Privacy Policy

Last updated: 17 July 2026

1. Who we are and how to reach us

Wahy is a “bookable website in minutes” service for Kenyan service businesses — lash studios, barbers, nail salons and similar. Each business (a “tenant”) gets a public booking website and an admin dashboard on its own subdomain of wahylabs.com.

This service is operated by Wahy Labs(“Wahy”, “we”, “us”, “our”), based in Nairobi, Kenya.

We follow Kenya’s Data Protection Act, 2019 and the regulations made under it. Because your data is stored and processed in the European Union (see Section 6), it is also handled by providers who are themselves subject to the EU General Data Protection Regulation (GDPR), and we rely on that equivalent level of protection.

2. The two kinds of relationship — please read this first

Wahy is a platform used by many independent businesses. Your relationship with us depends on who you are:

  • If you are a business using Wahy (a tenant admin) — for your own account (your login, name, email, billing), Wahy is the “data controller”: we decide how that information is used.
  • If you are a customer booking with a business that uses Wahy (for example, you booked a lash appointment with a studio) — the business you booked with is the data controller of your booking information, and Wahy acts as a “data processor”on that business’s behalf. We only handle your information to run the booking service for that business, on its instructions. For questions about how a specific business uses your data — or to exercise your rights against it — contact that business directly. We will help you reach them, and we honour deletion/export requests the business makes on your behalf.

3. Information we collect

3.1 Business owners / tenant admins (Wahy is the controller)

  • Account and identity: your name and email address.
  • Google sign-in (if you choose it): your Google profile — name, email address and profile picture.
  • Authentication: sign-in is passwordless — an email magic link or Google sign-in. We do not create or store passwords. We store a session record so you stay logged in.
  • Billing: your subscription plan, payment status, the phone number used for M-Pesa, the amount, and the M-Pesa transaction/receipt reference. We never see or store card numbers or bank credentials — M-Pesa is mobile money.
  • Content you create: your business name, city, country, gallery images, journal posts, FAQs, services and prices, Google Business URL, WhatsApp number and other site settings.

3.2 Customers of a business using Wahy (Wahy is the processor for the tenant)

  • Booking details: your name, phone number, WhatsApp number, the service, date and time, and — for a house-call — the address you provide.
  • WhatsApp messages: if the business uses our WhatsApp booking/messaging feature, we process your WhatsApp contact details, the content of messages between you and the business, and your opt-in/opt-out status.
  • Payments: if you pay through the platform, your M-Pesa phone number, the amount, and the M-Pesa receipt reference (again — no card or bank data).

3.3 Everyone (technical)

  • A session cookie to keep you signed in.
  • Cloudflare Turnstile — a privacy-friendly bot check on sign-up forms to prevent abuse.
  • Basic security logs and error diagnostics (see Section 8). We do not run advertising trackers or sell profiles.

4. Why we use your information, and our lawful basis

Under the Kenya Data Protection Act (s.30) and equivalent GDPR bases, we rely on:

  • Performance of a contract — to create and run tenant accounts, authenticate sign-in, take subscription payments via M-Pesa, and deliver the booking service.
  • Consent — for WhatsApp marketing/re-engagement messages (opt-in, with STOP/START). You can withdraw it at any time: reply STOP to opt out, START to opt back in.
  • Legitimate interests — bot-checking, security logging, error tracking and backups to keep the platform safe and reliable.
  • Legal obligation — to comply with legal, tax and regulatory duties.

5. Who we share information with (sub-processors)

We do not sell your personal data. We share it only with the service providers we need to run Wahy, each bound by its own data-processing terms to protect it and to use it only for the service it provides to us:

ProviderWhat forWhere
Google Cloud PlatformCore hosting — our database and cacheEU (Belgium)
CloudflareImage/media storage, backups, DNSEU (Western Europe)
Zoho MailSending sign-in (“magic link”) emailsProvider infrastructure
Safaricom (M-Pesa / Daraja)Processing M-Pesa payments (no card data)Kenya
Meta Platforms (WhatsApp Business)WhatsApp messaging with customersMeta infrastructure (US/global)
Google (Sign-In; future Calendar)Sign-in; optional future calendar syncGoogle infrastructure

We may also disclose information if required by law, to protect our rights or users’ safety, or as part of a business transfer (merger/acquisition), in which case we will tell you.

6. Where your data is stored, and international transfers

Please note: although Wahy, the businesses on it, and their customers are in Kenya, we store and process personal data on infrastructure located in the European Union — our database and cache run on Google Cloud servers in Belgium, and images and backups are stored on Cloudflare’s storage in Western Europe. Some WhatsApp messaging data is processed by Meta on US/global infrastructure.

This means your data is transferred outside Kenya. Kenya’s Data Protection Act (s.48) allows this where there are appropriate safeguards. Our safeguard is that the data is processed in the EU under the GDPR— a data-protection regime at least as strong as Kenya’s — by providers who are bound by their data-processing terms to protect it. We do not claim the GDPR governs Wahy itself; we rely on it as the protective standard applied by our EU providers. We do not treat your continued use of the service as your consent to this transfer — we rely on the safeguards above.

7. How long we keep your data (retention)

  • Active accounts and their content: kept while the account is active.
  • After a tenant deletes their account: a 30-day grace period (soft delete), then permanent deletion— cascading across all of that tenant’s data and media (a “hard purge”).
  • Bookings and WhatsApp messages: kept while your account is active and for a reasonable period afterward, then deleted.
  • Payment records: kept as long as tax and accounting law requires.
  • Backups: rotated on a rolling cycle; deleted data ages out of backups within that window.

8. How we protect your data

  • Tenant isolation:every business’s data is separated at the database level (PostgreSQL Row-Level Security scoped by tenant), so one business can never see another’s data.
  • Encryption: sign-in and WhatsApp access tokens are encrypted at rest; all traffic is encrypted in transit (TLS / HTTPS).
  • No passwords to steal: sign-in is passwordless (magic link / Google).
  • Error tracking with personal data scrubbed: our diagnostics remove personal data before it is recorded.
  • No system is perfectly secure, but if a breach occurs that poses a real risk to you, we will notify the Office of the Data Protection Commissioner within 72 hours and affected people where required (Kenya DPA s.43).

9. Your rights

Under the Kenya Data Protection Act (s.26) you have the right to: be informed about how your data is used; access your data; ask for correction of inaccurate data; ask for deletion; object to certain processing; and withdraw consent. We also voluntarily extend GDPR-style data export/portability.

How to exercise your rights:

  • Business owners (tenant admins): use the export/delete tools in your dashboard, or email contact@wahylabs.com.
  • Customers who booked with a business on Wahy: contact that business first — they control your booking data and we act on their instructions. You can also email us and we will route your request to them and assist.

You also have the right to complain to the Office of the Data Protection Commissioner (ODPC) in Kenya (odpc.go.ke).

10. Google user data (Sign-In and, in future, Calendar)

When you sign in with Google, we receive your name, email address and profile picture to create and secure your account. If a business later enables the optional Google Calendarintegration, Wahy would — only with that business’s explicit authorisation — create and manage booking events in that business’s calendar.

Wahy’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically: we use Google user data only to provide the sign-in and (future) calendar features you see in the product; we do not sell it, transfer it to advertisers or data brokers, or use it for advertising or credit decisions; and no human reads it except with your explicit consent, for security, or where the law requires. We request the minimumGoogle permissions needed. You can revoke Wahy’s access at any time in your Google Account settings.

11. Cookies

We keep cookies minimal:

  • A strictly necessary session cookie to keep you signed in.
  • Cloudflare Turnstile for bot protection on sign-up.

We do not use advertising cookies or cross-site tracking.

12. Children

Wahy is a business tool and its booking services are intended for adults. It is not directed at children, and we do not knowingly collect data from anyone under 18(the age of majority in Kenya). If you believe a child’s data has been collected, contact us and we will delete it.

13. Changes to this policy

We may update this policy as the service or the law changes. We will change the “Last updated” date above and, for material changes, take reasonable steps to notify tenants (e.g. by email or an in-app notice).

14. Contact

Questions or requests: contact@wahylabs.com. To complain to a regulator: the Office of the Data Protection Commissioner, Kenya — odpc.go.ke.


See also our Terms of Service.