Privacy Policy
Last updated: 18 August 2026
PataEstate flips the property search: instead of scrolling listings, you post what you are looking for and agencies and landlords bring matches to you. That only works if you can say what you want without handing your phone number to every agent in Nairobi. This page explains exactly what we collect, who can see it, and how to get rid of it.
This policy covers the PataEstate mobile app and this website, operated under the name PataEstate. If you have a question about anything here, write to [email protected].
1. What we collect
When you sign in with Google or Apple
We do not run passwords. You sign in with your existing Google or Apple account, and the only thing that reaches us is a signed token from them carrying at most three things:
- A stable account identifier — an opaque string Google or Apple uses to tell us it is the same person signing in again. This is what your PataEstate account is keyed to.
- Your email address — used to contact you about your account, and nothing else.
- Your name, as it appears on that account.
Sign in with Apple gives us less than that, and that is fine — we do not need more. Apple sends the account identifier, and your email address only if you agree to share it. If you choose Hide My Email, the address we get is one of Apple's private relay addresses and we never learn your real one. Apple does not send us your name at all, so an account created this way simply has no name on it until you type one in yourself.
We never see your Google or Apple password. From Google we request only the basic sign-in scopes (openid, email, profile) and we ask for no others; from Apple we request only name and email, which is the whole of what Sign in with Apple offers. We have no access to your Gmail, Drive, Calendar, Contacts, photos, iCloud or any other Google or Apple service, and we never read, download or store anything from them.
We do not import your Google or Apple profile picture. Any photo on your PataEstate profile is one you uploaded here yourself.
Your phone number
A request needs a phone number so an agency can reach you after you decide to answer them. You can also verify it by SMS, which puts a "verified phone" note on your profile so the supply side knows the number is real.
One-time codes are stored only as a hash, never as the code itself, and they expire after a few minutes and are destroyed once used. Sending an SMS means passing your number to an SMS provider so they can deliver the message.
Your profile
Optional: a short bio (up to 280 characters) and a profile photo. Both exist to help an agency decide you are a real person worth answering.
What you post
- Requests — the free text of what you are looking for, plus the structured version: sale or rent, areas, budget range, bedrooms, size, furnishing, and the features you ticked.
- Listings, if you use the supply side — title, description, price, area, photos, and the details of the property.
Technical data
- Push notification tokens, if you allow notifications, so we can tell you when a match arrives.
- The time you last used the app, so we can stop bothering dormant accounts.
- Ordinary server logs — IP address, timestamps and error traces — kept for security and debugging.
If you connect an EstateBax account
Agencies can link their existing EstateBax CRM account to PataEstate. If you do, we store the identifiers of that CRM account and agency so we can keep your inventory in step. You can disconnect it from the app at any time.
2. Who can see what
This is the part that matters most, so it is stated plainly. When your request appears on the board that agencies and landlords browse, it is anonymous.
The supply side sees what you are looking for. They do not see your name, your phone number, your email address, your photo or your account identifier. They cannot contact you. They can only send an offer through PataEstate, and your details stay withheld until you choose to answer one.
Because that protection lives entirely in us withholding your number, the app blocks phone numbers, email addresses and messaging handles inside free-text fields such as your request or your bio. This is not us being fussy — a number pasted into a request body is a leak you cannot take back once agents have it.
Your profile photo is stored but is never shown to the supply side. A photo attached to an anonymous request would undo the anonymity and hand a stranger a way to filter people by how they look, their apparent age, or their ethnicity. We will not build that.
3. What we do with it
- Matching. Your request is compared against available properties, and listings are compared against open requests. This is the product.
- Notifying you when a match or an offer arrives.
- Keeping the platform honest — preventing abuse, spam and impersonation.
- Fixing and improving things, using aggregate patterns rather than individual browsing.
We do not sell your personal data. We do not share it with advertisers, data brokers or lead-generation services, and we do not run behavioural advertising.
4. Who we share it with
Only the service providers we need to run the product. Each one gets the minimum required to do its job, and none of them may use your data for their own purposes.
| Provider | What they receive | Why |
|---|---|---|
| Google, Apple | The sign-in exchange itself | To authenticate you without a password |
| OpenAI | The text of requests and listings | Turned into numeric vectors so matching understands meaning, not just keywords |
| An SMS provider | Your phone number and the code | To deliver phone verification messages |
| Expo | Your device push token | To deliver push notifications |
| Cloudflare | Photos you upload | Storage and delivery of images |
| EstateBax | Agency and inventory data only | Only if you connect a CRM account, and only for your own agency |
Some of these providers process data outside Kenya. We may also disclose data where the law requires it, or to protect someone's safety or our legal rights.
5. How long we keep it
- Requests expire automatically 14 days after you post them. An expired request leaves the board and stops being matched.
- One-time SMS codes last minutes, then expire.
- Your account and profile are kept until you delete them.
- Server logs are kept for a short operational period and then rotated away.
6. Deleting your account
You can delete your PataEstate account from inside the app, without asking us and without waiting. Open your profile and choose Delete account.
Deleting is immediate and it takes everything with it: your profile, your photo, your requests, your listings, your device tokens and your sign-in sessions. It cannot be undone, and we cannot restore it afterwards. If you would rather we did it for you, email [email protected] from the address on your account.
7. Your rights
Under the Kenyan Data Protection Act, 2019, you have the right to be told what we hold about you, to get a copy of it, to have it corrected if it is wrong, to have it deleted, to object to how we use it, and to complain to the Office of the Data Protection Commissioner. Most of these you can exercise yourself in the app; for the rest, write to [email protected] and we will respond within 30 days.
8. Security
Traffic is encrypted in transit. Sign-in tokens are verified against Google's and Apple's published keys on every use. One-time codes are hashed. Access to production data is limited to the people who operate the service. No system is perfectly secure, and we will not pretend otherwise — but if a breach ever affects your data, we will tell you and the Data Protection Commissioner.
9. Children
PataEstate is for people aged 18 and over. We do not knowingly collect data from children. If you believe a child has an account, tell us and we will remove it.
10. Changes to this policy
If we change this policy we will update the date at the top, and we will tell you in the app before any change that materially affects your data takes effect.
11. Contact
Questions, requests and complaints: [email protected]. See also our Terms of Service.