Legal
Privacy Policy
Last updated: 28 September 2026
This policy explains what personal data PropMS collects, why we collect it, who we share it with and the rights you have under Kenya's Data Protection Act, 2019. It works alongside our Terms and Conditions.
1. Who we are and our role
PropMS is run by PropMS Technologies Kenya, Nairobi, Kenya. It helps landlords and hosts manage rentals and short stays through our web app, USSD (*789*1800#), SMS and WhatsApp.
For Admins' own account details, we are the data controller. For information an Admin (a landlord, host or property manager) adds about tenants, guests, caretakers and waitlist prospects, the Admin is the data controller and we process it on their behalf, following their instructions.
2. What we collect and why
| Who | Data we hold | Why we use it | Lawful basis |
|---|---|---|---|
| Admins | Name, email, phone, hashed password, company and payout account details, security settings | Run the account, sign-in, send payouts and alerts | Contract |
| Caretakers | Name, phone, optional email, hashed password or one-time PIN | Sign-in, notify them of new issues | Contract with the Admin; legitimate interest |
| Tenants | Name, phone, property and unit, rent, lease dates, deposit and credit balances, bills and payments, issues reported, hashed USSD PIN | Bills, reminders, receipts, issue handling, USSD and WhatsApp access | Contract (the tenancy) |
| Guests | Name, phone, optional email, booking dates and amounts, ID or passport type and number, ID photos (front and back), issues reported | Bookings, check-in verification, reminders, receipts, payments | Contract (the booking); legal obligation where guest registers apply |
| Prospects | Name, phone, property of interest | Tell them when a unit is vacant | Consent (joining the waitlist) |
| Payers | Phone number that received the payment prompt, amount, mobile-money reference, status | Process and reconcile payments, prevent fraud, keep accounting records | Contract; legal obligation |
| Everyone | USSD and WhatsApp session data (phone, menu choices), message delivery logs, technical error logs | Run the menus, prevent duplicate messages, fix faults, keep the service secure | Legitimate interest |
- Who
- Admins
- Data we hold
- Name, email, phone, hashed password, company and payout account details, security settings
- Why we use it
- Run the account, sign-in, send payouts and alerts
- Lawful basis
- Contract
- Who
- Caretakers
- Data we hold
- Name, phone, optional email, hashed password or one-time PIN
- Why we use it
- Sign-in, notify them of new issues
- Lawful basis
- Contract with the Admin; legitimate interest
- Who
- Tenants
- Data we hold
- Name, phone, property and unit, rent, lease dates, deposit and credit balances, bills and payments, issues reported, hashed USSD PIN
- Why we use it
- Bills, reminders, receipts, issue handling, USSD and WhatsApp access
- Lawful basis
- Contract (the tenancy)
- Who
- Guests
- Data we hold
- Name, phone, optional email, booking dates and amounts, ID or passport type and number, ID photos (front and back), issues reported
- Why we use it
- Bookings, check-in verification, reminders, receipts, payments
- Lawful basis
- Contract (the booking); legal obligation where guest registers apply
- Who
- Prospects
- Data we hold
- Name, phone, property of interest
- Why we use it
- Tell them when a unit is vacant
- Lawful basis
- Consent (joining the waitlist)
- Who
- Payers
- Data we hold
- Phone number that received the payment prompt, amount, mobile-money reference, status
- Why we use it
- Process and reconcile payments, prevent fraud, keep accounting records
- Lawful basis
- Contract; legal obligation
- Who
- Everyone
- Data we hold
- USSD and WhatsApp session data (phone, menu choices), message delivery logs, technical error logs
- Why we use it
- Run the menus, prevent duplicate messages, fix faults, keep the service secure
- Lawful basis
- Legitimate interest
We do not collect mobile-money PINs, and we do not sell personal data. PINs and passwords are stored only as one-way hashes. We do not use personal data for automated decisions that have legal effects on you.
We also use your data to bill Admins for their plan, give support, and send service messages such as bill reminders, receipts, PINs, check-in details, and a reminder to finish setting up an account. These are part of the service, not marketing, and we don't send marketing without separate consent.
4. How long we keep data
| Data | Kept for |
|---|---|
| Payment, transaction and accounting records | 7 years, for tax and audit |
| Tenant records | Length of the tenancy plus 2 years, then deleted or anonymised |
| Guest ID numbers and ID photos | Until 90 days after check-out, unless a longer period is required by law |
| Other guest booking records | 2 years after check-out |
| Waitlist entries | Until you ask to be removed, or 12 months |
| USSD and WhatsApp session data | Until the session ends or expires |
| Error and security logs | 90 days |
| Admin and caretaker accounts | Until closed, then 90 days |
- Data
- Payment, transaction and accounting records
- Kept for
- 7 years, for tax and audit
- Data
- Tenant records
- Kept for
- Length of the tenancy plus 2 years, then deleted or anonymised
- Data
- Guest ID numbers and ID photos
- Kept for
- Until 90 days after check-out, unless a longer period is required by law
- Data
- Other guest booking records
- Kept for
- 2 years after check-out
- Data
- Waitlist entries
- Kept for
- Until you ask to be removed, or 12 months
- Data
- USSD and WhatsApp session data
- Kept for
- Until the session ends or expires
- Data
- Error and security logs
- Kept for
- 90 days
- Data
- Admin and caretaker accounts
- Kept for
- Until closed, then 90 days
After a guest checks out, they keep payment-only access for up to 90 days so they can settle any balance.
5. How we protect data
We use encrypted connections (HTTPS), hashed passwords and PINs, limits on PIN attempts, access controls that separate each Admin's data, and restricted staff access. No system is completely secure, so please keep your password and PIN private.
If a breach is likely to harm you, we will tell the Data Protection Commissioner within 72 hours and tell the affected people without delay, as the law requires.
6. Your rights
Under the Data Protection Act, 2019 you have the right to:
- be told how your data is used (this policy);
- get a copy of your personal data;
- correct data that is wrong or incomplete;
- ask us to delete data we no longer need, except records the law requires us to keep, such as payment records;
- object to processing, or withdraw consent where we rely on it, for example leaving a waitlist;
- complain to the Office of the Data Protection Commissioner (ODPC).
Tenants and guests should usually contact their landlord or host first, because they control your data. You can also contact us directly at info@propertyms.org and we will pass the request on and help. We respond within 30 days and may need to confirm your identity first.
7. Cookies and browser storage
The PropMS website doesn't use advertising or third-party analytics trackers. The web app stores a few things in your browser so it works properly: your sign-in, your workspace choice (Rental or BnB), your setup progress and similar preferences. Clearing your browser's site data signs you out and resets these.
8. Stopping setup reminders
If we send an Admin an SMS reminder to finish setting up their account, they can reply STOP to stop those reminders. This doesn't affect service messages to tenants and guests, which are part of their tenancy or booking.
9. Children
PropMS is not for children under 18. Admins must not register a minor as a tenant or lead guest.
10. Changes to this policy
We will post any update here with a new date and notify Admins of material changes.
11. Contact us
PropMS Technologies Kenya, Nairobi, Kenya. For anything about your data, including the rights above, contact our data protection team at info@propertyms.org.