Legal

Privacy policy

Last updated 21 April 2026 · Governed by the Kenya Data Protection Act 2019.

What we collect

  • Email address — when you sign in. Required for magic-link authentication.
  • Name and phone number — when you make a booking, so the restaurant can confirm.
  • Approximate location — only if you grant browser permission, used client-side to show nearby restaurants. We do not store your location on our servers.
  • Booking history — the reservations you make on Tamu.
  • Basic usage data — pages visited, to help us improve the product. No third-party trackers in V1.

What we don't collect

  • National ID, passport, or KRA PIN numbers.
  • Payment card details — we don't charge diners.
  • Your contacts, messages, or photos.

How we use your data

Solely to deliver the service you asked for: confirming bookings, letting you sign in, and showing you restaurants. We don't sell your data and we don't share it with third parties except as required to complete the booking (the restaurant sees your name, phone number, and party size).

How long we keep it

Active accounts: as long as you use Tamu. Inactive accounts are deleted after 3 years. Booking records are kept for 2 years for customer-service and accounting purposes, then deleted.

Your rights

You can export or delete your data at any time by emailing privacy@tamu.app. We respond within 30 days.

Cookies

We use a single session cookie for authentication. No advertising or tracking cookies in V1.

Contact

Data protection questions: privacy@tamu.app.