Privacy policy
Siriana is a chain of salons in Kenya, run by Sirience Ltd (“we”). This policy explains what personal data the Siriana app, the siriana.app website and our salons collect, why, who we share it with, how long we keep it, and your rights. We are the data controller under the Kenya Data Protection Act, 2019.
Who to contact
For any privacy question or request, email ailosiri@gmail.com. You can also delete your account or download your data yourself in the app, under Profile.
What we collect
- Phone number. Your account is your phone number: you sign in with it and a one-time code. We also use it to send booking confirmations and reminders, and to request M-Pesa payments.
- Name and, if you add it, email address. So salons know who is coming, and for receipts.
- Bookings, purchases and payments. What you booked or bought, when, the amount, the M-Pesa reference and the phone number that paid. We never see or store your M-Pesa PIN, and there are no card payments.
- Loyalty Tokens. The Tokens you earn and redeem.
- Location. When you search for salons near you, your phone’s location is used to find and sort nearby salons. For staff and field agents, location is recorded when they check in at a salon, to verify the visit.
- Photos. Photos you add to a support conversation. Staff and field agents also take photos of salons as part of their work.
- Messages to support and your notification and marketing choices.
- Device data. A device identifier and a push-notification token, so we can keep you signed in safely and send notifications.
- Crash and error reports. If the app or our systems hit an error, we receive a report: what went wrong, your phone model, Android version and app version, the screens you visited just before, and an anonymous account ID. A short recording of the screen around the error may be included, with all text, images and typing hidden. Phone numbers, names and codes are removed before a report is sent.
We do not use advertising IDs, do not show ads, do not track you across other apps or websites, and do not sell your data.
Why we use it
- To run your account, bookings, purchases, payments, receipts and loyalty Tokens.
- To send you what you need about your bookings (confirmations, reminders, changes).
- To prevent fraud and keep accounts secure, for example the one-time sign-in codes.
- To find and fix errors in the app and our systems.
- To meet legal duties, such as tax invoicing to KRA and keeping financial records.
- To send offers and news, only if you switch this on. It is off by default, and you can switch it off at any time in the app.
Who we share it with
Only with the service providers that help us run Siriana, and only what each one needs:
- Safaricom (M-Pesa): your phone number, the amount and a reference, to request and refund M-Pesa payments.
- Meta (WhatsApp) and BulkGate (SMS): your phone number and the message, to send sign-in codes and booking messages.
- Resend: your email address and the message, if we email you.
- Google Firebase Cloud Messaging: a push-notification token, to deliver notifications to your phone.
- Sentry (stored in the European Union): crash and error reports, as described above.
- Cloudflare: hosts our systems and stores our data, in the European Union.
- Kenya Revenue Authority: tax invoices, as the law requires.
We may also share data when the law requires it, for example with a court or a regulator.
Where your data is stored
Our systems store data in Cloudflare’s European Union jurisdiction. Moving data outside Kenya is done with appropriate safeguards (Standard Contractual Clauses) and with your consent, which you give when you create your account, as the Kenya Data Protection Act requires.
How long we keep it
- Your account: until you delete it. When you ask to delete your account, you have 24 hours to change your mind; after that your name, phone number and email are erased.
- Payment records: 7 years, because financial and tax law requires it. They are kept without your name or contact details.
- Loyalty Tokens: can be restored for 30 days after you delete your account, in case you come back.
- Crash and error reports: deleted automatically after about 30 days.
Your rights
Under the Kenya Data Protection Act you have the right to:
- be told what data we hold about you, and get a copy (in the app: Profile, then download my data);
- have wrong data corrected;
- have your data deleted (in the app: Profile, then delete account);
- object to, or withdraw consent for, a use of your data, such as marketing;
- complain to the Office of the Data Protection Commissioner (odpc.go.ke).
For anything you cannot do in the app, email ailosiri@gmail.com. We reply within 7 days.
Security
All data travels encrypted. Sign-in codes, passwords and session keys are stored only in hashed or encrypted form, and staff access to customer data is limited to what their role needs.
Children
Siriana is for adults. We do not knowingly collect data from children under 18.
The website
The public pages of siriana.app use no analytics or advertising cookies. Sign-in pages for salon staff use a cookie only to keep staff signed in.
Changes
If we change this policy, we update the date at the top. If a change matters to how we use your data, we tell you in the app.