Privacy policy

How ardena collects, uses, and protects your personal information under the Data Protection Act, No. 24 of 2019 (Kenya).

Last updated: 28 May 2026

01 / The short version

Read this first.

A plain-English summary so you know where you stand before the detail. The numbered sections below are the binding terms.

  • Ardena Group Ltd is the data controller for personal data you provide while using ardena. Our partner Dojah Africa Ltd acts as a data processor for identity verification only.
  • We use your data to run the platform — to create your account, verify you, match you with a host or renter, take payment, support you, comply with the law, and keep the platform safe.
  • Verification data goes through Dojah, encrypted, and we do not keep the raw inputs. Your government ID number, ID document photo, selfie, and liveness data are transmitted directly to Dojah over TLS. Ardena receives a verification result (pass / fail, reference, timestamp) and stores that result — not the underlying ID image or biometric template.
  • Account data we do hold includes your name, email, phone number, profile photo, location at booking, communications with hosts or renters, and booking and payment history.
  • You have rights under the Data Protection Act, No. 24 of 2019 (Kenya): access, correction, erasure, objection, restriction, portability, and the right to complain to the Office of the Data Protection Commissioner (ODPC).
  • To delete your account and data, use the in-app option or the request form on the delete account page.
  • Account data

    Full name, email address, mobile number, password (stored hashed), profile photograph, date of birth, account creation timestamp, device and IP information for security. Used to create and run your account.

  • Verification data

    Government-issued ID number, ID document photograph, selfie/liveness capture, and location at the time of verification. Submitted in the app, routed to Dojah over TLS, and not retained by Ardena in raw form — see section 03.

  • Booking & transaction data

    Bookings made, vehicles browsed, pickup and drop-off locations, payment method (processed via PCI-compliant providers; we do not store full card numbers), invoices and refunds, and any incident reports.

  • Communications

    In-app messages between renters and hosts, support tickets, and platform-initiated SMS or email. Call content is not recorded; call metadata may be logged for safety.

  • Location data

    Approximate location (city or region) for compliance with Kenyan jurisdictional rules, and precise location only when you actively use a location feature (e.g. find nearby cars, share pickup point). Background location is not collected.

  • Technical data

    Device type, operating system, app version, browser, IP address, crash reports, and basic usage events. Used for security, fraud prevention, and platform reliability.

  • For hosts, additionally

    KRA PIN (tax compliance), payout details (M-Pesa or bank account), vehicle logbook, insurance certificate, and vehicle photographs.

02 / What we collect

What we collect, and what each piece is for.

We minimise what we collect to what we actually need to run a safe rental platform. Each item below maps to a specific operational or legal purpose.

03 / Identity verification

How verification works with Dojah.

Identity verification is the most sensitive thing we do. To reduce the risk to you, the raw data is handled by a specialist processor — Dojah — and Ardena does not retain the inputs.

Step 1 — you submit. In the app, you enter your full name, government-issued ID number, and take a selfie / liveness capture. You may also be asked to photograph the ID document and to share your location to confirm you are in Kenya.

Step 2 — encrypted in transit. The submission is sent over TLS 1.2 or higher directly to Dojah Africa Ltd, our identity verification processor. Encryption protects the data from interception while it moves over the network.

Step 3 — Dojah verifies. Dojah checks the ID number against the relevant government registries (such as IPRS), runs a biometric match between the selfie and the ID photograph, and performs liveness detection. Dojah processes this data under its own privacy policy and Kenyan law, on Ardena's instructions, as our processor.

Step 4 — Ardena receives a result, not the raw data. Ardena receives a structured verification result: pass or fail, a Dojah reference ID, a timestamp, and a small set of fields needed to operate your account (such as your verified legal name and date of birth). Ardena does not receive or store the ID document image, the selfie image, or the biometric template.

Step 5 — we store the result. Your verification status is attached to your account and used to authorise bookings, surface verification badges to counterparties, and meet our legal obligations. If verification fails or is flagged, Ardena may suspend or refuse the account at its discretion.

If you want details from Dojah about how they store, retain, or delete the raw data, refer to dojah.io/privacy-policy. You may also exercise rights against Dojah directly under the Data Protection Act.

  • Run your account

    Create, authenticate, and operate your account; provide customer support; let you communicate with the counterparty to a booking. Lawful basis: performance of contract (s.30(b)).

  • Verify identity

    Confirm that you are who you say you are before you can book or list. Reduces fraud, protects hosts and renters, and meets our KYC obligations. Lawful basis: compliance with a legal obligation (s.30(c)) and legitimate interest in platform safety (s.30(f)).

  • Take payment

    Process bookings, payouts to hosts, refunds, deposits, and the optional damage waiver. Card data is handled by PCI-compliant providers; we receive a tokenised reference. Lawful basis: performance of contract (s.30(b)).

  • Safety & security

    Detect and prevent fraud, account takeovers, abusive behaviour, and breaches of our Terms; investigate incidents and disputes. Lawful basis: legitimate interest in protecting users and the platform (s.30(f)).

  • Legal & tax compliance

    Respond to lawful requests from courts, the police, the National Transport and Safety Authority, the Kenya Revenue Authority, and other authorities; retain records as the law requires. Lawful basis: legal obligation (s.30(c)).

  • Improve the product

    Understand how the platform is used, fix bugs, develop features, and run aggregated analytics. Where this is not strictly necessary, you can object. Lawful basis: legitimate interest (s.30(f)).

  • Marketing

    Send you product news and offers, only where you have agreed to receive them. You can unsubscribe at any time from the footer of any marketing email. Lawful basis: consent (s.30(a)).

04 / Why we use it

Why we process your data.

Each purpose below sits on a specific lawful basis under section 30 of the Data Protection Act, No. 24 of 2019.

05 / Sharing & processors

Who we share data with.

We don't sell personal data. We share it only with the counterparty to a booking, the specific processors listed below, and authorities where the law requires it.

  • The other side of your booking. After a booking is confirmed, the renter and host see each other's first name, profile photograph, verification badge, and the communication channel in the app. Full surname, ID number, and contact details are not shared by default.
  • Dojah Africa Ltd (identity verification processor) — receives the verification inputs described in section 03. Acts on our instructions; processes personal data under its own privacy policy and Kenyan law.
  • Payment and payout providers — M-Pesa (Safaricom PLC), KuvarPay, and licensed card processors. They handle payment instructions and tokenisation; we do not store full card numbers.
  • Cloud infrastructure — reputable hosting and storage providers used to run the app and store account data. Bound by data processing agreements.
  • Communication providers — SMS and email delivery services used to send verification codes, booking notifications, and support replies.
  • Analytics and monitoring — Vercel Analytics, Cloudflare Web Analytics, and Contentsquare for performance and user-experience analytics. Configured to minimise personal identifiers.
  • Authorities — courts, police, NTSA, KRA, and the Office of the Data Protection Commissioner, where disclosure is required by law, court order, or to protect life or property. We assess each request before disclosing.
  • Corporate transactions — in the event of a merger, acquisition, or sale of assets, your data may transfer to the successor entity subject to the same protections and applicable law.
  • Encryption in transit. All traffic between the app, our servers, and our processors uses TLS 1.2 or higher. Sensitive verification submissions are encrypted from the app directly to Dojah.
  • Encryption at rest. Account data is stored in databases that encrypt data at rest using industry-standard algorithms (e.g. AES-256).
  • Access controls. Access to personal data is limited to authorised personnel on a need-to-know basis, logged, and protected by multi-factor authentication.
  • Data minimisation. We collect only what we need. The most sensitive class — raw ID and biometric data — is not retained by Ardena (see section 03).
  • Breach response. If a personal data breach is likely to result in risk to data subjects, we will notify the ODPC within 72 hours and affected users without undue delay, in line with sections 43 and 44 of the Data Protection Act.
  • Your responsibility. Keep your password and device secure, and tell us straight away if you suspect your account has been compromised. We are not liable for losses caused by your failure to protect your credentials.

06 / Security

How we secure your data.

No system is perfectly secure, but we use reasonable technical and organisational measures appropriate to the risk, as required by section 41 of the Act.

07 / Retention

How long we keep it.

We keep personal data for as long as we need it for the purpose it was collected, or for as long as the law requires — whichever is longer.

  • Account data

    For the life of the account; deleted or anonymised within 30 days of account closure, except where law or an open dispute requires longer.

  • Verification result

    Status, reference, and timestamp retained for 5 years after the last booking, for fraud-prevention and regulatory compliance. Raw inputs are not stored by Ardena.

  • Transaction records

    7 years, in line with the Tax Procedures Act, 2015 and Kenya Revenue Authority record-keeping requirements.

  • Communications

    2 years after account closure, for dispute resolution and safety. Support tickets are kept for the same period.

  • Location data

    6 months in identifiable form for service improvement, then aggregated and anonymised.

  • Incident records

    Retained for 7 years where related to an accident, insurance claim, or legal matter.

  • Where data is stored. Personal data is processed primarily in Kenya. Some processors operate cloud infrastructure outside Kenya (for example, in the European Union or the United States).
  • Safeguards for transfers. Any transfer outside Kenya is made only where one of the conditions in section 48 of the Data Protection Act is satisfied — including the existence of appropriate safeguards such as standard contractual clauses, your explicit consent, or the necessity of the transfer for the performance of our contract with you.
  • Your right to know. On written request to dpo@ardena.co.ke we will tell you which categories of data are transferred outside Kenya and on what safeguard.

08 / International transfers

When data leaves Kenya.

Some of our processors operate outside Kenya. When that happens we apply the safeguards required by section 48 of the Data Protection Act before any transfer.

09 / Your rights

Your rights — and how to use them.

Sections 25 and 26 of the Data Protection Act give you the following rights over the personal data we hold about you.

  • Right to be informed. Know what data we have, why we have it, and who we share it with — that's the purpose of this page.
  • Right of access. Request a copy of the personal data we hold about you.
  • Right to correction. Ask us to fix data that is inaccurate, incomplete, or out of date.
  • Right to erasure. Ask us to delete your account and personal data — use the in-app option or the delete account form. Some data must be retained for legal or fraud-prevention purposes.
  • Right to object & restrict. Object to processing that is based on legitimate interest, or ask us to restrict processing while a dispute is being resolved.
  • Right to portability. Receive your data in a structured, commonly used, machine-readable format.
  • Right not to be subject to a solely automated decision that produces legal effects. Verification decisions can be reviewed by a human on request.
  • Right to withdraw consent at any time, where processing relies on consent — without affecting the lawfulness of processing already carried out.
  • How to exercise these rights. Email dpo@ardena.co.ke. We will respond within 30 days, in line with section 26 of the Act. We may ask you to verify your identity first.
  • Right to lodge a complaint with the Office of the Data Protection Commissioner at odpc.go.ke if you believe we have not handled your data properly.
  • Essential cookies and storage are used to keep you signed in, remember basic preferences, and keep the platform secure. These cannot be turned off without breaking core functionality.
  • Analytics via Vercel, Cloudflare, and Contentsquare measure aggregate usage to help us improve the product. These can be limited via your browser's tracking settings.
  • No advertising trackers are deployed on this site by Ardena. We do not run programmatic advertising or sell data to ad networks.
  • Mobile permissions (location, camera, notifications) are requested only when needed for a specific feature. You can revoke each one at any time from your device settings.

10 / Cookies & tracking

Cookies, storage, and tracking.

A short, honest summary. We use what we need to run the platform; we don't run ad-tech.

11 / Other things to know

Children, changes, and limits.

Provisions that don't fit neatly elsewhere but you should know about.

  • Children. ardena is for adults aged 18 and over. We do not knowingly collect data from minors. If we learn we have, we will delete it.
  • Changes to this policy. We may update this policy from time to time. We will update the "last updated" date and, for material changes, notify active users by email or in-app message at least 14 days in advance.
  • Liability for processors and counterparties. Ardena is responsible for its own processing. We are not responsible for how Dojah, M-Pesa, banks, KRA, courts, or other independent controllers handle data within their own remit, beyond ensuring they are bound by appropriate contracts where they act as our processors.
  • Force majeure and third-party events. Ardena is not liable for losses arising from events outside our reasonable control, including outages or breaches at third-party processors, government action, or events beyond our control (e.g. natural disaster, war, cyber-attack of state-level sophistication), beyond what the law requires.
  • Suspension and refusal of service. Ardena may suspend, restrict, or close an account where verification fails, where there is reasonable suspicion of fraud, or where the user breaches our Terms & Conditions.
  • Governing law. This policy is governed by the laws of Kenya. Disputes are subject to the exclusive jurisdiction of the courts of Kenya.

Contact

Reach our Data Protection Officer.

For access, correction, deletion, objection, complaints, or any other data-protection question, talk to our DPO. We respond within 30 days.