Information
Privacy policy.
Short, plain, and honest. We collect the minimum we need to confirm a booking, send a confirmation email and reply when you ask us something. We don't run advertising, we don't sell your data, and we don't use third-party trackers.
Effective 2026-06-06
Who we are
Roisam Diani Retreat is a 16-unit boutique retreat in Ukunda, Kwale County, Kenya. This privacy policy covers personal data we collect through roisamretreat.co.ke and our reservation systems. If you have a question that this page doesn't cover, email booking@roisamretreat.co.ke.
What we collect
The only personal data we hold falls into three buckets:
- Booking forms. Your name, email, phone, number of guests, requested dates, optional dietary notes and arrival ETA. This is the minimum we need to confirm a stay and meet you at the door.
- Contact form. Name, email, optional phone, and the message itself.
- Admin magic-link logins. The owner's email address and a one-time login token — used only to access the booking admin. No password is stored.
We do not store credit-card or M-Pesa PIN details. Payments are made directly from your M-Pesa / Vooma app to our Paybill; we only see the transaction confirmation pushed to our server.
Where it goes
We use a small number of trusted third-party processors:
- Neon Postgres hosts the booking and inquiry database — region EU/West.
- Resend sends transactional email (booking confirmations, balance reminders, magic-link logins). They are a US-based email delivery provider with a data-processing agreement.
- Cloudflare runs the bot-protection challenge on our public forms (Turnstile). The challenge is cookieless.
- Cloudinary hosts and serves the photos used on the site. They do not receive any personal data from you.
- Plausible gives us aggregate visitor counts (cookieless, no personal identifiers, no cross-site tracking).
- KCB Buni / Vooma processes M-Pesa Paybill payments. They receive the transaction details (amount, your phone, your name as Safaricom holds it). We never see your PIN.
We do not use any third-party advertising networks, retargeting pixels, or social-media trackers.
How long we keep it
- Bookings & payment records: 7 years from the date of stay. This is the retention period required by the Kenya Revenue Authority for tax documentation; we are obligated by law.
- Contact inquiries: 2 years from the date you wrote in, then deleted.
- Email logs: Resend retains delivery logs for 30 days; we hold no copy beyond that.
- Bot-protection challenges: Cloudflare retains challenge metadata for ~7 days.
Your rights
Under the Kenya Data Protection Act (2019), you have the right to:
- access the personal data we hold about you,
- correct anything that's wrong,
- ask for deletion — within the limits of our tax-record retention obligation,
- object to specific processing.
To exercise any of these, email booking@roisamretreat.co.ke from the email address on the booking. We aim to respond within seven working days.
Cookies & analytics
We use a single cookie: auth_session — set only after the owner logs into the admin. There is no public-facing cookie and no consent banner because we don't run a third-party tracker that requires one.
Our analytics tool, Plausible, is fully cookieless. It counts pageviews using a daily-rotating server-side hash that can't be used to identify or re-identify visitors.
Changes to this policy
If we materially change how we handle your data, we'll update the effective date at the top of this page and — for active bookings — email registered guests directly. The previous version remains available on request for audit.
Questions about your data?
Email us — we reply in person.