Home › Privacy Policy

Privacy Policy

What we collect when you use wuoth.com, why, who we share it with, and how to exercise your rights over it.

⚠ Draft — not yet in effect— this text has not been reviewed by a lawyer or checked against Kenya's Data Protection Act, 2019 registration requirements, and must not be treated as final.

wuoth.com is committed to handling your personal data responsibly and in line with Kenya’s Data Protection Act, 2019. This policy explains what we collect, why, and the choices and rights you have. It applies to customers, vendors, and visitors browsing without an account.

1. What we collect

WhatWhyWhen
Account detailsName, email, phone number, and a securely hashed password when you create a customer or vendor account.When you sign up or update your profile
Booking detailsName, email, phone, the listing booked, travel dates, and amount paid — sent to the relevant vendor so they can deliver the service, and used to send your confirmation.When you complete a booking, including as a guest
Payment confirmationThe outcome of a payment (paid/failed), a receipt or transaction reference, and the last-used payment method. We do not receive or store your full card number — Stripe processes and stores that directly — and we never see or store your M-Pesa PIN.When you pay via M-Pesa or card
Browsing activityPages you visit, how long you spend on each, and a randomly generated session identifier stored in your browser for the visit.Automatically, on every page you view
Device & locationApproximate location (country/city, derived from your IP address — not precise GPS), device type, browser and operating system.Automatically, from your browser and network connection
Vendor business dataBusiness name, listings, commission rate, wallet transactions and payout history.If you register and operate as a vendor

2. How we use it

  • To create and confirm bookings, and to send you confirmation, receipt, and (where you’ve started but not finished a booking) reminder emails.
  • To operate customer accounts, vendor accounts, and administrator access, including authenticating you when you log in.
  • To process payments and payouts, split commission, and detect and prevent fraud or abuse of the platform.
  • To understand how the platform is used in aggregate — which pages, listings and destinations are popular, and from where — so we and our vendors can improve the site and their listings.
  • To meet legal and accounting obligations, and to respond to you when you contact support.

We do not sell your personal data to third parties.

3. Who we share it with

We share the minimum necessary data with:

  • The vendor you book with — your name, contact details, and booking details, so they can deliver the service.
  • Payment processors — Stripe (card payments) and Safaricom (M-Pesa, via the Daraja API), to process your payment. These providers have their own privacy policies governing the payment data they handle directly.
  • Infrastructure providers who host the platform, store the database, and deliver images — currently Vercel and Neon — under contracts that restrict them to processing data only on our instructions.
  • Our transactional email provider, to deliver booking confirmations and account emails.
  • Flight-search partners, when you search or book a flight, so a live fare and itinerary can be returned to you.
  • Law enforcement or regulators, only where we are legally required to.

4. Cookies & local storage

We use a small number of essential technologies to make the platform work:

  • A secure, httpOnly session cookie that keeps you signed in — this cannot be read by JavaScript and is not used for advertising.
  • Browser local storage, on your device only, to remember your trip cart, saved listings, and currency preference between visits.
  • A session identifier, generated in your browser and cleared when you close the tab, used to group your page views into one visit for analytics.

We do not currently use third-party advertising or cross-site tracking cookies.

5. How long we keep it

Account and booking records are kept for as long as your account is active and for a reasonable period afterward to meet accounting, tax, and dispute-resolution obligations. Browsing/session analytics are kept in aggregate for product improvement and may be retained longer in a form that is not tied to your identity where possible.

6. Your rights

Under Kenya’s Data Protection Act, 2019, you have the right to: access the personal data we hold about you; request correction of inaccurate data; request deletion of your data, subject to our legal obligation to retain certain records (such as payment and booking history); object to or restrict certain processing; and lodge a complaint with the Office of the Data Protection Commissioner.

You can view and update most of your account details directly from your account settings, and view your bookings under “My Trips”. For anything else, contact us as described below.

7. Children

wuoth is not directed at children, and accounts require the account holder to be at least 18 years old. We do not knowingly collect personal data from children.

8. Security

Passwords are stored using industry-standard hashing, not in plain text. Sessions are cryptographically signed. The platform is served over HTTPS, with security headers in place to reduce common web attacks. No system is completely secure, and we cannot guarantee absolute security of information transmitted over the internet.

9. International transfers

Some of the infrastructure and payment providers we use may process or store data outside Kenya. Where this happens, we rely on those providers’ own security and compliance commitments (including, for Stripe, its own regulatory status as a payment processor).

10. Changes to this policy

We may update this policy from time to time; material changes will be reflected on this page.

11. Contact

To exercise any of the rights above, or with any question about this policy, reach us via our Contact page.

See also our Terms of Service.