Last updated: 3 September 2026
This Privacy Policy explains how NaiHive collects, uses, discloses, stores, protects, and deletes personal data when you use the Service. It applies to visitors, account holders, profile owners, advertisers, reviewers, people who message or report content, and people whose information appears in content submitted by a user.
We aim to process personal data lawfully, fairly, transparently, securely, and only for clear purposes. This policy should be read with the Terms of Service. It is not a substitute for professional legal advice or a registration, assessment, contract, or operational control required by applicable law.
1. Who controls your data
NaiHive is the data controller for personal data collected and used to operate the Service. Some vendors process data on our instructions as data processors, while payment providers, email providers, hosting providers, and public authorities may process data under their own legal obligations or terms. The Service is operated for users in Kenya and may be used from other countries.
For privacy requests, contact NaiHive through the support or contact details published on the Site. We may ask for information needed to verify your identity and protect another person's data before completing a request. Do not send identity documents through an unverified channel.
2. Data we collect
Depending on how you use the Service, we may collect:
- Account and authentication data: name, email address, password credentials or password-related tokens, email-verification records, sign-in sessions, and linked authentication-account data.
- Profile and advert data: profile name, age, nationality, ethnicity, body type, biography, tagline, location or county, availability, rates, phone, WhatsApp, email, address, website, categories, and other information you choose to publish.
- Photos and media: images, videos, captions, cover selection, upload metadata, and the public URLs needed to display approved profile or advert media.
- Optional identity-verification data: date of birth, identity-document type and number, identity-document images, selfie images, verification status, and reviewer notes or outcomes - collected only if you choose to start the voluntary verification described in section 5. We do not collect any of it today, and we never collect it as a condition of using the Service.
- Communications and safety data: conversations, messages, reviews, reports, blocks, support requests, moderation decisions, and audit information connected to those events.
- Payment and promotion data: provider, amount, currency, payment type and duration, status, transaction or receipt references, callback events, and linked profile or advert. Payment credentials and mobile-money PINs are handled by the payment provider, not stored by NaiHive.
- Technical and security data: IP address or trusted proxy IP, user agent, device and browser details made available in requests, timestamps, request paths, error and audit logs, rate-limit identifiers, cookies, and security events.
- Usage data: pages, profiles, adverts, searches, interactions, and view counts used to operate the directory, understand demand, prevent abuse, and improve the Service. We do not use this policy to promise third-party advertising analytics that are not enabled.
We collect information directly from you, automatically from your use of the Service, from payment or infrastructure providers, and from other users when they submit a review, report, message, or block. If you publish another person's information, you are responsible for having a lawful basis and any consent required to do so.
3. Why we use data and our legal bases
We use personal data for the following purposes:
- to create and secure accounts, verify email addresses, authenticate sign-ins, recover accounts, and send essential one-time-code emails;
- to publish and deliver the profiles, adverts, search, contact, messaging, review, and promotion features you request;
- to process payments, reconcile callbacks, prevent duplicate or fraudulent transactions, provide receipts, and handle disputes;
- to receive, investigate, and act on reports, blocks, safety concerns, abuse, fraud, impersonation, and possible unlawful content;
- to enforce the 18+ requirement through age confirmation at sign-up and moderation, and to protect users and the public;
- to run the optional verification described in section 5 and issue or withdraw a verification badge, where you have chosen to take part;
- to operate, maintain, troubleshoot, monitor, measure, and improve the Service, including reliability, performance, rate limiting, and security;
- to comply with court orders, regulatory duties, tax or accounting requirements, lawful requests, and legal claims; and
- where allowed and separately permitted, to send optional communications or use consent-based features. You can withdraw consent where consent is the basis, without affecting earlier lawful processing.
Depending on the activity, the legal basis may be performance of a contract or pre-contract steps, compliance with a legal obligation, protection of vital interests, our legitimate interests in security and platform operation, or your consent. Where we rely on legitimate interests, we balance those interests against your rights and reasonable expectations. For optional identity verification the basis is your explicit consent, which you may withdraw.
4. What is public and what is private
Information in a published profile or advert - including name, description, location, availability, contact options, rates, reviews, and approved media - may be visible to visitors, searchable, copied, cached, or shared by other people. Do not publish anything you need to keep confidential. Removing a listing stops its ordinary display but cannot guarantee that third parties have deleted copies, screenshots, search results, or messages.
Account credentials, email-verification data, sessions, private messages, reports, any optional verification data, payment records, and internal moderation records are not intended for public display. Access is limited according to role, purpose, security controls, and operational need. A support, moderation, payment, hosting, or legal provider may access relevant data when needed for its service or legal obligation.
5. Optional identity verification
Identity verification is entirely optional and is not available today. We intend to offer it as something you start yourself, whenever suits you, in exchange for a verification badge on your profile. You will never need it to create an account, publish a profile, appear in the directory, receive messages, or buy promotion. Choosing not to take part costs you nothing but the badge. Because nothing currently asks for an identity document, treat any request for one as fraudulent, however it reaches you.
If you choose to take part once it exists, the submission may involve sensitive personal data under Kenyan law, including identity details, date of birth, identity-document images, selfie images, and information that may reveal sex, ethnicity, or other protected characteristics. We will process it only on your explicit consent, only through the designated secure flow, and only for confirming adult age and identity, preventing fraud and impersonation, administering the badge, and meeting legal obligations. We will not publish your document, show it to other users, or use it for advertising.
Verification documents are stored separately from public profile media in non-public storage, encrypted at rest where configured, and made available only to authorised reviewers or providers with a legitimate need. You may withdraw consent and ask us to delete a submission at any time; we will delete the documents and remove the badge, keeping only what a legal, tax, fraud, or safety obligation requires us to retain. A badge does not certify every profile claim, detect every fraud, or guarantee a person's conduct.
6. Sharing and service providers
We may share the minimum relevant data with:
- Cloud hosting, database, cache, queue, logging, monitoring, email, and object-storage providers that host or process the Service;
- email delivery providers, including AWS SES in production, to deliver authentication and other essential emails;
- payment providers such as M-Pesa, SasaPay, or Paystack to initiate, confirm, reconcile, and support payments;
- authorised staff, moderators, reviewers, contractors, and professional advisers who need it to operate, secure, or advise on the Service;
- other users and visitors where you intentionally publish profile, advert, contact, review, or media information; and
- law-enforcement, courts, regulators, emergency responders, or other persons where disclosure is required or reasonably necessary to comply with law, protect rights and safety, or investigate fraud or abuse.
We do not sell personal data. We do not disclose private account or verification data to advertisers for their own unrelated marketing. We may use aggregated or de-identified information that no longer reasonably identifies a person for measurement, security, research, or service improvement.
7. International processing and transfers
Some infrastructure and service providers may process data outside Kenya. Before a transfer, we seek an applicable legal basis and appropriate safeguards required by Kenyan data-protection law, such as contractual, organisational, technical, or other safeguards. Transfers of sensitive personal data receive additional protection and may require consent or other safeguards. You may request general information about relevant transfer safeguards through the privacy request channel.
8. Cookies and similar technologies
We use essential cookies and similar storage for authentication, session continuity, security, rate limiting, consent, and remembering necessary preferences. The adult-consent cookie is signed, short-lived, and configured as HttpOnly, Secure in production, SameSite=Lax, and scoped to the site. Blocking essential cookies may prevent sign-in or other features from working.
We may record server-side usage and view-count events needed to operate the directory. If we introduce non-essential analytics, advertising, or marketing cookies, we will provide any notice and choice required by law before enabling them.
9. Retention and deletion
We retain personal data only for as long as reasonably necessary for the purpose collected, unless a longer period is required or permitted by law, contract, accounting, dispute, fraud, safety, or legal obligations. Examples include:
- email-verification and one-time-code records are short-lived and used for the relevant verification window;
- temporary upload records and unattached files are eligible for cleanup after their upload window;
- public listings and media remain available until you remove them, they expire, or we remove them;
- sessions, security events, rate-limit records, logs, reports, and moderation records may remain for operational and safety periods; and
- account, payment, accounting, fraud, dispute, legal, and safety records may remain after account deletion where necessary.
When you delete your account, the account-deletion flow marks it as deleted and disables access while retaining the account-linked profile, advert, uploads, credentials, identity data, and related records. Information may still be removed where required by law or a separate retention rule applies.
10. Security and breach response
We use reasonable technical and organisational safeguards appropriate to the risk, including access controls, role restrictions, encryption or protected storage for selected sensitive and queue data, signed short-lived upload or review links, rate limiting, session controls, secure cookies, monitoring, and audit logs. No internet service or storage system is risk-free, and we cannot guarantee absolute security.
We investigate suspected personal-data incidents, contain them, preserve relevant records, and notify the Office of the Data Protection Commissioner and affected people where Kenyan law requires it. If you suspect an account or privacy incident, contact us promptly through the published support channel and include enough detail to investigate without sending unnecessary sensitive data.
11. Your rights
Subject to applicable law and lawful exceptions, you may request:
- information about how your personal data is used;
- access to personal data we hold about you;
- correction of inaccurate, false, or misleading data;
- deletion or erasure where the data is no longer necessary, processing is unlawful, or another legal ground applies;
- restriction of processing in appropriate circumstances;
- objection to processing, including certain direct-marketing or legitimate-interest processing;
- withdrawal of consent where consent is the legal basis; and
- data portability where the right applies and the data can reasonably be provided in a structured, commonly used, machine-readable format.
We may decline or limit a request where permitted or required by law, including to protect another person's rights, preserve evidence, prevent fraud, or comply with a legal obligation. We will explain the reason where legally permitted. You may also complain to Kenya's Office of the Data Protection Commissioner if you believe your rights have been infringed.
12. Children and minors
The Service is not for anyone under 18. We do not knowingly collect or publish a minor's information for account or listing purposes. If you believe a minor's information, image, or content appears on the Service, report it immediately through the support or report channel; do not copy or redistribute it. We may remove the content, restrict accounts, preserve evidence, and notify authorities where appropriate.
13. Changes and complaints
We may update this policy when our practices, technology, providers, or legal obligations change. We will post the new version and update the date above; where practical, we will give additional notice for material changes. If you continue using the Service after the effective date, the updated policy applies to future processing. Processing already completed remains governed by the policy that applied at the time, except where law permits otherwise.
If we cannot resolve a privacy concern, you may lodge a complaint with the Office of the Data Protection Commissioner through its official complaint channel at odpc.go.ke.