Privacy Policy

ShambaBoy Privacy Policy

ShambaBoy Digital is an agricultural verification and compliance infrastructure platform that helps farms, workers, and institutions create trusted, verifiable records of farm operations. This policy explains how we collect, use, protect, and share your personal information when you use our services.

Last Updated: January 2026Version 2.0

Company

ShambaBoy Digital

Registration: BN-QBSOQ76Z

Headquarters

104105-00101, Nairobi

Kenya

Support

support@shambaboy.com

+254-722575426

1. Introduction

This Privacy Policy applies to our website (shambaboy.com), mobile applications (Android and iOS), web dashboard, and any related services we provide. By using ShambaBoy, you agree to the terms described here. If you do not agree, please do not use our services.

2. Who We Are

Company Name

ShambaBoy Digital

Registration

BN-QBSOQ76Z

Address

104105-00101, Nairobi, Kenya

Email

support@shambaboy.com

3. What Personal Data We Collect

3.1 Information from Workers

Identity Information

  • Full name, national ID or passport number, date of birth, gender, contact details (phone number, email address)

Work Information

  • Task completion records, skills demonstrated, performance ratings, attendance history, supervisor comments

Location Information

  • GPS coordinates when submitting task verifications (to confirm you were at the farm)

Photos

  • Photos taken through the ShambaBoy apps to verify tasks. Photos cannot be uploaded directly from your gallery.

Device Information

  • Device model, operating system, unique device identifier (to prevent account sharing and fraud)

3.2 Information from Farm Owners and Supervisors

  • Name, contact details, farm location, farm size, crop types
  • Operational data (task assignments, inventory, schedules)
  • Payment information (for subscription billing)
  • Comments and notes about workers and farm operations

3.3 Information from Diaspora Users

  • Login credentials (email, password)
  • Location of access (to comply with cross-border data transfer laws)
  • Relationship to farm (owner, investor, family member, estate administrators)

4. How We Use Your Personal Data

4.1 To Provide Our Core Services

  • Task verification: Recording and verifying farm activities through photos, GPS, and timestamps
  • Worker identity profiles: Building portable work histories that workers can take to other farms
  • Farm management: Helping farm owners track operations, assign tasks, and manage workers
  • Compliance records: Creating audit trails for export standards (for example, GLOBALG.A.P), financial institutions, and government requirements

4.2 To Prevent Fraud and Ensure Platform Integrity

  • Detecting false task submissions
  • Identifying unusual patterns or activities that may indicate fraud
  • Preventing account sharing
  • Verifying worker identity

4.3 To Share with Institutional Partners

With your written consent, ShambaBoy may share verified data with:

  • The worker's supervisor and farm owner: Enhances monitoring and evaluation, work records, task submissions, and performance data
  • Potential employers: When a worker applies for jobs at other farms
  • Banks and microfinance institutions: For credit assessment and agricultural lending
  • Insurance companies: For agricultural insurance verification
  • Export buyers: For compliance certification and verification
  • Government agencies: When required by law (court orders, legal processes, requests from government authorities, or investigations by regulatory bodies)
  • Carbon and climate partners: For agricultural carbon credit verification (for example, Consuming Carbon)
  • Service providers: Cloud hosting providers (data stored in Kenya), SMS and email service providers (notifications), payment processors (subscription billing), and security and fraud prevention services

4.4 To Improve Our Services

  • Analysing usage patterns (anonymised)
  • Identifying best practices across farms
  • Improving fraud detection models
  • Enhancing user experience

4.5 To Improve Communication

  • Sending task notifications and reminders
  • Providing customer support
  • Notifying you of important changes to our services
  • Sending security alerts (unusual account activity)

Under Kenyan law, all service providers are contractually required to protect your data and use it only for specified purposes.

5. How We Protect Your Personal Data

5.1 Technical Security Measures

  • Encryption: All data transmitted between your device and our servers is encrypted using TLS 1.3
  • Data storage: All personal data is stored on secure servers physically located in Kenya
  • Access controls: Only authorised personnel can access your data, and all access is logged
  • Regular security audits: Quarterly security assessments and regular data security upgrades

5.2 Organisational Security Measures

  • Staff training upon hiring and regular refreshers during employment tenure
  • Confidentiality agreements signed upon hiring and updated annually
  • Data Protection Officer (DPO) overseeing compliance
  • Incident response mechanisms to respond to data breaches within 72 hours

6. User Information Protection

6.1 Your Data Stays in Kenya

  • All personal data is stored on servers physically located in Kenya
  • When you access your dashboard, you are viewing data through an encrypted connection
  • Data is not downloaded or stored on your device

6.2 Legal Protections for Cross-Border (Diaspora) Access

We use Standard Contractual Clauses approved by data protection authorities to ensure your data remains protected when accessed from: the European Union (EU), the United Kingdom (UK), the United States of America (USA), Canada, Australia, and other approved jurisdictions.

6.3 Diaspora User Responsibilities

  • Use only ShambaBoy's encrypted connections (do not screenshot or download personal data)
  • Access only from secure devices (not public or shared computers)
  • Comply with Kenyan data protection laws

7. Artificial Intelligence (AI) and Automated Decisions

7.1 What AI Does

  • Fraud detection: AI flags potentially fraudulent task submissions for human supervisor review
  • Image verification: AI checks if photos are authentic (not reused or manipulated)
  • Pattern recognition: AI detects unusual patterns that may need investigation

7.2 What AI Does Not Do

AI does not make final decisions about employment, compensation, or your legal rights and obligations. All important decisions are made by human supervisors and farm owners.

7.3 User Rights Regarding AI

  • Right to know if AI flags your submission
  • Right to request human review of any AI flag
  • Right to explanation in simple language for AI flags
  • Right to challenge: Provide evidence if you believe AI made a mistake
  • Right to opt-out: You can choose manual review (may take longer)

8. User Data Protection Rights

8.1 Right to Access

  • In-app: Tap "My Profile" or "My Data"
  • Download: Use "Export My Data" button
  • Request: Email support@shambaboy.com
  • SMS: Text "ACCESS" to +254-722575426

Response time: Within 48 hours electronically; 7 days for written requests.

8.2 Right to Data Portability

  • Export complete work history in JSON, CSV, or PDF
  • Transfer profiles to competing platforms
  • Share credentials with potential employers
  • Export as many times as needed (free, unlimited)

8.3 Right to Rectification

  • In-app: Tap "Report Error" next to any data field
  • Email: support@shambaboy.com with details

ShambaBoy will correct factual errors within 48 hours.

8.4 Right to Erasure (Deletion)

  • Marketing data is deleted immediately upon request
  • Core profile data is retained for 7 years to comply with the Kenya Employment Act and tax laws
  • After the retention period: Personal identifiers are removed and records are anonymised

8.5 Right to Object

  • Marketing communications (unsubscribe anytime)
  • Data sharing with specific institutional partners
  • AI processing of submissions (opt for manual review)

8.6 Right to Withdraw Consent

  • Biometric data processing
  • Data sharing with institutional partners
  • Marketing communications

Withdrawing consent may affect a user's ability to use certain features.

8.7 Right to Lodge a Complaint

  • Contact the ShambaBoy Data Protection Officer: support@shambaboy.com
  • File a complaint with Kenya's Office of the Data Protection Commissioner (ODPC)
  • Email: datacommissioner@odpc.go.ke
  • Website: www.odpc.go.ke
  • Phone: +254-20-2675580

9. How Long We Keep Your Data

  • Active worker profiles: Duration of employment + 7 years
  • Terminated worker profiles: 7 years from termination
  • Task verification images: 3 years (required by export compliance standards like GLOBALG.A.P)
  • Biometric identifiers: Active employment + 90 days after termination
  • Farm operational data: 7 years
  • Marketing consents: Until withdrawn + 30 days
  • Audit logs: 10 years

After these periods, personal identifiers are removed and records are anonymised.

10. Children's Privacy

ShambaBoy is strictly intended for users aged 18 years and above. We do not knowingly collect personal data from individuals under 18 years.

11. Changes to This Privacy Policy

ShambaBoy updates this Privacy Policy from time to time to reflect changes in our practices or legal requirements.

How We Notify You of Changes

  • Material changes: Notification via SMS, email, and in-app alert at least 30 days before changes take effect
  • Minor changes: Update the "Last Updated" date at the top of this policy
  • Your options: If you do not agree with the changes, you can close your account before the changes take effect

We recommend checking this Privacy Policy periodically for updates.

12. Contact Us

For any questions, concerns, or requests regarding your personal data or this Privacy Policy, please contact us:

Data Protection Officer

  • Email: support@shambaboy.com
  • Phone: +254-722575426 (Mon-Fri, 8am-5pm EAT)
  • WhatsApp: +254-722575426
  • SMS: Text "HELP" to +254-722575426

General Inquiries

  • Email: info@shambaboy.com
  • Website: shambaboy.com
  • Postal Address: ShambaBoy Digital, 104105-00101, Nairobi Kenya

Response Times

  • Data access requests: Within 48 hours (electronic); 7 days (written)
  • Data deletion requests: Within 48 hours (acknowledgment); 30 days (completion)
  • General inquiries: Within 24 hours (business days)
  • Complaints: Within 48 hours (acknowledgment); 14 days (resolution)

Thank you

Thank you for trusting ShambaBoy with your personal data. We are committed to protecting your privacy and empowering you with control over your data.

Last Updated: January 2026