KaribuKit — Privacy Policy
Effective date: 3 July 2026 Last updated: 7 August 2026
This Privacy Policy explains how KaribuKit, Inc. ("KaribuKit", "we", "us", "our") collects, uses, shares, and protects personal data in connection with the KaribuKit platform — including our web application, the Ranger mobile app, our APIs and MCP interface, our AI features, and the websites we operate for our customers (together, the "Service").
It applies to three groups of people:
- Property staff who sign in and use the Service (our customers' "Authorized Users");
- Guests of the hospitality properties that use KaribuKit, whose booking and stay data is processed through the Service; and
- Website visitors who interact with a KaribuKit-hosted property website or chat.
1. Our role: controller vs. processor
KaribuKit is a business-to-business platform sold to hospitality operators — independent safari lodges and boutique hotels (each a "Customer"). Understanding who is responsible for which data matters:
-
For Guest data (booking, stay, folio, payment, registration, and guest communications), the Customer is the data controller and KaribuKit is a data processor acting on the Customer's documented instructions. The Customer decides why guest data is collected (to fulfil a booking) and owns the guest relationship. If you are a guest, the property you booked with is primarily responsible for your personal data, and its own privacy notice governs that relationship. Our processing of Guest data is governed by our Data Processing Agreement with each Customer.
-
For Authorized User account data, Service usage data, our own analytics, our choice of sub-processors, and truly anonymized/aggregated data, KaribuKit is the data controller and this Privacy Policy governs.
This distinction is required by the EU/UK General Data Protection Regulation ("GDPR") and Kenya's Data Protection Act, 2019 ("Kenya DPA"), both of which may apply to the Service.
2. Data we collect
We collect only what the Service needs to operate.
2.1 Account and identity data (Authorized Users)
- Name and email address (used to sign you in; authentication is handled by Supabase on our behalf).
- Your role at the property and a hashed quick-unlock PIN, where you set one.
- API keys you or your property create (stored only as a hash).
2.2 Voice input (Ranger mobile app)
- When you tap the microphone to use the Ranger voice assistant, the audio you record is captured and sent to our servers, which forward it to our AI provider for transcription only. Recording happens only when you actively tap to record — it is never always-on, and there is no wake-word listening.
- We do not store the audio recording. It is held transiently in memory to produce a text transcript and then discarded.
- The resulting transcript text is retained as part of your conversation history (Section 7) and may appear in diagnostic logs. Those logs may be processed by our error-monitoring and log sub-processors (see Section 5).
2.3 Guest and booking data (processed on behalf of our Customers)
Entered by property staff, imported from online travel agencies via our channel manager, or provided by guests through self-service flows:
- Guest name(s), including additional named occupants on a stay;
- Contact details (email, phone, WhatsApp identifier);
- Nationality / country;
- Government identification / passport images uploaded during pre-arrival or check-in registration, stored in a private, access-controlled storage bucket;
- Emergency contact name and phone;
- Dietary requirements and allergies, and other stay preferences;
- Reservation, folio, and invoice records;
- Tax identifiers (e.g. KRA PIN) where required for invoicing;
- An indicator of whether an occupant is a minor, for room and booking purposes.
2.4 Payment data
- Payment method (cash, card, mobile money, bank transfer, or OTA-collected) and a reference string (for example an M-Pesa transaction code).
- We do not collect or store full payment card numbers, CVV codes, or bank credentials. Card and mobile-money payments are recorded in the folio, not processed within the Service.
2.5 Communications and AI conversations
- Messages exchanged through the Service — guest chat, staff copilot conversations, proposals, and, where a Customer enables it, WhatsApp and email threads brought into a unified inbox;
- AI-generated summaries, extracted observations, and per-user assistant memory;
- Records of the actions taken through the AI/MCP interface.
2.6 Technical and diagnostic data
- Standard app and server logs, error reports, device and session information needed to operate, secure, and troubleshoot the Service;
- For public property-website chat, a hashed (salted) IP address, the origin domain, and any name/email a visitor voluntarily provides.
We do not collect precise location, contacts, photo libraries, or advertising identifiers from the Ranger app, and we do not use any data for advertising or cross-app tracking.
3. How we use data
We use personal data to:
- Provide, authenticate, and secure access to the Service;
- Operate the Ranger AI assistant (transcribe voice input, answer requests, and — only after a human confirms — take the action you approve);
- Deliver property-management functions: reservations, check-in/out, folios, payments, invoicing, guest communications, and channel distribution;
- Meet legal, tax, and regulatory obligations (for example electronic tax invoicing via eTIMS/KRA, and record-retention duties);
- Monitor, debug, secure, analyse, and improve the reliability of the Service;
- Communicate with you about the Service (service notices, support).
Product and AI/model improvement. We may use data to develop and improve our products, services, and machine-learning models — but for that purpose we use only aggregated and/or anonymized data: data processed so that it no longer identifies, and cannot reasonably be used (alone or in combination with other data we hold) to identify, any individual. We do not use identifiable guest passport or government-identity data, and we do not use data concerning minors, to train models. Because anonymized data is not personal data, this use falls outside the scope of data-protection law once anonymization is complete.
We do not sell your personal data, and we do not "share" it for cross-context behavioural advertising.
Legal bases (GDPR / Kenya DPA). Where these laws apply, we rely on: performance of a contract (to provide the Service to Authorized Users); our legitimate interests (to secure, operate, analyse, and improve the Service); compliance with a legal obligation (tax and record-keeping); and consent where required (for example, device microphone access). Our product/model-improvement use relies on anonymization (above), not on a legal basis for processing personal data. For Guest data we process on a Customer's behalf, the Customer is responsible for establishing the legal basis.
3a. Automated decision-making
We do not use solely-automated decision-making that produces legal or similarly significant effects concerning an individual. The Ranger AI assistant is advisory: where it proposes an action that changes records (for example, creating or modifying a reservation, or recording a payment), a member of staff must review and confirm that action. You have the right to obtain human intervention in relation to any automated processing to the extent GDPR Article 22 or Kenya DPA section 35 applies.
4. AI processing and providers
Some Service features send your input — including voice transcripts and chat content, and any personal data contained in them — to third-party AI/large-language-model providers so the model can generate a response or transcription. We route AI requests through an AI gateway (currently OpenRouter), which may in turn route to underlying model providers (currently including Anthropic, Google, and Alibaba/Qwen for speech-to-text). Each provider processes your content under its own terms and retention practices. We are implementing configurations to limit providers' retention of your content where they offer it; until then, provider default terms apply. Voice audio is not retained by us (see Section 2.2).
If you would like the current list of AI sub-processors, contact us at
nj@karibukit.com.
5. Sharing and sub-processors
We share personal data only with service providers ("sub-processors") that help us run the Service, and only as needed to provide it. Current sub-processors and their purpose:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Managed database, authentication, and file storage (including ID/passport images). | EU (Ireland, eu-west-1) |
| OpenRouter (and the model providers it routes to, incl. Anthropic, Google, Alibaba/Qwen) | AI/LLM processing and voice transcription. | US / EU / global |
| Su (channel manager) | Distribution to and booking intake from online travel agencies (e.g. Booking.com, Expedia). | Global |
| Digitax | Kenya electronic tax invoicing (eTIMS/KRA). | Kenya |
| Resend | Transactional email delivery. | US / EU |
| Telegram | Operational notifications to property staff (where enabled). | Global |
| Sentry | Error monitoring and diagnostics (may capture limited PII in error contexts). | EU (Germany) |
| BetterStack | Log management (where enabled). | EU (Falkenstein, Germany) |
| Hetzner | Application server hosting. | EU (Helsinki, Finland) |
| Meta / WhatsApp and Google / Gmail | Source platforms for the unified inbox, where a Customer enables it — guest message content and contact details are ingested from these platforms. | US / global |
We do not currently use a third-party payment processor within the Service (payments are recorded, not processed). If we add one for subscription billing, we will list it here.
We may also disclose personal data: (a) to comply with law, legal process, or a lawful government request; (b) to enforce our agreements or protect the rights, safety, and property of KaribuKit, our Customers, or others; and (c) in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honour this Policy.
We do not otherwise sell, rent, or share personal data with third parties for their own purposes.
6. International transfers and data location
The Service is operated by a company incorporated in the United States (Delaware). Personal data is currently hosted in the European Union — our primary database and file storage are located in the EU (Paris), and our error-monitoring provider is in the EU (Germany). Some sub-processors (for example AI providers) may process data in the United States or elsewhere. Where personal data is transferred across borders (including out of the European Economic Area, the United Kingdom, or Kenya), we rely on appropriate safeguards such as Standard Contractual Clauses or an equivalent lawful transfer mechanism.
7. Data retention
We retain personal data for as long as needed to provide the Service and for the purposes described in this Policy:
- Account data — while your account is active (see Section 8 on deletion).
- Guest, booking, folio, and invoice records — for the duration of the Customer relationship and thereafter as required by law. Financial and tax records (including eTIMS/KRA invoices) are retained for the period required by applicable Kenyan tax law (generally five to seven years). A right-to-erasure request does not override a statutory obligation to retain tax records.
- Voice audio — not retained (discarded after transcription).
- Logs and diagnostic data — retained for a limited period and then deleted or minimised.
- AI conversation history and audit records — currently retained for the life of the account and Customer relationship; we do not yet apply a fixed deletion period and are implementing a defined retention window, after which these records will be deleted or anonymized.
On termination of a Customer relationship, we make Customer Data available for export for a limited window (see the Subscription Agreement) and then delete or de-identify it within a reasonable period, except where retention is required by law.
8. Your rights and account deletion
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent. Under CCPA/CPRA (California), you may have rights to know, delete, correct, and opt out of "sale"/"sharing" (we do not sell or share your data as those terms are defined).
- Authorized Users may exercise these rights, and may delete their KaribuKit
account by contacting us at
nj@karibukit.com. Deleting your account removes your personal account profile and authentication record. Property and booking records you created on behalf of the property remain with the property (the controller), and financial/tax records are retained where required by law. - Guests: because the property you booked with is the controller of your data, please contact that property first. If you contact us, we will refer your request to the property and assist it as its processor.
We will respond within the time required by applicable law. You also have the right to lodge a complaint with a supervisory authority — in Kenya, the Office of the Data Protection Commissioner (ODPC); in the EEA/UK, your local data-protection authority.
9. Security
We use reasonable technical and organisational measures designed to protect personal data, including encryption of data in transit (HTTPS), encryption at rest provided by our hosting sub-processors, access controls scoped to each property, and secure storage of authentication tokens on device (iOS Keychain / Android Keystore). Passport/ID images are held in a private storage bucket accessed only through short-lived signed URLs.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal-data breach, we will act in accordance with applicable law, including notifying the relevant supervisory authority and, where required, affected individuals or the responsible Customer.
10. Children
The Service is a business tool intended for property staff and is not directed to children. The Ranger app does not collect data about children directly. Guest data entered by a property may include information about minors travelling on a booking (for example, an occupant marked as a minor); that data is provided by the property, as controller, solely for the purpose of managing the stay, and the property is responsible for the appropriate lawful basis (including consent where required under Kenya DPA section 33 or GDPR). We exclude data concerning minors from product-improvement and model-training use.
11. Changes to this Policy
We may update this Policy from time to time. If we make a material change, we will update the "Last updated" date above and provide additional notice where appropriate. For changes that materially reduce your rights, we will give advance notice. Your continued use of the Service after an update takes effect constitutes acceptance of the updated Policy.
12. Contact us
KaribuKit, Inc. — a Delaware corporation
Privacy and general inquiries: nj@karibukit.com
Website: https://karibukit.com
If we appoint a representative in the EEA or UK under Article 27 GDPR, we will publish their contact details here.