Privacy Policy
Last updated: December 29, 2025
1. Introduction
Welcome to WABI ("we," "our," or "us"). WABI is a service marketplace application operated by KEPAS (Kenya Professionals in Application Solutions) that connects clients with skilled service providers ("fundis") in Kenya.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and website (collectively, the "Service"). This policy complies with the Kenya Data Protection Act, 2019 and applicable international data protection standards.
2. Information We Collect
2.1 Information You Provide
| Data Type | Examples | Purpose |
|---|---|---|
| Account Information | Name, phone number, email address | Account creation, authentication, communication |
| Profile Information | Profile photo, bio, skills (for workers) | Service matching, trust building |
| Identity Verification | National ID, KRA PIN (for workers) | Verification, compliance, safety |
| Payment Information | M-Pesa phone number | Processing payments via M-Pesa |
| Communication Data | Messages, reviews, support tickets | Service delivery, dispute resolution |
2.2 Information Collected Automatically
| Data Type | Details | Purpose |
|---|---|---|
| Location Data | GPS coordinates (with your permission) | Finding nearby workers, service delivery |
| Device Information | Device type, OS version, app version | App optimization, troubleshooting |
| Usage Data | Features used, booking history | Service improvement, personalization |
| Log Data | IP address, access times, errors | Security, debugging, analytics |
2.3 Sensitive Personal Data
We may collect the following sensitive data with your explicit consent:
- Biometric data: Facial recognition for identity verification (optional)
- Government IDs: National ID for worker verification
- Financial identifiers: KRA PIN for tax compliance
3. How We Use Your Information
We use your information for the following purposes:
3.1 Service Delivery
- Creating and managing your account
- Matching clients with appropriate service providers
- Processing bookings and payments via M-Pesa
- Facilitating communication between clients and workers
- Providing customer support
3.2 Safety and Security
- Verifying worker identities and qualifications
- Preventing fraud and unauthorized access
- Resolving disputes between users
- Complying with legal obligations
3.3 Improvement and Analytics
- Analyzing usage patterns to improve our Service
- Developing new features
- Conducting research and surveys
3.4 Communications
- Sending booking confirmations and updates
- Service-related notifications (SMS, push, email)
- Marketing communications (with your consent)
4. Information Sharing and Disclosure
We share your information only in the following circumstances:
4.1 With Other Users
- Clients see: Worker's name, profile photo, ratings, skills, and general location
- Workers see: Client's name, service location, and booking details
- Phone numbers are shared only after booking confirmation for service coordination
4.2 With Service Providers
- M-Pesa (Safaricom): Payment processing
- SMS providers: Sending notifications and OTPs
- Cloud services: Data storage and processing
- Analytics providers: App improvement (anonymized data)
4.3 Legal Requirements
We may disclose your information when required by:
- Kenyan law or legal process
- Government authorities (KRA, ODPC, law enforcement)
- Court orders or legal proceedings
4.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you of any such change.
5. Data Security
We implement robust security measures to protect your data:
- Encryption: All data transmitted using TLS/SSL encryption
- Secure Storage: Data stored in encrypted databases
- Access Controls: Limited access to personal data on need-to-know basis
- Authentication: OTP verification, secure session management
- Monitoring: Regular security audits and monitoring
6. Data Retention
We retain your data for the following periods:
| Data Type | Retention Period |
|---|---|
| Account Information | Duration of account + 2 years |
| Booking Records | 7 years (tax compliance) |
| Payment Records | 7 years (KRA requirements) |
| Messages | 1 year after booking completion |
| Location Data | 30 days (for active bookings only) |
After these periods, data is anonymized or securely deleted.
7. Your Rights (Kenya Data Protection Act 2019)
Under Kenyan law, you have the following rights:
7.1 Right to Access
Request a copy of the personal data we hold about you.
7.2 Right to Rectification
Request correction of inaccurate or incomplete data.
7.3 Right to Erasure
Request deletion of your data (subject to legal retention requirements).
7.4 Right to Restrict Processing
Request limitation of how we use your data.
7.5 Right to Data Portability
Receive your data in a structured, machine-readable format.
7.6 Right to Object
Object to processing of your data for certain purposes.
7.7 Right to Withdraw Consent
Withdraw consent at any time for processing based on consent.
8. Location Data
Location data is essential for connecting you with nearby service providers.
8.1 How We Use Location
- Finding workers near your service location
- Calculating accurate travel distances and times
- Showing workers jobs in their service areas
- Verifying job completion at correct locations
8.2 Your Control
- You can disable location access in your device settings
- Workers can set their service areas manually
- Precise location is only active during active bookings
9. Children's Privacy
WABI is not intended for children under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately at privacy@wabi.services.
10. Third-Party Links and Services
Our Service may contain links to third-party websites or integrate with third-party services (e.g., M-Pesa). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.
11. International Data Transfers
Your data is primarily stored and processed in Kenya. If data is transferred internationally (e.g., to cloud service providers), we ensure appropriate safeguards are in place in compliance with the Kenya Data Protection Act 2019.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes through:
- In-app notifications
- Email to your registered address
- SMS notification
Continued use of the Service after changes constitutes acceptance of the updated policy.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
KEPAS (Kenya Professionals in Application Solutions)
Data Protection Officer
Email: privacy@wabi.services
General: support@wabi.services
Website: https://wabi.services
Location: Nairobi, Kenya
Regulatory Authority
You may also lodge a complaint with the Office of the Data Protection Commissioner (ODPC) Kenya:
Office of the Data Protection Commissioner
Website: www.odpc.go.ke
14. Consent
By using WABI, you consent to the collection and use of your information as described in this Privacy Policy. For processing that requires explicit consent (such as marketing communications or sensitive data), we will request your specific consent separately.