Legal Center

Privacy Policy

Connect Local Africa collects the minimum personal information needed to run a safe marketplace. This policy explains exactly what we hold, why, who sees it, and how you stay in control.

Last updated: Questions? Email us

01Information we collect

We collect only what the marketplace needs to work:

  • Account data: name, email address, phone number, password hash, avatar.
  • Provider data: business details, service category, bio, service area, and verification documents you upload.
  • Booking data: job descriptions, addresses or areas, schedules, messages, reviews and photos.
  • Payment data: M-Pesa reference numbers, amounts, and payout destinations. We never store your PIN or full card numbers.
  • Technical data: device, browser, IP address, and usage analytics for security and product improvement.

02How we use your information

  • Matching customers with suitable, verified providers.
  • Processing bookings, escrow payments, commissions and payouts.
  • Verifying provider identity and preventing fraud or abuse.
  • Sending transactional notifications about your bookings and payments.
  • Improving search, reliability and safety of the platform.

04Sharing and disclosure

We do not sell your personal information. We share it only:

  • With the other party to a booking — providers see the request details you submit; customers see the provider profile.
  • With service processors: cloud hosting, database, email delivery, analytics and M-Pesa payment processing.
  • With authorities where legally required, or to prevent imminent harm or fraud.

05Cookies and analytics

We use essential cookies for authentication and security, and limited analytics cookies to understand usage. Details and controls are in our Cookie Policy.


06Data retention

  • Account data: kept while your account is active, then deleted or anonymised within 90 days of closure.
  • Booking and payment records: retained up to 7 years for tax, accounting and dispute-resolution obligations.
  • Verification documents: retained while the provider account is active, then deleted.
  • Support tickets and reports: retained up to 3 years.

07Security

Data is encrypted in transit (TLS) and at rest. Access to records is enforced at the database level with row-level security so users can only reach their own data. Verification documents live in a private bucket accessible only to authorised staff through short-lived signed links. Administrative access is role-based and audited.


08Your rights

Under Kenya’s Data Protection Act 2019 (and GDPR where applicable) you may request access, correction, deletion, restriction, portability, or object to processing.

Most of this is self-service in Settings — including editing your profile and deleting your account. For anything else, email supportconnectlocalafrica@gmail.com. We respond within 30 days.


09Children

Connect Local is not intended for anyone under 18. We do not knowingly collect data from children; if we learn we have, we delete it.


10International transfers

Our infrastructure providers may process data outside Kenya. Where that happens we rely on providers offering appropriate safeguards and contractual data-protection commitments.


11Changes to this policy

We may update this policy. Material changes are notified by email or in-app before they take effect, and the “last updated” date above always reflects the current version.

Need a human?

Our support team replies within 24–48 business hours.