ODIT PRIVACY POLICY
Operated by Wiva Technologies, Nairobi, Kenya
Last updated: 12th August 2026
1. INTRODUCTION
This Privacy Policy explains how Odit ("Odit", "we", "us", or "our") collects, uses, stores and protects your Personal Data when you use our Platform, which consists of the Odit Android application and the website at odit.site. This Policy applies to both Merchants and Consumers, and is incorporated by reference into our Terms and Conditions of Use.
By creating an Account or otherwise using the Platform, you agree to the collection and use of information as described in this Policy. If you do not agree, please do not use the Platform.
We process Personal Data in accordance with Kenya's Data Protection Act, 2019, and its subordinate legislation. If Odit expands to other jurisdictions, this Policy will be updated to reflect the laws applicable there.
2. WHO WE ARE
Odit is operated by Wiva Technologies, based in Kenya. For the purposes of the Data Protection Act, we act as the data controller for Personal Data processed through the Platform, and in certain cases, such as payments, we act as a conduit between you and our processors.
3. WHAT WE COLLECT AND WHY
3.1 Merchants
If you operate from a fixed physical shop, we collect and store the precise location of that shop so Consumers can find you and get directions. If you are a service provider without a fixed shop, we do not collect a precise address; instead, we collect a general operating radius. We store Merchant location data specifically to surface your business to nearby Consumers, this is the primary way location data is used to power discovery on the Platform.
We collect your business details, including listed products or services, pricing, and contact information (an email address or phone number). Your contact information is displayed publicly to Consumers so they can reach you; you may remove it from your profile at any time, and once removed it is no longer visible to others.
We collect your payment identifier only to trigger a payment prompt through Paystack, our payment processor, as described in Section 5.
3.2 Consumers
We never store your live or current device location on our servers. If you allow the app to access your location, it is used only in the moment, to query our systems and return nearby Merchants and approximate distances, and is discarded immediately afterward. We do not use your location, whether live or stored, for advertising, profiling, or any purpose beyond that single search request. If you prefer not to share your location this way, you can still use the in-app map to search manually, though results will not include distance information.
If you post a request for a product or service, we ask for an approximate locality rather than an exact address. This value may or may not reflect your actual current location, we treat it strictly as a general proximity indicator, and store it only to surface your request to nearby Merchants. We do not use this information for any other purpose, and we do not share it with third parties. Each request retains its own locality independently and is deleted when you delete the request.
To be clear: the only location data we retain in the ordinary course of operating the Platform belongs to Merchants (Section 3.1). Consumer location is either used transiently and never stored, or stored narrowly for the single purpose of a specific request you chose to post.
3.3 Everyone
We collect basic account information at signup, such as your name and login credentials, managed through Firebase Authentication. We collect device and usage data that helps us operate and secure the Platform. We store images and media you upload, such as product photos, through our storage providers, Supabase and Amazon Web Services, some media may be hosted on either provider.
4. THIRD-PARTY LOCATION AND MAPPING SERVICES
The Platform uses third-party mapping and places services, including Google Places API and Mapbox, to power search and map functionality. These providers may independently request or access device location as part of their own operation, under their own respective privacy policies and terms of service. This access is separate from, and not controlled by, how Odit itself collects, uses or stores location data as described in Section 3. We encourage you to review the privacy policies of Google and Mapbox directly if you have questions about how they handle location data.
5. PAYMENTS
We do not store your M-Pesa number or card details on our servers. When you make a payment, your number is passed to our server only long enough to trigger an STK push request through Paystack, our payment processor. Paystack processes the transaction and holds your payment data under its own privacy policy. We do not retain access to your payment number after the request is sent.
6. HOW WE USE YOUR DATA
We use the data described above to operate the core functions of the Platform: connecting Merchants with Consumers, processing payments, calculating approximate distances, and displaying relevant listings.
We also use aggregated, anonymized Merchant data for internal evaluation and research, including improving fraud and theft prevention tools and personalizing in-app product recommendations. Anonymization means we strip identifying information before this data is used this way, and we do not use it to identify a specific Merchant. We do not sell Merchant data, or any Personal Data, to any third party for any purpose. If this ever changes, we will update this Policy and notify you before the change takes effect.
7. THIRD PARTIES WE WORK WITH
We rely on the following third-party providers to operate Odit:
- Paystack, for processing payments.
- Supabase and Amazon Web Services, for storing images and media.
- Firebase, for account authentication.
- Google Places API and Mapbox, for search and mapping functionality.
Each provider processes data under its own privacy policy and terms of service while that data is within their systems. We work only with providers that demonstrate reasonable security and reliability, and while we take appropriate measures to protect your data on our own systems, we cannot control or be held responsible for the independent practices of these third parties, except as required by law.
8. DATA RETENTION
Merchant location and contact information are retained until removed by the Merchant. Consumer request locality data is retained until the associated request is deleted by the Consumer. We do not store live Consumer location at any point, so there is nothing to retain in that category. Account records and transaction history are retained for as long as your account is active, and for a reasonable period afterward as required for legal, accounting, or dispute resolution purposes.
9. YOUR RIGHTS UNDER THE DATA PROTECTION ACT
As a data subject under Kenyan law, you have the right to:
- Be informed about our processing practices;
- Access the Personal Data we hold about you;
- Request correction of inaccurate Personal Data;
- Request deletion of your Personal Data where we have no lawful basis to retain it;
- Object to processing you disagree with;
- Request portability of your Personal Data to the extent provided by law; and
- Lodge a complaint with the Office of the Data Protection Commissioner if you believe we have mishandled your data.
To exercise any of these rights, contact us using the details in Section 13. We will respond within a reasonable timeframe as required by law.
10. CROSS-BORDER DATA TRANSFERS
Some of our service providers, including Paystack, Supabase, Amazon Web Services, Firebase, Google, and Mapbox, may process or store data outside Kenya. Where this occurs, we rely on these providers maintaining adequate data protection safeguards consistent with the requirements of the Data Protection Act. This section will be updated if Odit expands to new markets.
11. SECURITY
We take reasonable technical and organizational measures to protect your data, including access controls and secure authentication. No system is perfectly secure, and we cannot guarantee absolute protection against every possible breach, but we take this seriously and will notify affected users and the relevant authorities of any breach likely to affect your rights, as required by law.
12. CHILDREN
The Platform is not intended for use by anyone under the age of 13, and we do not knowingly collect Personal Data from children below that age. Consumers between 13 and 18 may browse with the involvement of a parent or guardian, consistent with our Terms and Conditions. If you believe we have inadvertently collected data from a child, contact us using the details in Section 13 and we will delete it.
13. CONTACT US
If you have questions about this Policy or wish to exercise your data protection rights, contact us at:
Email: techwiva@gmail.com
Phone: +254 738 376082
You may also contact the Office of the Data Protection Commissioner, Kenya, directly with any complaint.
14. CHANGES TO THIS POLICY
We may update this Policy as the Platform evolves or as the law requires. If we make material changes, we will notify you through the app or by email before the changes take effect, and we will update the "Last Updated" date above.