Legal
Privacy Policy
Last updated: 12 July 2026
Kazinum (“we”, “our”, or “us”) operates the platform at kazinum.com. This policy explains what personal data we collect, why we collect it, how we use it, and your rights under the Kenya Data Protection Act 2019 (DPA) and related regulations.
By creating an account, posting a job, or using any Kazinum service you confirm that you have read this policy and consent to the practices described.
1. Who we are
Kazinum is a trust and verification layer for the local-work market in Nairobi, Kenya. We help customers find verified workers and help workers build a portable, proof-backed reputation. We are the data controller for all personal data collected through this platform.
Contact: privacy@kazinum.com
2. Data we collect
2.1 Account data (workers)
- Phone number — collected at sign-up via OTP verification. Used as your primary account identifier and to send you M-Pesa payment prompts.
- Display name, trade, location, bio — profile fields you choose to fill in. Displayed publicly on your Kazinum Card.
- Profile photos — images you upload. Stored in our cloud storage and displayed on your public card.
- Recovery email — optional. Used only to recover account access if you lose access to your phone number.
- Identity verification data — if you choose to complete identity verification (required for Gold score tier), we collect your government ID reference. This is used by our admin team to confirm identity and is never shared publicly.
2.2 Payment data
- M-Pesa transaction records — when a customer initiates a verified hire through Kazinum, we receive a Safaricom Daraja API callback containing: transaction amount, Safaricom confirmation code, timestamp, and the phone numbers of both parties. We do not store your M-Pesa PIN — that goes directly to Safaricom.
- Payment confirmation data — stored permanently as proof of completed jobs and displayed on the worker’s public Kazinum Card (amount, code, date — not full phone numbers).
2.3 Job posting data
- Job description — text you submit when posting a job. Processed by an AI model to extract structured fields (trade, location, budget). The raw text is retained for moderation purposes.
- Owner link — a unique URL generated for each job post, allowing anonymous job management without an account.
2.4 Usage data
- Card views — we record when a worker’s public card is viewed (worker ID and timestamp only). This powers the view counter visible to workers in their Pro dashboard.
- Browser / device data — standard web server logs including IP address, browser type, referrer, and page URL. Retained for up to 90 days for security and abuse prevention.
3. How we use your data
- To authenticate your account via OTP and maintain your session.
- To render your public Kazinum Card and make it shareable via WhatsApp and other channels.
- To initiate and record M-Pesa payment prompts when you complete a verified hire.
- To compute your Kazinum Score (Bronze / Silver / Gold) based on verified job count and identity status.
- To send you service notifications (e.g. job applications, payment confirmation).
- To detect and prevent fraud, abuse, and policy violations.
- To improve the platform — we analyse aggregate, anonymised usage patterns. We do not sell individual data.
We rely on the following legal bases under the DPA: contract performance (providing the service you signed up for), legitimate interest (security, fraud prevention, service improvement), and consent (optional features such as recovery email and identity verification).
4. Data sharing and third parties
We share data only as necessary to operate the platform:
- Safaricom (M-Pesa / Daraja API) — we transmit phone numbers and payment amounts to initiate STK push transactions. Safaricom’s own privacy policy governs their handling.
- Amazon Web Services (AWS) — our infrastructure provider. Data is stored in AWS data centres in the EU (Ireland) region. AWS is bound by data processing agreements.
- Africa’s Talking / SNS — used to deliver OTP SMS messages. Only your phone number and the OTP code are shared; no other profile data.
- OpenAI — job description text is processed by OpenAI’s API to extract structured fields. We use OpenAI’s zero-data-retention policy where available. No personal profile data is sent.
We do not sell, rent, or trade your personal data. We do not use your data for advertising profiling.
5. Public data on Kazinum Cards
The following fields on your Kazinum Card are publicly visible to anyone who visits your card URL:
- Display name, trade, location, bio
- Profile photos
- Verification badges (phone verified, ID verified, M-Pesa confirmed)
- Kazinum Score tier (Bronze / Silver / Gold)
- Number of verified jobs and total M-Pesa earnings (aggregate, not per-job)
- Customer reviews (star rating and text)
Your phone number is never displayed publicly. WhatsApp contact is facilitated via a link that opens WhatsApp without exposing your number in the page HTML.
6. Data retention
- Account data — retained for as long as your account is active. Deleted within 30 days of a verified account deletion request.
- Payment proof records — retained indefinitely as they form the permanent reputation record. Upon account deletion, your card is removed from public access but proof records may be retained in anonymised form for audit purposes.
- Server logs — retained for 90 days.
- OTP challenges — automatically expired after 3 minutes.
7. Your rights under the Kenya DPA
You have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — update or correct inaccurate data.
- Deletion — request deletion of your account and personal data.
- Object — object to processing based on legitimate interest, including direct marketing.
- Portability — request your profile data in a structured, machine-readable format.
- Withdraw consent — where processing is based on consent (e.g. identity verification, recovery email), you may withdraw at any time.
To exercise any of these rights, email privacy@kazinum.com. We will respond within 21 days. If you are unsatisfied with our response, you may lodge a complaint with the Office of the Data Protection Commissioner of Kenya.
8. Security
We implement industry-standard measures to protect your data, including: TLS encryption in transit, AES-256 encryption at rest (AWS), short-lived authentication tokens, rate-limited OTP requests, and least-privilege access controls for staff. We do not store M-Pesa PINs.
If you discover a security issue, please disclose it responsibly to security@kazinum.com.
9. Cookies and local storage
Kazinum uses browser local storage and session cookies to maintain your authenticated session (via Amazon Cognito). We do not use advertising cookies or third-party tracking pixels. Google Fonts are loaded from Google’s CDN, which may log your IP address according to Google’s privacy policy.
10. Children
Kazinum is not intended for persons under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has created an account, contact privacy@kazinum.com.
11. Changes to this policy
We may update this policy as the platform evolves. When we make material changes, we will notify active users via SMS or in-app notice at least 14 days before the changes take effect. The “Last updated” date at the top of this page always reflects the current version.
Questions?
Email us at privacy@kazinum.com. We aim to respond within 3 business days.