Privacy Policy
How Tambo handles your personal data — what we collect, why, how long we keep it, who else sees it, and what you can tell us to do about it.
We do not sell your personal data. We do not use it for advertising. We do not share it with data brokers. Tambo has no advertising SDKs in it.
The short version
| What we collect | Why | How long we keep it | Who else sees it |
|---|---|---|---|
| Your name, email address and WhatsApp number | To create your account and to deliver theft reports to you | While your account exists, then 30 days | Our email and WhatsApp delivery providers |
| Your device make, model, Android version, and the IMEI and serial you enter | To identify the device being protected and to include the IMEI in reports you give the police | While the device is on your account, then 30 days | Nobody outside Tambo unless you send a report |
| Your device location, continuously and in the background | So a stolen phone can report where it is | 90 days. Locations attached to a theft event: 12 months | The recipients you nominate; our hosting provider |
| A photograph from the front camera, only after a failed unlock attempt | To show you who has your phone | 12 months from the theft event, then deleted | The recipients you nominate; our hosting and messaging providers |
| Security events — failed unlock counts, SIM changes, reset attempts | To trigger reports and to show you what happened | 12 months | The recipients you nominate |
| Your M-PESA number, transaction reference and amount — not collected while Tambo is free | To take payment and to prove you paid | 7 years, because tax law requires it | Safaricom M-PESA; our payment processor; KRA on lawful demand |
| Crash and diagnostic logs, and your IP address | To find and fix faults, and to prevent abuse | 90 days | Our hosting and crash-reporting providers |
1Who we are
Tambo is a mobile anti-theft application published by Hoodlynk Innovations (registered company name and number), of registered postal address, Kenya ("we", "us", "Tambo"). Hoodlynk Innovations is the data controller for the personal data described in this policy.
Our registration with the Office of the Data Protection Commissioner is [ODPC registration number]. Our Data Protection Officer can be reached at privacy@tambo-app.com.
This policy applies to the Tambo Android application, this website, and the reports Tambo sends by email and WhatsApp. It is available at https://tambo-app.com/privacy without needing an account or a login.
2What Tambo does, in plain terms
Understanding the product makes the rest of this policy easier to read. Tambo runs on an Android phone you own. It records where that phone is, and when someone fails to unlock it, it takes a photograph with the front camera. It then sends that photograph, the location, the time and the device IMEI to the destinations you chose during setup — your email address, your WhatsApp number, and a trusted contact if you named one. It does this quietly, so that a person who has taken your phone is not prompted to remove the app.
Everything Tambo collects exists to make that one sequence of events work. Where a piece of data is not needed for it, we do not collect it.
3The personal data we collect, and why
Account and contact data
Your full name, email address, mobile number in international format, a hashed password, and your language choice. We collect these because they are the address the report is delivered to. Without a reachable email address and phone number the product does not work at all.
Trusted contact data
If you nominate a trusted contact, we collect their name, phone number and the relationship you describe. You are asking us to send that person your theft reports. You must have their permission before you enter their details. We will tell them, on first contact, that you added them and how to ask us to stop.
Device data
The make, model, Android version and Tambo version of the device; a Tambo installation identifier; the mobile network and the SIM number in use; and the battery level reported alongside each location.
We also store the IMEI and serial number of the device. On current versions of Android an application like Tambo is not permitted to read these from the phone, so you enter them yourself during setup. We keep them so we can put them in your reports — the IMEI is the first thing the police and your mobile network will ask for.
Location data
Latitude and longitude, the accuracy radius, the source of the fix (satellite, mobile network or Wi-Fi) and the time. Tambo requests location access all the time, including when the app is closed and the screen is off, because a stolen phone will not be in your hand to open the app with.
Location is collected at the interval you set — by default every fifteen minutes — and more frequently once you mark a device as stolen. When the phone has no connection the readings are held on the device and sent when a connection returns.
Photographs from the camera
A single still image from the front-facing camera, captured only after the number of failed unlock attempts you configured. No image is captured at any other time. Tambo does not record video, does not record audio, does not use the rear camera, and does not read the photographs already on your phone.
A photograph of a face may be treated as biometric data, and therefore as sensitive personal data, under the Data Protection Act 2019. We handle these images accordingly: they are encrypted, access is restricted, and they are deleted on the schedule set out below.
Security event data
The number and timing of failed unlock attempts and the method attempted; changes of SIM card, including the new number where the phone can read it; attempts to remove Tambo or to reset the device; and whether protection was on or off at the time.
Delivery records
Which report went to which recipient, when it was sent, and whether it was accepted for delivery. We keep these so that you can prove a report was sent, and so we can investigate when one does not arrive.
Payment data
Not currently applicable. Tambo is free while we are in beta. Nothing in this section applies until a paid plan is introduced, and we will give at least 14 days' notice by email and in the app before that happens.
The M-PESA number you paid from, the transaction reference, the amount and the date. If you pay by card, the card details are handled by our payment processor and never reach our systems; we receive only a token, the last four digits and the outcome.
Technical data
Crash reports, performance diagnostics, the app version, and the IP address the app connects from. We use these to fix faults and to detect abuse of the service.
4What Tambo does not collect
- The contents of your messages, calls, email or chats.
- Your call log or your contacts, other than the trusted contact you type in yourself.
- Photographs, videos or files already stored on your phone.
- Audio or video recordings. Tambo captures single still images only.
- Your browsing history, your app usage, or your keystrokes.
- Any data at all from a device that is not registered to your account.
Tambo contains no advertising software development kits and no third-party trackers for marketing purposes.
5Our lawful basis for each use
Under section 30 of the Data Protection Act 2019 we must have a lawful basis for processing your personal data. These are ours.
| What we do | Lawful basis |
|---|---|
| Create and run your account; deliver reports to your chosen recipients; take payment | Performance of the contract between you and us |
| Collect your location continuously in the background | Your explicit consent, given in the app before the permission is requested, and withdrawable at any time |
| Capture a photograph after a failed unlock attempt | Your explicit consent, given in the app before the permission is requested, and withdrawable at any time |
| Keep security event and delivery records | Our legitimate interest in providing a service that can be shown to have worked, and yours in being able to prove it |
| Fix faults, prevent fraud and abuse | Our legitimate interest in a working and secure service |
| Keep payment records for seven years | Compliance with a legal obligation under Kenyan tax law |
| Respond to a lawful request from the police or a court | Compliance with a legal obligation |
Where we rely on consent, you can withdraw it at any time by turning the relevant permission off in Android settings or in Tambo, or by deleting your account. Withdrawing consent for location or camera access stops the corresponding protection working — the app will tell you so plainly rather than continuing to imply you are protected.
6Photographs of other people
This deserves its own section, because an intruder photograph is a photograph of somebody who did not agree to be photographed.
We process that image on the basis of the legitimate interests of the device owner and of Tambo in preventing and detecting theft, and in establishing, exercising or defending a legal claim. We have weighed that against the privacy of the person photographed and consider it proportionate: the image is captured only after a deliberate failed attempt to unlock a device that is not the person's own, it is a single still image, and it goes only to the device owner and their nominated recipients.
What you may do with such an image is limited by our Terms of Service and by Kenyan law. In short: give it to the police. Do not publish it, do not post it on social media, and do not use it to confront, accuse or pursue anyone. A photograph proves that a person handled a phone; it does not prove who stole it, and a wrongly accused person has rights against you.
If you believe Tambo holds a photograph of you and you are not the account holder, write to privacy@tambo-app.com. You have rights over that image and we will deal with your request under the section on your rights below.
7Who else sees your data
The recipients you choose
The whole purpose of Tambo is to send your data somewhere off the phone. When a report is generated it goes to the email addresses, WhatsApp numbers and trusted contact on your account. You control that list and can change it at any time. Anyone on it will see the intruder photograph, the location and the device details.
Service providers who process data for us
| Provider | What they do | What they see |
|---|---|---|
| cloud hosting provider | Hosts the service and stores your data | All stored data, encrypted at rest |
| [WhatsApp Business API provider] and Meta Platforms | Delivers WhatsApp reports | The message content, including the photograph, and the recipient number |
| transactional email provider | Delivers email reports | The message content, including the photograph, and the recipient address |
| [SMS provider] | Sends verification codes | Your phone number and the code |
| Safaricom PLC (M-PESA) | Takes mobile money payments | Your M-PESA number, the amount and the reference |
| card payment processor | Takes card payments | Your card details, which we never see |
| crash reporting provider | Collects crash diagnostics | Device model, Android version, crash traces, IP address |
Each of these is bound by a written agreement to process data only on our instructions, to keep it secure, and to delete it when we tell them to. A current list is maintained at subprocessor list URL and we will give you notice before we add one that handles location or camera data.
Note on WhatsApp specifically: delivering a report by WhatsApp means the photograph and location pass through WhatsApp's systems, and Meta's own terms apply to that message. If you would rather they did not, use email delivery only — you can turn WhatsApp delivery off in Tambo.
Police, courts and regulators
We will disclose data where we are legally obliged to, for example under a court order or a lawful police request. We will tell you when that happens unless we are prohibited from doing so. We do not give bulk access to anyone.
A change of ownership
If Tambo or registered company name and number is sold or merged, your data may pass to the buyer. We will give you notice, and the buyer will be bound by this policy until it is lawfully replaced.
8Where your data is stored, and transfers out of Kenya
Your data is stored in cloud region — to be confirmed before launch. Some of our service providers operate outside Kenya, which means your personal data may be transferred out of the country.
Where that happens we rely on the safeguards permitted by sections 48 and 49 of the Data Protection Act 2019: written contracts imposing standard data protection clauses, a documented assessment that the destination provides appropriate protection, and — for location and camera data — your consent to the transfer, which we ask for separately during setup.
You may ask us for a copy of the safeguards that apply to a particular transfer by writing to privacy@tambo-app.com.
9How long we keep things
| Data | Retention | Why this period |
|---|---|---|
| Routine location check-ins | 90 days, then deleted automatically | Long enough to reconstruct a trail after a delayed report; short enough that we are not holding a year of your movements for no reason |
| Locations, photographs and event records attached to a theft event | 12 months from the event | Roughly the life of a police case or an insurance claim. You can ask us to delete them sooner |
| Account and device details | While your account is open, then 30 days | The 30 days let you change your mind about deleting |
| Delivery records | 12 months | So a report can be shown to have been sent |
| Payment records | 7 years | Required by Kenyan tax law |
| Crash and diagnostic logs | 90 days | Enough to diagnose a recurring fault |
| Backups | Deleted within 35 days of the live record being deleted | Backups roll on a cycle; a deletion propagates as the cycle turns |
When a retention period ends, records are deleted or irreversibly anonymised. We may keep an anonymous count of events for statistics, from which you cannot be identified.
10How we protect your data
- Encrypted in transit using TLS 1.2 or better, on every connection.
- Encrypted at rest, including photographs and location records.
- Access limited to named staff who need it for a specific task, with multi-factor authentication, and every access logged.
- Photographs and locations are not visible to our support staff by default; access requires a recorded reason and, for photographs, a second approval.
- Passwords stored only as salted hashes. We can never see your password.
- Regular vulnerability testing, and an independent penetration test before launch and annually after it.
If a breach occurs that is likely to affect your rights, we will notify the Office of the Data Protection Commissioner within 72 hours of becoming aware of it, and tell you without undue delay, in plain language, what happened and what to do.
No system is perfectly secure. We say what we do rather than promising that nothing can go wrong.
11Your rights
Under the Data Protection Act 2019 you have the right to:
- be told how your data is used — this policy;
- get a copy of the data we hold about you;
- have inaccurate data corrected;
- have your data deleted, subject to records we must keep by law;
- object to processing, or ask us to restrict it;
- receive your data in a portable format;
- withdraw a consent you gave, at any time; and
- complain to the Office of the Data Protection Commissioner.
To exercise any of these, write to privacy@tambo-app.com or use the form at https://tambo-app.com/support. We will acknowledge within 7 days and respond within 30 days. There is no charge. We may ask you to confirm your identity, because handing your location history to somebody impersonating you would be the worse outcome.
You can delete your account and data yourself, without contacting us, from within Tambo or at https://tambo-app.com/delete-my-data. What that removes and what it does not is set out on that page.
If you are unhappy with how we have handled a request you may complain to the Office of the Data Protection Commissioner, [ODPC contact details].
12Children
Tambo is not intended for anyone under 18 and we do not knowingly create accounts for children. A parent or guardian may protect a child's phone using their own Tambo account, in which case the reports come to the parent. If you believe a child has created an account, write to privacy@tambo-app.com and we will delete it.
13Automated decisions
Tambo decides automatically when to capture a photograph and when to send a report, based on the failed-attempt threshold you set. That is the product working as you configured it. We do not use your data for profiling, scoring, or any automated decision that has a legal effect on you.
14Changes to this policy
If we change this policy we will post the new version here with a new date. Where a change materially affects how we use your data, we will tell you in the app and by email at least 14 days before it takes effect, and where the law requires it we will ask for your consent again rather than assuming it.
Previous versions are kept at policy archive URL so you can see what changed.
15Contact us
Hoodlynk Innovations · registered postal address · Kenya
- Data Protection Officer: privacy@tambo-app.com
- General support: support@tambo-app.com
- Support WhatsApp: support WhatsApp number
- ODPC registration: [ODPC registration number]