Cookies Settings

    We use cookies to improve functionality and personalize your experience. You can manage your settings anytime. Read our cookies policy Cookies Policy

    Legal

    Privacy Policy

    Your privacy is at the heart of our journey. This policy explains how TembeaGo collects, uses, and protects your personal information in accordance with the Kenya Data Protection Act, 2019.

    Updated on: March 11, 2026

    Welcome to TembeaGo. By accessing TembeaGo, you are trusting us with your personal data — ranging from your name and contact details to your travel preferences and identification. We are committed to protecting that data with industry-standard security and being transparent about how it helps us get you to your next destination. If you do not agree with the practices described in this policy, please discontinue use of our Services.

    Table of Contents

    Your Rights as a Data Subject

    Under the Kenya Data Protection Act, 2019, you have specific rights regarding your personal information. TembeaGo is committed to ensuring you can exercise these rights easily:

    • Right to be Informed: Know why we collect your data and how we intend to use it.
    • Right of Access: Request a copy of the personal data we hold about you at any time.
    • Right to Rectification: Ask us to correct inaccurate, incomplete, or outdated information.
    • Right to Erasure: Request deletion of your account. It is deactivated immediately and your personal data is permanently and irreversibly erased within 30 days, unless we have a legal necessity to keep it.
    • Right to Object: Object to processing for specific purposes such as direct marketing or profiling.
    • Right to Data Portability: Request your data transferred to you or another provider in a structured electronic format.
    • Right to Withdraw Consent: Withdraw consent at any time where we rely on consent to process data.

    1. Information We Collect

    As a data controller and processor based in Kenya, TembeaGo collects and processes your personal data in strict accordance with the Kenya Data Protection Act (DPA), 2019. We only collect information that is necessary to facilitate your travel bookings and improve our services.

    A. Information You Provide Directly

    • Identity Data: Full name, gender, date of birth, and nationality.
    • Contact Data: Email address, phone number, and physical or postal address.
    • Travel Documentation: Passport numbers, issuance/expiry dates, and visa information — collected only when required by travel providers (e.g., airlines or hotels) to secure your reservation.
    • Profile Data: Your username, password, travel preferences (e.g., room types or dietary needs), and feedback.

    B. Information Collected Automatically

    • Technical & Usage Data: Your IP address, device type, browser information, and how you navigate the TembeaGo platform.
    • Location Data: With your explicit permission, we may collect GPS data to suggest local travel experiences within your vicinity.

    Device Fingerprinting for Security

    To protect our platform from automated abuse and API misuse — including by users who are not logged in — TembeaGo generates a lightweight device fingerprint in your browser. This applies to all users, including guests who have not created an account.

    Data points used to construct the fingerprint:

    • User Agent: Your browser name, version, and operating system string.
    • Language & Region: Your browser's configured language preference.
    • Screen Information: Screen resolution, color depth, and device pixel ratio.
    • Timezone: Your browser's reported timezone offset.
    • Hardware Concurrency: The number of logical CPU threads reported by your device.
    • Canvas Rendering Hash: A short hash derived from how your browser and graphics hardware render a hidden canvas element. This is a widely used, passive signal and no image is displayed or stored.

    Purpose: Fraud prevention, abuse detection, and rate-limiting of our AI Safari feature for unauthenticated (guest) requests. It is not used for advertising or cross-site tracking.

    Local storage: The computed fingerprint is cached in your browser's localStorage under the key _tg_dfp to avoid recomputing it on every page visit. It is not accessible to third-party scripts.

    Server-side retention: Device fingerprint values used for rate-limiting are held only within the active rate-limit window (typically 1 to 60 minutes) and are not written to our persistent databases beyond that window.

    Opt-out: The fingerprint is derived from stable browser and device characteristics, so clearing your browser's localStorage or site data will not change the fingerprint value itself — it will be recomputed identically on your next visit. To obtain a meaningfully different fingerprint, you would need to use a different browser or device. Privacy-hardening browser extensions (such as canvas blockers or strict fingerprint resistors) will reduce the precision of the fingerprint. Note that doing so may affect rate-limit allowances for the AI Safari feature.

    C. Payment Information

    TembeaGo does not currently collect or store any payment card details, bank account information, or financial credentials. Payments are not processed through our platform at this time. When payment features are introduced in the future, this policy will be updated and you will be notified in advance.

    2. How We Use Your Information

    At TembeaGo, we process your personal data only for specific, explicit, and legitimate purposes as permitted under Section 30 of the Kenya Data Protection Act.

    A. Booking Fulfillment

    • Service Coordination: We use your identity and contact data to process and confirm your travel reservations with third-party providers such as hotels, tour operators, and vendors.
    • Transactional Communication: We use your information to send booking confirmations, itinerary updates, and essential travel alerts.

    B. Personalization and AI-Driven Recommendations

    • Tailored Experiences: We use your search history and travel preferences to provide personalized travel suggestions via our AI Safari Chatbot and recommendations engine.
    • AI & Machine Learning: We may use AI algorithms to analyse your interactions with our platform to predict destinations or packages you might enjoy.
    • Opt-out Rights: In line with Section 35 of the Kenya Data Protection Act, you have the right not to be subject to a decision based solely on automated processing (profiling) that significantly affects you. You may opt out through your account settings or by contacting us.

    C. Safety, Security, and Fraud Prevention

    • Identity Verification: We use your data to verify your identity and prevent unauthorized access to your TembeaGo account.
    • Fraud Detection: We monitor platform activity to detect and prevent fraudulent bookings, payment scams, or malicious behaviour.
    • Legal Compliance: We may process your information to comply with Kenyan laws, including requests from the Office of the Data Protection Commissioner (ODPC) and law enforcement agencies.
    • Platform Integrity: We use technical data (like IP addresses) to protect our infrastructure from cyberattacks and ensure continuous service availability.

    We rely on the following legal grounds under Kenyan law to process your data:

    1. 1Contractual Necessity: To get you booked and on your way.
    2. 2Consent: For AI-driven personalization and marketing where you have specifically opted in.
    3. 3Legal Obligation: To meet our regulatory requirements within the Republic of Kenya.
    4. 4Legitimate Interests: To improve our platform's security and performance, provided these interests do not override your fundamental rights.

    4. Sharing Your Information

    In order to provide our services and ensure a smooth travel experience, TembeaGo may share your personal data with specific third parties. We do not sell your personal information. All sharing is conducted under strict confidentiality agreements and in compliance with the Kenya Data Protection Act, 2019.

    A. Service Providers

    • Infrastructure & Hosting: We use secure cloud service providers to store our data and host our platform.
    • Customer Support & Communication: We may share your contact details with tools that help us manage our email, SMS notifications, and support.

    B. Travel Suppliers (Hotels, Tour Operators, Vendors)

    • Booking Fulfillment: We share your identity data with the vendors and service providers whose listings you book so they can fulfil your reservation.
    • International Transfers: Where travel involves crossing borders, your data may be shared with suppliers outside Kenya. In such cases, TembeaGo ensures adequate safeguards are in place as required by Part VI of the Data Protection Act.

    C. Legal Disclosures and Business Transfers

    • Legal Compliance: We may disclose your information to the ODPC or law enforcement if required by law, a court order, or to protect the safety and rights of our users.
    • Fraud Prevention: We share data with fraud detection agencies to protect TembeaGo and our users from malicious activity.
    • Business Transfers: If TembeaGo undergoes a merger, acquisition, or sale of assets, we will notify you and ensure the new entity adheres to the same level of privacy protection.

    Data Sharing Safeguards

    • Data Minimization: We only share the specific information required to complete the task.
    • Contractual Protection: We use Data Processing Agreements (DPAs) to ensure third parties treat your data with the same level of care.
    • Accountability: We remain responsible for the data we share and conduct regular reviews of our partners' security practices.

    5. Cookies & Tracking Technologies

    TembeaGo uses cookies and similar tracking technologies to analyse trends, administer the platform, track users' movements, and gather demographic information. In line with the Kenya Data Protection Act, you have the choice to manage these technologies.

    Categories of Cookies We Use

    Strictly Necessary

    Essential for the platform to function — secure log-ins, page navigation, booking progress. Cannot be switched off.

    Functional

    Remember choices you make (preferred language, region) to provide enhanced, more personal features.

    Performance & Analytics

    Help us understand how visitors interact with TembeaGo by collecting anonymous usage data.

    Marketing & Targeting

    Track visitors across websites to display relevant travel ads based on your browsing activity.

    Your Choices

    • Cookie Banner: When you first visit TembeaGo, we will present a banner asking for your consent to use non-essential cookies.
    • Granular Control: You can choose to "Accept All," "Reject All," or select specific categories you are comfortable with.
    • Browser Settings: You can configure your browser to refuse all or some cookies. Note: disabling cookies may affect platform functionality.

    localStorage and Similar Browser Storage

    In addition to cookies, TembeaGo uses browser localStorage for certain security and functional purposes. Specifically, the device fingerprint described in Section 1.B above is cached in localStorage under the key _tg_dfp. Unlike cookies, localStorage values are not transmitted automatically with every HTTP request and are not accessible to third-party origins. You can clear localStorage at any time via your browser's "Clear site data" or privacy settings, which will also reset your local fingerprint cache.

    6. Data Retention & Security

    A. How Long We Keep Your Information

    • Active Accounts: We retain your profile information for as long as your TembeaGo account is active.
    • Deleted Accounts: When you delete your account, it is deactivated immediately and your name, email, phone, photo, and other personal data are permanently and irreversibly erased within 30 days. We keep this short window so our support and trust & safety teams can assist with any in-progress bookings or disputes before the data is gone for good.
    • Booking Records: We retain records of your bookings and related communications for a reasonable period to support dispute resolution and service continuity.
    • Travel Documents: Sensitive data like passport copies are deleted or anonymized once the travel service is completed and the dispute window has closed.
    • Inactivity: If your account remains inactive for more than 3 consecutive years, we will contact you. If no response, we will safely delete or anonymize your data.

    B. How We Protect Your Data

    • Encryption: All data transmitted between your device and our servers is protected using SSL/TLS encryption.
    • Access Control: Access to your personal information is strictly limited to authorized TembeaGo employees and partners who require it to fulfil your booking.
    • Storage Security: Our databases are hosted in secure data centers with advanced firewalls and 24/7 monitoring.
    • Incident Response: In the event of a data breach, we will notify affected users and relevant authorities as soon as practicable in accordance with Kenyan law.
    • Data Disposal: When retention periods expire, digital files are purged using secure deletion protocols and any physical records are shredded.

    7. Your Privacy Rights & Choices

    A. Accessing, Correcting, and Deleting Your Data

    • Right of Access: Request a copy of the personal data we hold about you in a structured, machine-readable format.
    • Right to Rectification: Update inaccurate or incomplete information directly through your account settings or by contacting us. We must act within 14 days.
    • Right to Erasure: Request deletion of your personal data ("Right to be Forgotten") by deleting your account. Your account is deactivated immediately, and — unless we have a legal or tax obligation to retain it — your personal data (name, email, phone, photo, and other identifying information) is permanently and irreversibly erased within 30 days. We keep the deactivated account record itself, stripped of your personal data, only as long as needed to preserve booking history, receipts, and dispute records for other parties involved in those transactions.

    B. Opting Out

    • Marketing Opt-Out: We only send promotional messages if you have given explicit consent. You can withdraw at any time by clicking "Unsubscribe" in any email or adjusting your notification preferences in your account.
    • Automated Profiling: You may opt out of AI-driven personalization at any time through your account settings.

    C. How to Exercise Your Rights

    Contact our Data Protection lead:

    Email: privacy@tembeago.com

    Response Timeline: We aim to respond to all legitimate requests within 7–14 days, as prescribed by the Data Protection (General) Regulations 2021. There is generally no fee for exercising these rights.

    8. Children's Privacy

    TembeaGo is not directed to children under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a minor, please contact us immediately and we will take steps to delete such information.

    9. Changes to This Privacy Policy

    We reserve the right to update or modify this Privacy Policy at any time in accordance with applicable law. When changes are made, we will post the revised version on our website and update the "Last Updated" date. If we make material changes, we will provide at least 30 days' notice before the updated policy takes effect. Your continued use of our Services after the effective date constitutes acceptance of the updated policy.

    10. Contact Us

    If you have any questions about this Privacy Policy or wish to exercise any of your data rights, please contact us:

    TembeaGo

    Email: privacy@tembeago.com

    General Inquiries: info@tembeago.com

    Regulated under the Kenya Data Protection Act, 2019. Supervised by the Office of the Data Protection Commissioner (ODPC).

    Last updated: March 11, 2026