Privacy Policy
Effective 29 July 2026
This policy explains what data the LimaPOS Tours application (the “Service”) collects, why it is collected, how it is stored and protected, and what rights you have over it. It applies to the people who sign in to the Service and to the records their business keeps in it.
1. Data we collect
Account data
- Your name and email address.
- Your business name and reporting currency.
- Your password, stored only as a one-way hash — never in a readable form.
- Your role in the business (owner, manager or staff) and, if you enable two-factor authentication, the secret used to verify your authenticator codes.
Business and financial data you enter
- Customer and guest records, including the names and contact details you choose to record for the people who book with you.
- Tours, departures, schedules, seat capacity and bookings.
- Staff and resource records, and timesheets where you use them.
- Invoices, receipts, credit notes, supplier bills and payments.
- Accounting data: journals, ledger entries, fixed assets and the reports derived from them.
This data is entered by you and your staff. Where it includes personal data about your customers, your business decides what is collected and why; we process it on your behalf in order to run the Service for you.
Operational data
- An activity and audit log of significant actions taken in your account — such as sign-ins, and the creation, approval or posting of financial records — with the user and timestamp, so a business can see who changed what.
- Standard server logs generated when the Service is accessed, used to keep it running securely and to diagnose faults.
What we do not collect
The Service does not run advertising, does not build marketing profiles, and does not sell data. It does not ask for payment card numbers within the application, and it does not collect special categories of personal data by design — if you enter such data into a free-text field, you do so as the controller of that data.
2. How data is used
- To create and administer your account and authenticate you when you sign in.
- To provide the Service’s features: scheduling, bookings, invoicing, payments and accounting.
- To send transactional messages that the Service itself requires — for example email address verification at sign-up, and password reset links you request.
- To keep an audit trail so account activity can be reviewed by the business.
- To secure the Service: detecting and preventing unauthorised access, abuse and fraud, and enforcing rate limits and account lockouts.
- To maintain, troubleshoot and improve the Service.
- To comply with legal obligations, including record-keeping requirements.
Data belonging to one business account is not used to provide the Service to another.
3. How data is stored and secured
Data is stored in the Service’s database, and each business’s records are separated by a business identifier that every query is scoped to, so one account cannot read another’s data. Safeguards include:
- Passwords stored only as one-way hashes using a modern hashing algorithm, and re-hashed automatically as standards improve.
- Optional two-factor authentication, plus throttling and account lockout after repeated failed sign-in attempts.
- Session cookies marked HttpOnly and SameSite, and marked Secure when the Service is served over HTTPS, with the session identifier regenerated at sign-in.
- Protection against cross-site request forgery on every action that changes data.
- Role-based access, so staff see only what their role permits.
No system can be guaranteed completely secure. You also play a part: use a strong, unique password, enable two-factor authentication, and grant staff only the access they need.
4. Data retention
Account and business data is retained for as long as the account is active, and afterwards only as long as needed for the purposes described here or to meet legal and accounting record-keeping obligations. Data that no longer needs to be kept is deleted or anonymised.
5. Sharing with third parties
We do not sell your data, and we do not share it for third-party advertising. Data is shared only in these circumstances:
- Service providers. Infrastructure and hosting providers that run the servers and database, and an email delivery provider used to send verification and password-reset messages. They process data only on our instructions and only as needed to provide their service.
- Within your business. Other users of your business account see the records their role gives them access to. Account owners can see account-wide activity.
- Legal requirements. Where we are required to disclose data by law, regulation or valid legal process, or where disclosure is necessary to protect rights, safety, or the security and integrity of the Service.
- Business transfer. If the Service is involved in a merger, acquisition or sale of assets, data may transfer as part of that transaction, and this policy will continue to apply until superseded.
Web fonts used by the application’s pages are requested from a third-party font provider when a page loads, which means your browser contacts that provider and it may receive your IP address as part of that ordinary request.
6. International transfers
Data may be stored or processed in a country other than your own, depending on where the Service and its providers operate. Where data is transferred across borders, appropriate safeguards are applied as required by Kenyan law
7. Your rights
Subject to the law that applies to you, you may have the right to:
- Access the personal data held about you.
- Correct data that is inaccurate or incomplete.
- Request deletion of your data, subject to records we must retain by law.
- Object to or restrict certain processing.
- Receive a copy of data you provided in a portable form.
- Withdraw consent where processing is based on consent, without affecting processing already carried out.
Many of these can be exercised directly in the application: you can view and update your name, email and password in Settings, manage two-factor authentication there, and correct or remove the business records you have entered. Staff users should raise requests with the owner of their business account, who administers that account. Where your business recorded your details as its customer, that business is the controller of those records and requests should be directed to it.
8. Cookies
The Service uses cookies only where they are necessary to make it work. Specifically, it sets a single session cookie that keeps you signed in as you move between pages. It is marked HttpOnly so it cannot be read by scripts, marked SameSite to limit cross-site sending, marked Secure when served over HTTPS, and it expires when your browser session ends or when you sign out.
The Service does not set advertising, marketing or cross-site tracking cookies. Blocking the session cookie will prevent you from signing in.
9. Children
The Service is a business application and is not directed at children. Accounts are intended for people acting on behalf of a business.
10. Changes to this policy
We may update this policy from time to time. When we do, we will revise the effective date at the top of this page, and material changes will be notified through the Service where reasonably practicable. Continuing to use the Service after a change takes effect means you accept the revised policy.