Privacy Policy
Last updated: February 2026
1. Introduction
Locci Realtors ("we", "us", "our") is committed to protecting your personal information. This Privacy Policy explains how we collect, use, and safeguard data when you use our property management platform. We comply with Kenya's Data Protection Act 2019 and the Office of the Data Protection Commissioner (ODPC) guidelines.
2. Data We Collect
We collect the following categories of personal data:
- Account data: Name, email address, and authentication tokens when you sign in via OAuth.
- Property data: Property details, addresses, and rental information that you enter on the Platform.
- Tenant data: Tenant names, phone numbers, email addresses, ID numbers, and emergency contacts that landlords enter on behalf of their tenants.
- Payment data: Transaction amounts, M-Pesa reference numbers, and payment status. We do not store full M-Pesa PINs or card numbers.
- Usage data: Pages visited, features used, and browser information for platform improvement.
3. How We Use Your Data
We use collected data to:
- Provide and operate the property management platform
- Process rent payments via M-Pesa and card
- Send SMS notifications to landlords and tenants via Africa's Talking
- Generate reports and analytics for your property portfolio
- Provide AI-powered assistance through our chat feature
- Respond to support requests and communicate platform updates
4. M-Pesa Transaction Data
M-Pesa payments are processed through IntaSend. When a payment is initiated, we receive transaction metadata including the amount, timestamp, and reference number from IntaSend's webhook. This data is stored in our database to enable payment tracking and reconciliation. We do not have access to your M-Pesa PIN or full account details.
5. Sharing with Third Parties
We share data with the following third-party service providers strictly for the purpose of delivering our services:
- Africa's Talking: Tenant phone numbers are shared to deliver SMS notifications. Africa's Talking processes these as a licensed telecommunications service provider.
- IntaSend: Payment amounts and phone numbers are shared to initiate and verify M-Pesa STK Push transactions.
- MongoDB Atlas: All platform data is stored on MongoDB Atlas servers. Data is encrypted at rest and in transit.
- Groq AI: Chat messages you send to the AI assistant are processed by Groq's API. Do not include sensitive personal data in chat messages.
We do not sell your personal data to any third party for marketing purposes.
6. Data Storage and Security
Your data is stored on MongoDB Atlas with enterprise-grade encryption at rest (AES-256) and in transit (TLS 1.3). Access to production databases is restricted to authorized personnel only. We conduct regular security reviews and follow industry best practices for data protection.
7. Your Rights (ODPC Kenya)
Under Kenya's Data Protection Act 2019, you have the right to:
- Access a copy of your personal data
- Correct inaccurate or incomplete data
- Request deletion of your data (right to be forgotten)
- Object to processing of your data
- Withdraw consent at any time where processing is based on consent
- Lodge a complaint with the ODPC
To exercise these rights, contact us at privacy@loccirealtors.co.ke.
8. Cookies
We use essential cookies to maintain your authentication session. We do not use third-party advertising cookies or cross-site tracking. Authentication tokens are stored as HTTP-only cookies and expire after your session ends or within 7 days, whichever comes first.
9. Data Retention
We retain your data for as long as your account is active. If you close your account, your data is retained for 90 days to allow for account recovery, after which it is permanently deleted. Payment transaction records may be retained for 7 years to comply with Kenyan financial regulations.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or a prominent notice on the Platform. Continued use of the Platform after changes constitute your acceptance of the updated policy.
11. Contact
For privacy-related questions or to exercise your rights, contact our Data Protection Officer at privacy@loccirealtors.co.ke or visit our contact page.