset.
Marketplace activity: the listings you save, the listings you unlock, the contacts revealed to you, move-in confirmations from both sides, commissions and payouts, ratings and reviews you leave, referral codes you send or use, disputes you raise, and support tickets and messages you send us.
Security and integrity records: the IP address and browser or device identifier attached to sensitive actions (sign-in, moderation, payments, admin changes), sign-in timestamps, and a log of administrative changes to your account. These exist so a fraudulent or disputed transaction can be reconstructed.
Waitlist details, if you join from the website before launch: your email address, your name if you give one, and which page you signed up from.
3. What we do not do
Some of the clearest facts about a privacy policy are the negatives, so they are stated plainly:
- We do not sell, rent, or trade your personal data. There is no arrangement under which anyone pays us for it.
- We run no advertising network, no ad SDK, and no cross-app or cross-site tracking. The app carries no third-party analytics or attribution SDK.
- We do not read your location in the background, or at any time other than while you are capturing a listing.
- We do not read your contacts, call logs, SMS messages, or photo library beyond the images you deliberately pick or capture for a listing.
- We never see your M-Pesa PIN, card numbers, or banking credentials.
- We do not make automated decisions about you that carry a legal effect. Listing moderation, disputes, and refunds are reviewed by a person.
4. Why we use it, and our lawful basis
Section 30 of the Data Protection Act requires a lawful basis for each purpose. Ours:
| What we do | Data used | Lawful basis |
|---|---|---|
| Create and run your account, sign you in, keep you signed in | Name, email, phone number, password hash, session tokens | Performance of a contract with you (s.30(1)(b)(i)) |
| Confirm your email address before you can post or pay | Email address, one-time verification code | Performance of a contract; fraud prevention as a legitimate interest |
| Publish your listing and show an approximate map pin to seekers | Listing details, photos, walkthrough video, coarse coordinates | Performance of a contract with you as the poster |
| Prove a listing is real, and detect fake or duplicate listings | Photo GPS coordinates and capture time, moderation records | Legitimate interest in a trustworthy marketplace (s.30(1)(b)(vii)) |
| Reveal an exact address and phone number after an unlock is paid | Poster and landlord contact details, unlock record | Performance of a contract with both sides of the unlock |
| Take payment, hold and release credits, pay out commissions | M-Pesa number, amounts, transaction references and status | Performance of a contract; compliance with tax and financial record duties (s.30(1)(b)(ii)) |
| Handle disputes, refunds, reports of dead listings, and support tickets | Unlock and confirmation history, your messages, related listing data | Performance of a contract; legitimate interest in resolving disputes fairly |
| Prevent fraud, abuse, and account takeover; keep an audit trail | IP address, device or browser identifier, action logs, sign-in times | Legitimate interest in security (s.30(1)(b)(vii)); legal obligation where reported |
| Send transactional notices: verification codes, payment receipts, unlock and confirmation updates | Email address, phone number, the event being notified | Performance of a contract with you |
| Send optional alerts you switch on, such as saved-search alerts | Email address, phone number, your saved searches and notification settings | Your consent (s.30(1)(a)) — withdrawable in Settings at any time |
We do not use your data for a new purpose that is incompatible with the ones above without telling you first.
5. What other people can see
This is the part of the product with the most privacy at stake, so it is spelled out step by step.
- Before anyone pays: a seeker browsing your listing sees your photos, the walkthrough video, the rent and deposit, the unit type, the county and neighbourhood, the amenities, the availability date, and an approximate map pin. The pin is deliberately rounded, so it shows the area and not your door.
- Your exact address, your phone number, and the landlord or caretaker contact stay hidden at this stage. Your surname is not shown on a public listing.
- After a seeker pays to unlock: that one seeker, and nobody else, sees the exact address and the contact phone number for that listing. Each unlock is recorded against that seeker.
- When a move-in is confirmed: both sides see that the other confirmed, because the payout depends on it.
- If you raise a dispute or a support ticket: our moderation and support staff read what you sent and the records for the listing or unlock it concerns.
- Ratings and reviews you leave after an unlock are not published on the listing or shown to the person you rated. They go to our team, who use them to act on bad experiences.
Once a contact is revealed we cannot un-reveal it. Treat an unlock the way you would treat handing someone your number in person, because that is what it is.
7. Where your data is stored
Our servers, database, and media storage are operated by international providers on infrastructure outside Kenya, and some of the providers in section 6 process data outside Kenya as well. That makes them cross-border transfers under sections 48 and 49 of the Data Protection Act. Your M-Pesa payments are processed inside Kenya by Safaricom.
We rely on two grounds for those transfers: they are necessary to perform the contract we have with you, and each provider is bound by contractual terms requiring safeguards at least as strong as the ones the Act demands. You can ask us for details of the safeguards for any specific provider.
8. How long we keep it
We keep personal data only as long as the purpose it was collected for is still live, then delete it. In practice:
| Data | Kept for | Why |
|---|---|---|
| Your account and profile | Until you delete your account | You need it to sign in |
| Listings, photos, and walkthrough videos | Until you delete the listing, or your account | The listing is the product |
| Email verification and password-reset codes | Minutes — they expire, then are removed | A code that outlives its use is a liability |
| Sign-in sessions (refresh tokens) | Until they expire or you log out | Keeping you signed in |
| Payment and payout records | Seven years after the transaction | Kenyan tax and financial record-keeping duties |
| Unlock, confirmation, and dispute records | Seven years, as they are part of the payment trail | Resolving late disputes and meeting the same record duties |
| Security and audit logs | Up to two years | Investigating fraud and account takeover |
| Waitlist entries | Until launch, or until you ask us to remove you | Telling you when the product reaches you |
When you delete your account, records we are legally required to keep — chiefly payment entries and audit logs — are retained but stripped of the link to your identity, so they no longer point back to you.
9. How we protect it
- Everything travels over HTTPS: the app and the website talk to our servers over an encrypted connection, and the API is not served over plain HTTP.
- Passwords are stored as one-way hashes and are never recoverable, by us or by anyone who obtained the database.
- Phone numbers are stored encrypted, with a separate hash used for lookups so the plaintext is not needed to find an account.
- The database enforces row-level access rules on the tables that hold your own records, so a query made for one signed-in user cannot return another user's rows even if application code has a bug.
- Administrative actions are logged with the actor, the change, and the IP address behind it.
- Access to production data is limited to the staff who need it to operate the service.
No system is perfect. If a breach affects your personal data we will notify the Office of the Data Protection Commissioner within 72 hours of becoming aware of it, and tell you without undue delay where there is a real risk to your rights, as section 43 of the Act requires.
10. Your rights, and how to use them
Section 26 of the Data Protection Act gives you the following rights. Every one of them is exercisable by emailing us; some are already buttons in the app, which is faster.
- Be told what we hold and why — this policy, plus a fuller answer on request.
- Get a copy of your personal data, in a portable format, at no charge.
- Correct anything inaccurate or incomplete. Your name, phone number, and email are editable in the app under Profile.
- Delete your account and the data attached to it. In the app: Settings, then Delete Account. This removes your profile, listings, photos, videos, saved listings, unlocks, credits, and messages. Only the legally required records described in section 8 remain, without the link to you.
- Object to processing we base on a legitimate interest, and withdraw consent for anything based on consent — notification toggles are in Settings and take effect immediately.
- Ask us to restrict processing while a complaint or correction is being resolved.
To use any of these, email info@dalakenya.com from the address on your account, or from any address if you tell us enough to find your account. We will respond within 30 days. If we need longer we will say so, and why, before that deadline. We will not charge you and we will not ask you to justify the request.
11. Children
PataSpace is for adults renting homes. You must be at least 18 to hold an account. We do not knowingly collect personal data from children, and we do not target the service at them. If you believe a child has created an account, tell us at info@dalakenya.com and we will delete it.
13. Changes to this policy
We update this policy when the product changes. The date at the top of the page tells you when it last changed in a way that matters. If a change affects how we use data you have already given us, we will tell you in the app or by email before it takes effect, and where the law requires consent we will ask for it rather than assume it.
14. Complaints
If something about your data bothers you, write to us first at info@dalakenya.com — we would rather fix it than have you escalate.
You also have the right to complain to the regulator at any time, whether or not you contacted us. In Kenya that is the Office of the Data Protection Commissioner (ODPC), which accepts complaints at odpc.go.ke and at info@odpc.go.ke.
Questions about your data?
Email info@dalakenya.com. PataSpace is based in Nairobi, Kenya.