See also: Terms of Service
The short version
- We collect what we need to take a booking and get you up a mountain safely — your name, contact details, group size, emergency contact, and proof that you paid.
- We do not run advertising trackers or analytics. There are no third-party cookies on this site.
- Your data is stored on Appwrite Cloud servers in Frankfurt, Germany. That means it leaves Kenya.
- We never sell your data, and we do not share it for marketing.
- You can ask us for a copy of your data, ask us to correct it, or ask us to delete it. Section 8 explains how.
1. Who we are
Kilele Adventures (“we”, “us”) organises guided hiking and adventure trips in Kenya. For the purposes of the Data Protection Act, 2019, we are the data controller for the personal data described in this policy — we decide what is collected and why.
| Registered name | [REGISTERED COMPANY NAME] |
|---|---|
| Registered address | [REGISTERED POSTAL ADDRESS], Karen, Nairobi, Kenya |
| ODPC registration | [DATA CONTROLLER REGISTRATION NO.] |
| Privacy contact | hello@kileleadventures.co.ke |
| Phone / WhatsApp | +254 794 244 693 |
2. What we collect, and when
We only collect data at the moments listed below. Browsing the site anonymously collects none of it.
2.1 When you create an account
Your email address, first and last name, and a password. The password is hashed by our authentication provider and is never visible to us. You may optionally add a phone number and a profile picture.
2.2 When you sign in with Google
If you choose “Continue with Google”, Google shares three things with us: your name, your profile picture, and your email address. Nothing else. We cannot read your Gmail, your contacts, or anything else in your Google account. You can revoke this at any time at myaccount.google.com/permissions.
2.3 When you book a trip
| Data | Why we need it |
|---|---|
| Trip, date and group size | To reserve the right number of places |
| Emergency contact name and phone | Safety. We call this person if something happens to you on a trek. |
| Special requests | Dietary needs, medical conditions, accessibility. Optional, and only what you choose to tell us. |
| Total amount payable | Calculated by us from the published price — not taken from your browser |
A note on emergency contacts. When you give us someone else’s name and number, you are sharing their personal data. Please make sure they are happy for you to do so. We use it only to reach them in an emergency, and we delete it with the rest of the booking.
A note on special requests. If you tell us about a medical condition, that is sensitive personal data under section 2 of the Act. We use it only to keep you safe on the trip, we share it only with the guide leading your trek, and you are never required to provide it.
2.4 When you pay
Payment is made by M-Pesa, directly to us — not through this website. We never see or store your card details, PIN, or M-Pesa credentials. What we do store is the transaction reference, the amount, the date, and the screenshot you upload as proof of payment, together with your name, email, group size and travel date so we can match it to your booking.
2.5 When you contact us or subscribe
The contact form collects your name, email, phone number, message, and optionally the kind of adventure, group size and preferred date. The newsletter collects only your email address.
2.6 When you leave a testimonial
Your words, your name and your rating. Testimonials are published publicly on this site once approved — please do not include anything in one you would not want the world to read.
3. What we do not collect
- No analytics. No Google Analytics, no Meta Pixel, no heatmaps, no session recording.
- No advertising trackers, and no third-party cookies of any kind.
- No payment credentials. The site has no card form and no payment gateway.
- No location tracking. We never request your device’s GPS.
- No profiling and no automated decisions that produce legal effects, within the meaning of section 35 of the Act.
4. Cookies and browser storage
We set no advertising or analytics cookies, which is why this site has no cookie banner — there is nothing to ask you to consent to. We do use three items of browser storage, all strictly necessary for the site to function:
| Key | Purpose | Lifetime |
|---|---|---|
appwrite-fallback-… | Keeps you signed in. Needed because browsers increasingly block the normal session cookie. | Until you sign out |
kilele_oauth_return_to | Remembers the page you were on so Google sign-in returns you there | Cleared the moment you return |
kilele_user_id | Identifies your session to the app | Until the browser tab closes |
Clearing your browser storage signs you out. It does not delete anything held on our side.
5. Why we are allowed to use your data
| What | Lawful basis (Data Protection Act, 2019) |
|---|---|
| Taking and fulfilling a booking | Performance of a contract — s.30(1)(b)(i) |
| Emergency contact and medical notes | Protection of vital interests — s.30(1)(b)(iv), and your explicit consent for health information |
| Payment records and receipts | Legal obligation — tax and accounting records |
| Newsletter | Consent — s.30(1)(a), withdrawable at any time |
| Published testimonials | Consent, withdrawable at any time |
| Keeping the site secure and working | Legitimate interests — s.30(1)(b)(vii) |
6. Who else sees your data
We do not sell your personal data, and we do not share it with anyone for their own marketing. We use these service providers:
| Provider | What they do | Where |
|---|---|---|
| Appwrite Cloud | Hosts our database, accounts and uploaded files. All of the data in section 2 is stored here. | Frankfurt, Germany (EU) |
| Sign-in, only if you choose it. Google will know you signed in to our service. | Global | |
| Google Fonts | Serves the typeface. Your browser requests it from Google on each visit, which means Google receives your IP address even if you never sign in. | Global |
| Safaricom (M-Pesa) | Processes your payment under its own privacy policy. We receive only the reference. | Kenya |
| Cloudflare | Serves this page. | Global edge network |
Our guides see the trip roster, group sizes and any safety-relevant notes for the trek they are leading — nothing more. We will also disclose data where the law requires it, such as a court order or a lawful request from a regulator.
7. Where your data is stored, and transfers out of Kenya
Our database and files are hosted in Frankfurt, Germany. Your personal data therefore leaves Kenya and is processed in the European Union, which is a cross-border transfer under sections 48 and 49 of the Data Protection Act, 2019.
We rely on that destination having data-protection law at least as strong as Kenya’s — the EU General Data Protection Regulation — and on our processor’s contractual commitments. If you would rather your data not be stored outside Kenya, please contact us before booking; we may not be able to offer the online service, but we can take a booking another way.
8. Your rights
Under section 26 of the Act you have the right to:
- Be informed of how your data is used — this document
- Access a copy of the data we hold about you
- Correct anything inaccurate or incomplete
- Delete data that is false, misleading, or no longer needed
- Object to processing, including withdrawing consent at any time
- Portability — receive your data in a usable format
You can see and edit much of this yourself on your profile page while signed in. For anything else, email hello@kileleadventures.co.ke. We will respond within 7 days as the Act requires, and we will not charge you for a reasonable request.
If you are unhappy with how we have handled it, you may complain to the Office of the Data Protection Commissioner — odpc.go.ke, or info@odpc.go.ke.
9. How long we keep things
| Data | Kept for |
|---|---|
| Your account | Until you ask us to close it |
| Booking records | [7] years after the trip — tax and insurance requirements |
| Payment proof screenshots | [7] years, with the booking |
| Emergency contacts and medical notes | Deleted [90 days] after the trip ends |
| Contact form enquiries | [2] years |
| Newsletter email | Until you unsubscribe |
10. Keeping it safe
The site is served over HTTPS. Passwords are hashed by our authentication provider and never stored in readable form. Access to booking and payment records is restricted per record — you can see your own; our staff can see those they need for the trips they run. Prices and payment amounts are calculated on our server and cannot be altered from a browser.
No system is perfectly secure. If a breach occurs that presents a real risk to your rights, we will notify the Data Commissioner within 72 hours and tell you directly, as section 43 requires.
11. Children
Our online booking service is not intended for anyone under 18, and we do not knowingly create accounts for children. Under-18s are welcome on our trips when booked by a parent or guardian, who provides their details. If you believe a child has given us data directly, tell us and we will delete it.
12. Changes to this policy
We will update this page when what we do changes, and revise the date at the top. If a change materially affects your rights, we will tell account holders by email rather than relying on you to notice.