Legal / Privacy
Your information should work for you, not against you.
Last updated: 27 August 2026
This Privacy Policy explains how Sinaps Technology ("Vyroo", "we", "us", or "our") handles personal information when you use the Vyroo mobile app, browse this website, create or manage an event, attend an event, contact us, or use a service connected to Vyroo. It applies to information we control and to information processed for us by service providers.
This notice is written for the current product and may be updated as the product grows. It is not a substitute for advice from qualified Kenyan privacy counsel. We will not use this policy to reduce a right that cannot lawfully be excluded.
1. Who is responsible for your information
Vyroo is the controller of the account, event, attendance, platform-security, and support information it determines how to use. An organizer may separately be responsible for information they collect or upload for their own event. Where a provider processes information only on our instructions, it acts as our processor or service provider.
For privacy questions, access, correction, objection, portability, or deletion requests, contact privacy@vyroo.app. We may ask for reasonable information to confirm that a request relates to the correct account.
2. Information we collect
We collect information you give us, information created when you use Vyroo, and limited information from providers that verify or support the service. Depending on how you use Vyroo, this can include:
- account details: display name, email, phone number, profile information, and preferences;
- identity and security data: Firebase phone or Google sign-in identifiers, verification timestamps, refresh sessions, device and installation details, and security events;
- event data: title, description, category, tags, venue, canonical place details, coordinates supplied for the event, dates, capacity, price, visibility, poster, and organizer updates;
- participation data: RSVPs, interest, waitlist position, attendance, entry-pass status, invitations, event staff assignments, and check-in records;
- community data: squads, follows or connections, messages, replies, reactions, calls or signalling metadata, and public or circle-limited experiences and media;
- payment data: order amount, currency, provider, transaction and refund references, status, timestamps, failure or reconciliation details, and the email needed by a payment provider. Vyroo does not receive or store your full card number, PIN, or payment password;
- device and delivery data: push-notification token, platform, app version, approximate device label, delivery attempts, and notification read or expiry state;
- support and communications: messages, attachments, account or transaction references, and records needed to respond; and
- website data: IP address, browser/device information, security logs, and information submitted through a contact or organizer enquiry. The current public website does not require non-essential advertising or analytics cookies to browse.
3. Location and map information
Organizers may enter a venue and use Google Places, geocoding, or map features to resolve a canonical place, label, place ID, or coordinates for an event. We use this to display an event’s location, support discovery, prevent ambiguous venues, and link to maps. Do not put a private home address or another person’s precise location in a public event unless authorised. The app may retain a coarse location label associated with a session or device for operational context; it is not a promise that Vyroo continuously tracks your device location.
4. Why we use information
- create accounts, verify identity, authenticate sessions, and secure access;
- publish, index, search, recommend, and display public events and organizer information;
- manage RSVPs, capacity, waitlists, invitations, entry passes, event updates, staff permissions, and check-in;
- initialize, verify, reconcile, refund, and audit payments, and prevent duplicate, fraudulent, or reversed transactions;
- deliver push notifications and essential service communications;
- host, process, moderate, secure, and show media and community content according to its visibility settings;
- provide Organizer Pro or other paid entitlements after provider confirmation;
- diagnose failures, protect users, investigate abuse, enforce terms, and defend legal claims; and
- meet legal, accounting, tax, regulatory, and law-enforcement obligations.
5. Legal grounds
The applicable legal basis depends on the activity. We may rely on performance of a contract or steps you request before a contract, consent where required, our legitimate interests in operating a safe event platform, compliance with a legal obligation, or protection of vital interests. When we rely on consent, you can withdraw it for future processing; withdrawal does not undo lawful processing or prevent processing required for safety, payment, or law.
6. Public, private, and shared information
A published public event may be visible to anyone and indexed by search engines. This can include its title, description, category, date, time, venue, public location, poster, price, capacity summary, organizer display information, and public updates. Public content can be copied or retained by people outside Vyroo.
Private events, account details, payment records, staff tools, attendance records, private messages, squad content, and restricted media are access-controlled and are not intended to be public listings. You remain responsible for choosing an appropriate visibility setting.
7. Providers and sharing
We share only what is reasonably necessary for a stated purpose. Current service categories include Firebase for sign-in proofs and push notifications; Google Maps Platform for venue search and geocoding; Paystack and enabled payment providers for payments and refunds; RevenueCat or an equivalent service for Organizer Pro entitlements; and cloud hosting, databases, queues, monitoring, email, and R2-compatible object storage for the service and media. We may also share relevant event information with organizers, event staff, attendees, or authorities where the workflow, your settings, your request, safety, or law permits it.
We do not sell personal information or share account or payment information for third-party advertising. We may disclose information to professional advisers, a successor in a merger or acquisition, or public authorities where necessary and lawful.
8. International processing
Some providers may process information outside Kenya. Before transferring personal information, we use an applicable lawful transfer route and appropriate contractual, organisational, or technical safeguards, and obtain consent where the law requires it. Contact us if you need information about safeguards for a particular request.
9. Security and incidents
We use measures appropriate to the risk, including encrypted connections, provider-side verification, access controls, account-scoped authorization, hashed session credentials, payment signature checks, limited webhook records, and audit trails. No service or transmission is completely secure. Never send us an OTP, password, PIN, full card number, or secret key.
If we discover a personal-data incident that requires notice, we will assess it, contain it, document it, notify the relevant regulator within the applicable period, and communicate with affected people where required and reasonably practicable.
10. Retention and deletion
We keep identifiable information only for as long as needed for the purpose collected, the active relationship, safety and abuse prevention, payment/refund reconciliation, accounting, disputes, legal claims, or another lawful purpose. Retention depends on the record: public event content may remain while needed; financial and audit records may need a longer statutory or dispute period; security logs, delivery records, caches, backups, and derived media are expired or removed under operational schedules. We delete, anonymise, or pseudonymise information that is no longer authorised to be retained.
11. Account closure and deletion requests
You may request deletion through the supported account flow or by contacting us. For security, we may require a fresh sign-in proof and an idempotency reference. A valid request immediately revokes active sessions and stops profile discoverability while pending. The current service supports a short, configurable cooling-off period so you can cancel before irreversible purge begins.
When deletion becomes due, Vyroo schedules a bounded purge. This removes or anonymises the account profile, sessions, provider identity links, discoverability, push registrations, and account-owned content where authorised. We then request deletion of linked authentication-provider identities. A provider outage, fraud investigation, legal hold, unresolved payment/refund, or evidence requirement may delay or limit deletion; we retain only the narrow information needed for that reason and record the restriction. Information already made public or copied by others may continue outside our control. Deletion does not erase another person’s lawful records or remove a legal obligation.
12. Your rights and how to exercise them
Subject to applicable exceptions, you may ask to be informed, access your information, correct inaccurate or misleading data, object to processing, withdraw consent, request erasure, request portability where technically available, or complain about our handling. Send requests to privacy@vyroo.app with enough context to locate the record. We will respond within the period required by applicable law, or explain why an exception or extension applies. Requests are normally free; a lawful, reasonable fee may apply only where permitted for manifestly unfounded or excessive requests.
If you are not satisfied with how we handle a privacy request, you may contact us first so we can investigate. You may also contact the Office of the Data Protection Commissioner in Kenya or another competent authority where applicable. This does not limit any right or remedy available under data-protection law.
13. Children and age-appropriate use
Vyroo is not designed to knowingly collect personal information from children without the consent and involvement required by law. Do not create an account for a child or upload a child’s information unless you have authority and required consent. If you believe a child’s information was submitted improperly, contact privacy@vyroo.app.
14. Changes and contact
We may revise this policy when the product, providers, or law changes. The current version and date will appear on this page; material changes will be communicated through an appropriate channel where required. Contact privacy@vyroo.app for privacy requests, support@vyroo.app for account or payment support, and legal@vyroo.app for legal notices.