Privacy Policy
Effective date: August 11, 2026 · Last updated: August 11, 2026
1 Scope
This Privacy Policy explains how QuickDuuka ("we", "us") collects, uses, stores, and protects personal information in connection with QuickRentals (the "Service"). It applies to landlord owners, managers, staff users, and — where relevant — tenants whose information is entered into the Service by our customers.
2 The roles: controller and processor
3 What we collect
From owners & team members (account holders)
- Business name, business type, country, currency, timezone, address.
- Owner and team-member name, email, phone number, hashed password.
- Login timestamps, IP address, browser/device information for security purposes.
Data you enter about your rental business
- Branch names, addresses, managers, houses, categories.
- Tenant records: name, phone, email, national ID (if you choose to record it), address, move-in / move-out dates, deposit.
- Invoices, payments (amount, method, reference), expenses.
- Content of any messages you send to tenants via the Service.
Technical data
- Server logs, error reports, and basic analytics necessary to operate the Service.
- Cookies used for authentication and session management only. We do not use third-party tracking or advertising cookies.
4 How we use the data
- To provide the Service you signed up for.
- To authenticate users and enforce role-based permissions.
- To send transactional notifications you configure (e.g. new-user welcome emails, payment-recorded notifications).
- To pass messages to third-party gateways (SMS via Africa's Talking, email via your configured SMTP provider) when you use the messaging features.
- To secure the Service, detect abuse, comply with legal obligations, and improve the product.
We do not sell your data. We do not use your data to train advertising models or profile your tenants.
5 Sub-processors
We rely on a small number of trusted infrastructure providers to run the Service. Current sub-processors:
- Cloud hosting & database: QuickDuuka production infrastructure (Postgres, container hosting).
- SMS delivery: Africa's Talking, when you enable SMS features.
- Email delivery: your configured SMTP provider.
Each sub-processor is contractually bound to appropriate security and confidentiality obligations. We will update this list as sub-processors change and give you reasonable notice of material changes.
6 Security
We take reasonable and appropriate technical and organisational measures to protect your data, including:
- Passwords hashed with bcrypt — we never see your plain-text password.
- HTTPS/TLS encryption in transit.
- Encryption of database backups at rest.
- Role-based access control at the application layer — each landlord's data is scoped by their landlord ID; other landlords cannot see it.
- Regular security patching of our operating system, PHP runtime, and dependencies.
- Access to production infrastructure is restricted to a small number of authorised engineers under confidentiality obligations.
7 Data retention
We retain your data for as long as your account is active. When you close your account, we will delete or anonymise your data within 90 days, except where we are required to keep it longer to comply with tax, accounting, or legal obligations. You can request an export of your data before closing your account.
8 Your rights & your tenants' rights
Depending on your jurisdiction, you and your tenants may have rights to access, correct, delete, or restrict the processing of personal data. For your own account data, you can update most information from Settings inside the Service, or email us at privacy@quickduuka.com.
Because you are the data controller for tenant information, requests from your tenants should be directed to you first. We will support you in responding to those requests where technically feasible.
9 International transfers
Data may be processed in data centres located in the country of our hosting provider. Where data is transferred across borders, we rely on appropriate safeguards including contractual clauses with our sub-processors.
10 Children
The Service is not intended for individuals under 18. We do not knowingly collect data from children. If you believe we have, contact privacy@quickduuka.com and we will delete it promptly.
11 Data-breach notification
In the unlikely event of a personal-data breach that is likely to result in a risk to your rights, we will notify you without undue delay and, where required, notify the appropriate regulator in accordance with applicable law.
12 Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified via email or an in-app notice. The "Last updated" date at the top always shows the current version.
13 Contact
Questions or requests about your data? Email privacy@quickduuka.com.