MutugiTech (“we”, “us”, “our”) operates BookMe. This Privacy Policy explains how we collect, use, store, and share personal information when you use our websites, APIs, and mobile apps.
We designed BookMe for solo professionals in Kenya and their clients. We aim to collect only what we need to run scheduling, payments, and support—clearly and carefully.
1. Who we are
Controller: MutugiTech Product: BookMe (web and mobile) Contact: mutugitechadmin@gmail.com · +254 798 718 682
If you have privacy questions or wish to exercise your rights, email us. We aim to respond within a reasonable time (typically within 30 days where required).
2. Information we collect
Account and profile (providers)
- Email address, name, and password (stored hashed—we never store plaintext passwords).
- Optional social login identifiers when you sign in with Google or GitHub via our auth partners (including Neon Auth).
- Business profile: business name, username/slug, bio, category, phone, address, website or social links.
- Profile images: uploaded photos may be stored in our database and served from BookMe URLs (for example `/api/v1/public/providers/{username}/avatar`). Anyone with that URL can load the image.
- Preferences such as timezone, currency display, and whether bookings are paused.
- Legal acceptance records (terms version and acceptance time) when an account is created.
Bookings (providers and clients)
- Customer name, email, phone (if provided), notes, selected service, start/end time, status, and price / deposit amounts associated with a booking.
- Clients generally do not create accounts; they submit details only to complete a booking with a specific provider.
- Providers see booking details for their own business.
Reviews
- Name, email, star rating, and optional comment when a client leaves a review.
- Email is used to enforce one review per business and for abuse prevention. Public pages and marketplace summaries are intended to show name, rating, and comment—not email.
Subscriptions and payments
- Plan selection, subscription status, and period dates.
- Phone number used for M-Pesa checkout, payment references, receipts/status from partners (including PayHero), and confirmation via callbacks and/or status polling.
- We do not store your M-Pesa PIN.
- Deposit amounts on services/bookings may be stored as information only; BookMe does not currently process client deposit payments inside the app.
Notifications
- In-app notification records for providers (titles, body text, read state, optional links)—for example new bookings, reviews, or subscription updates. We do not currently send SMS or marketing email campaigns as part of core BookMe.
Device and usage
- Technical logs (IP address, timestamps, app/browser type, error diagnostics) needed to secure and improve BookMe.
Support
- Messages and contact details you send to mutugitechadmin@gmail.com or share when you call / WhatsApp +254 798 718 682.
3. How we use information
We use personal data to:
- Create and secure accounts (email/password or social sign-in); operate booking pages and the marketplace.
- Show availability, create bookings, store in-app notifications for providers, and display reviews.
- Process subscription payments via M-Pesa partners and keep pages live while subscriptions are active.
- Prevent fraud, abuse, and security incidents.
- Improve reliability, diagnose errors, and develop features.
- Comply with Kenyan law and respond to lawful requests.
- Respond to support requests.
Legal bases under the Kenya Data Protection Act, 2019 (where applicable) include performance of a contract, legitimate interests in operating a secure platform, consent where we ask for it, and legal obligation.
4. Marketplace and public pages
Information you publish on a public booking page or marketplace card—such as business name, bio, category, photo, address you choose to show, ratings, and reviews—can be viewed by anyone with the link or who browses the marketplace.
Do not publish sensitive personal data in bios or service descriptions.
5. Sharing
We do not sell personal information.
We share data only with:
- Infrastructure providers (hosting, database) that process data on our instructions.
- Authentication partners (for example Neon Auth and Google/GitHub) when you use social sign-in.
- Payment partners (for example PayHero / M-Pesa channels) to complete subscription checkout and confirm payment status.
- Providers you book with, who receive the booking details you submit.
- Authorities, when required by law or to protect rights, safety, and integrity of the Service.
International transfers may occur when our processors store data outside Kenya. Where we do so, we take steps appropriate under applicable law to protect the information.
6. Cookies and app sessions
Web
- Essential session cookies such as `bookme_session` to keep you signed in.
- Cookies or storage used by our auth partner when OAuth is enabled.
- Minor UI preferences (for example layout state). We do not use third-party advertising trackers in core BookMe booking flows.
Mobile
- Secure access tokens stored on device to call our API. Tokens are not used for advertising.
7. Retention
- Account and profile data: while your account remains open; after closure we delete or anonymize within a reasonable period unless law requires longer retention.
- Bookings: retained as needed for the provider’s history, disputes, and platform integrity.
- Reviews: may remain visible until removed under our policies or upon lawful deletion requests.
- Payment records: retained as required for accounting, tax, and fraud prevention.
- Logs and in-app notifications: typically shorter-lived unless needed for security investigations.
- Profile images: retained while associated with an active profile; removed or orphaned when deleted via the product or support.
8. Security
We use HTTPS in transit, hashed passwords, access controls, and least-privilege practices. No method of transmission or storage is 100% secure; please use a strong unique password and contact us if you spot a vulnerability.
9. Your rights
Depending on applicable Kenyan data protection law, you may request to:
- Access a copy of personal data we hold about you.
- Correct inaccurate data.
- Delete data (subject to legal or legitimate retention needs).
- Object to or restrict certain processing.
- Withdraw consent where processing is consent-based.
Providers can update much of their profile in Settings. Account deletion and full data export are not yet self-serve in the product—email mutugitechadmin@gmail.com and we will process verified requests. We may ask for identity verification. Typical handling time is within 30 days unless complexity requires longer (we will say so).
After closure, public booking pages and marketplace listings stop being available for new bookings; historical booking records may be retained briefly for legal and operational reasons before deletion or anonymization.
10. Children
BookMe is not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child has provided data, contact us and we will take appropriate steps.
11. Changes
We may update this Policy and the version date. Material changes will be reflected here and, where appropriate, called out in the product. Continued use after updates means you acknowledge the revised Policy.
12. Contact
MutugiTech — BookMe privacy & support Email: mutugitechadmin@gmail.com Phone / WhatsApp: +254 798 718 682 Support centre: /support