Privacy Policy
This policy explains how Exploring Mombasa collects, uses, shares, stores and protects personal data when people browse the website, create an account, make or manage a booking, register as a Partner, contact us or otherwise use the Platform.
In summary: We collect only the information reasonably needed to operate Exploring Mombasa, process bookings, support Guests and Partners, keep the Platform secure, comply with the law and improve our services.
We do not sell personal data to advertisers. We share information only where necessary for a booking, payment, support, security, legal compliance or another purpose explained in this policy.
1. Who this policy applies to
This Privacy Policy applies to personal data processed through the Exploring Mombasa website, booking pages, Partner and Guest accounts, forms, emails, support channels and related online services (the “Platform”).
It applies to:
- people browsing or using the Platform;
- Guests making, managing or using bookings;
- Partners and their employees, representatives or contractors;
- people submitting events, listings, reviews, photographs, articles or other content;
- newsletter subscribers and people who contact us; and
- other people whose information is provided in connection with a booking or service.
2. Our role
Exploring Mombasa is the data controller where we decide why and how personal data is processed for operation of the Platform, account management, bookings, payments, support, marketing, security and legal compliance.
A Partner may be a separate data controller for personal data it receives and uses to provide accommodation, a tour, an experience, transport or another booked service. Partners are responsible for their own lawful handling of Guest information.
Where another organisation processes personal data only on our instructions, it acts as our data processor and must protect the information under applicable law and its agreement with us.
3. Personal data we collect
3.1 Account and contact information
We may collect a name, email address, telephone or WhatsApp number, password or account credentials, preferred language, location and communication preferences.
3.2 Booking and travel information
When a booking is made or managed, we may collect:
- the lead Guest’s name and contact details;
- the names or number of other travellers;
- booking dates, arrival or pick-up details and destination;
- room, tour, experience, vehicle or service selections;
- special requests, accessibility needs or dietary information voluntarily provided;
- payment status, transaction references, refunds and outstanding balances;
- cancellation, no-show, complaint and support records; and
- communications between the Guest, Partner and Exploring Mombasa.
3.3 Partner and business information
For Partner registration, verification and payment, we may collect:
- business and trading names;
- contact details for owners, managers and authorised representatives;
- business registration, licence, permit, insurance and tax information;
- identity or authority documents where verification is required;
- bank-account, M-Pesa or other payout details;
- listing information, photographs, rates, availability and policies; and
- booking performance, payouts, complaints and account records.
3.4 Payment information
Payments may be handled by payment providers made available through the Platform. We may receive a payment status, transaction reference, payer name, masked payment details, mobile-money number, amount and fraud or verification result.
Exploring Mombasa does not intentionally store complete card numbers or card security codes. Those details should be processed by the authorised payment provider used at checkout.
3.5 Content and communications
We collect information contained in emails, forms, support requests, reviews, comments, surveys, photographs, articles, listing submissions and other material sent to or published through the Platform.
3.6 Technical and usage information
When the Platform is used, we may automatically receive:
- IP address, browser, device type and operating system;
- pages viewed, links selected, search terms and session activity;
- referral source and approximate location derived from an IP address;
- login, security, error and diagnostic records; and
- cookie, analytics and similar technology identifiers.
3.7 Information from other sources
We may receive information from Partners, payment providers, identity or fraud-prevention services, social-media platforms, publicly available business sources and people booking or communicating on another person’s behalf.
4. How we use personal data
We use personal data where it is necessary and lawful to:
- create, verify and manage Guest and Partner accounts;
- display, receive, confirm and manage bookings;
- share booking information with the Partner supplying the service;
- collect payments, calculate commission, issue refunds and make Partner payouts;
- send booking confirmations, reminders, service messages and policy updates;
- respond to enquiries, complaints and support requests;
- review, publish and promote approved listings and submitted content;
- prevent fraud, misuse, duplicate payments, unauthorised access and other security threats;
- maintain, troubleshoot, analyse and improve the Platform;
- understand demand, website use and service performance;
- send marketing where consent has been given or another lawful basis applies;
- exercise or defend legal rights and resolve disputes;
- comply with tax, accounting, consumer, data-protection, payment and other legal obligations; and
- protect the life, health or safety of a Guest, Partner or another person in an emergency.
5. Lawful bases for processing
| Lawful basis | When we may rely on it |
|---|---|
| Performance of a contract | To create an account, process and manage a booking, make or receive payment, provide support and perform the Guest or Partner agreement. |
| Consent | For optional marketing, non-essential cookies, publication of certain submitted content or another activity for which consent is requested. |
| Legal obligation | To meet tax, accounting, consumer-protection, data-protection, fraud-prevention, regulatory or lawful disclosure requirements. |
| Legitimate interests | To operate and improve the Platform, protect accounts, prevent fraud, maintain records, communicate about services and promote Exploring Mombasa, where those interests do not override a person’s rights. |
| Vital interests | Where processing is necessary to protect a person’s life, health or physical safety and another lawful basis cannot reasonably be used. |
Where we rely on consent, it may be withdrawn at any time. Withdrawal does not affect processing that was lawful before consent was withdrawn.
6. When we share personal data
We may share personal data with the following recipients where reasonably necessary:
- Partners. A Partner receives the information needed to provide and manage the booked service.
- Payment and payout providers. Information may be shared to collect, verify, refund or transfer money and prevent payment fraud.
- Technology providers. Hosting, website, booking, email, security, analytics, storage and support providers may process data on our behalf.
- Professional advisers. Lawyers, accountants, auditors, insurers and other advisers may receive information where necessary.
- Authorities and regulators. We may disclose information where required by law, court order, regulatory request or to protect legal rights and safety.
- Business successors. Information may be transferred as part of a lawful merger, restructuring, financing, sale or transfer of the Platform or business.
- Other recipients authorised by the person concerned. We may share information where clear permission has been provided.
We do not give Partners permission to use Guest contact details for unrelated marketing without a lawful basis and any consent required by law.
7. Public information
Information deliberately published in a public listing, profile, event, review, comment, article, photograph credit or other public area can be viewed and shared by other people. Do not submit personal information for public display unless you are comfortable with it being public.
We may moderate, edit for formatting or remove public content under the applicable platform rules, but we cannot control copies made by other people or search engines before removal.
8. Cookies and similar technologies
The Platform may use cookies, pixels, local storage and similar technologies. Cookies are small files or identifiers stored on or read from a device.
| Cookie type | Purpose |
|---|---|
| Strictly necessary | Enable security, account login, booking functions, checkout, fraud prevention, consent choices and other essential features. |
| Preferences | Remember settings such as language, location, currency, saved choices or display preferences. |
| Analytics | Help us understand visits, performance, errors and how people use the Platform. |
| Marketing | Measure campaigns or personalise promotion where these tools are enabled and the required consent has been obtained. |
Non-essential cookies should be used only after the required choice or consent has been obtained. A person can manage available choices through the cookie banner and may also block or delete cookies through browser settings. Blocking necessary cookies may prevent account, booking or payment functions from working correctly.
Embedded maps, videos, social-media posts, payment tools or other third-party content may set their own cookies or collect information under their own privacy policies.
9. Marketing communications
We may send newsletters, offers, destination updates or Partner information where a person has subscribed, consented or another lawful basis permits the communication.
Marketing emails will include an unsubscribe method. A person may also ask us to stop marketing by contacting support. We may continue sending essential booking, account, security, legal and service messages after marketing has been stopped.
10. International data transfers
Some technology or payment providers may store or process personal data outside Kenya. Where personal data is transferred internationally, we will take reasonable steps to use a transfer permitted by Kenyan law, such as an approved destination, contractual safeguards, consent where appropriate or another lawful transfer mechanism.
11. Data security
We use reasonable technical and organisational measures designed to protect personal data against accidental loss, destruction, alteration, unauthorised access, disclosure or misuse. Measures may include access controls, password protection, restricted staff access, secure connections, backups, monitoring and contractual obligations for service providers.
No online service can guarantee complete security. Users should protect passwords, use trusted devices and networks, and notify us promptly about suspected account misuse or security concerns.
12. Personal-data breaches
If a personal-data breach occurs, we will investigate, contain and assess it and take the notifications and protective steps required by law. Where required, we will notify the Office of the Data Protection Commissioner and affected individuals within the applicable legal timeframes.
13. How long we retain personal data
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including to:
- maintain an active account or listing;
- complete bookings, refunds, payouts and support;
- meet tax, accounting, consumer, regulatory and legal-record obligations;
- prevent fraud and protect Platform security;
- resolve complaints, chargebacks and legal disputes; and
- establish, exercise or defend legal claims.
Retention periods differ according to the type of information and legal requirements. When personal data is no longer needed, we will delete, securely destroy or anonymise it where reasonably possible.
14. Children’s personal data
A person must be at least 18 years old to create a Partner account or make a booking unless a parent, guardian or other authorised adult is responsible for the transaction.
A Guest may provide limited information about a child where necessary for a family booking, age-based price, room occupancy, safety requirement or service delivery. The adult providing the information confirms that they are authorised to do so.
We do not knowingly use children’s personal data for behavioural marketing. If personal data was submitted by a child without proper authority, contact us so that we can review and, where appropriate, delete it.
15. Automated tools and fraud screening
We or our providers may use automated tools to identify suspicious transactions, account misuse, security threats or booking risks. These tools may flag a matter for review, delay payment or request additional verification.
We do not intend to make a decision producing a significant legal or similarly serious effect solely through automated processing without the safeguards required by law.
16. Your data-protection rights
Subject to Kenyan law and any lawful limitations, a person may have the right to:
- be informed about how personal data is used;
- request access to personal data held about them;
- request correction of inaccurate or incomplete information;
- object to some processing;
- request restriction of processing in appropriate circumstances;
- request deletion of data that is no longer required or is being processed unlawfully;
- withdraw consent where processing is based on consent;
- request transfer of personal data where the right to portability applies; and
- raise a complaint about the processing of personal data.
We may request information to confirm identity and authority before acting on a request. We will respond within the period required by applicable law. Some information may need to be retained despite a request where this is required for bookings, payments, fraud prevention, legal obligations or legal claims.
17. How to exercise your rights or complain
Privacy requests and complaints should be sent to:
Exploring Mombasa
Email: support@exploringmombasa.com
Website: exploringmombasa.com
Please use the subject line Privacy Request and include enough information for us to understand and verify the request.
18. Third-party websites and services
The Platform may contain links to Partner websites, social-media platforms, maps, videos, payment services and other third-party services. Their privacy practices are controlled by those third parties, and this policy does not replace their privacy notices.
Guests should review a Partner’s privacy information where the Partner collects additional information directly.
19. Changes to this policy
We may update this Privacy Policy to reflect changes in the Platform, providers, business practices or law. The updated version and effective date will be published on the Platform. Where a change materially affects a person’s rights or how existing data is used, we will provide additional notice where reasonably required.
20. Related policies
This Privacy Policy should be read together with the Guest Booking, Cancellation and Refund Policy, the Partner Terms and Conditions, the booking terms shown at checkout and any cookie choices displayed on the Platform.