TAJA policy
Privacy Policy
What we collect, why, who it goes to, how long we keep it, and the rights you have over it under the Kenya Data Protection Act.
Who we are and scope
TAJA is the data controller for the personal information described in this policy. We are established in Kenya and process personal data in line with the Kenya Data Protection Act, 2019, and, where they apply to you, other data-protection laws of your country of residence. This policy explains what we collect, why, how we share it, and your rights. Contact for anything privacy-related: info@taja.co.ke. By using the Platform you acknowledge this policy.
What we collect
Account details: your name, email, phone number and role. If you sign in with Apple or Google, we receive the name and email address that service shares with us (with Apple's Hide My Email, a private relay address), never your password for it. Booking details: the service, professional, time, address and status of each booking, plus reviews. Messages: what you and the other person on a booking write to each other in the app, kept with the booking and used to deliver them and, if something is reported or disputed, to look into it. Reports and blocks: what you report to us and who you block, so we can act on the report and enforce the block. Payment details: the amount, currency, a reference, the instrument type (M-Pesa, card or bank transfer) and the receipt. Your M-Pesa PIN and card data are entered on Paystack's own checkout page and never reach TAJA. Where you pay by M-Pesa we also hold the number in 254 format. Payout details: a Professional's chosen M-Pesa payout name and number. Location: a Professional's live position during their active bookings, and a Client's saved address for home services. Photos: profile and portfolio images. Verification details, for Professionals: the outcome of the identity check, the ID number, and the licence or certificate a trade requires. Safety contact: a Professional may give us the name and phone number of someone to alert if a job runs well past its end and they have not checked out; we use that number only for that alert, and never show it to Clients. Device data: a push-notification token for your device, so we can send you booking updates. Technical and security data: crash diagnostics (device model, OS version, error trace) and an audit log of administrative and security-relevant actions, including IP addresses, used to operate and protect the Platform.
Why we use it and our legal bases
We process personal data to: provide the Platform (perform our contract with you) — matching, bookings, payments, payouts, receipts and tracking; keep it safe and prevent fraud and abuse (our legitimate interests and legal obligations) — vetting, rate-limiting, audit logging and investigating reports; meet legal, tax and accounting obligations; and support and improve the service. We do not sell your personal data and we do not show third-party advertising.
International transfers
TAJA is available internationally, and some of our service providers process data outside your country. Where personal data is transferred across borders — including to or from Kenya — we take steps to ensure it remains protected to a standard consistent with the Kenya Data Protection Act, 2019 and any other data-protection law applicable to you, including through appropriate contractual safeguards with those providers.
How long we keep it
We keep account data while your account is active. Booking, payment and payout records are kept for as long as needed for receipts, dispute resolution, and our legal, tax and accounting obligations. Live-location points are transient — only the latest position of an active booking is retained, and it stops when the booking ends. Crash reports are kept for a limited period for debugging. Security and audit logs — the record of sensitive actions such as sign-ins, payouts and account changes — are kept for as long as we need them to investigate fraud and abuse and to meet our legal and accounting obligations. When data is no longer needed, we delete or anonymise it.
Security
All traffic between the app and our servers is encrypted in transit (TLS). Passwords are stored only as strong one-way hashes (BCrypt) on the server, never in the app or in plain text. Card data is handled entirely by Paystack's PCI-certified systems and never touches TAJA's servers. Sessions use short-lived tokens with single-use rotating refresh tokens. Access controls ensure only you (and your booked counterpart) can see your bookings and location, brute-force and abuse protections are in place, and administrative actions are recorded in an audit log. No system is perfectly secure, and we cannot guarantee absolute security; you are responsible for keeping your credentials safe.
Your rights
Subject to the Kenya Data Protection Act, 2019, you may request to access, correct, delete, or restrict the personal data we hold about you, object to certain processing, or request portability. You can download a copy of your data, in a machine-readable format, at any time from Account in the app. For anything else, email info@taja.co.ke from your account email and we will respond within the timeframes the law requires. Deleting your account removes your profile and personal details; records we are required to keep by law (such as payment records) are retained only as long as required. You also have the right to lodge a complaint with the Office of the Data Protection Commissioner in Kenya or, if you are resident elsewhere, with your local data-protection supervisory authority.
Children
TAJA is strictly for adults aged 18 and over. We do not knowingly collect data from anyone under 18 and will delete such accounts and data when we become aware of them.
Changes
If we change this policy we will signal material changes in the app. Continued use after changes take effect means you acknowledge the updated policy.