PRIVACY POLICY
How We Collect, Use, Share & Protect Your Personal Data
1. Introduction & Who We Are
Your privacy matters to us. This Privacy Policy explains how Kainook Travel OÜ ("Kainook", "we", "us", "our"), a private limited company registered in Tallinn, Estonia, collects, uses, shares, stores, and protects your personal data when you use our platform — including our website and mobile application (collectively, the "Platform").
Kainook operates as a marketplace connecting travellers ("Guests") with accommodation providers, vehicle rental companies, and activity operators ("Providers") primarily across Africa and internationally. In doing so, we process personal data as a data controller under applicable data protection law, including the European Union General Data Protection Regulation (GDPR) and the Estonian Personal Data Protection Act.
Our Commitment to You
- We collect only the data we genuinely need to operate the Platform.
- We never sell your personal data to third parties.
- We are transparent about how your data is used and with whom it is shared.
- We give you meaningful control over your data, including the right to access, correct, and delete it.
- We apply strong technical and organisational security measures to protect your data.
This Policy applies to all users of the Platform, including Guests, Providers, and visitors. It should be read alongside our Terms of Use. If you do not agree with this Policy, please do not use the Platform.
2. Data Controller
The data controller responsible for your personal data is:
For any data protection enquiry or to exercise your rights, please contact us at info@kainook.com. We aim to respond to all requests within 30 days.
3. What Personal Data We Collect
We collect personal data in three ways: data you provide directly, data generated through your use of the Platform, and data received from third parties.
3.1 Data You Provide Directly
| Category | Examples |
|---|---|
| Account Registration | Full name, email address, phone number, password (hashed), profile photo, preferred language and currency. |
| Booking Information | Travel dates, number of guests, special requests, guest names, nationality. |
| Payment Information | Card details (processed securely via Stripe), mobile money account details (processed via Tara), billing address. Full card numbers are never stored by Kainook. |
| Identity Verification | Government-issued ID (where required for certain Providers or age verification), date of birth. |
| Communications | Messages exchanged via in-app messaging between Guests and Providers, support tickets, feedback, reviews and ratings. |
| Provider Onboarding | Business name, registration number, address, banking details for payouts, listing information (descriptions, photos, pricing, availability). |
| Preferences & Settings | Notification preferences, saved searches, wishlist/favourites, loyalty programme (AfriPoints) activity. |
3.2 Data Generated Automatically
When you use the Platform, we automatically collect certain technical and behavioural data:
- Device and browser information (device type, operating system, browser type, screen resolution).
- IP address and approximate geolocation (country/city level, not precise GPS unless explicitly granted).
- Usage data (pages visited, search queries, filters applied, listings viewed, time spent on pages).
- Booking funnel data (steps completed, drop-off points, booking reference, confirmation status).
- Session identifiers, cookies and similar tracking technologies (see Section 10 on Cookies).
- App performance data and crash reports.
3.2a Data You Give Us About Others
When making a booking that includes other travellers — for example, booking accommodation for a family member, colleague, or group — you may provide us with personal data about those individuals. This may include their names, dates of birth, nationality, dietary or accessibility preferences, or identification information required for check-in. You are responsible for ensuring those individuals are aware their data will be shared with Kainook and that they have accepted this Privacy Policy before you provide their information to us.
3.3 Data We Receive from Third Parties
- Payment processors (Stripe, Tara): transaction status, fraud signals, payment method verification results.
- Social login providers (Google, Apple, Facebook — if you choose to sign in via these): name, email address, profile picture, unique identifier.
- Channel managers and OTAs (Airbnb, Booking.com): availability and reservation data synced via iCal integration (Providers only).
- Identity verification services: verification status and risk flags (where applicable).
- Analytics and advertising partners: aggregated behavioural data to improve the Platform.
4. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA) and where the GDPR applies, we rely on the following legal bases to process your personal data:
| Processing Activity | Legal Basis | Details |
|---|---|---|
| Account creation and management | Contract (Art. 6(1)(b)) | Necessary to provide you with a user account. |
| Processing bookings and payments | Contract (Art. 6(1)(b)) | Necessary to execute the booking you requested. |
| Fraud prevention and security | Legitimate interest (Art. 6(1)(f)) | Protecting users, Providers, and the Platform from fraud and abuse. |
| Sending booking confirmations and service communications | Contract (Art. 6(1)(b)) | Necessary for providing the service. |
| Customer support | Contract / Legitimate interest | Resolving your queries and improving service quality. |
| Marketing emails and push notifications | Consent (Art. 6(1)(a)) | Only where you have opted in. Withdraw at any time. |
| Analytics and Platform improvement | Legitimate interest (Art. 6(1)(f)) | Understanding usage patterns to improve the Platform. |
| Legal compliance (tax, anti-money laundering) | Legal obligation (Art. 6(1)(c)) | Compliance with applicable Estonian and EU law. |
| Reviews and ratings | Legitimate interest (Art. 6(1)(f)) | Maintaining Platform quality and transparency. |
| AfriPoints loyalty programme | Contract (Art. 6(1)(b)) | Administering rewards for qualifying bookings. |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and interests. You may object to processing based on legitimate interests at any time (see Section 9).
5. How We Use Your Personal Data
5.1 To Provide and Operate the Platform
- Create and manage your user account.
- Process and confirm bookings between Guests and Providers.
- Facilitate payment collection and Provider payouts (within 24 hours of Guest check-in).
- Send booking confirmations, vouchers, receipts, and itinerary updates.
- Enable in-app messaging between Guests and Providers.
- Administer the AfriPoints loyalty programme and reward eligible bookings.
5.2 To Ensure Safety, Security & Trust
- Verify user identity and prevent fraudulent or abusive activity.
- Monitor messaging for prohibited content (e.g., contact details shared to circumvent the Platform).
- Detect and investigate suspicious transactions or policy violations.
- Enforce our Terms of Use and take action against users or Providers who breach them.
- Maintain review integrity and investigate reported fake or malicious reviews.
5.3 To Improve and Personalise the Platform
- Analyse usage patterns to improve search, recommendations, and booking flows.
- Personalise search results, listing recommendations, and promotional content based on your preferences and history.
- Conduct A/B testing and product research to improve Platform features.
- Train internal models (non-identifiable, aggregated data only) to improve fraud detection and recommendations.
5.4 To Communicate with You
- Send transactional communications: booking confirmations, cancellation notices, payment receipts, check-in reminders.
- Send service-related notifications: policy updates, security alerts, account notices.
- Send marketing communications (with your consent): personalised travel recommendations, promotional offers, AfriPoints updates. You may unsubscribe at any time.
5.5 For Market Research & Service Improvement
Invite Guests and Providers to voluntarily participate in surveys, feedback programmes, and market research initiatives. We analyse aggregated and anonymised booking and search data to understand travel demand trends and improve destination coverage across Africa.
Any invitation to participate in market research will clearly describe what personal data is collected and how it will be used. Participation is always voluntary.
5.6 To Display Relevant Pricing
When displaying search results and pricing, we may use data such as your approximate location (derived from your IP address), device type, currency preference, and prior searches to display pricing in your local currency and the most relevant rates for your market. This reflects currency localisation and market availability — not individualised or discriminatory pricing targeting you personally.
5.7 To Comply with Legal Obligations
- Retain transaction records as required by Estonian tax law and applicable financial regulations.
- Respond to lawful requests from law enforcement or regulatory authorities.
- Comply with anti-money laundering (AML) and know-your-customer (KYC) requirements where applicable.
8. How Long We Keep Your Data
| Data Category | Retention Period |
|---|---|
| Account data | For the duration of your account, plus 3 years after account closure (to resolve post-closure disputes and comply with legal obligations). |
| Booking and transaction records | 7 years from the date of the transaction (required under Estonian accounting and tax law). |
| Payment data | As required by payment processor regulations; card data is never stored by Kainook beyond the transaction. |
| Communications & support tickets | 3 years from the date of the last interaction. |
| Reviews and ratings | Retained while the listing is active; may be anonymised or deleted upon request if no longer needed. |
| Marketing preferences & consent records | Until you withdraw consent, plus 3 years thereafter for compliance purposes. |
| Fraud and security logs | Up to 5 years to detect and prevent recurrent fraud. |
| Legal hold data | For the duration of any ongoing legal proceeding or regulatory investigation. |
9. Your Data Protection Rights
Depending on your location and the applicable law, you have the following rights regarding your personal data: Right of Access, Right to Rectification, Right to Erasure, Right to Restriction of Processing, Right to Data Portability, Right to Object, Right to Withdraw Consent, and Right to Lodge a Complaint with the Estonian Data Protection Inspectorate.
How to Exercise Your Rights
Submit your request to: info@kainook.com or through the Privacy Settings section of your Account. We respond within 30 days. No fees apply unless requests are manifestly unfounded or excessive.
10. Cookies & Tracking Technologies
| Cookie Type | Purpose | Can You Opt Out? |
|---|---|---|
| Strictly Necessary | Session management, authentication, security, booking flow. | No — required. |
| Functional | Remembering your language, currency, and search preferences. | Yes — via settings. |
| Analytics | Understanding how users navigate the Platform to improve it. | Yes — via settings. |
| Performance | Measuring page load speed and identifying technical issues. | Yes — via settings. |
| Marketing / Retargeting | Serving relevant travel-related advertising on third-party platforms. | Yes — withdraw consent. |
11-18. Security, Account Deletion & Other Policies
11-12. Children's Privacy & Data Security
We do not knowingly collect data from children under 18. We apply industry-standard security measures including TLS encryption in transit, encryption at rest, strict staff access controls, and PCI-DSS compliance for payment processors.
13. Privacy & Providers
Providers are independent data controllers for data they collect directly from guests. They are contractually obligated to process Guest data only for the booking, not use it for marketing without consent, and comply with data protection laws.
14-16. Third-Party Links, Accessibility & Changes
This policy doesn't apply to third-party links. We are committed to digital accessibility and providing alternatives. Changes to this Policy will be notified at least 14 days before taking effect.
17. Account Deletion Policy
You can delete your account via App Settings or by emailing info@kainook.com. Requests are processed within 30 days. Deletion is irreversible.
Data Retained after Account Deletion:
- Transaction & booking records: 7 years for tax and accounting compliance.
- Reviews and ratings: Retained anonymously with display name removed.
- Fraud logs: Up to 5 years.
- Legal hold & Dispute records: For the duration of any proceeding/investigation, or 3 years.
18. Contact & Supervisory Authority
Data Protection: info@kainook.com
General Support: support@kainook.com
Kainook Travel OÜ — Tallinn, Estonia
Estonian Data Protection Inspectorate
Website: www.aki.ee
Email: info@aki.ee
Address: Tatari 39, 10134 Tallinn, Estonia
— End of Kainook Travel Privacy Policy —
Effective Date: June 2026
Kainook Travel OÜ · Tallinn, Estonia · info@kainook.com