Hotelz
Your privacy, explained clearly.
We collect only what we need to run the service. We don't sell your data. We don't use it for ads. Here's exactly what we do.
Last updated: October 2026
Hotelz is a food-ordering and hotel-management platform operated in Kenya. We act as a data processor on behalf of hotels (who are the data controllers for their guest orders) and as a data controller for platform accounts we manage directly.
This distinction matters under Kenya's Data Protection Act 2019. Hotels that use Hotelz are responsible for how they instruct us to process their guest data. We are responsible for how we operate the platform itself.
If you're a guest ordering food
Your nameOptional — only if you type it when placing an order
Email & passwordOnly if you create an optional account
Order detailsWhat you ordered, your table, the time, and the total amount
Push notification tokenA device identifier so we can notify you when your food is ready
Food preferencesTags like "Chicken" or "Vegetarian" — only if you set them in the app
If you're a hotel manager or staff
Name and PINUsed to authenticate you — PINs are stored as a bcrypt hash, never plain text
Push notification tokenSo the app can alert you to new orders when the screen is off
Hotel detailsName, city, address, phone, email, menu items, and M-Pesa payment details you add
Subscription recordsM-Pesa payment confirmation references and subscription status — we never store your M-Pesa PIN
To run the ordering serviceOrder details are needed to display them to kitchen staff and track their status
To send notificationsPush tokens are used solely to deliver order status updates
To personalise suggestionsPreferences you set are used to show relevant menu items — nothing is inferred without your input
To manage hotel subscriptionsPayment records let us activate and renew hotel access
AnalyticsAggregated order data helps hotels understand peak hours and popular items — not tied to individuals
We do not sell your data. We do not use it for advertising. We do not build profiles for third parties.
Firebase (Google)
Push notifications. Your device token is stored with Google. Data may be processed outside Kenya.
Firebase Privacy →
Safaricom / M-Pesa
Hotel subscription payments. We receive a confirmation reference only — no PIN or card data.
Cloud hosting provider
Our database and API server run on a cloud VPS. Data is stored within Kenya where the provider allows.
The hotel you're visiting
Your order (items, table, name if provided) is shared with kitchen staff so your food can be prepared. The hotel is the data controller for this data.
Some data (push notification tokens sent to Firebase) may be transferred outside Kenya to Google's servers. If you have concerns, you can disable notifications in your phone settings.
In transitAll communication uses HTTPS/TLS — data is encrypted as it travels
Passwords and PINsStored as bcrypt hashes — we cannot recover your plain-text PIN
AuthenticationEvery API call is authenticated with a signed JWT — your session cannot be forged
DatabaseRuns on a private server, not publicly accessible. Encryption at rest depends on the hosting provider's configuration.
Guest orders90 days from placement, then permanently deleted
Guest accountsUntil you delete your account
Hotel and staff dataFor the duration of the active subscription, plus 30 days after cancellation
Push notification tokensRefreshed automatically. Stale tokens are removed when a new one is registered.
Payment recordsM-Pesa transaction references are kept for 7 years as required by Kenyan accounting and tax law
When you delete your account, we delete your profile, preferences, and order history. M-Pesa transaction references and subscription records kept for legal/accounting reasons are retained for 7 years. Backups may retain deleted data for up to 30 additional days.
Hotelz is a restaurant ordering tool used in public venues. Children may use the app to place orders at a table, typically under the supervision of a parent or guardian. We do not create child-specific profiles and do not knowingly collect data from unaccompanied children under 13 for account registration.
If you believe a child under 13 has created an account without parental consent, contact us at [email protected] and we will delete it promptly.
The Data Protection Act 2019 gives you the following rights:
AccessSee a copy of all personal data we hold about you
CorrectionFix inaccurate or incomplete data
DeletionDelete your account and personal data (subject to legal retention obligations)
ObjectionObject to processing where we rely on legitimate interest
RestrictionLimit how we use your data while a dispute is resolved
PortabilityReceive your data in a machine-readable format
How to submit a request: Email
[email protected] with subject "Data Request". We respond within 21 days (we aim for 7 for straightforward requests).
To complain to the regulator: Contact Kenya's Office of the Data Protection Commissioner (ODPC) at
odpc.go.ke.
When we make material changes, we will notify hotel managers through the app and update the date at the top of this page. Where the law requires your consent for a specific processing activity, we will obtain it directly. Continued use of the service alone does not constitute consent to every type of data processing.
Questions, requests, or concerns about your privacy: