Privacy Policy
This policy explains how Tufariji handles personal data for memorial creators, collaborators, visitors, and partners using the platform.
Tufariji ("Tufariji", "we", "us" or "our") operates a digital memorial and funeral coordination platform designed primarily for use in Kenya. Our service allows families, their representatives, and partners such as funeral homes and churches to create and share online memorial and funeral pages (the "Service").
We are committed to protecting the privacy of everyone who uses our Service in line with the Data Protection Act, No. 24 of 2019 of the Laws of Kenya and the Data Protection (General) Regulations, 2021.
This Privacy Policy explains how we collect, use, disclose, and protect personal data when you use Tufariji, and describes your rights as a data subject under Kenyan law.
1. Data controller, scope, and legal basis
1.1 Data controller and contact details
For the purposes of the Data Protection Act, Tufariji is the data controller in respect of personal data processed through our platform.
Data Controller: Tufariji
Jurisdiction: Republic of Kenya
Primary users: Individuals and organizations located in or dealing with funerals in Kenya
If you have any questions or concerns about this Privacy Policy or how we handle your personal data, contact us at privacy@tufariji.co.ke.
We may designate a data protection contact or officer as our operations grow, and any such details will be added here and on our website.
1.2 Scope of this Privacy Policy
This Privacy Policy applies to personal data that we collect and process when:
- You visit or interact with our website and public memorial pages.
- You create, edit, or administer a memorial or funeral page, including as a family coordinator or partner.
- You view a memorial page and submit content, such as condolences or stories, where enabled.
- You contact us via email, contact forms, or support channels.
This Privacy Policy does not apply to:
- Third-party websites, platforms, or services accessed through Tufariji, such as YouTube, Facebook Live, payment gateways, or Google Maps.
- Processing that our partners carry out independently of Tufariji in their own systems.
1.3 Legal basis and processing principles
We process personal data in accordance with the principles and obligations set out in Kenyan data protection law, including:
- Lawfulness, fairness, and transparency: we process personal data only where there is a valid legal basis and in a transparent manner.
- Purpose limitation: we collect and process personal data only for specific, explicit, and legitimate purposes related to providing and improving the Service.
- Data minimization: we only collect personal data that is adequate, relevant, and limited to what is necessary for those purposes.
- Accuracy: we take reasonable steps to ensure personal data is accurate and kept up to date where necessary.
- Storage limitation: we retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law.
- Integrity and confidentiality: we use appropriate technical and organizational measures to secure personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage.
Our primary legal bases for processing personal data are consent, performance of a contract, compliance with a legal obligation, and legitimate interests.
2. Personal data we collect
2.1 Account and profile information
When you create an account, including as a family coordinator or partner, we may collect:
- Name
- Email address
- Authentication-related details, such as OAuth identifiers or magic-link token logs
- Basic account metadata, including account type and roles such as owner, admin, or contributor
We do not store your password where we use federated login or magic-link authentication.
2.2 Memorial page content
For each memorial page, the creator or collaborators may provide:
- Full name of the deceased
- Dates of birth and death
- Biography or obituary text
- Photos of the deceased and related events
- Funeral program details and uploaded PDF
- Event information including date, time, venue name, address, and map links
- Hymn titles and, where added, lyrics
- Eulogies, tributes, stories, timeline milestones, optional scripture verses, or epitaphs
This content may include personal data of the deceased and living individuals, such as names and relationships of family members or authors of tributes. It is provided and managed by the page creator and collaborators.
2.3 Visitor submissions
If the memorial page owner enables interactive features such as a condolence wall or stories, visitors may submit:
- Name or chosen display name
- Email address, where configured
- Message content such as condolences, stories, or tributes
- Date and time of submission
- Moderation status and related activity, such as approved, rejected, or edited
2.4 Payment, technical, and support data
For paid tiers or other monetized features, we collect limited payment-related data such as:
- Payment reference numbers or transaction IDs returned by payment providers
- Tier purchased and related billing metadata
We do not store your full payment instrument details, such as card numbers. These are processed by the relevant payment providers under their own privacy policies.
When you access or use the Service, we may automatically collect technical and usage data such as:
- IP address and general location derived from it
- Device type, operating system, and browser type
- Referring site or source
- Pages viewed, actions taken, and timestamps
- Basic performance and error logs
If you contact us for support, we may also collect your contact details, message content, attachments, and internal notes relating to your request.
3. How we use personal data
We may use the personal data described above for the following purposes:
- Providing the Service. This includes creating, hosting, and displaying memorial pages, enabling owners and collaborators to manage content, and allowing visitors to view pages, submit messages, and access directions, programs, and live streams.
- Account management and security. This includes creating and managing accounts, authenticating users, authorizing access to memorials and dashboards, and detecting or preventing fraud, abuse, or misuse of the Service.
- Payments and billing. This includes initiating and verifying payments for paid tiers and recording payment references for accounting and audit purposes.
- Improving and developing the Service. This includes understanding how users interact with the Service, debugging issues, and improving usability and performance.
- Communications. This includes responding to requests and sending essential service messages such as account notices, passwordless login links, and page expiry reminders.
- Compliance and enforcement. This includes complying with legal obligations and enforcing our Terms of Service, including investigating potential violations.
We do not use personal data for direct marketing without your explicit consent, and we do not sell your personal data.