Privacy Policy
Your data, handled carefully.
This policy explains what we collect, why we need it, who may see it, how long we keep it, and how people can ask questions or exercise privacy rights.
Effective date: 18 June 2026. This policy is written with Kenya's Data Protection Act and Data Protection (General) Regulations in mind. It applies to Pangisha websites, admin portals, tenant portals, the tenant app experience, payment flows and support channels.
1. Who We Are
Pangisha is a cloud rent and property management platform operated by G&G Marketing or its authorised operator. You can reach us at info@ggmarketing.co.ke or 0793 553 860.
When a landlord or property manager enters tenant and portfolio data, that landlord or property manager usually decides why the data is used. Pangisha processes it so the service can work. For our own website, billing, support, security and platform administration, Pangisha decides how that data is used.
2. Personal Data We Collect
- Account data: names, email addresses, phone numbers, hashed passwords, roles, workspace names and session activity.
- Tenant verification data: tenant names as shown on ID, ID number, phone, email, building name, house or unit number, signup and reset information.
- Property data: building names, unit counts, unit numbers, tenancy status, rent amounts, balances, payment history and tenant records.
- Payment data: transaction references, amounts, currencies, status, receipts, phone number used for M-Pesa, Paystack references and provider metadata. We do not store full card numbers or card security codes.
- Communications: notices, replies, invoice emails, contact form messages, OTP emails, support requests and delivery status.
- Technical data: IP address, device/browser details, log data, security events, app install state, cookies, local storage and session identifiers.
3. How We Use Data
We use personal data to run tenant portals, admin dashboards, rent tracking, payments, notices, invoices, account security, support, billing, subscriptions, analytics, legal compliance and service improvement.
The legal basis depends on the situation. It may be contract performance, our legitimate interest in running and securing Pangisha, legal compliance, consent where needed, or protecting legal claims.
4. How Data Is Shared
We only share personal data where it is needed to run Pangisha, follow the law, protect the service, or carry out Customer instructions. Recipients may include:
- landlords, property managers, admins and tenants within the relevant portfolio;
- payment providers such as M-Pesa service providers and Paystack;
- email, hosting, domain, security and infrastructure providers such as Cloudflare and email delivery services;
- WhatsApp or messaging relay providers where messaging features are enabled;
- professional advisers, auditors, insurers, dispute-resolution bodies and public authorities where legally required.
5. International Transfers
Some providers may process or store data outside Kenya. Where that happens, we use appropriate safeguards, contracts, service-delivery necessity, consent where needed, or another lawful transfer route recognised by data protection law.
6. Security
We use security measures such as account controls, password hashing, session controls, access restrictions, encrypted provider secrets, security logging, role-based access and provider security controls. No internet service can promise perfect security, but we work to prevent unauthorised access, alteration, disclosure or loss.
7. Retention
We keep personal data only as long as reasonably needed. That may be to provide the service, meet accounting and tax duties, resolve disputes, keep security logs, enforce agreements or follow Customer instructions. The Data Retention and Deletion Policy gives the current schedule.
8. Your Rights
Subject to the law, people may ask to be informed about processing, access their data, correct inaccurate data, object to certain processing, restrict processing, request deletion, request portability where available, withdraw consent where consent is used, and complain to the Office of the Data Protection Commissioner.
Tenants should usually start with their landlord or property manager for tenancy records controlled by that Customer. You can also contact Pangisha at info@ggmarketing.co.ke, and we will either respond directly or help the relevant Customer respond.
9. Marketing
We may send product updates or marketing to Customers and prospective Customers where allowed. You can opt out by contacting us or using any unsubscribe option we provide. We do not sell tenant personal data.
10. Children
Pangisha is meant for landlords, property managers and tenants who can lawfully manage rental accounts. Customers must not upload children's personal data unless they have a lawful basis and any required parent or guardian consent.
11. Changes and Contact
We may update this Privacy Policy as Pangisha, the law or our providers change. Material changes will be posted here. Privacy questions can be sent to info@ggmarketing.co.ke.