harakacount is a product of harakacount Ltd ("harakacount," "we," "our," or "us"), and we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our restaurant inventory management application.
harakacount Ltd is a Kenyan company, registered with Kenya's Office of the Data Protection Commissioner, and we handle personal data in accordance with the Kenya Data Protection Act 2019. We also apply the practices set out in this policy — including access, correction, deletion, export and objection — to everyone who uses the Service, wherever they are, rather than only where a particular law compels it.
1. Information We Collect
We collect the following types of information:
Account Information:
- Restaurant name and business information
- Contact details (name, email address, phone number)
- Account credentials (email, password hash, PIN)
- User role and permissions
Operational Data:
- Inventory items, stock levels, and counts
- Supplier information and delivery records
- Recipe data and production schedules
- Waste tracking and cost analysis data
- Menu profitability and sales data
- Stock take and adjustment records
Technical Information:
- Device information (model, operating system, unique device identifiers)
- IP address and approximate location
- Usage data and analytics (screens visited, features used, session duration)
- Error logs and performance data
2. How We Use Your Information
We use your information for the following purposes:
Service Provision (Legal Basis: Contract Performance):
- Provide and maintain the inventory management Service
- Process and store your inventory data
- Authenticate users and manage access permissions
- Generate reports and analytics
Service Improvement (Legal Basis: Legitimate Interest):
- Analyze usage patterns to improve features and user experience
- Develop new features and functionality
- Monitor and troubleshoot technical issues
- Optimize Service performance and reliability
Communication (Legal Basis: Contract Performance / Legitimate Interest):
- Send technical notices, updates, and security alerts
- Provide customer support and respond to inquiries
- Send important Service announcements
- Request feedback (with your consent)
Legal Compliance (Legal Basis: Legal Obligation):
- Comply with applicable laws and regulations
- Respond to lawful requests from authorities
- Enforce our Terms of Service
- Protect against fraud and security threats
3. Data Storage and Security
We implement comprehensive security measures to protect your data:
- Encryption at rest for data and backups, provided by our infrastructure providers' managed database and storage services
- Encryption in transit using TLS 1.2+ for all data transmission
- Secure authentication with bcrypt password and PIN hashing, and short-lived access tokens
- Additional encryption of any third-party accounting or point-of-sale credentials you connect, using AES-256-GCM
- Role-based permissions, with every request scoped to your restaurant using the identity in your verified session
- Rate limiting and automated lockout after repeated failed sign-in attempts
- Automated dependency vulnerability scanning on every change and on a weekly schedule
- Logging of sign-in, sign-out, permission-denial, account-lockout and data-export events
- An activity trail of changes to business records, such as stock counts, adjustments, recipes and deliveries, recording what changed, which user made the change and when. Fields we classify as sensitive are redacted from this trail. Owners and managers of a business can review and export the trail for their own business
- Automated backups of our managed database, taken and retained by our infrastructure provider on their schedule
Your data is stored on secure servers located in reputable data centers that comply with industry security standards. While we implement robust security measures, no system is completely secure, and we cannot guarantee absolute security.
If there is a data breach
A personal data breach means a security incident that leads to personal data being lost, destroyed, altered, disclosed or accessed without authorisation. If one happens, we will:
- Notify Kenya's Office of the Data Protection Commissioner within 72 hours of becoming aware of the breach, as required by the Data Protection Act 2019
- Tell the people affected without undue delay, where the breach is likely to result in a real risk of harm to them. We will explain what happened, what data was involved, what we are doing about it, and what we suggest you do
- Notify the business whose account is affected without undue delay, where the data involved is data that business entered or uploaded. In that situation the business is the controller of that data and we handle it on their behalf, so they may have their own notification duties and need to hear from us promptly in order to meet them
- Record the incident, its effects and the action we took, and review what needs to change so it does not happen again
We do not wait for certainty before telling you. If we know enough to say something useful and we are still investigating, we will say that rather than delay.
We publish a detailed breakdown of these controls, including the areas we are still working on, on our Security and Trust page.
4. Data Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following limited circumstances:
- With Your Consent: When you explicitly authorize us to share specific information
- Service Providers: With trusted third-party vendors who perform services on our behalf, including cloud hosting and database providers, analytics and crash-reporting providers, error and performance monitoring providers, email delivery providers, image storage providers, optical character recognition (OCR) providers, and providers that power certain AI-generated insights, under strict confidentiality agreements and instructions to use your data only to provide these services to us
- Legal Requirements: When required by law, court order, or governmental authority
- Protection of Rights: To protect our rights, property, or safety, or that of our users or the public
- Business Transfers: In connection with a merger, acquisition, or sale of assets (you will be notified)
We never share your confidential business data (inventory levels, costs, supplier information) with third parties except as required by law.
5. Data Retention
We retain your data for different periods depending on the type of information:
- Account and Inventory Data: Retained while your account is active. When an account owner deletes the business, the account records and the files uploaded to it, including invoice and delivery photographs, are deleted immediately rather than after a waiting period
- Individual Team Members: When a team member deletes their profile, their credentials, sessions and profile photograph are deleted and their name and contact details are replaced. The records they created, such as stock counts, remain with the business, because they belong to the restaurant rather than to the individual
- Security Logs: Sign-in, permission and export logs are kept for 12 months and then deleted automatically. Logs of events we classify as critical are kept indefinitely, because they are the record of a possible security incident
- Activity Trail: The record of who changed which business records, and what they changed, is kept for 12 months and then deleted automatically. Views of analytics and insights pages are kept for 90 days. Critical events are kept indefinitely. The business records themselves, including the stock movement history that shows every stock change and who made it, are kept for as long as the business account is active
- In-App Notifications: Kept for 90 days, other than critical notifications, which are kept indefinitely
- Analytics Data: Aggregated and anonymized data may be retained indefinitely for statistical purposes
- Legal Hold: Data may be retained longer if required by law or pending legal proceedings
You may request deletion of your account and associated data at any time through the settings page or by contacting support. Where deletion is not immediate, we will complete it within 30 days unless legal retention requirements apply.
Deleted data can persist in our infrastructure provider's encrypted database backups until those backups expire on their normal rotation. We do not restore deleted accounts from backups, and backup copies are not accessible through the Service.
6. Your Privacy Rights
Depending on your location, you have the following rights regarding your personal data:
Rights for All Users:
- Access: Request a copy of your personal information
- Correction: Update or correct inaccurate data
- Deletion: Request deletion of your account and data
- Export: Receive your data in portable CSV format. Self-service export inside the app is a feature of our Pro plan, but the right itself is not conditional on what you pay us: on any plan, email [email protected] and we will export your data for you at no charge
- Turn Off AI Processing: Account owners can disable the features that send data to our AI provider, which are invoice scanning and AI-generated insights, from their business settings. The rest of the Service continues to work normally. See the section on AI processing below
- Opt-Out: Unsubscribe from marketing communications
- Portability: Receive your data in a structured, machine-readable format
- Restriction: Ask us to limit how we process your data
- Object: Object to processing we carry out on the basis of our legitimate interests
- Withdraw Consent: Withdraw consent for any processing that relies on it
- Object to Automated Decisions: Object to decisions made about you by automated means
- No Penalty: We will not degrade your service or charge you more for exercising any of these rights
Raising a complaint
- You can complain to us directly at any time, at [email protected] or [email protected]
- You may lodge a complaint with Kenya's Office of the Data Protection Commissioner, our home regulator, at www.odpc.go.ke
- If you are outside Kenya, you may also be able to raise a complaint with the data protection authority where you live
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within the timeframes required by applicable law (typically 30 days).
7. Analytics and Monitoring Technologies
We use third-party analytics and monitoring tools to understand how the Service is used and to keep it reliable:
- Product Analytics: In both our mobile app and our web app we use a third-party product-analytics tool to understand which features and screens are used, how people move through the Service, and where they encounter errors. In the mobile app this relies on app and device identifiers; in the web app it uses first-party cookies and browser storage. Events are associated with your user account identifier and with your business account, so that we can measure how a business uses the Service rather than only how individual people do. This provider stores data in the European Union.
- Session Replay (Web): Our web app records a reconstruction of your interactions with the interface — pages visited, clicks and navigation — so we can see where the Service is confusing or broken. Text content is masked before it leaves your browser, including all form inputs and on-screen figures such as costs, prices and margins; we record how the interface was used, not the business data displayed in it.
- Crash Reporting: Our mobile app uses a third-party crash-reporting tool that automatically captures diagnostic information when the app fails, so we can diagnose and fix it.
- Error Monitoring: Our web app and backend use a third-party error-monitoring tool that records diagnostic information when something fails, so we can diagnose and fix it. Reports are associated with your user account identifier.
- Usage Counters (Our Own Servers): We keep aggregate counts on our own infrastructure of how often each feature is used by each business, by client and by role. These counts contain no user identifier and describe the business account, not the individual.
- Essential Cookies (Web): Our web app uses cookies and similar storage that are required for authentication and core functionality.
We do not collect advertising identifiers and we do not use this data for advertising. You can limit some collection through your device settings; note that disabling essential cookies or storage may impact Service functionality.
8. AI Processing
Two features in the Service send data to a third-party AI provider. Nothing else in the Service does.
- Invoice scanning: when you photograph a supplier invoice or delivery note, the image is sent to our AI provider to read the line items. The image may contain information about people, such as a driver's name or a signature, so we treat it accordingly.
- AI insights: when you open an insight, summary figures such as inventory, variance and cost totals are sent to our AI provider to produce the written explanation.
We do not send your account credentials, your team's contact details, or your customers' details to our AI provider. Our provider processes this data on our instructions under a data processing agreement and does not use it to train their models.
You can turn this off. An account owner can disable both features for the whole restaurant at any time, under Settings, Business Settings, AI Features. With AI processing off, invoice scanning is unavailable and insights fall back to figures calculated on our own servers. Everything else in the Service is unaffected, and no further data is sent to our AI provider for these purposes.
Because invoices you upload may contain information about people at your suppliers, you are the controller of that information and we process it on your behalf. Our Security and Trust page explains how to request our data processing agreement.
9. Children's Privacy
Our Service is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete such information promptly.
If you believe a child has provided us with personal information, please contact us immediately at [email protected].
10. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, including countries that may have different data protection standards.
Where data crosses a border, these safeguards apply:
- Every provider that hosts or processes data on our behalf does so under a written data processing agreement that restricts them to acting on our instructions
- We follow the cross-border transfer requirements of the Kenya Data Protection Act 2019, and we record for each provider the country in which the receiving entity is established
- Data is encrypted in transit to and between our providers
We will tell you which providers hold data outside Kenya, and where, on request. Email [email protected].
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:
- Posting the updated policy in the app with a new "Last updated" date
- Sending an email notification to your registered email address
- Displaying an in-app notification
Material changes will take effect 30 days after notification. Your continued use of the Service after the effective date constitutes acceptance of the updated Privacy Policy. If you do not agree to the changes, you must stop using the Service and may request account deletion.
12. Data Protection Officer
For users in jurisdictions that require a Data Protection Officer (DPO), you may contact our DPO regarding any questions or concerns about our data practices:
Email: [email protected]
13. Contact Us
If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have concerns about our data practices, please contact us:
harakacount Ltd (Reg. PVT-8Z1ZRWD2)
Vihiga Rd, Kileleshwa, Nairobi, Nairobi County, 00100, Kenya
Email: [email protected]
Data Protection Inquiries: [email protected]
Website: www.harakacount.com
If you would rather raise something with a regulator:
- Our home regulator is Kenya's Office of the Data Protection Commissioner (www.odpc.go.ke)
- If you are outside Kenya, you may also be able to contact the data protection authority where you live
We will respond to all requests within the timeframes required by applicable law.