Back to Home
Kenya Data Protection Act (DPA 2019) Compliant

Privacy Policy & Data Protection

Effective Date: August 28, 2026 | Version 2.0

Tenant Isolation

Your workshop data is cryptographically isolated via PostgreSQL Row Level Security.

Customer PII Shield

Public QR passports and PDF links never expose customer phone numbers or private emails.

Offline Storage Safety

Local device caches in IndexedDB are sandboxed strictly to your browser domain.

1. Scope & Legal Capacity

This Privacy Policy governs the collection, processing, and protection of personal and automotive data across the GaragePulse software platform, operated by Apollos Digital Solutions (“Company”, “we”, “us”).

In accordance with the Kenya Data Protection Act, 2019 (DPA), Apollos Digital Solutions acts as a Data Controller for workshop account administration and billing, and as a Data Processor on behalf of automotive workshops for customer records and vehicle history.

2. Categories of Information Processed

  • Workshop Identity Data: Garage name, physical location, KRA PIN (optional), contact phone, and administrative owner credentials.
  • Vehicle & Operational Records: Vehicle registration plates, chassis/VIN numbers, makes, models, mileage readings, fault descriptions, and inspection photos.
  • Customer Contact Records: Customer full names and phone numbers used by the workshop to issue WhatsApp quotations and SMS pickup alerts.
  • Financial Ledgers: Workshop wallet balance, subscription deposits, daily service fees, customer invoice amounts, and M-Pesa transaction reference IDs.

3. Public Digital Passports & Police Verification

GaragePulse provides public vehicle verification passports (e.g. /portal/vehicles/[id]) and digital invoice gate passes (e.g. /portal/invoices/[id]) for vehicle resale inspection, roadworthiness verification, and police traffic checkpoints.

Privacy Guarantee: When a vehicle passport or gate pass link is opened by a third party, our servers strictly project verification fields (vehicle make, model, registration plate, clearance status) and never expose customer personal phone numbers, email addresses, or residential information to public scrapers.

4. Security Measures & Offline Caching

We employ strict technical and organizational measures to safeguard your records:

  • Multi-Tenant Isolation: Enforced at the PostgreSQL database level via Row-Level Security (RLS) policies.
  • Encryption in Transit & at Rest: All traffic is encrypted using TLS 1.3, and cloud storage buckets enforce cryptographic access policies.
  • PWA Offline Security: Temporary offline queues stored in device IndexedDB (Dexie) are origin-bound and cleared upon database synchronization.

5. Data Subject Rights (DPA Section 26)

Under the Kenya Data Protection Act, workshop owners and their customers have the right to:

  • Request a copy of all personal and vehicle records stored in their account.
  • Rectify inaccurate or obsolete vehicle specifications and contact info.
  • Request account closure and data deletion, subject to KRA statutory accounting retention rules (up to 7 years for financial ledgers).

6. Contact Data Protection Officer

For inquiries, data access requests, or compliance concerns, reach out to our Data Protection Office:

Apollos Digital Solutions — Data Protection Office
Email: privacy@garagepulse.co.ke / johnapollosolal@gmail.com
Location: Nairobi, Kenya