Legal
Privacy Policy
Effective Date: September 2026 · Last Updated: September 2026
Compliance: Kenya Data Protection Act, 2019 (No. 24 of 2019) · Data Protection (General) Regulations, 2021
1. Data Controller
The data controller responsible for your personal data is:
Entity Name: Ma3flow Technologies Limited
Registered Address: Nairobi, Kenya
Email: privacy@ma3flow.com
Phone: +254 700 000 000
Registration: Registered with the Office of the Data Protection Commissioner (ODPC) of Kenya
2. Data Protection Officer (DPO)
In accordance with Section 24 of the Data Protection Act, 2019, we have designated a Data Protection Officer who acts as the contact point for the Data Commissioner and data subjects on all data protection matters.
Name: Ma3flow Data Protection Officer
Email: dpo@ma3flow.com
Response Time: Within 72 hours of receiving your inquiry
3. Introduction
Ma3flow Technologies Limited (“Ma3flow,” “we,” “us,” or “our”) is committed to protecting your personal data in accordance with the Kenya Data Protection Act, 2019 (the “DPA”), the Data Protection (General) Regulations, 2021, and all other applicable data protection laws and regulations in Kenya.
In short: We collect only what we need to provide live matatu tracking, M-Pesa payments, and route recommendations. We never sell your data. You can delete your account and data at any time. You have the right to access, correct, delete, and port your data within the timeframes required by law.
4. Personal Data We Collect
We collect personal data in three ways: when you provide it directly, when you use the platform, and from third-party services. We apply the principle of data minimisation — collecting only what is necessary for the specified purposes (Section 39(b) DPA).
Account Information
Consent (Section 30(1) DPA) and Contract (Section 30(1)(b) DPA)- •Phone number and name when you register as a commuter or driver
- •Email address (optional, for notifications and account recovery)
- •Profile photo (optional, for driver identification)
- •SACCO affiliation and route assignment (drivers only)
- •Password hash (stored securely via Supabase Auth — we never see your plaintext password)
GPS & Location Data
Consent (Section 30(1) DPA) and Legitimate Interest (Section 30(1)(f) DPA)- •Driver GPS coordinates during active trips — shared with commuters in real-time for live tracking
- •Commuter approximate location — used only to show nearby matatus, never shared with third parties
- •Historical trip routes — anonymized after 30 days, used for traffic analysis and ETA improvements
Payment Data
Contract (Section 30(1)(b) DPA) and Legal Obligation (Section 30(1)(c) DPA)- •M-Pesa transaction references (STK Push confirmations)
- •Stage and route data reported by commuters
- •We never store your M-Pesa PIN, Safaricom account details, or full transaction receipts
Usage & Interaction Data
Legitimate Interest (Section 30(1)(f) DPA) and Consent (Section 30(1) DPA)- •Routes searched, stages viewed, nganyas voted for
- •App feature usage patterns (which screens you visit, how long you spend)
- •Device type, OS version, and app version for compatibility
- •Error logs and crash reports for debugging
5. Lawful Basis for Processing
Under Section 30 of the DPA, we process your personal data only when we have a lawful basis to do so. The table below sets out the legal basis for each processing activity:
| Processing Activity | Lawful Basis |
|---|---|
| Account creation and authentication | Consent & Contract |
| Real-time GPS tracking during trips | Consent & Legitimate Interest |
| ETA and route predictions (ML) | Legitimate Interest |
| M-Pesa payments | Contract & Legal Obligation |
| Live location sharing | Consent |
| Push notifications (arrival, disruptions) | Consent |
| Analytics and performance monitoring | Legitimate Interest |
| Fraud detection and security | Legitimate Interest |
| Legal and regulatory compliance | Legal Obligation |
| Nganya voting and reviews | Consent |
6. How We Use Your Data
In compliance with the purpose limitation principle (Section 39(a) DPA), we use your personal data only for the specific purposes for which it was collected:
Live Tracking
Share driver GPS with commuters in real-time
ETA Predictions
ML-powered arrival times based on traffic patterns
Payment Processing
M-Pesa STK Push payments via Safaricom
Route Recommendations
Suggest fastest routes based on live traffic
Personalization
Remember saved routes, frequent destinations, preferences
Notifications
Arrival alerts and service disruptions
Safety
Verify driver identity, track trip history for disputes
Improvement
Aggregate analytics to improve accuracy and performance
7. Data Sharing and Recipients
We do not sell, rent, or trade your personal data. We share data only in these specific circumstances and with the following categories of recipients (Section 25(1)(c) DPA):
M-Pesa transaction references for payment processing
When: During M-Pesa payments
Anonymous usage data for map tile rendering
When: When you view maps
Account data, authentication tokens, database records
When: When you use the platform
Driver GPS location and vehicle info
When: During active trips only
Commuter pickup location (approximate)
When: When a trip is requested
Account data and trip history
When: When legally required (court order)
8. GPS and Location Data
Drivers
GPS data is transmitted every 5 seconds during active trips and shared with commuters in real-time via MQTT. After a trip ends, granular GPS data is anonymized and retained for 30 days for traffic analysis, then permanently deleted. You may disable background GPS tracking at any time in the app settings.
Commuters
Approximate location is used only to show nearby matatus on the live map. We never share your location with drivers, third parties, or advertisers. Location data is processed locally on-device when possible.
Background Tracking
Drivers can opt into background GPS tracking for trip detection. This is clearly indicated in the app, requires explicit consent, and can be disabled at any time in settings.
9. Data Security
In accordance with Section 41 of the DPA, we implement appropriate technical and organizational measures to protect your personal data against unauthorized access, disclosure, alteration, or destruction:
In Transit
TLS 1.3 encryption on all API and WebSocket connections
At Rest
AES-256 encryption for database storage
Authentication
Supabase Auth with JWT tokens and refresh rotation
Payments
Safaricom-certified M-Pesa infrastructure (PCI DSS compliant)
Infrastructure
Redis for session management, isolated service containers
Access Control
Role-based access — drivers, commuters, admins have separate permissions
10. Cross-Border Data Transfers
Under Section 48 of the DPA, personal data shall not be transferred outside Kenya unless the recipient country provides adequate data protection safeguards, the data subject has consented, or there are appropriate contractual clauses in place.
| Recipient | Country | Data Transferred | Safeguard |
|---|---|---|---|
| Supabase Inc. | United States | Account data, authentication, database records | Standard Contractual Clauses (SCCs) |
| Mapbox Inc. | United States | Anonymous map tile requests, usage metrics | SCCs + Data Processing Agreement |
| Google Analytics | United States | Anonymous usage statistics (if analytics cookies accepted) | SCCs + User IP anonymization |
All cross-border transfers are subject to Data Protection Impact Assessments (DPIAs) as required by Section 31 of the DPA. We ensure the recipient country provides adequate safeguards or that appropriate contractual measures are in place.
11. Data Retention
In accordance with Section 39(c) of the DPA (storage limitation principle), personal data shall not be retained for longer than is necessary to fulfill the purposes for which it was collected. We maintain accurate and up-to-date records of processing activities as required by the General Regulations, 2021.
| Data Type | Retention Period | Justification |
|---|---|---|
| Account information | Until account deletion | Service provision |
| Active trip GPS | Duration of trip only | Real-time tracking |
| Historical GPS | 30 days (then anonymized) | Traffic analysis |
| Stage reports | 1 year (aggregated after 90 days) | Community mapping |
| Trip history | Until account deletion | Service provision & disputes |
| Analytics data | 26 months (anonymized) | Service improvement |
| Cookie consent record | 1 year | Compliance evidence |
| Payment references | 7 years | Tax/legal obligation |
12. Your Rights as a Data Subject
Under Sections 26–34 of the DPA and the Data Protection (General) Regulations, 2021, you have the following rights. We are committed to fulfilling these rights within the statutory timeframes:
Right to be Informed (Section 26)
At point of collection and upon requestYou have the right to be informed of the use of your personal data. This Privacy Policy fulfils that obligation.
Right of Access (Section 27)
Within 7 days of request (General Regulations, 2021)You have the right to obtain confirmation of whether we process your data, access to that data, and a copy in a machine-readable format.
Right to Rectification (Section 28)
Within 14 days of request (General Regulations, 2021)You have the right to request correction of any false, misleading, or inaccurate personal data.
Right to Erasure (Section 29)
Within 30 days of requestYou have the right to request deletion of your personal data where it is no longer necessary, consent is withdrawn, or processing is unlawful.
Right to Data Portability (Section 33)
Within 14 days of requestYou have the right to receive your personal data in a structured, commonly used, and machine-readable format (JSON/CSV) and to transmit it to another data controller.
Right to Object to Processing (Section 34)
Immediate cessation pending reviewYou have the right to object to the processing of your personal data based on legitimate interests, unless we demonstrate compelling legitimate grounds.
Right Not to Be Subject to Automated Decision-Making (Section 35)
N/A — no automated decisions with legal effect are madeYou have the right not to be subject to decisions based solely on automated processing, including profiling, that significantly affects you. Our ML-powered ETA predictions do not produce legal or similarly significant effects.
Right to Prevent Direct Marketing (Section 36)
Immediate cessation of marketing communicationsYou have the right to object to the processing of your personal data for direct marketing purposes at any time.
Right to Withdraw Consent (Section 30)
Immediate effectWhere processing is based on consent, you have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
How to exercise your rights: Email dpo@ma3flow.com or use the in-app settings panel. You may also authorize a guardian, administrator, or third party to exercise these rights on your behalf (Section 37 DPA).
13. Automated Decision-Making and Profiling
Ma3flow uses machine learning algorithms for:
- •ETA predictions based on historical traffic patterns and real-time GPS data
- •Stage directory updates based on community reports
- •Traffic congestion analysis and AI bypass route suggestions
- •Driver behavior profiling for safety scoring
- •Demand prediction for route planning
Important: None of these automated processes produce decisions that have a legal effect on you or similarly significantly affect you. ETAs are estimates, not guarantees. Stage data is advisory. Driver safety scores are internal metrics.
You have the right to request human review of any automated output that you believe is inaccurate (Section 35 DPA). Contact dpo@ma3flow.com.
14. Children's Privacy
Ma3flow is not intended for users under 13 years of age. We do not knowingly collect personal data from children. In accordance with the ODPC's Guidance Note on Processing Children's Data, if we become aware that a child under 13 has provided us with personal information, we will take steps to delete it immediately. For users between 13 and 18, parental or guardian consent is required for registration.
15. Data Breach Notification
In the event of a personal data breach, we follow the procedures mandated by Section 43 of the DPA and the Data Protection (General) Regulations, 2021:
Notify the Office of the Data Protection Commissioner (ODPC) without undue delay after becoming aware of a personal data breach.
Data processors (e.g., Supabase, Mapbox) must notify us of a breach within 48 hours of becoming aware.
Where the breach is likely to result in a high risk to your rights and freedoms, we will notify affected individuals without undue delay.
16. Data Protection Impact Assessment (DPIA)
In compliance with Section 31 of the DPA, we conduct Data Protection Impact Assessments before carrying out high-risk processing activities, including large-scale GPS tracking, ML-based profiling, and cross-border data transfers. Our DPIAs include a systematic description of the processing, an assessment of necessity and proportionality, an assessment of risks to data subjects, and the measures identified to address those risks.
17. How to Lodge a Complaint
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC):
Contact us first
Email dpo@ma3flow.com. We aim to resolve all complaints within 30 days.
Lodge with the ODPC
If you are not satisfied with our response, you may file a complaint with the ODPC:
- • Website: www.odpc.go.ke
- • Email: complaints@odpc.go.ke
- • Phone: +254 20 271 4444
- • Address: CRC Tower, 14th Floor, Waiyaki Way, Nairobi
Alternative Dispute Resolution
The ODPC also offers an Alternative Dispute Resolution (ADR) framework for resolving data protection disputes.
18. Changes to This Policy
We may update this Privacy Policy as Ma3flow evolves. In compliance with Section 25 of the DPA, we will update this notice in line with any changes to our processing activities. The “Last Updated” date at the top reflects the most recent revision. For material changes — such as new data sharing partners, changes to GPS data handling, or new automated processing — we will notify you through the app, via email (if provided), or by displaying a notice on the website at least 30 days before the changes take effect.
19. Contact Us
For any privacy-related inquiries, data access requests, or to exercise your rights under the DPA:
Data Protection Officer: dpo@ma3flow.com
Privacy Inquiries: privacy@ma3flow.com
Access Request Response: Within 7 days (General Regulations, 2021)
Rectification Response: Within 14 days (General Regulations, 2021)
More info: Contact Page