This policy explains what personal data we collect, why we collect it, who we share it with, and the control you have over it.
1. Introduction
EveryFinder ("we", "us") runs the EveryFinder app, a marketplace for events, shops and products. This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the choices you have.
It applies to everyone who uses the Platform: buyers, ticket holders, event organizers and shop owners. It forms part of our Terms of Service.
By using the Platform you agree to this policy. If you do not agree with it, please stop using the Platform.
2. Information We Collect
Information you give us:
Account details: your name, email address, profile picture and the campus you select.
Your phone number, which we use for payments, delivery and ticket verification.
Delivery addresses, including a label, the recipient name and phone number, and — only if you choose to use your device location — the coordinates we use to fill the address in for you to review.
Business details if you open a shop: shop name, handle, logo, category, descriptions, contact methods, location, opening hours, delivery and pickup settings, and accepted payment methods.
Event details if you publish an event: title, description, poster, category, venue, date and time, ticket types, and the payout number, till or paybill with the account name.
Product listings: titles, descriptions, prices, stock, condition, attributes and images.
The buyer name and phone number you enter for each ticket at checkout.
Reviews and ratings you write, and any message or attachment you send our support team.
Information we collect automatically:
Your device push notification token and platform (iOS or Android), so we can send you order, ticket and event notifications.
Basic usage signals such as event view counts, and which orders, tickets, shops and listings belong to your account.
Technical and security logs with timestamps, and rate-limiting records tied to your account, which we use to keep the Platform available and to stop abuse.
Information we receive from others:
From Google, if you sign in with Google: your name, email address and profile picture, according to your Google account settings.
From our payment partner and M-Pesa: the payment result, the amount, the receipt number and the paying phone number.
We never receive or store full card numbers, your M-Pesa PIN, or your Google password.
3. How We Use Your Data
We use your data to:
Create and secure your account and keep you signed in.
Show you listings, and tailor what appears on your home screen to the campus you selected.
Take payments, apply deposits, calculate and deduct commission, and pay out organizer balances.
Issue tickets and their QR codes, and let organizers scan and verify them at the door.
Fulfil orders, which means passing the delivery details you entered to the shop you ordered from.
Send you transactional messages: order status, ticket confirmations, event approvals, payment results and important account notices.
Provide support, investigate payment issues, and resolve disputes between buyers, shops and organizers.
Detect and prevent fraud and abuse, and enforce our Terms of Service.
Understand how the Platform is used so we can fix problems and improve it.
Meet our legal, tax and accounting obligations.
We do not sell your personal data, and we do not share it with third parties for their own advertising.
4. Data Sharing
We share only what is needed, and only with:
Shop owners, when you place an order with them: your name, phone number, the items ordered, and your delivery address or your pickup choice.
Event organizers, when you buy a ticket: the ticket holder name and phone number you entered, so they can verify entry.
Other users, where you chose to publish it: your shop or event profile, the contact methods you enabled, your listings, and reviews you write.
Service providers who run parts of the Platform for us: Supabase for the database, authentication and server functions, Firebase Cloud Storage for images you upload, Google for sign-in, Expo for push notifications, our email provider for notifications, and Safaricom M-Pesa through our payments partner.
Authorities or advisers, where we are legally required to disclose, or where we need to establish, exercise or defend a legal claim.
A buyer or successor, if the business is ever sold, merged or reorganised. We will tell you before that happens.
Some of these providers process data outside Kenya. Where that happens we rely on their contractual and technical safeguards to keep your data protected to the same standard.
5. Data Security
We protect your data with measures including:
Encryption in transit over HTTPS/TLS, and encryption at rest in our database and file storage.
Row-level security rules on the database, so your orders, tickets, addresses and shop data are only readable by you and by the parties who need them.
Money-related operations — payments, commission, balances and withdrawals — run on the server under privileged functions, never in the app.
Ticket QR codes are cryptographically signed so they cannot be forged or reused.
Sign-in is handled by our authentication provider and by Google, so we never see your password.
Internal access is limited to the people who need it to operate and support the Platform.
No system is perfectly secure. Keep your device and account details safe, and tell us immediately if you think someone has used your account without permission.
6. Your Rights
Depending on where you live, you have the right to:
Ask for a copy of the personal data we hold about you.
Have inaccurate or incomplete data corrected — most of it you can edit yourself in the app.
Ask us to delete your data and close your account, subject to records we are required to keep.
Object to, or ask us to restrict, certain uses of your data.
Withdraw a consent you gave us, for example by turning off push notifications or location access in your device settings.
Receive the data you gave us in a portable format, or ask us to transfer it.
Complain to a data protection authority. In Kenya, that is the Office of the Data Protection Commissioner.
To exercise any of these, contact us using the details at the bottom of this page. We will respond within a reasonable time and may need to verify your identity first.
7. Data Retention
We keep data only as long as we need it:
Account and profile data: while your account is open, and for a short period afterwards in case you come back or a dispute is raised.
Orders, ticket purchases, payments, commission and payout records: for as long as tax, accounting and anti-fraud rules require, normally at least seven years.
Listings, shops and reviews you delete are removed from the Platform, though copies may persist in backups for a limited period before they are overwritten.
Push notification tokens: until you sign out, uninstall the app, or the token expires.
Guest checkout sessions and unpaid reservations: they expire and are cleared automatically.
Security and rate-limiting logs: only as long as needed to protect the Platform.
When we no longer need data, we delete it or anonymise it so that it can no longer identify you.
8. Changes to This Policy
We may update this policy as the Platform changes or as the law requires. The current version always lives here in the app, and the date at the top of this page tells you when it last changed.
If a change materially affects how we use your data, we will notify you in the app, by email or by push notification before it takes effect.
Continuing to use the Platform after a change takes effect means you accept the updated policy.
9. Contact Us
For any question about this policy, or to make a request about your personal data, contact us here: