Kazi pilot

Privacy notice

Last updated: 2 October 2026

This notice explains what information Kazi uses to run its online gigs marketplace and how it is shared when you use the site. It describes the current pilot version and should be updated as Kazi’s services or providers change.

Information used by Kazi

  • Account details such as your name, email address, optional phone number, and password record. Passwords are stored as hashes, not as readable passwords.
  • Worker profile details you provide, such as your bio, location, skills, and hourly rate.
  • Marketplace activity, including gigs you post or apply for, application messages, work submissions, application status, and saved searches.
  • If you provide one after an employer accepts your application, your M-Pesa contact number for that gig application.
  • Details you submit in a payment problem report, such as your explanation, reported amount, and payment due date.
  • Account safety reports and the date of your most recent sign-in. Kazi uses sign-in dates to flag accounts with no sign-in for 180 days for admin review.
  • Session information needed to keep you signed in and protect your account.

How information is used and shared

Kazi uses this information to create and secure accounts, show and manage gigs, process applications, support work submissions, save searches, and follow up on reports.

When you apply for a gig, the employer who posted it can see information associated with your application, including your name, email, and profile details. If you submit an M-Pesa number after acceptance, it is shown to that employer in the context of that application. Kazi administrators can access information needed to operate the service and review reports.

Gig listings are visible to people browsing Kazi. Kazi also links to opportunities listed on other websites; those sites have their own privacy practices.

Database provider and location

Kazi currently uses Neon to host its PostgreSQL database. The Kazi Neon project is currently in AWS US East (Ohio), outside Kenya. The provider or region may change; this notice should be updated if it does.

How long information is kept

Kazi has not yet published a fixed retention schedule. An account with no sign-in for 180 days is flagged for admin review; it is not automatically deactivated or deleted. Admins can deactivate accounts, and can restore them later. Account, gig, application, and report records may remain in the service while needed to operate the pilot.

Your information requests

Kenya’s Data Protection Act provides rights relating to personal information, including being informed about its use, access, objection to processing, and correction or deletion of false or misleading information. See the Office of the Data Protection Commissioner’s data subject rights guidance.

For privacy questions or requests, email Kazi at [email protected].

Pilot notice

This is an operational notice for the current Kazi pilot, not a substitute for review of the final privacy policy. The Kazi operator still needs to set and publish a data-retention schedule.

See also Kazi Terms of Use.