Legal
Privacy Policy
How Panya Routes handles personal information.
Effective 26 September 2026 · Version 3 · Revision 47fff4db-489e-4217-ba6c-418569a7e8e2
Version 1.0. Effective 26 September 2026.
This policy explains what personal data Panya Routes collects, why, who we share it with, how long we keep it, and the rights you have under the Data Protection Act, 2019 of Kenya and the Data Protection (General) Regulations, 2021.
It covers the Panya Routes mobile app, the website at panyaroutes.com, the pages that open when you follow a live-share or convoy link, and the console used by sponsors. Sponsors should also read section 12.
1. Who is responsible for your data
The data controller is Panya Routes Limited, a private company registered in Kenya, with its registered office in Nanyuki, Kenya.
- Registered with the Office of the Data Protection Commissioner (ODPC) as a data controller.
- Data protection officer: privacy@panyaroutes.com.
- General contact: support@panyaroutes.com.
2. The short version
- You can browse public routes without an account.
- If you sign in, we hold your email address and the things you choose to add: a profile, your garage, saved routes, contributions.
- Your position is used on your phone for navigation. It leaves your phone only when you choose to: a live share, a convoy, a hazard report, a route photograph, a route plan, or a saved recording.
- Crash reports and product analytics are off until you say yes, and you can switch each off again.
- We do not sell your data and we do not use it to target advertising. Sponsored placements are chosen by route, not by who you are. Sponsors see daily totals, never people.
- You can download your data and delete your account in the app.
3. What we collect, where it comes from, and why
Data you give us
- Email address. You give it to sign in. We send a one-time code to it, with a link that does the same job if you would rather not type the code. We do not use passwords, phone numbers or sign-in through another company.
- Your statement that you are 18 or older, and your acceptance of these terms. Before we send a sign-in code, you confirm "I am 18 or older, and I accept the Terms of Service and Privacy Policy". We record which version of each document you accepted and when.
- Profile. A display name, a short bio, a home city and a profile photograph, if you add them. Your profile is private unless you choose to share it.
- Garage. The vehicles you add and their capability: drivetrain, ground clearance, tyres, lockers, winch, snorkel and similar. The garage is stored on our servers against your account so it follows you to another phone. It is private to you.
- Saved routes, collections and private route plans.
- Hazard reports. The hazard type, whether the route was passable, the position of the hazard, the time, a note of up to 500 characters, and a summary of the vehicle you were driving.
- Route photographs. The photograph and the position the app records for it.
- Community content, such as challenge participation, and anything else you choose to post.
- Messages to support, including anything you tell us when you write to support@panyaroutes.com.
- Recorded drives and walks. Activity recording is switched off in the current version of the app. Where it is available, a recording stays on your phone until you save it, and then uploads the track, distance, duration and elevation with the visibility you choose.
Data collected when you use the service
- Location. See section 4.
- Account and security data. Your account identifier, your app role, sign-in times, the standing of your account (active, suspended or banned) with the reason for any restriction, and any appeal you send with the answer staff give.
- Push notification token. If you allow notifications, a token that lets us send notifications to your phone, and a record of what we sent.
- Technical data. When your phone or browser talks to our servers, our hosting providers process your IP address, the time, and the request, to deliver the service and protect it from abuse. To enforce limits on signed-out route planning and on sponsor delivery counts, we keep a salted one-way hash of your network address for up to two days, never the address itself.
- Crash reports and product analytics, only with your consent. See section 5.
- Sponsor delivery counts. When a sponsored placement is shown or tapped, or a sponsored challenge is joined, we record the event against a one-way identifier, not your name or email, so we can count distinct people. The identifier is a keyed hash (HMAC) of a random identifier the app creates on your phone for this count alone, or of your account identifier when the phone has none, made with a secret key that only our server holds. The event record does not contain your account identifier and is not linked to your account. For a challenge join we check, at the moment the event is recorded, that the signed-in account is a member of the challenge; that check is not stored with the event.
Data from other sources
- Payment providers, for sponsors only (section 12).
Data kept only on your phone
Some data never leaves your phone: your home region, recent searches, downloaded routes and maps, device settings, your consent choices, and the position your phone uses during navigation. Hazard reports along a route you have downloaded are stored on the phone so that hazard warnings work with no signal.
4. Location data
Location is the most sensitive data Panya handles, so this section sets out each use.
Showing you on the map and navigating (foreground). With your permission, the app reads your phone's position to show where you are, to sort routes by the drive to their start, and to give turn directions and hazard warnings. This position is processed on your phone. It is not sent to our servers during navigation.
Navigation with the screen locked (background). When you start navigating a route, the app keeps reading your position while the screen is locked or another app is open, so that turn cues and hazard warnings keep coming. On Android this runs as a foreground service with a visible notification. On iPhone it uses background location updates. It needs only the "While Using the App" permission and it stops when navigation ends. The position stays on your phone.
Recording (background). Activity recording is switched off in the current version of the app, and the app does not ask for background location ("Allow all the time" on Android, "Always" on iPhone). If we switch recording on, the app will ask for that permission separately after explaining why, it will not start recording if you refuse, and the track will stay on your phone until you save it.
Live share. You can start a live share and get a link to send to whoever you choose. The link is the only access rule: there is no list of named recipients. While the share is active, your latest position, speed and the time it was recorded are sent to our servers and shown to anyone who opens the link, on any device, with or without a Panya account. We do not know or record who you sent it to. We keep only your latest position, not a trail. A share lasts at most 24 hours. It ends when it expires or when you stop it.
Convoy. When you create or join a convoy on a route, your latest position, speed and time are shared with the other members while the convoy is active. A convoy lasts at most 24 hours. Leaving a convoy stops sharing your position with it.
Hazard reports and route photographs. A hazard report carries the position of the hazard. A route photograph carries the position the app records for it, which is published with the photograph if it is approved. Before anyone other than you can see a contributed photograph, we remove the location, device and capture-time data that phones store inside the image file. Photographs contributed before we started doing this are cleaned the same way by a scheduled job that runs every hour.
Route plans. If you ask the app to plan a route between points, the points you choose are sent to our routing service to calculate the route. A point can be your current position if you choose it.
Weather forecasts. When you open a route's forecast, the app sends the route's identity and a start time rounded to the hour. Our server asks the forecast provider about five fixed points on the published route. Your own position is not sent.
Your control. You can refuse or withdraw location permission at any time in your phone's settings. Browsing and route details keep working without it. Stopping a live share or leaving a convoy stops sharing at once.
5. Crash reports and product analytics
The app asks two separate questions: may it send crash reports, and may it send product analytics. Until you answer, neither is sent. You can change either answer at any time in the app under Settings.
- Crash reports go to Sentry. They describe the error and the state of the app when it failed. Default personal information collection is switched off, and we do not attach your account to a report.
- Product analytics go to PostHog. They record app lifecycle events (such as opening the app) and a fixed list of product events: a route viewed (with the route's identifier), an offline download finished, navigation started, navigation finished (with a distance band), a hazard reported (with its type), a convoy started or joined, and the SOS screen opened. They are tagged with the app version and platform. We do not attach your name, email or account to analytics.
If we change what these streams collect, the app asks you again.
The website and the console also send error reports to Sentry from their servers, and the console from the browser, with user details, cookies, request headers, query strings and addresses removed. See the Cookie Policy at https://panyaroutes.com/legal/cookies.
6. Why we use your data, and our lawful basis
The Data Protection Act, 2019 (section 30) requires a lawful basis for each use.
- Create and run your account, and sign you in. Data: email, account identifier, sign-in records. Basis: performance of a contract (the Terms of Service).
- Record that you are 18 or older and accepted the terms. Data: acceptance record, document version, time. Basis: legal obligation, and legitimate interest in proving the agreement.
- Show vehicle verdicts and keep your garage across phones. Data: garage. Basis: performance of a contract.
- Save routes, plans and collections. Data: saved items. Basis: performance of a contract.
- Navigation, including with the screen locked. Data: location on the phone. Basis: consent (the operating-system permission), and performance of a contract.
- Live share and convoy. Data: latest position, speed, time, convoy members. Basis: consent, given when you start or join.
- Publish hazard reports and route photographs. Data: report, photo, position, vehicle summary. Basis: consent, given when you submit, and legitimate interest in warning other drivers.
- Moderation, account standing, appeals and preventing abuse. Data: contributions, standing history, appeals, audit records, hashed network addresses. Basis: legitimate interest in a safe service, and legal obligation where the law requires us to act.
- Push notifications. Data: push token, dispatch log. Basis: consent.
- Crash reports. Data: diagnostics. Basis: consent.
- Product analytics. Data: usage events. Basis: consent.
- Support requests. Data: your messages. Basis: legitimate interest in answering you, and performance of a contract.
- Sponsor delivery counts. Data: hashed identifier and event. Basis: legitimate interest in reporting delivery to sponsors in aggregate.
- Security logs and backups. Data: technical data, database copies. Basis: legitimate interest in keeping the service secure and recoverable.
- Sponsor billing and tax records. Data: sponsor contact and invoice data. Basis: performance of a contract, and legal obligation (tax law).
Where we rely on consent, you can withdraw it at any time. This does not affect what we did before you withdrew. Where we rely on legitimate interest, you can object (section 10).
7. Who we share data with
Other people, when you choose. Approved route photographs, hazard reports (type, passability, position, time and vehicle summary, without your name), and your profile if you make it public. Live-share and convoy positions go to the people described in section 4.
Sponsors get aggregates only. Sponsors see daily totals of impressions, clicks, joins and spend for their campaign. Any day with fewer than five distinct people is withheld and left out of totals. Sponsors never receive names, accounts, positions, tracks or individual events.
Service providers (sub-processors). They process data on our instructions to run the service:
- Supabase: database, sign-in, file storage, server functions and daily backups. Data: all account and content data. Where: European Union (Ireland).
- Supabase (sign-in email): sends sign-in emails through its built-in email service. Data: email address, sign-in code and link. Where: European Union. If we move sign-in email to a dedicated email provider, we will name it here.
- Mapbox: map tiles and imagery shown in the app. Data: IP address, device and map-request data, and the approximate area of the map you view. Where: United States.
- GraphHopper: calculates planned routes through our routing service. Data: the points you choose, no account data. Where: Germany.
- Expo (650 Industries): delivers push notifications. Data: push token and notification text. Where: United States.
- MET Norway: weather forecasts. Data: five fixed points on a published route, no personal data. Where: Norway.
- Sentry: crash and error reports, with your consent in the app. Data: diagnostics. Where: European Union (Germany).
- PostHog: product analytics, with your consent. Data: usage events. Where: European Union.
- Cloudflare: hosts the website and the console. Data: IP address and request data. Where: Cloudflare's global network.
- Google Cloud: planned, processing of editorial photographs. Data: photographs of routes, which may show people. Where: Belgium.
- Paystack: sponsor card payments by hosted checkout. Data: sponsor payer details. Where: Nigeria and Kenya.
- Google Cloud Storage: planned, an encrypted off-site copy of the database and stored files. Data: all data, encrypted. Where: Belgium.
GitHub hosts our source code. It does not hold user personal data.
App stores (Apple and Google) process data under their own policies when you download the app.
Authorities. We disclose data where Kenyan law requires it, for example under a court order, or where it is needed to protect someone's life or safety. We check that each request is lawful before we answer it.
Business transfer. If Panya Routes Limited is reorganised, merged or sold, your data may pass to the new owner under this policy. We will tell you first.
We do not sell personal data.
8. Transfers outside Kenya
Several providers above store or process data outside Kenya. Under section 48 of the Act and regulations 39 to 45 of the Data Protection (General) Regulations, 2021, we transfer data only where the provider has committed, in its data processing agreement with us, to appropriate safeguards for the security and protection of the data (including standard contractual clauses where the provider offers them), or where the transfer is necessary to perform our contract with you. We keep a record of each transfer and its safeguard, and you can ask us for a copy.
9. How long we keep data
Scheduled jobs in our database enforce the periods below for live shares, convoys, hazard reports, photo uploads, push notifications and hashed network addresses. We apply the other periods through our providers' settings or our own procedures.
- Account, profile, garage, saved routes, plans and collections: until you delete your account.
- Record of the terms and privacy version you accepted: until you delete your account.
- Live-share position: cleared as soon as the share ends or expires (at most 24 hours).
- Live-share session: deleted 7 days after the share ended.
- Convoy member positions: cleared as soon as the convoy ends or expires (at most 24 hours).
- Convoy session and its member list: deleted 7 days after the convoy ended.
- Hazard reports: shown on the public route listing for 30 days, and deleted 90 days after they were filed, with their photo. If we take a report down, its photo is deleted 7 days later. A scheduled job deletes each photo file within about an hour of its record.
- Route photographs: until you delete your account. This includes photographs waiting for review, photographs we declined and photographs we took down. A photograph we take down leaves public view at once, but its record and file stay in private storage, readable only by you and our moderators, so that a takedown made in error can be reversed. You can ask us to delete any of your photographs sooner by writing to privacy@panyaroutes.com.
- Photo uploads never attached to a report, photograph or recording: deleted about 24 hours after upload.
- Push notification log: 30 days after the notification was sent.
- Push token: disabled when you sign out, and deleted 30 days after it was disabled.
- Hashed network address used for rate limits: up to 2 days. The address itself is never stored.
- Account standing history, appeals and staff audit log: kept after account deletion as moderation and security evidence, without a link to your account, for 2 years.
- Account deletion receipt: 2 years.
- Support emails: 2 years.
- Crash reports (Sentry): 90 days.
- Product analytics (PostHog): 12 months.
- Sponsor delivery events: 13 months. Daily totals are kept for the life of the sponsor account.
- Sponsor invoices and payment records: 5 years, as the Tax Procedures Act, 2015 requires.
- Server and hosting logs: 30 days.
- Database backups: Supabase keeps daily backups for up to 7 days; an encrypted off-site copy, once enabled, is kept for up to 12 weeks. Deleted data stays in a backup until that backup expires.
10. Your rights
Under sections 26 and 40 of the Act you have the right to:
- be told how your data is used (this policy);
- get a copy of your data;
- have wrong data corrected;
- have data deleted;
- object to our use of your data, including where we rely on legitimate interest;
- restrict our use of your data while a question about it is settled;
- receive your data in a portable, machine-readable form;
- withdraw consent at any time;
- not be subject to a decision based only on automated processing that has legal effects on you or affects you in a similarly serious way. Vehicle verdicts are calculated on your phone for your information only, and account standing is decided by a person.
In the app:
- Download your data: Settings, then Download your data. You get a file with your account, profile, garage, plans, collections, notification choices, activities, hazard reports, live shares, community activity and challenge memberships. It does not include your route photographs, your record of accepted terms, or your account standing and appeals; ask us by email if you need them.
- Delete your account: Settings, then Delete account. You confirm with a fresh sign-in code. We delete your private files and then your account and everything linked to it, straight away. There is no waiting period and it cannot be undone. Your standing history and audit records are kept as described in section 9, without a link to your account. Data in backups is removed when the backup expires.
- Correct your data: edit your profile and garage in the app.
- Withdraw consent: switch off crash reports or analytics in Settings; switch off location or notifications in your phone's settings; stop a live share or leave a convoy.
By email: write to privacy@panyaroutes.com or support@panyaroutes.com from the address on your account. If you write from another address we will ask you to prove the account is yours. A suspended account can still sign in, download its data and see its standing in the app, but it is read-only, so write to us to have it deleted. A banned account cannot sign in, so it can ask for its data or for deletion by email.
Timeline. We reply within 7 days to confirm we have your request and complete it within 30 days. If we need longer, or refuse a request, we will tell you why. Requests are free unless they are clearly unfounded or excessive.
11. Children
Panya is for people aged 18 and over. You must confirm you are 18 or older before you can sign in. We do not knowingly collect data about children. If you believe a child has an account, write to us and we will delete it. Do not photograph children for route photographs or hazard reports.
12. Sponsors
If you use the sponsor console for a business, we process your name, work email address, phone number, role in the sponsor team, and your company's legal name, KRA PIN, billing details, campaigns, invoices and payments. Sponsor accounts use a second sign-in factor. Card payments are made on Paystack's hosted checkout; we do not receive card numbers. We keep invoices and payment records for 5 years, as the Tax Procedures Act, 2015 requires.
13. Security
We protect your data with:
- encryption in transit (HTTPS) between the app, the website and our servers;
- encryption at rest for the data our hosting provider stores, including the database, file storage and its backups;
- row-level access rules in our database, so each account can reach only its own private data;
- private file storage for contributed photographs until they are cleaned of hidden metadata and approved;
- a second sign-in factor for every staff and sponsor account, and an audit log of staff actions;
- live-share and convoy links stored only as one-way hashes;
- encryption of the off-site backup copy, once it is enabled, before it is stored.
No system is perfectly secure. If a breach puts your data at risk, we will notify the Data Protection Commissioner within 72 hours of becoming aware of it, as section 43 of the Act requires, and tell you without delay where there is a real risk of harm, unless the law says otherwise.
14. Complaints
If you are unhappy with how we handle your data, please write to us first at privacy@panyaroutes.com. You also have the right to complain to the Office of the Data Protection Commissioner:
- Website: https://www.odpc.go.ke
- Online complaints: https://cie.odpc.go.ke
- Email: info@odpc.go.ke
- Office: Britam Tower, 12th and 13th Floor, Hospital Road, Upper Hill, Nairobi
- Post: P.O. Box 30920-00100, G.P.O. Nairobi, Kenya
15. Changes to this policy
When we change this policy we publish a new version with a new version number and effective date. If a change matters to how we use your data, we tell you in the app before it takes effect and, where the change needs your consent, we ask for it again. Earlier versions are available on request.
16. Contact
- Panya Routes Limited, Nanyuki, Kenya
- Data protection officer: privacy@panyaroutes.com
- Support: support@panyaroutes.com
