Legal / Privacy

Privacy, in plain language.

This policy explains how MooreTech handles personal data across our websites, APIs, dashboards, communications, ticketing, dealership, fleet, payment, and photo-matching services.

Effective and last updated: 12 August 2026

1. Scope and our role

This Privacy Policy applies to MooreTech websites and products that link to it, including services for business messaging, WhatsApp onboarding, SMS, ticketing, payments, dealership inventory and leads, fleet operations, reporting, rentals, and event photo discovery (together, the Services).

MooreTech is a data controller when we decide why and how to use information about our own visitors, prospects, account administrators, billing contacts, and support contacts. When a dealership, SACCO, event organiser, photographer, merchant, or another customer uses our Services to handle its customers, passengers, crew, attendees, recipients, or leads, that organisation usually controls the data and MooreTech acts as its data processor or service provider.

If your information was collected by one of our customers, contact that organisation first where practical. We will support the organisation in answering your request, or route your request to the correct controller.

2. Data we collect

The information depends on the Service and how you use it. It may include:

  • Identity and contact data: name, username, business name, phone number, WhatsApp number, email address, and authorised-user role.
  • Account and tenant data: organisation, dealership, SACCO, event, store, staff memberships, permissions, login and verification records.
  • Communications data: message content, templates, recipient details, consent and opt-out records, attachments, delivery/read/failure status, and support conversations.
  • Meta business data: business portfolio, WhatsApp Business Account, phone number, template, Flow and catalogue identifiers; permissions granted during Embedded Signup; and access tokens needed to provide the connection.
  • Commercial and payment data: orders, tickets, invoices, amounts, currencies, transaction references, M-Pesa phone numbers, payment status, refunds, deposits, and provider responses. Payment PINs must never be provided to MooreTech.
  • Event and attendance data: event registration, ticket holder and attendee details, ticket type, QR code, check-in and scanner activity, and checkout answers.
  • Vehicle and operations data: vehicle listings and media, buyer enquiries, crew and investor records, fuel and finance logs, routes, assignments, safety incidents, and—where tracking is enabled—vehicle position and telemetry.
  • Photos and matching data: uploaded event images, selfies submitted for matching, face embeddings generated from those images, match results, watermarked previews, purchases, and download records.
  • Device and usage data: IP address, browser/device type, timestamps, pages and features used, referring page, session identifiers, audit logs, errors, and security signals.
  • Content you provide: documents, media, catalogues, descriptions, preferences, feedback, and any other information submitted to a Service.

We use essential cookies or similar storage for sessions, security, and preferences. Where enabled, limited analytics help us understand aggregate use and performance. We do not use MooreTech Services to build or sell third-party advertising profiles.

We do not sell or rent personal data.

3. Location and biometric data

Some Services involve higher-risk data. Fleet tracking may reveal a vehicle's route and, indirectly, the location or working pattern of assigned crew. The customer operating the fleet must have a lawful purpose, provide appropriate notices, limit access, and avoid using tracking for unrelated surveillance.

PichaYangu-style photo discovery uses a selfie to generate a mathematical face embedding and compare it with faces in an event's photo collection. This is biometric processing. It is designed only to return likely event photo matches—not to establish legal identity. The event operator or photographer must have an appropriate lawful basis and provide any required notice or consent. You may ask us or the relevant operator to delete your selfie, embeddings, and match records.

The Services may automatically calculate photo-match scores, fuel or route insights, delivery states, and safety alerts. These outputs support human decisions and are not intended to make solely automated decisions that have legal or similarly significant effects on an individual. Material decisions should be checked by an authorised person.

4. Where data comes from

We collect data:

  • directly from you when you visit, register, connect an account, submit a form, upload content, pay, message, or request support;
  • from the organisation that gives you access to a MooreTech Service or uploads operational/customer records;
  • from Meta, WhatsApp, SMS networks, M-Pesa and other payment providers, tracking systems, and integrations you or a customer authorises;
  • automatically from our websites, APIs, applications, logs, fraud controls, analytics, and security services; and
  • from public or licensed sources where permitted, such as public vehicle information or properly attributed demonstration media.

5. How and why we use data

We process personal data only where there is a lawful and specific purpose, including to:

  • provide, authenticate, operate, customise, and support the Services;
  • send requested WhatsApp or SMS communications and record their delivery status;
  • process orders, ticketing, deposits, payment requests, refunds, check-ins, reports, and downloads;
  • connect and manage authorised Meta, payment, storage, mapping, tracking, and customer systems;
  • protect accounts, prevent abuse and fraud, troubleshoot faults, maintain audit trails, and enforce our terms;
  • measure service performance and improve reliability, usability, and capacity;
  • respond to enquiries and, where permitted, tell business contacts about relevant MooreTech products; and
  • comply with law, lawful requests, tax/accounting duties, and dispute resolution.

Depending on the activity, we rely on performance of a contract, compliance with legal obligations, your specific consent, or our/customer's legitimate interests where those interests do not override your rights. You may withdraw consent for future processing at any time, although earlier lawful processing remains valid.

6. Meta and WhatsApp connections

During WhatsApp Embedded Signup, Meta presents and controls the Facebook login and business-selection window. MooreTech does not receive your Facebook password. If you approve the connection, Meta sends us the identifiers, permissions, and authorisation needed to connect your chosen business assets. We store service credentials in protected form and use them only to provide the authorised features.

Meta and WhatsApp also process data under their own policies. Removing MooreTech from Facebook's Apps and Websites settings stops future authorised access, but may not erase operational records already held by us or a customer. Follow our data deletion instructions for that separate request.

7. When data is shared

We disclose only what is reasonably needed to:

  • the customer organisation whose account, event, dealership, fleet, store, or workflow you interact with, including its authorised staff;
  • communications providers such as Meta/WhatsApp and the configured SMS network;
  • payment providers such as Safaricom M-Pesa or another provider selected for a transaction;
  • infrastructure and security providers used for hosting, database, email, storage, CDN, analytics, error monitoring, fraud prevention, and human verification, including Cloudflare and Vercel where enabled;
  • professional advisers and authorities when needed for legal compliance, safety, audits, claims, or enforcement; and
  • a successor organisation in a merger, financing, reorganisation, or sale, subject to appropriate confidentiality and notice.

Our providers may use the data only under their applicable terms, our instructions, and suitable safeguards.

8. International transfers

Some providers and technical systems operate outside Kenya. Where personal data is transferred across borders, we use measures appropriate to the data and the recipient, such as contractual protections, access controls, recognised adequacy safeguards, or consent where the law requires it.

9. How long we keep data

We keep personal data only for as long as reasonably necessary for the stated purpose. The period depends on the product, the customer's instructions, the account lifecycle, contractual and legal recordkeeping duties, payment or dispute needs, security requirements, and whether records can be safely anonymised.

Short-lived authentication codes, raw diagnostic events, signed download links, and temporary uploads are intended to expire sooner than core account, transaction, ticket, consent, or audit records. When retention is no longer justified, data is deleted, anonymised, or isolated for scheduled deletion. Encrypted backups may retain a copy until they rotate, and that copy is not restored for ordinary business use.

10. How we protect data

We use measures appropriate to the risk, including access controls and tenant separation, encrypted transport, protected integration credentials, private object storage and time-limited links where suitable, logging, backups, rate limiting, human-verification controls, dependency and vulnerability management, and incident response. No online service is completely risk-free, so please use strong credentials, restrict staff access, and report suspected compromise promptly to a@moore.co.ke.

11. Your choices and rights

Subject to applicable law, you may ask to be informed about processing, access your personal data, correct it, object to or restrict processing, withdraw consent, request portability where applicable, or request erasure. You can also opt out of direct marketing and stop WhatsApp or SMS messages using the instructions in the message or by contacting the sender.

Send a request to a@moore.co.ke or follow our data deletion instructions. We may need to verify your identity and authority without collecting more information than reasonably necessary. If a customer controls the record, we may refer the request to that customer and assist it.

If you are not satisfied with our response, you may lodge a complaint with Kenya's Office of the Data Protection Commissioner.

12. Children

MooreTech business accounts are not intended for children. A customer offering an event or other service that involves a child must obtain appropriate parent or guardian authority and apply age-appropriate safeguards. If you believe a child's data was collected without proper authority, contact us and the relevant customer promptly.

13. Changes and contact

We may update this policy as the Services or law changes. We will post the new version here, change the date at the top, and provide additional notice when a change materially affects how we use personal data.

For privacy questions or requests, email a@moore.co.ke. Please name the MooreTech product and customer organisation involved so we can locate the correct records.