Skip to content

Privacy Policy

Language notice. This document is provided in English, which is the authoritative version under our Terms of Service. Your browser can auto-translate it for reading, but legal nuance may be lost in translation. For clarification in your language, please contact us.

support@proptraka.ke

1. Introduction

PropTraka, a product of PropTraka Ventures("we," "us," or "our"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our property management platform, compliant with the Kenya Data Protection Act, No. 24 of 2019.

PropTraka Ventures is registered with the Office of the Data Protection Commissioner (ODPC) of Kenya as a Data Controller (Registration No. 684-4423-0396, valid 7 July 2026 – 7 July 2028). You can verify our registration on the ODPC public register or view our certificate of registration.

2. Information We Collect

We collect information that you provide directly to us, including:

  • Identity Data: Name, ID number, and contact details for verification.
  • Property Data: Details of the properties you manage or inhabit.
  • Property Owner Data:Where an account holder manages a property on behalf of its owner, they may record that owner's name, ID or passport number, KRA PIN, phone number, email address and postal address. This is used solely to name the correct landlord on tenancy agreements and related documents. The account holder is the data controller for these details and handles a property owner's access, rectification and erasure requests directly; you can also contact us at privacy@proptraka.ke. Where an owner is named on a signed tenancy agreement, their details are retained for the life of that agreement and the statutory record-keeping period that follows it, even after the owner record is archived.
  • Financial Data: Rent payment history, M-Pesa transaction identifiers (for reconciliation), and billing information.
  • Usage Data: How you interact with our platform and ARDO™ (our AI assistant).
  • Tax Compliance Data: KRA PINs (landlord and tenant), eTIMS OSCU credentials, invoice numbers, and VAT registration details for tax compliance purposes.
  • M-Pesa Daraja Credentials: Optional Consumer Key and Consumer Secret for landlords who connect their Safaricom Daraja API for automatic rent reconciliation. Both values are encrypted at rest with AES-256-GCM before they reach Firestore and are never displayed back to you in full once saved. PropTraka uses these credentials solely to call Safaricom on your behalf to receive C2B payment confirmations and initiate STK Push prompts to your tenants. You can disconnect at any time from Settings → Compliance → Daraja, which deletes the credentials and de-registers our callback URL with Safaricom.
  • SMS Forwarding Hash: A short opaque identifier (typically 4 characters) generated when you set up email-based SMS forwarding for Pochi La Biashara or Send Money channels. The hash forms the local part of your unique forwarding address (pay-{hash}@proptraka.com) and is used solely to route your forwarded M-Pesa SMSes to your account. The hash is non-reversible — it cannot be used to identify you outside our system.
  • Device Tokens: Push notification tokens for delivering push notifications to your browser or mobile device. Tokens are stored in your user profile and refreshed automatically.
  • Referral Data: Referral codes, referrer and referred user identifiers, and referral completion status for administering the referral rewards programme.
  • Passkey Credential Data: Passkey credential identifiers and public keys for passwordless authentication. The fingerprint, face unlock, or PIN you use to unlock a passkey on your own device is processed entirely on that device and never leaves it — we never receive or store it. This on-device claim applies only to passkey unlock, and is separate from the selfie and government-ID images collected during identity / TrustTraka™ verification (described below), which we do upload and securely store, and process using facial-recognition technology, for the duration of the identity check.
  • API Usage Data: API request counts, timestamps, and endpoints accessed for rate limiting and usage monitoring purposes.
  • Applicant Screening & Identity Verification Data:When a landlord initiates tenant screening, we collect the applicant's name, national ID number, date of birth, phone number, email address, and KRA PIN. We also collect and securely store government-ID images (front and back) and biometric data — a selfie processed with facial-recognition technology to confirm it matches the ID for identity verification, together with uploaded financial documents (M-Pesa and bank statements, payslips, and other income records) for behavioural analysis. KRA PINs are sent to the Kenya Revenue Authority for verification — only the verification result (valid/invalid) is stored; the full KRA response is not retained. These identity and financial documents are held for a short retention period tied to the screening (see "Data Retention" below).

3. How We Use Your Information

We use the collected data to:

  • Provide, maintain, and improve our property management services.
  • Generate TrustTraka™ reports based on verified financial and identity data.
  • Automate rent reconciliation and financial reporting.
  • Detect and prevent fraudulent activities.
  • Comply with statutory requirements from the Kenya Revenue Authority (KRA) and other regulatory bodies.
  • Where you have enabled eTIMS (a capability being rolled out subject to KRA go-live), generate and submit eTIMS-compliant rent invoices and credit notes to KRA.
  • Where enabled, deliver tenant notifications via WhatsApp (rent reminders, maintenance updates, payment confirmations). WhatsApp delivery depends on Meta's WhatsApp Business Platform availability and may be unavailable for certain accounts or message categories.
  • Screen prospective tenants on behalf of landlords, including AI-assisted identity verification, financial document analysis, and KRA PIN validation.

4. Cookies & Tracking Technologies

PropTraka uses cookies and similar technologies to enhance your experience:

  • Essential Cookies: Required for authentication, session management, and security (e.g., session cookies, CSRF tokens). These cannot be disabled.
  • Functional Cookies: Store your preferences such as language, currency, theme, and locale settings.
  • Analytical Cookies: Help us understand usage patterns to improve the platform. These are set only with your consent and are keyed to an internal identifier plus IP/approximate location (see §6); they are not fully anonymised. Off until you opt in.

You control non-essential cookies through our Cookie Policy and the in-app Cookie preferences manager (in the footer). Disabling essential cookies may prevent the platform from functioning correctly.

5. Data Minimisation & AI

When using ARDO™, our AI assistant, we employ strict data separation as per our AI Safety Policy. Your Personally Identifiable Information (PII) is never used to train general public models. Where tenant financial or identity-document content is analysed, we minimise it and redact third-party and non-essential personal details before processing. This is redaction, not full anonymisation— some personal data necessarily remains in the content our AI partners process on our behalf (see "Third-Party Data Sharing").

6. Third-Party Data Sharing

We may share your data with the following third parties strictly for the purpose of providing our services:

  • Safaricom / M-Pesa (independent controller): When money moves through M-Pesa (via the Daraja API), Safaricom PLC processes the transaction data as an independent data controller in its own right— for payment settlement, fraud and anti-money-laundering checks, and its own legal and regulatory obligations — not on PropTraka's behalf. PropTraka is a separate controller of the payment records it receives back for rent management. See Safaricom's Data Privacy Statement.
  • Paystack (independent controller / processor): Billing and card-payment data is handled by Paystack Payments Kenya Limited. Paystack acts both as our processor for the payment data we instruct it to handle and as a data controller in its own rightwhere it determines its own purposes — for example settlement, KYC / identity verification, anti-money-laundering, fraud prevention and card-scheme compliance. Card details are tokenised by Paystack on capture; PropTraka does not store or transmit full card numbers (PAN), CVV, or magnetic-stripe data. See Paystack's Privacy Policy.
  • Kenya Revenue Authority (KRA): Rent invoice data, credit note data, tenant KRA PINs (when provided), VAT amounts, and invoice line items are shared when you use eTIMS integration for invoice generation and submission.
  • Meta / WhatsApp:Phone numbers, message content (rent amounts, due dates, maintenance status), and delivery status data are shared with Meta for WhatsApp message delivery via the WhatsApp Business Platform (Cloud API). Meta's privacy policy governs their processing of this data.
  • Google Cloud / Firebase:We use Google Cloud Platform's Firestore for data storage and Firebase Authentication for user authentication. Firebase regions used are governed by Google's privacy policies and standard contractual clauses that provide protections compatible with the Kenya Data Protection Act, 2019.
  • Google reCAPTCHA Enterprise:We use Google reCAPTCHA Enterprise to protect public and account forms (for example sign-up, sign-in, and invite-accept) from bot abuse. When you submit a protected form, your browser sends a token to our server, which we verify with Google. Google may collect interaction signals (mouse, keyboard, timing) to score the request 0.0–1.0; we reject submissions scoring below 0.5. Use of reCAPTCHA is subject to Google's Privacy Policy and Terms of Service.
  • AI Processing Partners (Google Gemini & Anthropic Claude): Tenant financial and identity-document content is processed by our AI infrastructure partners — Google (Gemini) and Anthropic (Claude) — for ARDO™ features, in accordance with our AI Safety Policy. Before this content is sent we redact third-party and non-essential personal details; this is redaction, not anonymisation, so some personal data remains in what they process on our behalf. Both providers contractually do not use API data to train their public models. Where you upload lease templates or other agreements for merge-field analysis, the document text is sent transiently for placeholder suggestion only and is not retained by them beyond the request.
  • Market Data (Bright Data):Publicly available rental listing data from Kenyan property portals is aggregated via Bright Data to power ARDO™'s market intelligence features (rent comparisons, suburb analysis). Only public listing data is fetched; no personal user data is shared with Bright Data.
  • Email Delivery (Resend):Transactional email (receipts, security alerts, lifecycle and rent notifications) is delivered via Resend. Recipient address and message body transit Resend's infrastructure under their data-processing agreement.
  • Error Monitoring (Sentry): Application errors, performance traces, and request metadata are logged to Sentry to diagnose technical issues. Stack traces are scrubbed of PII where detected; request bodies are not captured by default.
  • Product Analytics (PostHog): Product-usage events (page views, feature clicks, funnel timings) are processed by PostHog (PostHog Inc.) so we can understand and improve how the platform is used. These events are keyed to an internal user identifier plus IP address / approximate location, so this is not fully anonymised. PropTraka processes this analytics data as an independent data controller for product improvement, and — where the platform offers it — tenants can opt out of product-improvement analytics without affecting their core tenancy.
  • Guarantor Data:Where a tenancy is marked as needing a guarantor and the landlord has not provided the guarantor's contact details up front, the tenant supplies the guarantor's full name and email when signing their agreement. PropTraka acts as data processor on the landlord's behalf for this guarantor data; the landlord remains the data controller and is responsible for ensuring the guarantor has consented to the use of their personal data.
  • Landlord (Applicant Screening): When you apply as a prospective tenant, your screening data (identity verification results, financial analysis summary, and KRA PIN validation status) is shared with the landlord who initiated the screening process. The landlord receives the screening outcome to inform their tenancy decision.

We do not sell your personal data to third parties. We do not share your data for advertising or marketing purposes without your explicit consent.

7. Data Retention

We keep personal data only for as long as we have a lawful reason to. In practice:

  • While your account is active: we retain your data for as long as your account or subscription is active and you are using the platform — and, once your account is no longer active, for the retention periods set out below (a recovery window, then the statutory and operational floors in the table).
  • On deletion or cancellation: when you delete your account, or after cancellation, data is kept for a limited recovery window to allow for reactivation and dispute resolution, after which it is purged from active systems. We do not promise instantaneous erasure, and residual copies may persist briefly in routine backups before those backups are rotated and overwritten.
  • Records we are legally required to keep: where the law requires it — chiefly financial-transaction and tax records for the Kenya Revenue Authority, including eTIMS invoice records (invoice numbers, amounts, SCU IDs, receipt numbers, and QR verification codes) — we retain those records for the statutory tax-record period of five years (Tax Procedures Act, 2015 (Cap. 469B), s.23), even after account closure, and they remain protected by the security and confidentiality measures in this Policy until deleted.
  • Applicant screening & identity documents: government-ID images, selfies, and uploaded financial documents collected for tenant screening are held for a short period tied to the screening. If an applicant is approved and becomes a tenant, the relevant data is migrated to their tenant profile; if the application does not proceed, the screening data is retained only for a limited period (for dispute resolution and audit) and then deleted. This purpose-limited approach is informed by anti-money-laundering good practice, though PropTraka is not itself a reporting institution under those rules.
  • Tenant portal after a landlord leaves:when a landlord's subscription expires or is deactivated, the tenant portal transitions to read-only mode — tenants can still view their payment history and documents but cannot make new payments or submit maintenance requests — and the associated tenancy data follows the same recovery-window and statutory-retention rules above.
  • Tenant notifications on deactivation:when a landlord's subscription is deactivated, tenants linked to that landlord's properties receive a one-time email with the landlord's contact details so they can arrange payments directly.

At a glance, here is how long we keep each category of data:

CategoryKept forLegal basis
Payments, invoices & tax recordsWhile active, then 5 yearsTax Procedures Act 2015 (Cap. 469B) s.23 (5-year floor) + Data Protection Act 2019 s.39(1)(a)
Data-request & signed-agreement audit trailsWhile active, then 5 yearsData Protection Act 2019 Reg.35 (logs) + establishment/defence of a legal claim
Records of who accessed your data1 yearData Protection Act 2019 Reg.35
Items you deleted (recoverable window)90 daysData Protection Act 2019 s.39
Backup metadata180 daysOperational security
WhatsApp conversation windows60 daysOperational
One-time passwords & passkey challenges7 daysData Protection Act 2019 s.39
Who's-online status7 daysData Protection Act 2019 s.39 (storage limitation)
Product-usage & messaging logs1 yearData Protection Act 2019 s.39 (data minimisation)
Application error reports90 daysData Protection Act 2019 s.39 (data minimisation)
Prospect screening & identity data (applicants who did not become tenants)90 daysData Protection Act 2019 s.39 (purpose limitation & minimisation)

8. Data Localisation & Security

In line with the Data Protection Act (s.48–49), we ensure that sensitive personal data is stored and processed under appropriate safeguards — whether by hosting that meets any applicable Kenyan localisation rules or by contractual and technical protections providing equivalent standards. We implement industry-standard encryption for all financial records and mobile money transaction data.

All uploaded files are scanned for malware before being stored. Files that fail security validation (invalid type, excessive size, or detected malware) are rejected immediately and are never persisted to our servers. This ensures that no infected or malicious content is stored alongside your data.

9. International Data Transfers

PropTraka uses enterprise cloud infrastructure, which may process data on servers located outside Kenya. All such transfers are subject to appropriate safeguards under the Kenya Data Protection Act, including:

  • Our cloud provider's Data Processing Agreement, which provides protections equivalent to the Kenya DPA.
  • Encryption of all data in transit (TLS) and at rest using industry-standard encryption.
  • Strict access controls, and audit logging of key administrative and access actions (rather than every event).

10. Data Breach Notification

In the unlikely event of a data breach, PropTraka is committed to notifying the Office of the Data Protection Commissioner (ODPC) within 72 hours of becoming aware of the breach, as required by law, and to communicating with affected users without undue delay where the breach poses a real risk of harm to them.

11. Children's Privacy

PropTraka is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have inadvertently collected data from a person under 18, we will take immediate steps to delete such data. A parent or guardian may contact us at privacy@proptraka.keto request deletion of a minor's data.

12. Who Is Responsible for Your Data: Your Landlord and PropTraka

PropTraka is the software your landlord, property manager, or agent uses to manage your tenancy. Because of that, two organisations handle your personal data, in two different ways — and the Kenya Data Protection Act, 2019 treats each role differently.

(a) For your tenancy data, PropTraka is your landlord's processor. The information tied to your tenancy — your name, phone number, email address, national ID number, KRA PIN, date of birth, and your rent and payment records — is controlled by your landlord (or the property manager or agent acting for them). They decide why it is collected and used. PropTraka simply processes it on their instructions to run the service: recording your rent, generating and e-signing your tenancy agreement (using our own e-signature capability), and sending the tenancy messages your landlord asks us to send. For this data, your landlord is the Data Controller and PropTraka is their Data Processor. If you want to access, correct, or delete your tenancy data, you can contact your landlord, or contact us and we will pass your request to them.

(b) For some purposes, PropTraka uses your data for its own reasons — as an independent controller. Separately, PropTraka processes some of your data for its own purposes, as an independent Data Controller(not on your landlord's instructions, and not as a joint controller). These purposes are:

  • TrustTraka™ — producing a tenant risk indicator to give landlords guidance;
  • ARDO™ and analytics — AI-assisted insights and understanding how the platform is used; and
  • Fraud prevention and platform security — keeping the platform safe and detecting misuse.

For these purposes PropTraka relies on its own lawful basis under the Act. Where the platform offers it, you choose whether to opt in to TrustTraka™, ARDO™, or product-improvement analytics. If you are a tenant, you can view and withdraw these optional consents anytime in the portal under Settings (/portal/settings); alternatively you can change or withdraw those choices by emailing privacy@proptraka.ke — your core tenancy keeps working either way.

TrustTraka™ — how the indicator is used. Any TrustTraka™ indicator we generate about you is advisory only. It is one input; your landlord (a human) makes every decision to approve, decline, or convert an application. The indicator is private to the landlord who requested it, and it is not sent to the Central Bank of Kenya (CBK) or to any Credit Reference Bureau (CRB). You can ask us about it and object to it.

One cross-landlord fraud check.To prevent fraud, PropTraka runs a duplicate-identity check across landlords: if an applicant's identity appears in more than one landlord's screening, the system shares only a match count(how many times that identity has appeared) — never a landlord's name, notes, or decision. This check is non-blocking: it can flag a possible concern but never automatically prevents you from being added as a tenant.

13. Marketing Communications

We will only send you marketing communications (product updates, promotions, newsletters) if you have provided explicit opt-in consent during registration or via your account settings. You may withdraw this consent at any time by:

  • Updating your notification preferences in your account Settings.
  • Clicking the "Unsubscribe" link at the bottom of any marketing email.

Transactional communications (payment receipts, security alerts, lease reminders) are not considered marketing and will continue regardless of your marketing preference.

13A. Mandatory Notifications (Auto Opt-In)

Certain notifications are classified as mandatory and cannot be opted out of. By creating an account, you automatically consent to receiving the following:

  • Legal Document Updates: Changes to these Terms of Service, Privacy Policy, or any other binding document.
  • Security Breach Notifications: In line with the Data Protection Act, 2019, we notify the Data Commissioner within 72 hours and will inform you without undue delay where a breach affecting your personal data poses a real risk of harm to you.
  • Emergency Service Disruptions: Critical platform incidents, scheduled maintenance, or service outages.
  • Regulatory Compliance Updates: Changes to Kenyan laws (KRA, Data Protection Act, POCAMLA) that affect your use of the platform.
  • Account Security Alerts: Login notifications, suspicious activity, and password changes.

These mandatory notifications are delivered via email and in-app push notifications. They are essential to the operation of your account and our legal obligations under Kenyan law, and cannot be disabled while your account is active.

14. Your Rights

Under the Data Protection Act, you have the right to access, rectify, or erase your personal data held by PropTraka. You also have the right to object to processing or request data portability.

If you are an account holder— a landlord, property manager, or agent with a PropTraka account — you can exercise these rights directly from your Data & Privacy settings.

The right to erasure is honoured for everyone whose data is held on a landlord's behalf, not only account holders — tenants, rental applicants, guarantors, contractors, witnesses, emergency contacts, and referees can all request it. If you fall into one of these groups, submit a request at proptraka.ke/data-request. We verify your identity with a one-time email code, then route the request to the landlord responsible for your data (or handle it ourselves where PropTraka is the Controller) for review and release.

How we fulfil an erasure request. We deleterecords that are solely about you. Where a record is shared — a tenancy or maintenance record a landlord is required to keep, for example — we anonymise it: your identifying details are severed so the operational record survives without them. We retainonly what the law requires, with the legal basis recorded against the request — chiefly tax records (Tax Procedures Act, 2015 (Cap. 469B), s.23) and records needed to defend a legal claim, including signed tenancy agreements (Kenya Data Protection Act, 2019, legal-obligation and legal-claim grounds).

We are honest about the limits of erasure. Five apply:

  • Your PropTraka portal account is not deleted by an erasure request made to one landlord — the account is yours across every landlord you're linked to. Delete it yourself from account settings, or ask us to.
  • Signed agreements and leases are retained as legal and contractual evidence — not anonymised.
  • Data inside historical multi-tenant reports and inbound payment-gateway logs cannot always be surgically removed (the proportionate-effort principle); these age out on our published retention schedule instead.
  • In free-text notes and messages, we remove your known identifiers — but an unrecognised mention of you in prose may remain.
  • Some erasure requests need a manual completion step by our team; we tell you once it's fully done.

This is a plain-English summary of how erasure works, not legal advice — if you need advice on your specific situation, consult a qualified professional.

To exercise these rights or raise any data protection concerns, please contact our Data Protection Officer:

  • Email: privacy@proptraka.ke
  • Address:PropTraka Ventures, P.O. Box 44875–00605, Nairobi, Kenya

You also have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) if you believe your data protection rights have been violated.

Last Updated: 2 August 2026. Nairobi, Kenya.