Kilele Adventures • The Tribe • Kenya

Privacy Policy

How we collect, use, store and share your personal data — and what you can tell us to do about it.

Last updated: 15 September 2026  ·  Applies to: kileleadventures.anchorstack.tech and any Kilele Adventures booking service

The short version

1. Who we are

Kilele Adventures (“we”, “us”) organises guided hiking and adventure trips in Kenya. For the purposes of the Data Protection Act, 2019, we are the data controller for the personal data described in this policy — we decide what is collected and why.

Registered name[REGISTERED COMPANY NAME]
Registered address[REGISTERED POSTAL ADDRESS], Karen, Nairobi, Kenya
ODPC registration[DATA CONTROLLER REGISTRATION NO.]
Privacy contacthello@kileleadventures.co.ke
Phone / WhatsApp+254 794 244 693

2. What we collect, and when

We only collect data at the moments listed below. Browsing the site anonymously collects none of it.

2.1 When you create an account

Your email address, first and last name, and a password. The password is hashed by our authentication provider and is never visible to us. You may optionally add a phone number and a profile picture.

2.2 When you sign in with Google

If you choose “Continue with Google”, Google shares three things with us: your name, your profile picture, and your email address. Nothing else. We cannot read your Gmail, your contacts, or anything else in your Google account. You can revoke this at any time at myaccount.google.com/permissions.

2.3 When you book a trip

DataWhy we need it
Trip, date and group sizeTo reserve the right number of places
Emergency contact name and phoneSafety. We call this person if something happens to you on a trek.
Special requestsDietary needs, medical conditions, accessibility. Optional, and only what you choose to tell us.
Total amount payableCalculated by us from the published price — not taken from your browser

A note on emergency contacts. When you give us someone else’s name and number, you are sharing their personal data. Please make sure they are happy for you to do so. We use it only to reach them in an emergency, and we delete it with the rest of the booking.

A note on special requests. If you tell us about a medical condition, that is sensitive personal data under section 2 of the Act. We use it only to keep you safe on the trip, we share it only with the guide leading your trek, and you are never required to provide it.

2.4 When you pay

Payment is made by M-Pesa, directly to us — not through this website. We never see or store your card details, PIN, or M-Pesa credentials. What we do store is the transaction reference, the amount, the date, and the screenshot you upload as proof of payment, together with your name, email, group size and travel date so we can match it to your booking.

2.5 When you contact us or subscribe

The contact form collects your name, email, phone number, message, and optionally the kind of adventure, group size and preferred date. The newsletter collects only your email address.

2.6 When you leave a testimonial

Your words, your name and your rating. Testimonials are published publicly on this site once approved — please do not include anything in one you would not want the world to read.

3. What we do not collect

4. Cookies and browser storage

We set no advertising or analytics cookies, which is why this site has no cookie banner — there is nothing to ask you to consent to. We do use three items of browser storage, all strictly necessary for the site to function:

KeyPurposeLifetime
appwrite-fallback-…Keeps you signed in. Needed because browsers increasingly block the normal session cookie.Until you sign out
kilele_oauth_return_toRemembers the page you were on so Google sign-in returns you thereCleared the moment you return
kilele_user_idIdentifies your session to the appUntil the browser tab closes

Clearing your browser storage signs you out. It does not delete anything held on our side.

5. Why we are allowed to use your data

WhatLawful basis (Data Protection Act, 2019)
Taking and fulfilling a bookingPerformance of a contract — s.30(1)(b)(i)
Emergency contact and medical notesProtection of vital interests — s.30(1)(b)(iv), and your explicit consent for health information
Payment records and receiptsLegal obligation — tax and accounting records
NewsletterConsent — s.30(1)(a), withdrawable at any time
Published testimonialsConsent, withdrawable at any time
Keeping the site secure and workingLegitimate interests — s.30(1)(b)(vii)

6. Who else sees your data

We do not sell your personal data, and we do not share it with anyone for their own marketing. We use these service providers:

ProviderWhat they doWhere
Appwrite Cloud Hosts our database, accounts and uploaded files. All of the data in section 2 is stored here. Frankfurt, Germany (EU)
Google Sign-in, only if you choose it. Google will know you signed in to our service. Global
Google Fonts Serves the typeface. Your browser requests it from Google on each visit, which means Google receives your IP address even if you never sign in. Global
Safaricom (M-Pesa) Processes your payment under its own privacy policy. We receive only the reference. Kenya
Cloudflare Serves this page. Global edge network

Our guides see the trip roster, group sizes and any safety-relevant notes for the trek they are leading — nothing more. We will also disclose data where the law requires it, such as a court order or a lawful request from a regulator.

7. Where your data is stored, and transfers out of Kenya

Our database and files are hosted in Frankfurt, Germany. Your personal data therefore leaves Kenya and is processed in the European Union, which is a cross-border transfer under sections 48 and 49 of the Data Protection Act, 2019.

We rely on that destination having data-protection law at least as strong as Kenya’s — the EU General Data Protection Regulation — and on our processor’s contractual commitments. If you would rather your data not be stored outside Kenya, please contact us before booking; we may not be able to offer the online service, but we can take a booking another way.

8. Your rights

Under section 26 of the Act you have the right to:

You can see and edit much of this yourself on your profile page while signed in. For anything else, email hello@kileleadventures.co.ke. We will respond within 7 days as the Act requires, and we will not charge you for a reasonable request.

If you are unhappy with how we have handled it, you may complain to the Office of the Data Protection Commissionerodpc.go.ke, or info@odpc.go.ke.

9. How long we keep things

DataKept for
Your accountUntil you ask us to close it
Booking records[7] years after the trip — tax and insurance requirements
Payment proof screenshots[7] years, with the booking
Emergency contacts and medical notesDeleted [90 days] after the trip ends
Contact form enquiries[2] years
Newsletter emailUntil you unsubscribe

10. Keeping it safe

The site is served over HTTPS. Passwords are hashed by our authentication provider and never stored in readable form. Access to booking and payment records is restricted per record — you can see your own; our staff can see those they need for the trips they run. Prices and payment amounts are calculated on our server and cannot be altered from a browser.

No system is perfectly secure. If a breach occurs that presents a real risk to your rights, we will notify the Data Commissioner within 72 hours and tell you directly, as section 43 requires.

11. Children

Our online booking service is not intended for anyone under 18, and we do not knowingly create accounts for children. Under-18s are welcome on our trips when booked by a parent or guardian, who provides their details. If you believe a child has given us data directly, tell us and we will delete it.

12. Changes to this policy

We will update this page when what we do changes, and revise the date at the top. If a change materially affects your rights, we will tell account holders by email rather than relying on you to notice.