Last updated September 2026
This policy explains what personal data D·Stays collects through dstays.co.ke, why, and what rights you have over it, in line with Kenya’s Data Protection Act, 2019. It covers guests making booking requests and visitors browsing the Site; it does not cover the separate admin system used internally by D·Stays staff.
When you submit a booking request, we collect:
We do not collect or store payment card numbers, M-Pesa PINs, or bank credentials — payment happens directly between you and your payment provider (e.g. Safaricom for M-Pesa), and we only ever see confirmation that it happened.
Simply browsing the Site (viewing listings, searching by town or type) doesn’t require you to submit any personal data.
We do not use your data for advertising, and we do not sell or rent it to third parties.
We process your booking data because it’s necessary to perform the contract formed when you request and confirm a booking (Data Protection Act, 2019, s.30(a)), and to meet our legal obligations around financial record-keeping.
Your booking details are visible to authorized D·Stays staff handling reservations, and to the owner/manager of the property you’re booking, to the extent needed to prepare for your stay (typically your name, dates, and guest count). We use Google (Gmail) to send booking emails. We do not share your data with advertisers or analytics companies — the Site does not run any advertising or analytics trackers.
The public Site does not use advertising or analytics cookies. It sets one functional session cookie when you submit the booking form, used only to protect the form against forgery (a security measure, not tracking) — it isn’t used to identify you across visits or follow you elsewhere on the web. The separate admin system uses a session cookie to keep staff logged in.
Booking and guest contact records are kept for 5 years for accounting and legal purposes. Marketing videos generated from property photos are automatically deleted from our servers within 30–35 minutes of creation and are not linked to any guest’s personal data.
Staff accounts are password-protected (passwords are hashed, never stored in plain text) and the Site is served over HTTPS. Access to booking and guest records is limited to authorized D·Stays admin accounts.
Under the Data Protection Act, 2019, you can ask us to:
To exercise any of these, email diana@dstays.co.ke. If you’re not satisfied with our response, you can complain to the Office of the Data Protection Commissioner (ODPC), Kenya.
The Site is not directed at children, and bookings must be made by an adult (18+).
We may update this policy as the Site changes; the current version will always be posted here with its last-updated date.
D Stays is the data controller for the personal data described in this policy, based in Nairobi, Kenya. Contact: diana@dstays.co.ke, WhatsApp +254 725 347 321.