WATERPESA · PILOT DOCUMENT
Privacy notice
Draft version · 30 September 2026
Information used by the pilot
Account registration uses your email address and password through Supabase Authentication. The app uses your account ID and session to identify you. Passwords and session tokens are not included in account exports.
If account storage is enabled, you can save meter identifiers, manufacturer and model details, declared protocols and units, self-reported cloud readings, a display name, organization, water provider, service area, optional utility account reference, language preference and connection-request description. We record which pilot notice you acknowledged and when you saved your setup.
Why this information is used
The account features use these details to sign you in, restore your setup across devices, show your saved requests and provide an account-data download. Selecting a provider does not send information to that provider or establish a partnership. The notice acknowledgement does not subscribe you to marketing.
Cookies and local demo data
Authentication uses session cookies in your browser. Resident and operator sign-ins are stored separately. Resident demo readings, simulated payment receipts and support records are saved in browser storage on that device; signing in does not automatically upload them into your account.
Signing out does not erase local demo records. Use the demo reset controls where available, or clear site data in your browser. Clearing site data can permanently remove local records, so export anything you need first. Downloaded files remain on your device until you delete them.
Services and access
Supabase provides authentication and configured account storage. The hosted web apps use Vercel. These providers may process technical information such as network addresses and service logs to operate their services. Hosting regions, provider retention and any international-transfer arrangements must be confirmed before production use.
Account records are designed to be restricted to the signed-in owner using database access policies. Authorized service administrators may have operational access. M-Pesa and utility systems are not connected by saving a request. Never include credentials, payment PINs or customer lists in request descriptions.
Access, corrections and requests
You can edit your saved profile and service details from My account. The account-data download includes your profile, onboarding and connection requests from both apps; local demo data and infrastructure logs are outside that export. Self-service account deletion is not available yet.
Kenyan data-subject rights include being informed, access, objection to processing, and correction or deletion of false or misleading data. See the ODPC explanation of your rights and complaint channels. The WaterPesa privacy-request contact remains to be confirmed before this notice can be finalized.
Retention and changes
Local demo data remains until you reset it or clear browser storage. A production retention schedule for accounts, requests, backups and operational logs has not yet been established. This draft makes no automatic-deletion promise. Material changes to the pilot data flows require an updated notice.