Legal & Compliance

Global Privacy Policy

This comprehensive document details NearLink's protocols for data processing, algorithmic decision-making, and compliance with international regulations including GDPR, CCPA, and the Kenya Data Protection Act.

Effective: January 14, 2026Version: 3.0 (Enterprise)
01. PREAMBLE

Definitions & Scope

NearLink Inc. ("NearLink", "we", "us", or "our") provides a multi-sided digital platform. This Privacy Policy applies to all users of our ecosystem, including Guests, Hosts, Drivers, and Experience Providers.

Data Controller

NearLink Inc. is the Data Controller for data collected directly from you (e.g., account creation, booking requests).

Data Processor

For certain corporate services, NearLink acts as a Data Processor on behalf of enterprise clients.

02. COLLECTION

Data Collection Protocols

Biometric & Identity Data

To comply with Anti-Money Laundering (AML) and Know Your Customer (KYC) regulations, we collect:

  • Government ID: Images of National ID, Passport, or Driver's License.
  • Facial Recognition: "Selfie" imagery used solely for liveness checks and matching against Government ID.
  • Background Check Data: Criminal history and credit reports (where permitted by law) for Hosts and Drivers.

Telematics & Mobility Data

For our Transport and Mobility services, we collect granular sensor data:

  • Precise Geo-location: GPS data collected in foreground and background (for Drivers).
  • Driving Behavior: Accelerometer and gyroscope data to detect speed, braking, and collision events.
  • Device Status: Battery level, signal strength, and app version to optimize dispatch algorithms.
03. PROCESSING

AI & Algorithmic Decision Making

NearLink utilizes proprietary machine learning models to automate decisions. You have the right to request human review of significant decisions.

1

Dynamic Pricing

Algorithms analyze supply, demand, weather, and traffic to set real-time pricing for Stays and Rides.

2

Fraud Detection

AI models analyze payment patterns to block suspicious transactions and prevent account takeovers.

3

Search Ranking

Listings are ranked based on user preferences, booking history, and host performance metrics.

04. DISCLOSURE

Data Sharing Matrix

Recipient CategoryData Types SharedPurpose
Payment ProcessorsCard hash, Transaction ID, AmountPCI-DSS compliant processing.
Identity VendorsBiometric hash, ID DocumentKYC/AML Verification.
Law EnforcementMetadata, Location History, PIIResponse to valid subpoenas/warrants.
05. INTERNATIONAL

Cross-Border Data Transfers

NearLink operates globally. Your data may be transferred to, and processed in, countries other than the country in which you are resident. These countries may have data protection laws that are different to the laws of your country.

Transfer Mechanisms

We rely on Standard Contractual Clauses (SCCs) approved by the European Commission and relevant Data Protection Authorities to ensure your data remains protected when transferred internationally (e.g., to AWS servers in the US or EU).

06. SECURITY

Security Infrastructure

Encryption at Rest

All sensitive database fields are encrypted using AES-256 standards.

Encryption in Transit

All data transmission occurs over TLS 1.3 encrypted channels.

PCI-DSS Level 1

We maintain full compliance for handling payment card data.

Access Controls

Strict Principle of Least Privilege (PoLP) for internal employee access.

07. TRACKING

Cookie Schedule

We use the following categories of cookies:

  • Strictly NecessaryEssential for authentication and security (e.g., Session tokens). Cannot be disabled.
  • PerformanceGoogle Analytics and Mixpanel to understand user behavior and load times.
  • AdvertisingMeta Pixel and Google Ads to serve relevant advertising based on your interests.

Legal Contact

Data Protection Officer (DPO)

For specific inquiries regarding your data rights, deletion requests, or regulatory compliance.

dpo@nearlink.com

Mailing Address

NearLink Inc. Legal Dept.
West Park Towers, 6th Floor
Westlands, Nairobi, Kenya