1. Introduction & Who We Are
Nairobi Feast (the “Platform”) is a curated restaurant discovery, dining guide, and table booking platform for the Nairobi dining community, operated by Naifeast Digital, a company registered in Kenya. We are the Data Controller for personal data processed in connection with your use of the Platform.
Nairobi Feast is an open, free discovery platform. We do not require or operate consumer diner accounts, passwords, or public user profiles. Diners browse venues, run AI searches, coordinate group dining, and book tables without creating an account.
2. Lawful Basis for Processing
Under Section 30 of the Data Protection Act, 2019 (Kenya), we process personal data on the following lawful bases:
- Performance of a contract: To facilitate table reservations you initiate with partner restaurants via DineBook.
- Consent: Where you voluntarily opt in, such as subscribing to our free email newsletter.
- Legitimate interests: To operate and secure the Platform, detect bot scraping, enforce fair-use limits on our free AI features (AI Mode search and the Naya chat assistant), and understand dining interest trends in Nairobi.
- Legal obligation: To comply with applicable Kenyan tax, statutory, and regulatory requirements.
3. Information We Collect
A. Information You Provide Voluntarily
- Table Reservations: When booking a table at a partner venue via DineBook, you provide your name, phone number, email address, date, time, party size, and dietary notes to confirm your table.
- Newsletter Subscription: Your email address when subscribing to our dining guides and updates.
- Contact & Feedback Forms: Name, email address, and message text when you contact our support or legal team.
- Restaurant Inquiries: Contact details and venue information submitted by hospitality managers.
What We Do NOT Collect: We do not collect or store consumer passwords, account profiles, user reviews, public photo uploads, or payment/card details.
B. Information Collected Automatically
- Usage Data: Pages visited, features accessed, cuisine and neighbourhood filters applied, and time spent exploring listings.
- Device & Technical Data: Browser type, operating system, approximate screen size, referring URL, and IP address for DDoS security and rate limiting.
- Device Identifiers for Fair Use: When you use AI Mode search or the Naya chat assistant, we use three signals to apply the free usage limits fairly: your IP address, a random device ID stored in your browser, and a browser fingerprint (a code derived from your browser's technical characteristics, such as screen, fonts and settings). These are used only to count how many AI requests a device makes in a minute, an hour and a day, so that one visitor or bot cannot exhaust the free service for everyone. They are not used for advertising, profiling, or to identify you by name.
- Approximate Location: If you explicitly grant browser permission for “Near Me” searches, your approximate device coordinates are used solely in that session to calculate venue distance. We do not track your location in the background.
C. AI Mode & Search Data
- Search Queries: Natural language queries entered into AI Mode are processed by large language models (primarily Google's Gemini via Google Cloud Vertex AI, with Vercel AI Gateway and Anthropic's Claude as fallbacks) to return dining recommendations from our database.
- Naya Chat Assistant: Messages you send to Naya, and the recent conversation they belong to, are sent to the same AI providers to generate replies and recommendations. If you chat as a guest, your chat history is saved only in your own browser (local storage); it is not stored on our servers. You can delete any chat at any time from the chat window.
- Naya Account (optional): You can sign in to Naya with Google or with an email and password. Nothing else on Nairobi Feast needs an account. When you do, we store your name, email address and profile photo; your Naya chats (so they follow you to other devices); the things Naya remembers about you from your chats, such as your name, the food and places you like or avoid, and places you've been; and any preferences you set (usual areas, budget, cuisines, vibes and dietary needs). Memory can be switched off, and each memory, each chat, or all of your Naya data can be deleted at any time from the Account tab. Email sign-ups are confirmed with a one-time code sent to your address, and passwords are stored only as secure hashes.
- Naya Plus Payments: If you buy a Naya Plus pass, payment (M-Pesa or card) is handled by Paystack; we never see or store your card or M-Pesa PIN. We keep the payment reference, amount, pass length and expiry date. Passes are one-off purchases and are never renewed or charged automatically.
- Browser-Native Voice: Voice search operates entirely via your device's native browser speech-to-text API (Web Speech API). Voice audio is transcribed locally in your browser and is never recorded, stored, or sent to external voice servers.
- No Model Training: Individual search queries are never used to train public machine learning models.
4. How We Use Your Information
- To provide, operate, maintain, and optimize the restaurant discovery platform and AI Mode.
- To facilitate table reservations with partner restaurants via DineBook.
- To deliver conversational dining recommendations matching your culinary preferences.
- To send transactional reservation confirmations and requested email newsletter issues (with 1-click unsubscribe).
- To respond to user inquiries, partner requests, and feedback.
- To detect and prevent automated scraping, malicious attacks, and infrastructure abuse.
- To apply fair-use limits to our free AI features so they stay available and affordable for everyone.
- To analyze aggregated, non-identifying dining trends across Nairobi neighbourhoods.
- To comply with statutory legal obligations under Kenyan law.
5. Data Sharing & Third Parties
We do not sell, rent, or trade your personal information. We share data only with the trusted sub-processors and partners listed below:
- Service Providers (Sub-Processors):
- DineBook (dinebook.co) — table reservation processing and venue confirmation
- Google Cloud (Vertex AI, Gemini) — AI search and Naya chat processing
- Vercel AI Gateway and Anthropic (Claude) — fallback AI processing for search and chat
- Neon — database hosting (venue directory, reservations, fair-use counters, Naya accounts)
- Google — optional “Continue with Google” sign-in for Naya
- Paystack — Naya Plus payments (M-Pesa and card)
- Cloudinary and Supabase — image and file storage
- Resend — transactional notifications and newsletter delivery
- Google Maps — map views and distance calculations
- Vercel — web application hosting and secure edge network
- Restaurant Partners: When you reserve a table, your booking details (name, contact, party size, date/time, dietary notes) are securely transmitted to that specific venue to fulfill the reservation.
- Legal Compliance: We may disclose information if required to do so by a valid court order, Kenyan law enforcement, or regulatory authority.
We do not integrate consumer payment gateways, consumer credit card processing, or third-party conversational voice servers.
6. International Data Transfers
Some cloud service providers (including Google Cloud, Neon, Cloudinary, Supabase, Anthropic, and Vercel) maintain infrastructure in secure data centers located in the European Union and the United States. Where personal data is processed internationally, we ensure appropriate safeguards are maintained in compliance with Section 48 of the Data Protection Act, 2019, including Standard Contractual Clauses and encryption protocols.
7. Data Retention
We retain personal information only for as long as necessary to fulfill the specific purpose:
- Reservation Records: Retained for up to 12 months for operational fulfillment, attendance verification, and customer service.
- Newsletter Subscriptions: Retained until you click unsubscribe or request deletion.
- AI Search Queries: Processed in memory during your active session; not permanently stored or tied to user identities. Identical searches may be cached for up to 10 minutes, without any identifier, to answer them faster.
- Naya Chat History: As a guest, kept only in your browser (up to your 25 most recent chats) until you delete it or clear your browser data. When signed in, kept in your Naya account until you delete it; older chats beyond your plan's limit (100 on Free, 500 on Plus) are removed automatically.
- Naya Account Data: Your memories and preferences are kept until you delete them or erase your Naya data from Settings. Naya Plus payment records are kept for as long as needed for accounting and legal purposes.
- Fair-Use Counters: Request counts linked to an IP address, device ID or browser fingerprint are kept only until their time window ends (at most one day) and are then deleted automatically.
- Security & Server Logs: Retained for up to 90 days for cybersecurity and audit purposes.
8. Security
We enforce technical and organizational safeguards to protect personal data against unauthorized access, loss, or alteration:
- Strict TLS 1.3 / HTTPS encryption for all data in transit.
- Database encryption at rest.
- Strict least-privilege access controls on all backend APIs and administrative dashboards.
- Automated DDoS protection and rate limiting.
In the event of a security incident affecting personal data, we will notify affected individuals and the Office of the Data Protection Commissioner (ODPC) in accordance with the Data Protection Act, 2019.
9. Your Rights
Under the Data Protection Act, 2019 (Kenya), you have the following rights regarding your personal data:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure: Request deletion of your personal data (“right to be forgotten”), subject to legal retention requirements.
- Right to object: Object to the processing of your data for legitimate interests or direct marketing.
- Right to data portability: Receive your data in a structured, commonly used, machine-readable format.
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint: You have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) at odpc.go.ke.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. We may need to verify your identity before processing your request.
10. Cookies & Analytics
Nairobi Feast uses cookies and similar technologies (local storage, session storage) for the following purposes:
- Strictly necessary cookies: Required for the Platform to function securely, including CSRF security protection, DDoS mitigation, and rate limiting. These cannot be disabled.
- Preference cookies: Remember your settings, such as saved filters, favourite restaurants, and display preferences.
- AI features (local storage): Your Naya chat history (as a guest, or a cached copy of recent chats when signed in, cleared when you sign out), a random device ID, and any active usage-limit countdown, so limits and chats persist between visits on the same device. Clearing your browser's site data removes them.
- Analytics cookies: Used to understand how visitors use the Platform (pages visited, features used, time on site) to help us improve the experience. We use privacy-respecting analytics tools.
You can control cookies through your browser settings. Disabling certain cookies may affect the Platform's functionality. We do not use advertising or tracking cookies for cross-site behavioural advertising.
11. Children's Privacy
Nairobi Feast is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe we have inadvertently collected data from a child under 13, please contact us at [email protected] and we will take prompt steps to delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the “Last updated” date at the top of this page and, where appropriate, notify you by email or prominent in-platform notice.
We encourage you to review this page periodically. Your continued use of the Platform after the effective date of changes constitutes your acceptance of the updated Policy.