Privacy Policy
Last updated: 1 January 2026
This Privacy Policy explains how WhizzRent (“we”, “us”, “our”) collects, uses, stores, and discloses personal information when you use our property management platform - including the web application, mobile apps, and APIs - as a tenant, landlord, staff member, or visitor.
1. Data controller
WhizzRent is operated by [COMPANY NAME], registered in Kenya, with its principal office at [ADDRESS]. For data-protection questions, contact [DPO EMAIL].
2. Information we collect
2.1 Information you provide directly
- Account details: name, email, phone number, role (tenant / landlord / staff / caretaker), profile photo.
- Identity verification: ID type + number, KRA PIN (encrypted at rest).
- Tenant records: emergency contact, occupation, employer, alternate phone, date of birth, gender.
- Property + lease data: property addresses, unit numbers, rent amounts, deposit amounts, lease dates.
- Financial transactions: M-Pesa payments (amount, transaction reference, receipt number, phone number used), bank transfers, cash receipts, expense records.
- Communications: complaints submitted with optional photos, suggestions, notices, SOS alerts (with optional location + photo / audio attachment).
- Support communications: messages submitted via the contact form.
2.2 Information collected automatically
- Device + technical data: IP address, user-agent string, device type (for the mobile app), Firebase Cloud Messaging tokens for push notifications.
- Audit logs: a tamper-evident record of sensitive actions (payment verification, deposit refunds, staff CRUD, settings changes, MFA enable/disable, impersonation, anonymisation). Records the actor user ID, organisation, IP, user-agent, and before/after diff.
- Error reports: via Sentry, with personal identifiers and credentials redacted at source. PII is off by default.
2.3 Information from third parties
- M-Pesa Daraja API: we receive payment confirmations from Safaricom that include the payer's phone number, name, and receipt number.
3. How we use information
- To provide and operate the platform for your account
- To process M-Pesa, bank, and other rent payments
- To send invoices, receipts, payment reminders, and SOS escalations via SMS, email, WhatsApp, and push notifications
- To enable property managers to manage their tenants, leases, and properties
- To respond to support requests and contact-form submissions
- To detect and prevent fraud, abuse, and security incidents
- To comply with legal and regulatory obligations
- To improve the service (aggregated analytics only - no individual profiling)
4. Lawful basis (Data Protection Act, 2019)
We process personal data on one or more of these bases:
- Performance of a contract - to operate the tenant portal you signed up for, or the management platform your organisation contracted with us.
- Legitimate interest - fraud prevention, audit logging, security incident response.
- Consent - for optional notifications (WhatsApp marketing messages, email newsletters); you may withdraw consent at any time.
- Legal obligation - financial records retention for tax / bank-reconciliation requirements.
5. Sharing with third parties
We share personal information only with the service providers that operate the platform on our behalf, under data-processing agreements:
- Safaricom (M-Pesa Daraja API) - payment processing
- Africa's Talking - SMS delivery
- Meta (WhatsApp Cloud API) - WhatsApp messaging
- Google Firebase - push notification delivery (tokens only; no message content stored by Firebase)
- SMTP provider - transactional email
- S3-compatible storage - encrypted off-site backups
- Sentry - error reporting (PII redacted at source)
We do not sell or rent personal information to third parties for marketing.
6. International transfers
Some service providers above may process data outside Kenya. We rely on standard contractual clauses where required.
7. Retention
How long each category of data is kept is set by the landlord or property manager who is the data controller for it, category by category, with the period, the point it is measured from and the basis for it recorded. Those settings are not decided by this platform, and this page does not state a period on the controller's behalf.
Where a category has no confirmed retention rule, the platform will not destroy anything in it. A request about that category is still received and assessed, and the answer you are given says which categories were acted on and which were not, and why.
- Account data: kept while your account is active, and afterwards under the controller's confirmed rule for it.
- Financial records: kept where the landlord is required to keep them. Removing your identity from a record is a different act from destroying the record, and this platform treats them as different: an erasure destroys, an anonymisation keeps the record and takes you out of it, and which of them is carried out is stated in the answer you are given.
- Legal holds: a controller may record a decision that a category must not be destroyed - for example while a dispute is live. A hold has no expiry and is lifted only by a second authorised person, and nothing in a held category is destroyed while it stands.
- Audit records: the record of who did what to personal data is append-only, and is not removed by a request about the data it describes.
8. Your rights
Under the Data Protection Act, 2019, you have the rights below. Every one of them is exercised the same way here: from the privacy page in your account, or from the mobile app. What happens then is the same for all of them, and is worth reading once.
Asking changes nothing by itself. Each request opens a case with a reference you can follow. Somebody who is neither you nor whoever raised it for you decides it, item by item, so part of what you ask for may be agreed and part refused, each with its own reason. Nothing is carried out until that decision has been taken, and your account keeps working in the meantime. You are then given an answer that states what was actually done rather than what was asked for, and where something was kept, why it was kept.
- Access - a copy of the personal data held about you, as a readable document and a structured file, prepared after the request is reviewed and downloaded from your own account.
- Correct inaccurate data. A correction is asked for on your profile page and is answered field by field.
- Erasure - destroys data the landlord is not required to keep. It is not an anonymisation and it is not immediate: your account keeps working until the case has been decided and the authorised part carried out.
- Anonymisation - keeps the records and takes you out of them, where the sources allow it. It is a separate right from erasure and is decided separately.
- Object to a use of your data, or ask for a restriction to be lifted. Safety alerts cannot be stopped this way: they are what the platform is for.
- Withdraw consent for optional communications at any time.
- Complain to the Office of the Data Protection Commissioner (Kenya).
Where an account has been withdrawn and you can no longer sign in, contact [DPO EMAIL]. Requests are not accepted on a reference alone: a reference is printed on the answer you were given and identifies nobody, so it is never enough on its own.
9. Security
We protect personal data with: TLS in transit, AES-256 for sensitive fields and backups, role-based access control with optional MFA for staff, tamper-evident audit logging, database- level organisation isolation, and IP-restricted webhook endpoints. Sensitive admin actions require fresh MFA proof.
10. Children
WhizzRent is not intended for use by children under 18. We do not knowingly collect personal data from anyone under 18.
11. Changes to this policy
We may update this policy from time to time. Material changes will be communicated by email to account holders at least 30 days before they take effect.
12. Contact
For questions about this policy or to exercise any of your rights: /contact, email [DPO EMAIL], or call [PHONE].