Privacy Policy
Last updated: August 13, 2026
WilTrak helps producers, collectors, recyclers and regulators track materials and meet extended producer responsibility (EPR) obligations. This policy explains what personal data we handle, why, who we share it with, how long we keep it, and what rights you have.
It covers our marketing website (wiltrak.tech), the WilTrak dashboard, the WilTrak mobile app, and our APIs (together, the “Service”).
1. Who we are and how to reach us
WilTrak Ltd., Nairobi, Kenya, is the company behind the Service.
- Privacy questions and rights requests: support@wiltrak.tech
- General and legal: info@wiltrak.tech
- Billing: sales@wiltrak.tech
Please put “Privacy request” in the subject line so we can route it correctly.
2. The two roles we play — read this first
WilTrak is a business tool. Most of the personal data inside it was put there by a customer organization about other people — its own field staff, the waste collectors it pays, and contacts at producers and recyclers. Who is accountable for that data depends on which role applies.
We are the data controller — we decide why and how the data is processed — for:
- account registration, login and profile data;
- billing, payment and invoicing records;
- support conversations with us;
- security, fraud, abuse and signup-quality monitoring;
- our audit logs of platform activity; and
- our own communications and marketing to account holders and website visitors.
We are a data processor acting on our customer’s instructions — the customer organization is the controller — for the operational records inside a workspace: producers, products, batches, pickups, collectors, facilities, shipments, recovery transfers, payouts, levy records, uploaded photographs and uploaded documents.
If your data is in WilTrak because an organization put it there, that organization decides what happens to it, and its own privacy notice governs. See section 5. Our commitments to customers in that role are in Annex A of the Terms.
3. Personal data we collect as controller
You give us:
- Identity and contact data — name, email address, phone number, organization, job role, country. Collected when you request a demo, sign up, contact us, or are added to an organization by its administrator.
- Account credentials and authentication data — a hashed password (never the password itself), passkey (WebAuthn) public keys and credential identifiers, one-time codes we generate (stored hashed), your chosen multi-factor method, and notification preferences.
- Billing data — billing country, tax status and identifiers, invoice and receipt history, plan, term, add-ons, subscription status, and payment references and authorization tokens issued by our payment provider. We never see or store your full card number, CVV, or bank credentials — those go directly to the payment provider.
- Support and enquiry content — messages, attachments, demo requests, enterprise enquiries and service requests.
We collect automatically:
- Usage and device data — pages and screens viewed, features used, approximate location derived from IP, browser and device type, operating system, app version, referral source, and timestamps.
- Security and integrity data — IP address at signup and at login, login times and outcomes, failed authentication attempts, session and token metadata, rate-limit events, and error diagnostics.
- Audit records — a log of who did what in a workspace: the acting user, the action, the affected record, and the time. Audit records are a security and integrity control and cannot be edited by users or by us.
We receive from others:
- Payment status and authorization data from Paystack or DPO after you pay.
- Identity assertions from your employer’s identity provider if your organization uses single sign-on — typically your email address, name and a subject identifier.
- Delivery and bounce data from our email and SMS providers.
4. Personal data our customers put into WilTrak
When a customer organization uses WilTrak, its staff record field operations. Those records commonly include personal data about people who are not our users:
| Who | What typically gets recorded |
|---|---|
| Collectors (waste collectors paid by the organization — they have no WilTrak login) | Name, phone number, national identification number, an internal account ID, pickups attributed to them, weights and materials, performance targets and evaluations, payout records, and SMS messages sent to them about targets or incentives |
| Field agents and staff (organization employees using the app) | Name, email, role and permissions, which records they created, the time of each action, the GPS coordinates captured when they record a pickup, photographs they take, and anomaly reviews they perform |
| Producer, recycler, facility and recovery-partner contacts | Name, organization, email, phone, registration numbers, addresses and site coordinates |
| Anyone appearing incidentally | People or vehicles visible in evidence photographs, and names appearing in uploaded compliance documents, permits and certificates |
Location. GPS coordinates are captured at the moment a record is created, to evidence where a pickup happened. The mobile app does not perform continuous or background location tracking, and does not build a movement trail of a worker’s day.
Photographs. Evidence photos are uploaded, stored, and analysed by our material-classification model. Where a photo carries GPS metadata, we compare it against the submitted coordinates as a plausibility check. Most phone cameras strip this metadata, so its absence is normal and is not treated as suspicious on its own.
Offline data. The mobile app keeps unsent records on the device until they sync. Device security is the responsibility of the organization that issued or authorized the device.
5. If your data is in WilTrak because an organization put it there
If you are a collector, field agent, contact person, or anyone else whose data was entered into a WilTrak workspace by an organization:
- The organization is the data controller. It decided to collect your data, it is responsible for telling you about it and for having a lawful basis, and it controls how long the data stays and who inside its team can see it.
- Direct your requests to that organization first — access, correction, deletion, objection. We are contractually required to refer such requests back to them rather than act unilaterally, because acting alone could destroy records they are legally required to keep, or reveal data to the wrong person.
- We will still help. Email support@wiltrak.tech and, if you tell us which organization is involved, we will pass your request on without undue delay and support them in responding. If you do not know which organization holds your data, tell us what you can and we will try to identify it.
- You can always complain to a regulator (section 16), whether or not you go through the organization first.
6. Why we use personal data, and our legal bases
| What we do | Why | Legal basis (KDPA / GDPR where applicable) |
|---|---|---|
| Create and administer accounts, authenticate users | To let you use the Service | Performance of a contract |
| Host and process workspace records | To provide the Service to our customer | Performance of a contract (with our customer); we act on their instructions as processor |
| Take payment, issue invoices and receipts, chase overdue amounts | To bill for the Service | Performance of a contract; legal obligation (tax and accounting records) |
| Send verification codes, password resets, security alerts, invoices and service notices | Essential account and transaction messages | Performance of a contract; legitimate interests (account security) |
| Prevent fraud, abuse, data falsification and unauthorized access; rate limiting; IP and signup-pattern checks | To keep the Service and its data trustworthy | Legitimate interests (security and integrity of the Service, protection of third parties and regulators); legal obligation |
| Maintain audit logs of workspace activity | Accountability and dispute resolution | Legitimate interests; performance of a contract |
| Provide support, including accessing a workspace to resolve an issue | To answer your requests | Performance of a contract; legitimate interests |
| Monitor product quality, diagnose errors, plan capacity | To keep the Service working and improve it | Legitimate interests |
| Improve classification and anomaly models using aggregated, de-identified data | To make the product more accurate | Legitimate interests (no identification of any person or organization) |
| Detect stalled or low-quality signups and send follow-up or escalate internally | To manage abuse and support genuine customers | Legitimate interests |
| Send product updates and marketing | To tell you about relevant features and offers | Consent, or legitimate interests for existing business contacts — always with an opt-out |
| Website analytics and cookies | To understand and improve the site | Consent |
| Respond to lawful requests, defend legal claims, meet regulatory duties | Legal compliance | Legal obligation; establishment, exercise or defence of legal claims |
Where we rely on legitimate interests, we have assessed that our interest is not overridden by your rights. You can ask us for that assessment, and you can object (section 15).
7. Automated processing, profiling and AI
We use automated processing in a small number of places. None of it produces a legal or similarly significant effect on an individual on its own, and each has a human in the loop.
- Material classification. An image model predicts the likely material class of a photographed item and returns a confidence score. It is a probabilistic aid, not a laboratory analysis, and can be wrong.
- Anomaly detection. Rules flag pickups that look unusual — implausible weights, duplicate scans in a short window, mismatched materials, coordinates outside the expected service area, or photo metadata that disagrees with the submitted location. A flag is a prompt for a human to look, not an accusation. Flags are reviewed by the customer’s own staff, not by us.
- Collector performance evaluation. Where a customer sets a target for a collector, the system compares recorded activity to that target on a schedule and may send the collector an SMS. The target, the reward and any consequence are set and applied by the customer, not by us.
- Signup-quality monitoring. We assess new organizations for signs of abandoned or abusive signups, using signals such as whether an email address was ever verified, whether anyone returned after the first login, whether onboarding produced any real records, whether the email domain is a known disposable-address provider, and whether several signups share a signup IP address within a short window. The outcome is a follow-up email to the account administrator, or internal escalation to our team. It can result in a human decision to suspend an account for abuse; it never suspends an account by itself.
- Data assistant (optional). Where an administrator enables it, questions asked in the “Ask WilTrak” widget are sent, together with a summary of that workspace’s own figures, to OpenAI to generate an answer. See section 9.
You can ask for human review of, or contest, any of these outcomes by emailing support@wiltrak.tech.
8. When WilTrak staff can see your data
We keep this deliberately narrow, and we log it.
Authorized WilTrak personnel may access a customer workspace only to: provide support that has been requested; investigate a technical, security, billing or abuse issue; comply with a legal obligation or lawful request; or protect the rights, property or safety of WilTrak, our customers, or others.
Some support and platform tasks are carried out by our staff entering a workspace through an internal “act as” mechanism, which gives them an administrator’s view of that workspace. This access:
- is limited to designated superadmin and customer-care roles;
- requires the staff member to complete a step-up authentication ceremony (a passkey or equivalent) at the time;
- is time-limited and recorded in the workspace’s audit log, so the customer can see it;
- requires a second authorization from a designated approver for sensitive platform actions such as changing a subscription, granting or revoking staff privileges, deactivating or deleting a user or organization, or recording a payout while acting as a customer; and
- is never used to view, extract or use customer records for any other purpose.
We do not sell personal data, we do not share it with data brokers, and we do not use it for advertising or ad targeting.
9. Third parties we share data with
We share personal data only with the categories below. Each is bound by a written contract limiting what it may do with the data.
Sub-processors and infrastructure providers
| Provider | Purpose | Data involved | Primary locations |
|---|---|---|---|
| Neon | Managed PostgreSQL database — the primary datastore | All account and workspace records | United States / European Union |
| Koyeb | Application hosting for the API and dashboard | All data in transit through the application | European Union / United States |
| Cloudflare R2 | Object storage for evidence photos, uploaded documents, invoices and generated PDFs | Photographs, documents, PDFs | Global (S3-compatible object storage) |
| Paystack | Payment processing for subscription and service fees | Billing name and email, amount, payment reference, card authorization token | Nigeria / South Africa / United States |
| DPO Group | Alternative payment processing for certain currencies | As above | Kenya / South Africa |
| Twilio | SMS delivery — one-time codes and collector notifications | Phone number, message content | United States |
| Expo | Push notification delivery to the mobile app | Device push token, notification content | United States |
| OpenAI | Optional data assistant, only where an administrator enables it | The question asked, plus a summary of that workspace’s own aggregate figures | United States |
| Namecheap (Private Email / SMTP) | Email delivery — verification codes, password resets, invoices, receipts, notifications | Recipient name and email, message content, invoice and receipt attachments | United States |
| Google Analytics | Marketing website analytics only — not used in the dashboard or mobile app | Pseudonymous identifiers, IP-derived approximate location, pages viewed | United States |
Error monitoring, diagnostics and material-image similarity search run on our own infrastructure, not through a third-party vendor.
We will give at least 30 days’ notice before adding or replacing a sub-processor that handles personal data, by updating this table and notifying organization administrators. Customers may object on reasonable data protection grounds — see Annex A6 of the Terms.
Others we may share with
- Your own organization. If you are added to a workspace, its administrators can see your account details, your permissions, and your activity in the audit log.
- Endpoints you configure. If your organization sets up webhooks or single sign-on, data is sent to the URL or identity provider you chose. Once it leaves our systems it is under your control, not ours.
- Professional advisers — lawyers, auditors, accountants and insurers, under a duty of confidence.
- Acquirers. If we are involved in a merger, acquisition, financing or sale of assets, data may be transferred as part of that transaction, subject to this policy continuing to apply. We will notify affected customers.
- Authorities and affected parties. We may disclose data where required by law, court order or a lawful regulatory request; to establish, exercise or defend legal claims; to prevent or investigate fraud, security incidents or serious abuse; or to protect the rights, property or safety of any person. Where we reasonably believe records have been falsified in a way that affects a regulatory filing, a levy, a certificate, or a third party’s rights, we may notify the affected regulator, producer responsibility organisation, or counterparty and provide the relevant records — see section 8.3 of the Terms.
We will, where lawful and practicable, notify the affected customer before disclosing their data to an authority so they can seek protection.
10. Publicly accessible information
Two features deliberately expose limited data to people without an account:
- Certificate verification. Anyone holding a certificate’s verification code can check the certificate’s status and the limited details shown on the verification page. This is the point of the feature — it lets a regulator, PRO or buyer confirm a certificate is genuine. Treat verification codes as semi-public.
- Recovery transfer confirmation links. When a transfer is sent to a recycler for confirmation, the recycler receives a link with a time-limited, single-purpose token. Anyone holding that link, while it is valid, can view the transfer details and confirm or dispute it. Do not forward these links.
Do not put anything in a certificate, transfer note or reference field that you would not want a third party to read.
11. Cookies and similar technologies
Dashboard and mobile app. We use only what is strictly necessary: session and authentication cookies and tokens, secure storage of session credentials on the device, and preference storage (language, theme, notification settings). There is no advertising or cross-site tracking in the dashboard or the app.
Marketing website. In addition to strictly necessary cookies, we use Google Analytics 4 to understand how the site is used — which pages are visited, how visitors arrive, and roughly where they are, derived from IP address. These are not strictly necessary and we set them on the basis of consent.
You can control cookies through your browser settings, and you can opt out of Google Analytics using Google’s browser opt-out add-on. Blocking strictly necessary cookies will stop you being able to sign in.
12. Mobile app permissions and device data
The app asks only for what a specific feature needs, and you can decline or withdraw each one in your device settings:
- Camera — to scan batch barcodes and QR codes and to take evidence photographs. Declining means you cannot record a pickup with photo evidence.
- Location (while in use) — to capture the coordinates of a pickup at the moment you record it, for verification and compliance records. Not collected in the background and not used to build a movement trail.
- Photo library — only where you choose to attach an existing image.
- Face ID / fingerprint — optional, to unlock a restored session and to confirm sensitive actions.
- Push notifications — optional, to deliver approval and operational alerts.
Biometrics. Face ID, Touch ID and fingerprint checks are performed entirely by your device’s operating system. Your fingerprint or face data never leaves your device, is never transmitted to us, and is never stored by us. We receive only a yes/no result. We do not collect or process biometric identifiers.
The app also stores a queue of unsent records and your session credentials on the device, in the operating system’s secure storage where available, so that field work continues without a connection. Signing out clears the session.
13. International transfers and data residency
WilTrak’s infrastructure runs on cloud providers and is not currently hosted in an East African data centre. Data collected in Kenya, Uganda, Tanzania, Rwanda, Ethiopia, Burundi or elsewhere in the region may be processed and stored outside the country where it was collected — principally in the European Union and the United States, as set out in the table in section 9.
Kenya’s Data Protection Act, 2019 and the Data Protection (General) Regulations, 2021, and Uganda’s Data Protection and Privacy Act, 2019, place conditions on transferring personal data out of the country, including demonstrating appropriate safeguards. We address this through:
- encryption in transit, and encryption at rest for our managed database and object storage;
- written data processing terms with every infrastructure provider, restricting what they may do with the data and requiring equivalent protection;
- limiting cross-border transfer to what is operationally necessary to run the Service;
- contractual transfer safeguards, including standard contractual clauses where a recipient relies on them; and
- disclosing this practice here, so that organizations can assess it against their own regulatory obligations before they upload anything.
If your organization is subject to an in-country data residency requirement for particular record types, contact info@wiltrak.tech before onboarding. We cannot retrospectively relocate data you have already uploaded.
14. How long we keep data
We keep personal data only as long as we need it for the purposes above, or as the law requires. In practice:
| Data | Retention |
|---|---|
| Account and profile data | For the life of the account. Deactivated and deleted users are retained in a disabled state so that the audit trail stays intact, with identifiers removed on request where the law allows |
| Workspace operational records (pickups, batches, collectors, documents, photographs) | For the life of the subscription, then 30 days for export after termination, then deleted or irreversibly anonymized — except where retention is legally required |
| Billing, invoices, receipts and tax records | 7 years from the end of the relevant financial year, as required by Kenyan tax and company law |
| Audit logs of workspace and platform activity | 7 years, as a compliance and accountability record |
| Security and abuse data (login IPs, signup IP, failed attempts, rate-limit events) | Up to 24 months, or longer where needed for an ongoing investigation or legal claim |
| Support conversations | 3 years from the last message |
| One-time codes, verification and reset codes | Minutes — they expire on use or on their short timer, and are stored hashed |
| Marketing contacts and demo requests | 3 years from the last engagement, or until you unsubscribe |
| Backups | Deleted on their ordinary rotation cycle, normally within 35 days of the source record’s deletion |
| Aggregated, de-identified statistics | Indefinitely — these no longer identify anyone |
Deletion from live systems happens first; backups follow on their rotation. During that window, data is not restored or used except for disaster recovery.
15. Your rights
Subject to applicable law, you may ask us to:
- access the personal data we hold about you, and receive a copy;
- correct data that is inaccurate or incomplete;
- delete data, where we no longer have a lawful reason to keep it;
- restrict or object to processing, including profiling and processing based on legitimate interests;
- port data you gave us, in a structured, commonly used, machine-readable format;
- withdraw consent at any time, where we relied on consent — this does not affect processing already carried out; and
- opt out of marketing at any time, using the unsubscribe link, your notification preferences in the dashboard or app, or by emailing us. We will still send essential transactional messages — verification codes, password resets, security alerts, invoices and receipts — because you cannot safely operate an account without them.
How to exercise them. Email support@wiltrak.tech with “Privacy request” in the subject. We will acknowledge promptly and respond within the statutory period — normally 30 days, extendable where a request is complex, in which case we will tell you why. We may need to verify your identity, and we may decline or partially fulfil a request where the law requires or permits us to (for example, where records must be kept for tax, audit, fraud prevention or the establishment or defence of legal claims). We do not charge for a first request; we may charge a reasonable fee for manifestly unfounded or repetitive requests.
Account deletion. See Request account deletion for how deletion works and why it is handled by a verified manual process rather than a one-click button.
If the data is in a customer’s workspace, see section 5 — the organization decides, and we will route your request to them.
16. Complaints
If you are unhappy with how we handle your data, contact us first at support@wiltrak.tech so we can put it right. You also have the right to complain to a supervisory authority:
- Kenya — Office of the Data Protection Commissioner (ODPC), Nairobi
- Uganda — Personal Data Protection Office
- Elsewhere — the data protection authority in your country of residence, work, or where the issue arose
You do not have to contact us first, but it usually resolves things faster.
17. Security
We protect data using: encryption in transit; encryption at rest for our managed database and object storage; role- and scope-based access control with strict separation between customer workspaces; multi-factor authentication and passkeys, with a step-up ceremony required for sensitive actions; dual authorization for sensitive platform actions; optional IP allowlisting and enterprise single sign-on; rate limiting; audit logging; least-privilege internal access; and regular backups.
No system is completely secure. If a breach affects your personal data, we will notify the affected customer organization within 72 hours of becoming aware, with the information they need to meet their own obligations, and we will notify affected individuals and the relevant authority where the law requires it.
If you believe you have found a security vulnerability, please email support@wiltrak.tech — see section 8.4 of the Terms for our responsible-disclosure position.
18. Children
The Service is for business use and is not directed at anyone under 18. We do not knowingly collect personal data from children. Customers must not record data about children in a workspace. If you believe a child’s data is in WilTrak, tell us at support@wiltrak.tech and we will act on it.
19. Changes to this policy
We may update this policy. For changes that materially affect how we use personal data, or that add a sub-processor, we will give at least 30 days’ notice by email to organization administrators or by in-dashboard notification before they take effect. Other changes take effect when posted. The “Last updated” date always reflects the current version, and superseded versions are available on request.
Contact
WilTrak Ltd., Nairobi, Kenya
support@wiltrak.tech (privacy and rights requests) · info@wiltrak.tech (general and legal)
See also: Terms and Conditions · Request account deletion