Privacy Policy
Absolute transparency on how we collect, store, and protect your corporate and personal data.
1. Introduction and Compliance
Sherehe Events Limited ("we", "our", "us") respects your privacy and is legally committed to protecting your personal data. This privacy policy complies with the rigorous standards set forth by the Kenya Data Protection Act, 2019 (DPA) and outlines how we handle data collected through our website, during physical consultations, and via our WhatsApp API integration.
2. The Data We Collect
To execute highly complex logistical events, we must collect specific, accurate data. This includes:
- Identity Data: First name, last name, and corporate entity name (if booking on behalf of an organization).
- Contact Data: Billing addresses, delivery locations, email addresses, and active telephone/WhatsApp numbers for on-site coordination.
- Financial Data: M-Pesa phone numbers used for till payments, bank account details for refunds, and invoicing history. (Note: We do not store credit card numbers).
- Logistical Data: Private venue addresses, geolocation pins, guest counts, and event specific timelines.
- Technical Data: IP addresses, browser types, and operating systems collected anonymously via standard web analytics.
3. Purpose of Data Processing
We process your data strictly under the legal basis of "Contractual Necessity" and "Legitimate Interests". Specifically:
- To register you as a new client and issue legally binding quotations.
- To calculate accurate transport logistics and surcharges using your venue geolocation.
- To dispatch 3-10 ton trucks and coordinate our setup crews to your private residence or venue securely.
- To process payments, issue KRA-compliant ETR receipts, and rapidly refund damage deposits.
- To notify you of any emergency changes to delivery schedules due to traffic or weather.
4. Data Sharing & Third Parties
Sherehe Events operates a strict zero-sale policy regarding your data. We only share necessary data with vetted third parties essential for event execution:
- Logistics Contractors: Third-party truck drivers receive ONLY the venue pin and a designated contact number for delivery day execution. They do not receive invoicing data.
- Financial Gateways: Safaricom PLC (for M-Pesa API integration) and our banking partners to clear payments.
- Government Authorities: Kenya Revenue Authority (KRA) for mandatory tax compliance on invoicing.
5. Data Retention Limits
We do not hold data indefinitely. Our retention policies are mathematically tied to Kenyan law:
- Financial Records: Invoices, contracts, and MPESA logs are retained for seven (7) years as mandated by Kenyan corporate tax laws (KRA).
- Logistical Data: Private venue addresses and event details are wiped from our active logistics dashboard thirty (30) days post-event, unless you opt-in to become a recurring corporate client.
6. Security & Breach Protocols
We have implemented heavy physical and digital security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorized way. In the highly unlikely event of a suspected data breach, we adhere strictly to the DPA requirement of notifying the Office of the Data Protection Commissioner (ODPC) and all affected clients within 72 hours of the breach discovery.
7. Your Legal Rights (DPA 2019)
Under the DPA 2019, you retain full control over your data. You have the explicit right to:
- Request Access: Obtain a full export of all personal data we hold on you.
- Request Correction: Demand immediate correction of inaccurate venue or billing data.
- Request Erasure: Demand the deletion of your data (subject to our overriding legal tax retention obligations for 7 years).
To exercise these rights, please email our appointed Data Protection Officer at legal@shereheevents.co.ke. We aim to respond to all legitimate requests within 14 working days.
8. Cookies, Web Tracking & Advertising
8.1 Essential Cookies
We use essential session cookies that are strictly necessary for the site to function. These include: maintaining your quote / Event List across pages, CSRF protection on our enquiry form, and remembering your privacy preference (the sh_consent cookie). You cannot opt out of essential cookies without affecting core site functionality.
8.2 Advertising & Analytics — your consent required
With your permission, we use the following advertising and analytics tools. None of these activate until you have given explicit consent on the privacy notice that appears after you have engaged with the site.
- Google Analytics 4 (Google LLC, USA) — cookies
_ga,_ga_*— aggregate traffic analysis: which pages are visited, how users navigate. - Google Ads conversion tracking (Google LLC, USA) — cookies
_gcl_aw,_gcl_dc— measures whether a Google Ad click resulted in an enquiry. - Meta Pixel (Meta Platforms, Inc., USA) — cookies
_fbp,_fbc— tracks pages viewed and actions taken after clicking a Meta (Facebook / Instagram) ad; powers retargeting audiences. - Meta Conversions API (Meta Platforms, Inc., USA) — server-to-server, no cookies — sends enquiry and booking conversion events directly from our server to Meta, improving attribution accuracy where browser cookies are blocked.
8.3 Hashed personal data sent to Meta
If you submit an enquiry and tick the advertising consent checkbox on the enquiry form, we send a cryptographically hashed (SHA-256) version of your email address and/or phone number to Meta via their Conversions API. This is called “advanced matching” and helps Meta confirm whether your enquiry was influenced by a Sherehe ad, even when browser cookies are blocked.
What “hashed” means: Before sending, your email or phone is converted to a fixed-length string using a one-way mathematical function. This transformation cannot be reversed. Meta uses the hash only to match it against their own hashed records for attribution, and may not use it for any other purpose under their data processing terms.
Legal basis: Explicit consent (Kenya Data Protection Act 2019, §43). You may withdraw this consent at any time by contacting us — withdrawal does not affect any processing already carried out, and does not affect your booking or pricing in any way.
8.4 International data transfers
Google LLC and Meta Platforms, Inc. are based in the United States. Sending data to these services constitutes an international transfer under the Kenya Data Protection Act 2019. Both providers operate under recognised data transfer safeguards. You can review their policies: Google Privacy Policy · Meta Privacy Policy.
8.5 Managing your consent
You can withdraw advertising consent at any time by clicking the control below, or by clearing your browser cookies (which removes the sh_consent preference — you will be asked again on your next visit), or by contacting us to exclude your record from future advertising sends. Withdrawing consent does not affect any site functionality — all features work with essential cookies only.
9. Event Photography & Marketing Imagery
Our crew may photograph or film equipment and completed setups at your event, typically before guests arrive, so that we can show real work rather than stock imagery on our website, catalogues and social media.
We do not photograph your guests as the subject of an image, and we do not identify you, your family or your company by name in any marketing material without asking you first. Where an image would show identifiable people, we treat it as personal data under the Data Protection Act 2019 and seek consent before publishing it.
You can opt out. Tell us at any point — when you book, on the day, or after the event — and we will not photograph your setup, or we will remove images already published. There is no charge for this and it will not affect your booking or your pricing in any way. Requests go to our team or to the number on our contact page.
Photography carried out by your own photographer, your guests or a third-party supplier is outside our control and is not covered by this section. The equivalent hire-contract wording is set out in our booking terms.