Privacy Policy
Last updated: 1 January 2025. Effective date: 1 January 2025.
1. Introduction
Daybook ("we", "our", or "us") is committed to protecting the privacy of your business data. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our platform — the web application at daybook.co.ke and any associated mobile applications (collectively, the "Service").
By using the Service, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
We collect information that you provide directly to us when you register, create sales, manage inventory, or configure integrations:
•Account data: business name, owner name, email address, KRA PIN.
•Business data: sales records, product inventory, customer profiles, invoices, expenses, and payment records.
•Integration credentials: M-Pesa, WhatsApp, KRA eTIMS, and SMS credentials — stored AES-256 encrypted and never returned in API responses.
•Usage data: page views, feature usage, error logs (Sentry), and performance metrics.
•Device data: IP address, browser type, and operating system (for security and abuse prevention).
3. How We Use Your Information
We use the information we collect to:
•Provide, maintain, and improve the Service.
•Process transactions and send related information, including KRA eTIMS submissions.
•Send WhatsApp, SMS, and email notifications as configured by you.
•Monitor for security incidents and prevent fraud.
•Comply with legal obligations, including Kenyan tax and data protection law.
•Communicate with you about updates, new features, and support.
4. Data Isolation and Multi-Tenancy
Daybook is a multi-tenant platform. Each business account ("tenant") is isolated at the database level using a tenant_id on every record and a global query scope that prevents cross-tenant data access.
No user from one business can access data belonging to another business. Super Admin access to tenant data is explicit, authorized by the super-admin role, and fully audited via an activity log.
5. Data Storage and Security
Your data is stored in PostgreSQL 16 hosted on Railway, with backups encrypted at rest. Our API and infrastructure run on Railway and Vercel, both of which maintain SOC 2-compliant environments.
Security measures include:
•AES-256 encryption for all third-party credentials.
•httpOnly cookies for authentication tokens (tokens are never exposed to JavaScript).
•Timing-safe comparison for webhook secrets and CSRF tokens.
•Parameterized queries to prevent SQL injection.
•Role-based access control enforced at the API level.
6. Third-Party Integrations
When you enable integrations (M-Pesa, WhatsApp, KRA eTIMS, SMS, email), we transmit your data to those third-party services on your behalf. Each provider has its own privacy policy:
•M-Pesa (Safaricom): payments processing.
•WhatsApp Cloud API (Meta): message delivery.
•KRA eTIMS: statutory invoice compliance.
•Africa's Talking: SMS delivery.
•Resend: transactional email delivery.
•Anthropic Claude: AI insights (your data is not used to train Claude models).
We pass only the minimum data required for each integration to function.
7. Data Retention
We retain your business data for as long as your account is active. If you close your account, we will delete your data within 90 days unless we are required by law to retain it longer (for example, KRA transaction records).
You may request a full export of your data at any time by contacting us at hello@daybook.co.ke.
8. Your Rights
Under the Kenya Data Protection Act (2019), you have the right to:
•Access: request a copy of the personal data we hold about you.
•Rectification: request correction of inaccurate data.
•Erasure: request deletion of your data (subject to legal retention requirements).
•Data portability: receive your data in a machine-readable format.
•Object: object to certain processing activities.
To exercise any of these rights, contact us at hello@daybook.co.ke.
9. Cookies
We use a single httpOnly, Secure, SameSite=Strict cookie (auth_token) to maintain your authenticated session. This cookie is not accessible to JavaScript and cannot be read by third-party scripts.
We do not use advertising cookies or third-party tracking cookies.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email and display a notice in the application at least 14 days before the changes take effect.
Continued use of the Service after the effective date constitutes acceptance of the updated policy.
11. Contact
If you have questions about this Privacy Policy or our data practices, please contact us:
Email: hello@daybook.co.ke
Address: Nairobi, Kenya