SalamaWay Trace
Back to home

Privacy

Privacy Policy

This Policy explains what personal data SalamaWay Trace collects, why we use it, when it is shared, how it is protected, and the choices and rights available to you.

Effective and last updated: 15 August 2026

At a glance: We use account, item, report, claim, notification, and security data to operate the lost-and-found workflow. We do not sell personal data. Finder contact details are disclosed to the claimant only after an administrator approves the claim.

1. Scope and who controls your data

This Privacy Policy applies to the SalamaWay Trace website, application, notifications, and related support or administration (the “Service”). SalamaWay Trace is the data controller for personal data processed through the Service unless a deployment-specific notice or agreement identifies another organisation as controller. In an organisation-managed deployment, that organisation may control user administration and some processing while SalamaWay Trace acts as its service provider or processor.

This Policy does not govern websites, apps, or services operated independently by third parties. Please read their privacy notices when choosing to use those services.

2. Personal data we collect

Account and identity data

  • name, email address, phone number, account role, department, and account timestamps;
  • a securely hashed password where password sign-in is used;
  • Google account identifier, verified email, and name where you choose Google sign-in; and
  • passkey name, public credential material, authenticator information, creation date, and last-used date. The Service does not receive your fingerprint, face scan, device PIN, or private passkey key.

Item and report data

  • item category, serial or identifying number, descriptive name, and optional image;
  • whether an item was lost or found, the location and date, and report status;
  • saved item records you create to help identify property later; and
  • report and item creation or update timestamps.

Claim and recovery data

  • the linked lost and found reports, claimant identity, match indicators, claim status, and review timestamps;
  • information or evidence you provide in connection with ownership verification; and
  • after approval, finder contact details made available to the claimant to coordinate recovery.

Technical, usage, and security data

  • IP address, device or browser information, user agent, session data, authentication events, and activity logs;
  • security and audit events such as registration, login, logout, profile updates, password changes, passkey activity, and administrator actions;
  • access tokens stored in your browser, notification status, and preference or interface state; and
  • reCAPTCHA token, risk score, action, hostname, and error information used to distinguish genuine requests from abuse.

Communications

We process in-app notifications, email delivery details, support requests, complaint correspondence, and any information you include when communicating with us or an administrator.

3. Where the data comes from

Most data comes directly from you when you register, sign in, save an item, file a report, upload an image, make a claim, manage passkeys, or contact us. We also generate operational data through your use of the Service, receive identity data from Google if you choose Google sign-in, receive anti-abuse results from Google reCAPTCHA, and may receive claim-related information from finders, claimants, administrators, or authorised authorities.

4. How we use personal data

We process personal data to:

  • create and secure accounts, authenticate users, maintain sessions, and administer roles and permissions;
  • store item records and lost or found reports;
  • compare reports, calculate potential matches, prevent duplicate claims, and notify relevant users;
  • allow authorised administrators to review claims and disclose contact details after approval;
  • send transactional email and in-app notices about the Service, security, matches, and claim outcomes;
  • provide support, respond to requests, and maintain accurate records;
  • detect, prevent, investigate, and document spam, fraud, abuse, unauthorised access, and other security incidents;
  • debug, maintain, monitor, and improve the reliability and usability of the Service; and
  • comply with law, court orders, lawful government requests, and establish, exercise, or defend legal claims.

Depending on the context and applicable law, we rely on one or more of the following:

  • performance of a contract, to provide the account, reporting, matching, claim, and recovery features you request;
  • legitimate interests, to secure, administer, troubleshoot, and improve the Service, prevent misuse, and facilitate the safe return of property, after considering your rights;
  • consent, where you choose optional functionality or where consent is otherwise required; you may withdraw consent without affecting earlier lawful processing;
  • legal obligations, including record preservation, lawful disclosure, and data-protection compliance; and
  • protection of vital interests or public-interest grounds in exceptional safety or law-enforcement circumstances permitted by law.

Providing required account and report fields is voluntary, but we cannot create your account or process the relevant report or claim without them. Optional fields, including an item image, location, and date, may improve matching but are not always required.

6. Automated matching and human review

The Service generates possible matches between lost and found reports. It first limits comparisons by item category. An exact normalised serial-number match may result in a 100% score; otherwise, descriptive names are compared and candidates meeting an internal similarity threshold may be shown. Reports can be inaccurate and the matching method can produce false positives or miss a genuine match.

The match score does not by itself approve or reject a claim and does not determine legal ownership. A user chooses whether to submit a claim, and an authorised administrator makes the operational approval or rejection decision. You may contact us or your administrator to question a result, correct report data, or request human review.

7. When we share personal data

We may share data only as reasonably needed with:

  • claim participants: relevant item and report information may be shown to a potential claimant; after approval, the finder’s name, email, and phone may be disclosed to the claimant for recovery coordination;
  • authorised administrators: depending on assigned permissions, administrators may access member details, reports, item images, claims, departments, notifications, and activity logs including IP and device data;
  • service providers: hosting, storage, email, security, maintenance, and other vendors processing data on our instructions and subject to appropriate obligations;
  • Google: where you use Google sign-in or when reCAPTCHA operates on login and registration requests, under Google’s applicable terms and privacy policy;
  • professional advisers and transaction parties: where reasonably necessary for legal, audit, insurance, financing, merger, reorganisation, or sale purposes, subject to confidentiality and law; and
  • authorities or affected persons: where disclosure is required by law or reasonably necessary to protect rights, safety, property, users, or the Service, investigate fraud or theft, or respond to lawful process.

We do not sell personal data or share it for third-party behavioural advertising.

8. Visibility of reports and images

Account details are not intended to be generally public. However, relevant report details and item images may be displayed to other authenticated users involved in matching and to authorised administrators. Uploaded item images are stored on publicly served media storage and should be treated as potentially accessible to anyone who obtains the direct image link. Do not include a face, home address, full identity document, vehicle plate, or other unnecessary personal data in an image or description.

9. International data transfers

Some service providers, including Google or hosting and email vendors, may process data outside Kenya. Where personal data is transferred internationally, we will use a lawful transfer mechanism and appropriate safeguards as required, which may include adequacy protections, contractual commitments, consent where appropriate, or another mechanism recognised by applicable law.

10. How long we retain data

We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including providing the Service, maintaining a reliable claim history, preventing fraud, resolving disputes, enforcing agreements, and meeting legal or audit obligations. Because retention depends on context:

  • account and authentication data is generally kept while the account is active and for a reasonable period after closure;
  • item, report, and claim records may remain while a report is open and afterwards where needed to document a recovery, prevent duplicate or fraudulent claims, or comply with law;
  • security, access, and activity logs are kept for a limited operational and security period; and
  • backups may retain deleted data until they are overwritten through the ordinary backup cycle.

We may anonymise data so it no longer identifies you and retain that anonymised information. A deletion request may be limited where retention is required by law, necessary for a legal claim, or needed to protect the rights and safety of others.

11. How we protect data

We use reasonable administrative, technical, and organisational safeguards, including access controls, permission-based administration, password hashing, token-based authentication, passkey support, request throttling, anti-abuse checks, audit logging, and transport security where properly deployed. No internet transmission or storage system is completely secure. You should use a strong unique password, protect your device and email account, remove unfamiliar passkeys, sign out on shared devices, and report suspected unauthorised access promptly.

12. Your choices and data-protection rights

Subject to the Data Protection Act, 2019 of Kenya and other applicable law, you may have rights to:

  • be informed about how your personal data is used;
  • request access to and a copy of personal data we hold about you;
  • correct inaccurate, incomplete, false, or misleading data;
  • object to or request restriction of certain processing;
  • request deletion where the legal conditions are met;
  • receive eligible data in a structured, commonly used, machine-readable format and request portability;
  • withdraw consent where processing relies on consent; and
  • raise a concern about automated processing and request human review.

You can update your name and phone number in your profile and manage your passkeys from the Service. Other requests, including account closure, access, objection, portability, or deletion, should be sent using the contact details below. We may need to verify your identity and may retain or withhold information where law permits or requires it. You may use an authorised representative as allowed by law.

13. Cookies, sessions, and browser storage

The Service uses a session cookie for security-sensitive browser interactions such as passkey ceremonies and request protection. It may contain or reference an identifier rather than readable profile details. Session cookies are configured with protective attributes such as HTTP-only and SameSite where applicable.

After sign-in, the application stores an access token in your browser’s local storage so you remain authenticated, and may remember your email address and passkey availability on that device. Local storage persists until it is cleared by the application, you, or the browser. Anyone with access to an unlocked browser profile may be able to use stored authentication state, so do not use remembered access on an untrusted device.

Google reCAPTCHA may set or read cookies and collect device and interaction data to assess abuse. Browser controls can block or clear cookies and storage, but doing so may prevent authentication or other Service features from working.

14. Children’s privacy

The Service is not directed to children under 18 acting independently. A child may use it only with a parent or legal guardian’s involvement. If you believe a child provided personal data without appropriate permission, contact us so we can investigate and take appropriate action. A parent or guardian may exercise the child’s rights as provided by law.

15. Changes to this Policy

We may revise this Policy as the Service, our practices, or the law changes. We will post the revised version and update the date above. Where a change is material, we will provide additional notice through the Service or registered contact information where reasonably practicable.

16. Contact and complaints

To exercise a privacy right, report a concern, or ask a question, contact:

SalamaWay Trace
Your organisation’s SalamaWay Trace administrator or the contact channel published within the Service.

Please describe your request and the account email involved, but do not send passwords, passkey credentials, or unnecessary identity documents. You also have the right to lodge a complaint with the Office of the Data Protection Commissioner of Kenya or another competent supervisory authority. We encourage you to contact us first so we can try to resolve the issue.