Privacy Policy

Last updated: August 13, 2026

WilTrak helps producers, collectors, recyclers and regulators track materials and meet extended producer responsibility (EPR) obligations. This policy explains what personal data we handle, why, who we share it with, how long we keep it, and what rights you have.

It covers our marketing website (wiltrak.tech), the WilTrak dashboard, the WilTrak mobile app, and our APIs (together, the “Service”).

1. Who we are and how to reach us

WilTrak Ltd., Nairobi, Kenya, is the company behind the Service.

Please put “Privacy request” in the subject line so we can route it correctly.

2. The two roles we play — read this first

WilTrak is a business tool. Most of the personal data inside it was put there by a customer organization about other people — its own field staff, the waste collectors it pays, and contacts at producers and recyclers. Who is accountable for that data depends on which role applies.

We are the data controller — we decide why and how the data is processed — for:

  • account registration, login and profile data;
  • billing, payment and invoicing records;
  • support conversations with us;
  • security, fraud, abuse and signup-quality monitoring;
  • our audit logs of platform activity; and
  • our own communications and marketing to account holders and website visitors.

We are a data processor acting on our customer’s instructions — the customer organization is the controller — for the operational records inside a workspace: producers, products, batches, pickups, collectors, facilities, shipments, recovery transfers, payouts, levy records, uploaded photographs and uploaded documents.

If your data is in WilTrak because an organization put it there, that organization decides what happens to it, and its own privacy notice governs. See section 5. Our commitments to customers in that role are in Annex A of the Terms.

3. Personal data we collect as controller

You give us:

  • Identity and contact data — name, email address, phone number, organization, job role, country. Collected when you request a demo, sign up, contact us, or are added to an organization by its administrator.
  • Account credentials and authentication data — a hashed password (never the password itself), passkey (WebAuthn) public keys and credential identifiers, one-time codes we generate (stored hashed), your chosen multi-factor method, and notification preferences.
  • Billing data — billing country, tax status and identifiers, invoice and receipt history, plan, term, add-ons, subscription status, and payment references and authorization tokens issued by our payment provider. We never see or store your full card number, CVV, or bank credentials — those go directly to the payment provider.
  • Support and enquiry content — messages, attachments, demo requests, enterprise enquiries and service requests.

We collect automatically:

  • Usage and device data — pages and screens viewed, features used, approximate location derived from IP, browser and device type, operating system, app version, referral source, and timestamps.
  • Security and integrity data — IP address at signup and at login, login times and outcomes, failed authentication attempts, session and token metadata, rate-limit events, and error diagnostics.
  • Audit records — a log of who did what in a workspace: the acting user, the action, the affected record, and the time. Audit records are a security and integrity control and cannot be edited by users or by us.

We receive from others:

  • Payment status and authorization data from Paystack or DPO after you pay.
  • Identity assertions from your employer’s identity provider if your organization uses single sign-on — typically your email address, name and a subject identifier.
  • Delivery and bounce data from our email and SMS providers.

4. Personal data our customers put into WilTrak

When a customer organization uses WilTrak, its staff record field operations. Those records commonly include personal data about people who are not our users:

WhoWhat typically gets recorded
Collectors (waste collectors paid by the organization — they have no WilTrak login)Name, phone number, national identification number, an internal account ID, pickups attributed to them, weights and materials, performance targets and evaluations, payout records, and SMS messages sent to them about targets or incentives
Field agents and staff (organization employees using the app)Name, email, role and permissions, which records they created, the time of each action, the GPS coordinates captured when they record a pickup, photographs they take, and anomaly reviews they perform
Producer, recycler, facility and recovery-partner contactsName, organization, email, phone, registration numbers, addresses and site coordinates
Anyone appearing incidentallyPeople or vehicles visible in evidence photographs, and names appearing in uploaded compliance documents, permits and certificates

Location. GPS coordinates are captured at the moment a record is created, to evidence where a pickup happened. The mobile app does not perform continuous or background location tracking, and does not build a movement trail of a worker’s day.

Photographs. Evidence photos are uploaded, stored, and analysed by our material-classification model. Where a photo carries GPS metadata, we compare it against the submitted coordinates as a plausibility check. Most phone cameras strip this metadata, so its absence is normal and is not treated as suspicious on its own.

Offline data. The mobile app keeps unsent records on the device until they sync. Device security is the responsibility of the organization that issued or authorized the device.

5. If your data is in WilTrak because an organization put it there

If you are a collector, field agent, contact person, or anyone else whose data was entered into a WilTrak workspace by an organization:

  • The organization is the data controller. It decided to collect your data, it is responsible for telling you about it and for having a lawful basis, and it controls how long the data stays and who inside its team can see it.
  • Direct your requests to that organization first — access, correction, deletion, objection. We are contractually required to refer such requests back to them rather than act unilaterally, because acting alone could destroy records they are legally required to keep, or reveal data to the wrong person.
  • We will still help. Email support@wiltrak.tech and, if you tell us which organization is involved, we will pass your request on without undue delay and support them in responding. If you do not know which organization holds your data, tell us what you can and we will try to identify it.
  • You can always complain to a regulator (section 16), whether or not you go through the organization first.
What we doWhyLegal basis (KDPA / GDPR where applicable)
Create and administer accounts, authenticate usersTo let you use the ServicePerformance of a contract
Host and process workspace recordsTo provide the Service to our customerPerformance of a contract (with our customer); we act on their instructions as processor
Take payment, issue invoices and receipts, chase overdue amountsTo bill for the ServicePerformance of a contract; legal obligation (tax and accounting records)
Send verification codes, password resets, security alerts, invoices and service noticesEssential account and transaction messagesPerformance of a contract; legitimate interests (account security)
Prevent fraud, abuse, data falsification and unauthorized access; rate limiting; IP and signup-pattern checksTo keep the Service and its data trustworthyLegitimate interests (security and integrity of the Service, protection of third parties and regulators); legal obligation
Maintain audit logs of workspace activityAccountability and dispute resolutionLegitimate interests; performance of a contract
Provide support, including accessing a workspace to resolve an issueTo answer your requestsPerformance of a contract; legitimate interests
Monitor product quality, diagnose errors, plan capacityTo keep the Service working and improve itLegitimate interests
Improve classification and anomaly models using aggregated, de-identified dataTo make the product more accurateLegitimate interests (no identification of any person or organization)
Detect stalled or low-quality signups and send follow-up or escalate internallyTo manage abuse and support genuine customersLegitimate interests
Send product updates and marketingTo tell you about relevant features and offersConsent, or legitimate interests for existing business contacts — always with an opt-out
Website analytics and cookiesTo understand and improve the siteConsent
Respond to lawful requests, defend legal claims, meet regulatory dutiesLegal complianceLegal obligation; establishment, exercise or defence of legal claims

Where we rely on legitimate interests, we have assessed that our interest is not overridden by your rights. You can ask us for that assessment, and you can object (section 15).

7. Automated processing, profiling and AI

We use automated processing in a small number of places. None of it produces a legal or similarly significant effect on an individual on its own, and each has a human in the loop.

  • Material classification. An image model predicts the likely material class of a photographed item and returns a confidence score. It is a probabilistic aid, not a laboratory analysis, and can be wrong.
  • Anomaly detection. Rules flag pickups that look unusual — implausible weights, duplicate scans in a short window, mismatched materials, coordinates outside the expected service area, or photo metadata that disagrees with the submitted location. A flag is a prompt for a human to look, not an accusation. Flags are reviewed by the customer’s own staff, not by us.
  • Collector performance evaluation. Where a customer sets a target for a collector, the system compares recorded activity to that target on a schedule and may send the collector an SMS. The target, the reward and any consequence are set and applied by the customer, not by us.
  • Signup-quality monitoring. We assess new organizations for signs of abandoned or abusive signups, using signals such as whether an email address was ever verified, whether anyone returned after the first login, whether onboarding produced any real records, whether the email domain is a known disposable-address provider, and whether several signups share a signup IP address within a short window. The outcome is a follow-up email to the account administrator, or internal escalation to our team. It can result in a human decision to suspend an account for abuse; it never suspends an account by itself.
  • Data assistant (optional). Where an administrator enables it, questions asked in the “Ask WilTrak” widget are sent, together with a summary of that workspace’s own figures, to OpenAI to generate an answer. See section 9.

You can ask for human review of, or contest, any of these outcomes by emailing support@wiltrak.tech.

8. When WilTrak staff can see your data

We keep this deliberately narrow, and we log it.

Authorized WilTrak personnel may access a customer workspace only to: provide support that has been requested; investigate a technical, security, billing or abuse issue; comply with a legal obligation or lawful request; or protect the rights, property or safety of WilTrak, our customers, or others.

Some support and platform tasks are carried out by our staff entering a workspace through an internal “act as” mechanism, which gives them an administrator’s view of that workspace. This access:

  • is limited to designated superadmin and customer-care roles;
  • requires the staff member to complete a step-up authentication ceremony (a passkey or equivalent) at the time;
  • is time-limited and recorded in the workspace’s audit log, so the customer can see it;
  • requires a second authorization from a designated approver for sensitive platform actions such as changing a subscription, granting or revoking staff privileges, deactivating or deleting a user or organization, or recording a payout while acting as a customer; and
  • is never used to view, extract or use customer records for any other purpose.

We do not sell personal data, we do not share it with data brokers, and we do not use it for advertising or ad targeting.

9. Third parties we share data with

We share personal data only with the categories below. Each is bound by a written contract limiting what it may do with the data.

Sub-processors and infrastructure providers

ProviderPurposeData involvedPrimary locations
NeonManaged PostgreSQL database — the primary datastoreAll account and workspace recordsUnited States / European Union
KoyebApplication hosting for the API and dashboardAll data in transit through the applicationEuropean Union / United States
Cloudflare R2Object storage for evidence photos, uploaded documents, invoices and generated PDFsPhotographs, documents, PDFsGlobal (S3-compatible object storage)
PaystackPayment processing for subscription and service feesBilling name and email, amount, payment reference, card authorization tokenNigeria / South Africa / United States
DPO GroupAlternative payment processing for certain currenciesAs aboveKenya / South Africa
TwilioSMS delivery — one-time codes and collector notificationsPhone number, message contentUnited States
ExpoPush notification delivery to the mobile appDevice push token, notification contentUnited States
OpenAIOptional data assistant, only where an administrator enables itThe question asked, plus a summary of that workspace’s own aggregate figuresUnited States
Namecheap (Private Email / SMTP)Email delivery — verification codes, password resets, invoices, receipts, notificationsRecipient name and email, message content, invoice and receipt attachmentsUnited States
Google AnalyticsMarketing website analytics only — not used in the dashboard or mobile appPseudonymous identifiers, IP-derived approximate location, pages viewedUnited States

Error monitoring, diagnostics and material-image similarity search run on our own infrastructure, not through a third-party vendor.

We will give at least 30 days’ notice before adding or replacing a sub-processor that handles personal data, by updating this table and notifying organization administrators. Customers may object on reasonable data protection grounds — see Annex A6 of the Terms.

Others we may share with

  • Your own organization. If you are added to a workspace, its administrators can see your account details, your permissions, and your activity in the audit log.
  • Endpoints you configure. If your organization sets up webhooks or single sign-on, data is sent to the URL or identity provider you chose. Once it leaves our systems it is under your control, not ours.
  • Professional advisers — lawyers, auditors, accountants and insurers, under a duty of confidence.
  • Acquirers. If we are involved in a merger, acquisition, financing or sale of assets, data may be transferred as part of that transaction, subject to this policy continuing to apply. We will notify affected customers.
  • Authorities and affected parties. We may disclose data where required by law, court order or a lawful regulatory request; to establish, exercise or defend legal claims; to prevent or investigate fraud, security incidents or serious abuse; or to protect the rights, property or safety of any person. Where we reasonably believe records have been falsified in a way that affects a regulatory filing, a levy, a certificate, or a third party’s rights, we may notify the affected regulator, producer responsibility organisation, or counterparty and provide the relevant records — see section 8.3 of the Terms.

We will, where lawful and practicable, notify the affected customer before disclosing their data to an authority so they can seek protection.

10. Publicly accessible information

Two features deliberately expose limited data to people without an account:

  • Certificate verification. Anyone holding a certificate’s verification code can check the certificate’s status and the limited details shown on the verification page. This is the point of the feature — it lets a regulator, PRO or buyer confirm a certificate is genuine. Treat verification codes as semi-public.
  • Recovery transfer confirmation links. When a transfer is sent to a recycler for confirmation, the recycler receives a link with a time-limited, single-purpose token. Anyone holding that link, while it is valid, can view the transfer details and confirm or dispute it. Do not forward these links.

Do not put anything in a certificate, transfer note or reference field that you would not want a third party to read.

11. Cookies and similar technologies

Dashboard and mobile app. We use only what is strictly necessary: session and authentication cookies and tokens, secure storage of session credentials on the device, and preference storage (language, theme, notification settings). There is no advertising or cross-site tracking in the dashboard or the app.

Marketing website. In addition to strictly necessary cookies, we use Google Analytics 4 to understand how the site is used — which pages are visited, how visitors arrive, and roughly where they are, derived from IP address. These are not strictly necessary and we set them on the basis of consent.

You can control cookies through your browser settings, and you can opt out of Google Analytics using Google’s browser opt-out add-on. Blocking strictly necessary cookies will stop you being able to sign in.

12. Mobile app permissions and device data

The app asks only for what a specific feature needs, and you can decline or withdraw each one in your device settings:

  • Camera — to scan batch barcodes and QR codes and to take evidence photographs. Declining means you cannot record a pickup with photo evidence.
  • Location (while in use) — to capture the coordinates of a pickup at the moment you record it, for verification and compliance records. Not collected in the background and not used to build a movement trail.
  • Photo library — only where you choose to attach an existing image.
  • Face ID / fingerprint — optional, to unlock a restored session and to confirm sensitive actions.
  • Push notifications — optional, to deliver approval and operational alerts.

Biometrics. Face ID, Touch ID and fingerprint checks are performed entirely by your device’s operating system. Your fingerprint or face data never leaves your device, is never transmitted to us, and is never stored by us. We receive only a yes/no result. We do not collect or process biometric identifiers.

The app also stores a queue of unsent records and your session credentials on the device, in the operating system’s secure storage where available, so that field work continues without a connection. Signing out clears the session.

13. International transfers and data residency

WilTrak’s infrastructure runs on cloud providers and is not currently hosted in an East African data centre. Data collected in Kenya, Uganda, Tanzania, Rwanda, Ethiopia, Burundi or elsewhere in the region may be processed and stored outside the country where it was collected — principally in the European Union and the United States, as set out in the table in section 9.

Kenya’s Data Protection Act, 2019 and the Data Protection (General) Regulations, 2021, and Uganda’s Data Protection and Privacy Act, 2019, place conditions on transferring personal data out of the country, including demonstrating appropriate safeguards. We address this through:

  • encryption in transit, and encryption at rest for our managed database and object storage;
  • written data processing terms with every infrastructure provider, restricting what they may do with the data and requiring equivalent protection;
  • limiting cross-border transfer to what is operationally necessary to run the Service;
  • contractual transfer safeguards, including standard contractual clauses where a recipient relies on them; and
  • disclosing this practice here, so that organizations can assess it against their own regulatory obligations before they upload anything.

If your organization is subject to an in-country data residency requirement for particular record types, contact info@wiltrak.tech before onboarding. We cannot retrospectively relocate data you have already uploaded.

14. How long we keep data

We keep personal data only as long as we need it for the purposes above, or as the law requires. In practice:

DataRetention
Account and profile dataFor the life of the account. Deactivated and deleted users are retained in a disabled state so that the audit trail stays intact, with identifiers removed on request where the law allows
Workspace operational records (pickups, batches, collectors, documents, photographs)For the life of the subscription, then 30 days for export after termination, then deleted or irreversibly anonymized — except where retention is legally required
Billing, invoices, receipts and tax records7 years from the end of the relevant financial year, as required by Kenyan tax and company law
Audit logs of workspace and platform activity7 years, as a compliance and accountability record
Security and abuse data (login IPs, signup IP, failed attempts, rate-limit events)Up to 24 months, or longer where needed for an ongoing investigation or legal claim
Support conversations3 years from the last message
One-time codes, verification and reset codesMinutes — they expire on use or on their short timer, and are stored hashed
Marketing contacts and demo requests3 years from the last engagement, or until you unsubscribe
BackupsDeleted on their ordinary rotation cycle, normally within 35 days of the source record’s deletion
Aggregated, de-identified statisticsIndefinitely — these no longer identify anyone

Deletion from live systems happens first; backups follow on their rotation. During that window, data is not restored or used except for disaster recovery.

15. Your rights

Subject to applicable law, you may ask us to:

  • access the personal data we hold about you, and receive a copy;
  • correct data that is inaccurate or incomplete;
  • delete data, where we no longer have a lawful reason to keep it;
  • restrict or object to processing, including profiling and processing based on legitimate interests;
  • port data you gave us, in a structured, commonly used, machine-readable format;
  • withdraw consent at any time, where we relied on consent — this does not affect processing already carried out; and
  • opt out of marketing at any time, using the unsubscribe link, your notification preferences in the dashboard or app, or by emailing us. We will still send essential transactional messages — verification codes, password resets, security alerts, invoices and receipts — because you cannot safely operate an account without them.

How to exercise them. Email support@wiltrak.tech with “Privacy request” in the subject. We will acknowledge promptly and respond within the statutory period — normally 30 days, extendable where a request is complex, in which case we will tell you why. We may need to verify your identity, and we may decline or partially fulfil a request where the law requires or permits us to (for example, where records must be kept for tax, audit, fraud prevention or the establishment or defence of legal claims). We do not charge for a first request; we may charge a reasonable fee for manifestly unfounded or repetitive requests.

Account deletion. See Request account deletion for how deletion works and why it is handled by a verified manual process rather than a one-click button.

If the data is in a customer’s workspace, see section 5 — the organization decides, and we will route your request to them.

16. Complaints

If you are unhappy with how we handle your data, contact us first at support@wiltrak.tech so we can put it right. You also have the right to complain to a supervisory authority:

  • Kenya — Office of the Data Protection Commissioner (ODPC), Nairobi
  • Uganda — Personal Data Protection Office
  • Elsewhere — the data protection authority in your country of residence, work, or where the issue arose

You do not have to contact us first, but it usually resolves things faster.

17. Security

We protect data using: encryption in transit; encryption at rest for our managed database and object storage; role- and scope-based access control with strict separation between customer workspaces; multi-factor authentication and passkeys, with a step-up ceremony required for sensitive actions; dual authorization for sensitive platform actions; optional IP allowlisting and enterprise single sign-on; rate limiting; audit logging; least-privilege internal access; and regular backups.

No system is completely secure. If a breach affects your personal data, we will notify the affected customer organization within 72 hours of becoming aware, with the information they need to meet their own obligations, and we will notify affected individuals and the relevant authority where the law requires it.

If you believe you have found a security vulnerability, please email support@wiltrak.tech — see section 8.4 of the Terms for our responsible-disclosure position.

18. Children

The Service is for business use and is not directed at anyone under 18. We do not knowingly collect personal data from children. Customers must not record data about children in a workspace. If you believe a child’s data is in WilTrak, tell us at support@wiltrak.tech and we will act on it.

19. Changes to this policy

We may update this policy. For changes that materially affect how we use personal data, or that add a sub-processor, we will give at least 30 days’ notice by email to organization administrators or by in-dashboard notification before they take effect. Other changes take effect when posted. The “Last updated” date always reflects the current version, and superseded versions are available on request.

Contact

WilTrak Ltd., Nairobi, Kenya

support@wiltrak.tech (privacy and rights requests) · info@wiltrak.tech (general and legal)

See also: Terms and Conditions · Request account deletion