Privacy Policy
Effective 14 August 2026 · Last updated 14 August 2026
KanairoXO is operated from Nairobi, Kenya. We handle your personal data under Kenya’s Data Protection Act 2019. This page describes what we actually collect, why, who else sees it, and what you can make us do about it.
1. What we collect
You give us: your name, email address, phone number, date of birth, gender and relationship intent, profile photos, a written profile, and an optional voice introduction. If you use the couples features: photos, voice notes, memories, milestones and written entries you save there.
You create as you use it: messages and any photos, videos or voice notes you send in them; moments you post at events; events you save or attend; tickets you buy; connections you make.
We collect automatically: device type and operating system, app version, IP address, and general usage patterns. If you enable notifications, a push token from Firebase Cloud Messaging.
When you pay: the amount, the time, and the M-Pesa or card transaction reference. We never see or store your full card number or your M-Pesa PIN — those go directly to the payment provider.
When someone buys you a ticket: their purchase gives us your name and email address, supplied by them. You can ask us to delete it (see section 7) whether or not you ever open an account.
2. What we do with it
To create and secure your account; to suggest people and events; to deliver tickets and let you into events; to process payments and issue receipts; to send you service messages about things you bought; to keep the platform safe and investigate abuse; and to meet our legal and accounting obligations.
We do not sell your personal data. We do not share it with advertisers.
3. Who else sees your data
Event organisers and venue partners. This one matters, so it is stated plainly: when you buy or receive a ticket to an event, the organiser of that event can see your name, email address and phone number on their attendee list, and can export it. They need it to run the door and to contact you about the event. They may email you about that event through us. They do not get your dating profile, your messages, or anything unrelated to that event.
Other users see what you put on your profile, and whatever you send them.
Service providers who process data on our instructions:
- Safaricom (M-Pesa) and Paystack — payments. Kenya and Nigeria.
- Resend — sends our email. United States.
- Google Firebase — push notifications. United States.
- Cloudflare — traffic routing and protection. Global.
- Our hosting provider, which runs the servers holding the database and uploaded files.
Transfers outside Kenya. As listed above, some of these providers operate outside Kenya, so some of your data is processed abroad. We use providers that offer contractual data-protection commitments, and we share only what the provider needs to do its job — an email address to send an email, a push token to send a notification.
Law enforcement, where we are legally required to, or where there is a genuine risk to someone’s safety.
4. How long we keep it
- Your account and profile — while your account is open. If you delete your account we remove your profile, photos, voice intro and messages within 30 days.
- Transaction records (what was bought, when, for how much, the payment reference) — seven years, because Kenyan tax and accounting law requires it. This survives account deletion; we cannot delete a record of a sale.
- Tickets and attendance — kept while the event is upcoming and for 12 months afterwards, then reduced to the transaction record above.
- Messages — until you or the other person deletes them, or you close your account.
- Moderation and safety records — where we have acted on a report, we keep enough to enforce the outcome, so that a banned account cannot simply be recreated.
5. Where your files live
Photos, voice notes and other files you upload are stored on our servers. Private files — message attachments, voice notes, couple memories, your ticket PDFs — are not publicly reachable: they are served only through short-lived signed links, and are not cached on any content network.
6. Security
Traffic is encrypted with TLS. Passwords are hashed, never stored in readable form. Access to production data is limited to the people who need it. No system is perfectly secure; if we ever have a breach affecting your data, we will tell you and the Office of the Data Protection Commissioner as the law requires.
Report anything suspicious to [email protected].
7. Your rights
Under the Data Protection Act 2019 you may ask us to:
- tell you what data we hold about you, and give you a copy;
- correct anything wrong;
- delete your data (subject to the retention rules in section 4);
- stop using it for a particular purpose, or withdraw a consent you gave;
- object to a decision, or ask a human to look at it.
Write to [email protected]. We respond within 30 days. You can delete your account yourself from Settings in the app at any time.
If you are not satisfied with how we handle it, you can complain to the Office of the Data Protection Commissioner (ODPC), Kenya — odpc.go.ke.
8. Notifications and marketing
Service messages — your ticket, your receipt, a change to an event you are attending — are part of what you bought and are not marketing. Anything promotional is opt-in and every such email has an unsubscribe link. Turn push notifications off in your device settings or in the app at any time.
9. Age
KanairoXO is for people aged 18 and over. We do not knowingly collect data from anyone under 18. If we find an underage account we delete it. If you believe a minor is using the platform, tell us at the address below.
10. Changes
If we change this policy in a way that materially affects you, we will notify you in the app or by email before it takes effect. The date at the top always reflects the current version.
11. Contact
Data protection queries:
[email protected]
Security: [email protected]
Anything else: [email protected]