Last updated: 24 September 2026.
Olengugih Safaris respects your privacy and is committed to handling personal data lawfully, fairly, transparently and securely. This Privacy Policy explains how we collect, use, store, share, transfer and protect information when you use our website, create a client account, send an enquiry, request a quotation, book a safari, make a payment, communicate with us, or otherwise use our travel services.
This policy is written for travellers, prospective clients, website visitors, account holders, parents or guardians booking for children, suppliers and other people who interact with Olengugih Safaris. It should be read together with our Terms & Conditions and, where applicable, the booking, cancellation and refund terms that apply to a particular safari or travel service.
1. Who we are and who controls your personal data
Olengugih Safaris is a Kenya-based travel and safari business. For personal data that we collect directly for our own travel-planning, booking, website, client-account, marketing and business-administration purposes, Olengugih Safaris generally acts as the data controller. This means we determine why and how that personal data is processed.
Some travel suppliers and service providers that receive information from us may act as independent data controllers for their own purposes. Examples can include hotels, lodges, camps, airlines, payment providers, park or reserve authorities, immigration authorities, insurance providers and other operators whose services form part of a trip.
Our privacy practices are primarily guided by the Kenya Data Protection Act, 2019, its applicable regulations and guidance issued by the Office of the Data Protection Commissioner of Kenya. Where another privacy law applies to a particular traveller or processing activity, we will also seek to meet those applicable obligations.
2. Our data-protection principles
When we process personal data, we aim to follow the core principles of Kenyan data-protection law. In practical terms, this means that we seek to:
- process personal data lawfully, fairly and transparently;
- collect information for clear, specific and legitimate purposes;
- collect only information that is relevant and reasonably necessary;
- keep personal data accurate and update it where appropriate;
- retain identifiable information only for as long as necessary for the relevant purpose or legal requirement;
- apply appropriate safeguards to protect personal data against unauthorized access, loss, misuse, alteration or disclosure; and
- apply appropriate safeguards to transfers of personal data outside Kenya where required.
3. Personal data we may collect
The information we collect depends on how you interact with us. We do not require every category of information from every traveller.
3.1 Enquiry and contact information
When you contact us through a safari enquiry, destination enquiry, hotel enquiry, contact form, telephone call, email, social-media message or another communication channel, we may collect:
- your full name;
- email address;
- telephone or WhatsApp number where you provide it;
- country of residence;
- preferred travel dates;
- number of adult and child travellers;
- trip duration;
- destinations, safari style and accommodation preferences;
- approximate travel budget where you choose to provide one;
- special requests and notes you include in the enquiry; and
- records of our communications with you.
3.2 Client-account information
If you create a client account, we may process information needed to identify your account, authenticate your login, link your enquiries, bookings, quotations, invoices, receipts or vouchers, and provide account-related services. This can include your name, email address, telephone number, country, profile photograph where you upload one, account status and login-related records.
Passwords are intended to be stored in protected hashed form rather than as readable plain-text passwords. You are responsible for keeping your login credentials confidential and for notifying us promptly if you believe your account has been compromised.
3.3 Booking and traveller information
When an enquiry becomes a booking, additional information may be required to arrange the trip. Depending on the service, this can include:
- traveller names and contact details;
- dates of birth or age information needed for child rates, rooming, park fees or transport rules;
- passport or identity-document information where required for flights, border crossings, park or conservancy registration, permits, hotel registration or other travel formalities;
- nationality or residency information where it affects immigration, entry charges or resident/non-resident tariffs;
- flight arrival and departure details;
- rooming arrangements;
- dietary requirements;
- mobility, accessibility or assistance requirements;
- emergency contact details where reasonably necessary; and
- other information required by a hotel, airline, transport company, park, reserve, conservancy, government authority or other supplier providing part of your itinerary.
3.4 Sensitive or special-category information
Travel planning can occasionally require information that is more sensitive, for example allergies, dietary restrictions, mobility limitations or health-related assistance needs. We ask you to provide such information only when it is relevant to your safety, comfort or the delivery of the requested service.
Please do not send unnecessary medical records or other highly sensitive information. Where sensitive data is necessary, we seek to limit access and share only the information reasonably required by the supplier or person who needs it to provide the relevant service.
3.5 Payment and transaction information
Our website may use Pesapal for supported online payments. When you proceed to a Pesapal payment flow, payment information is processed through Pesapal's systems and is subject to Pesapal's own privacy and security practices.
Olengugih Safaris may receive and retain transaction information such as the amount, currency, booking or merchant reference, payment method, payment status, confirmation code and payment date. We do not need to store your full payment-card number in our normal booking database in order to confirm a Pesapal transaction.
3.6 Website, device and security information
When you use the website, our server and security tools may process technical information such as:
- IP address;
- browser and device type;
- operating system;
- date and time of a request;
- requested pages or routes;
- referring page where provided by the browser;
- session identifiers;
- security and anti-spam signals;
- form-submission timing and validation information; and
- error, diagnostic or server-log information.
This information helps us keep the website secure, maintain sessions, prevent abuse, troubleshoot technical issues and understand how the website is being used.
3.7 Reviews, testimonials, photographs and other content
If you voluntarily provide a review, testimonial, photograph, video or other content for publication, we may process your name, location, trip information and the submitted content for the purpose agreed with you. Where appropriate, we may ask for permission before publishing identifiable client media.
4. How we collect personal data
We may collect personal data:
- directly from you when you complete a form, create an account, request a quote, make a booking, telephone us, email us, send a message or meet us;
- from another person in your travelling party where one lead traveller provides information needed to arrange services for other travellers;
- from travel partners or suppliers when necessary to manage a shared booking, transfer, accommodation, flight or other service;
- automatically from your device through session technology, server logs and cookies or similar technologies; and
- from payment or security providers when they return transaction status, fraud-prevention or verification information to our systems.
If you provide personal data about another traveller, you should ensure that you are authorized to provide it and that the traveller understands that the information will be used to arrange the requested trip.
5. Why we use personal data
We may use personal data for the following purposes:
- to respond to enquiries and provide travel advice;
- to prepare quotations, itineraries and proposals;
- to create and administer client accounts;
- to process bookings and payments;
- to arrange accommodation, transport, flights, park entries, permits, activities and other travel services;
- to communicate itinerary changes, payment information, operational updates and important travel notices;
- to issue invoices, receipts, vouchers and other booking documents;
- to provide customer support before, during and after travel;
- to personalize a requested safari according to dates, destinations, interests, rooming and budget;
- to prevent spam, fraud, misuse, cyber attacks and unauthorized access;
- to maintain and improve the website and client portal;
- to keep records required for accounting, taxation, legal, audit, dispute or insurance purposes;
- to send marketing or travel inspiration where you have requested it or where another lawful basis permits it;
- to manage reviews, feedback and service quality;
- to enforce our contractual rights and protect the rights, safety and property of Olengugih Safaris, our clients, staff, guides, suppliers and the public; and
- to comply with lawful requests, court orders, regulatory duties and other legal obligations.
6. Legal bases for processing
Depending on the circumstances, we may rely on one or more lawful grounds for processing personal data:
- Consent: where you have freely given permission for a particular use, for example certain marketing communications or optional information.
- Performance of a contract or steps before a contract: when we need information to answer a booking request, prepare a quotation, reserve services, manage payment or deliver a confirmed safari.
- Legal obligation: when records or disclosures are required by tax, accounting, regulatory, immigration, law-enforcement or other applicable rules.
- Legitimate interests: where processing is reasonably necessary to operate and protect our business, prevent fraud, improve services, manage customer relationships or defend legal claims, provided those interests are not overridden by your rights and freedoms.
- Vital interests or safety: in exceptional circumstances where processing is necessary to protect a person's life or physical safety.
Where we rely on consent, you may withdraw that consent for future processing, subject to any lawful processing already carried out and any other legal basis that continues to apply.
7. Cookies and similar technologies
Cookies are small text files or identifiers stored by a browser to help a website remember information or maintain a session. Our public website is designed to use a limited number of operational cookies. Some third-party services may also use their own cookies or similar technologies when those services are activated.
| Cookie or technology | Purpose | Typical duration |
|---|---|---|
| PHP session identifier | Maintains a secure website session, supports forms, account authentication and other session-based functions. | Normally a browser/session cookie or according to server session configuration. |
| olengugih_market | Remembers the international market or regional website experience selected by the visitor. | Up to 12 months. |
| olengugih_ui_theme and olengugih_ui_palette | Remember interface preferences in staff/admin areas. These do not normally apply to ordinary public visitors. | Up to 12 months. |
| Cloudflare Turnstile data | Where Turnstile is enabled, helps distinguish legitimate visitors from automated abuse on protected forms. | Controlled by Cloudflare and may vary by service configuration. |
| Analytics tags | If analytics such as Google Analytics or Google Tag Manager are enabled, they may measure visits, traffic sources, browser/device information and interaction with the website. | Depends on the analytics configuration and provider. |
| Payment-provider technologies | When you continue to Pesapal, Pesapal may use cookies or similar technologies to secure and process the payment session. | Controlled by Pesapal under its own policies. |
You can usually block or delete cookies through your browser settings. Blocking essential session cookies may prevent login, forms, account functions or other parts of the website from working properly.
At the time of this policy's review, the public website primarily relies on operational/session and market-preference functionality. If we introduce additional non-essential tracking that requires consent under applicable law, we will review our consent mechanism and this policy accordingly.
8. Analytics and website measurement
The website has technical support for analytics services such as Google Analytics or Google Tag Manager if these are configured by the website administrator. Where such services are enabled, information such as pages viewed, device/browser characteristics, approximate location inferred from IP address, referral source and interaction events may be processed by the analytics provider.
We use website measurement to understand performance, identify technical problems and improve content and navigation. We do not use analytics as a reason to collect information that is unrelated to operating or improving the website.
9. Anti-spam and website security services
Public enquiry and booking forms may use technical anti-spam controls such as CSRF protection, honeypot fields, submission-timing checks, IP-based security signals and, where configured, Cloudflare Turnstile. These controls help protect our clients and systems against automated abuse, malicious submissions and fraud.
Cloudflare or another security provider may process technical data independently in accordance with its own privacy terms. We encourage users to review a third-party provider's privacy information where they want more detail about that provider's processing.
10. Who we may share personal data with
We do not sell your personal data to advertisers or data brokers. We share information only where it is reasonably necessary for the trip, our business operations, security, legal compliance or another lawful purpose.
Recipients may include:
- hotels, safari lodges, camps, resorts and other accommodation providers;
- safari guides, driver-guides, transport operators and transfer companies;
- airlines, charter operators and airstrip-transfer providers;
- parks, reserves, conservancies, activity providers and permit-issuing bodies;
- tour operators or destination-management partners where they provide part of an itinerary;
- payment providers, including Pesapal, banks and other financial institutions involved in a transaction;
- website hosting, email, IT, cloud, security and support providers;
- professional advisers such as accountants, auditors, insurers or lawyers where necessary;
- government, immigration, tax, regulatory, law-enforcement or judicial authorities where we are legally required or lawfully requested to provide information; and
- a purchaser, investor or successor entity if our business or relevant assets are reorganized, merged or transferred, subject to appropriate confidentiality and data-protection arrangements.
We seek to limit the information shared with each recipient to what is reasonably necessary for that recipient's role.
11. International and cross-border data transfers
Travel is inherently international. If your itinerary includes services outside Kenya, or if a supplier, cloud provider, airline, hotel or technology service is located or hosts data outside Kenya, personal information may be transferred or accessed across borders.
For example, a trip involving Tanzania, Uganda or Rwanda may require traveller information to be shared with accommodation providers, operators, airlines, permit authorities or other suppliers in those countries. International technology providers may also process data in regional or global infrastructure.
Where Kenyan law requires safeguards for transfers outside Kenya, we seek to use an appropriate lawful transfer basis, contractual protection, consent or other permitted safeguard. The exact mechanism can depend on the destination, recipient and nature of the information.
12. Data retention
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including operational, contractual, tax, accounting, fraud-prevention, dispute-resolution and legal requirements. Retention can vary according to the record.
| Record category | Typical retention approach |
|---|---|
| Enquiries that do not become bookings | Normally retained for up to 24 months after the last meaningful communication, unless you ask us to delete the information sooner and no legal or operational reason requires retention. |
| Confirmed bookings, invoices, receipts and payment records | Typically retained for approximately 5 to 7 years after the relevant trip or transaction, or for a different period where tax, accounting, legal-claims or regulatory rules require it. |
| Client-account profile | Retained while the account is active and for a reasonable period after closure or inactivity. Booking and financial records linked to the account may need to be kept for longer. |
| Passport, identity or permit information | Retained only as long as reasonably necessary to arrange and evidence the relevant travel service, unless a legal, security or dispute-related reason requires longer retention. |
| Marketing preferences | Retained until you unsubscribe or withdraw consent. We may retain a minimal suppression record so that we can respect an opt-out request. |
| Website and security logs | Generally retained for a limited period, commonly up to 12 months, unless required longer for investigation, security or legal purposes. |
| Cookies | Session cookies usually expire with the session; preference cookies may remain for up to 12 months; third-party cookie periods depend on the relevant provider. |
| Reviews, testimonials and approved media | May be retained while published or while the relevant permission or lawful basis continues. Requests to withdraw or remove identifiable content will be considered in context. |
These periods are operational guidelines rather than guarantees that every record is deleted on the same calendar day. Data may be retained longer when required by law, where a dispute or investigation is active, where a payment or fraud issue remains unresolved, or where it is necessary to establish, exercise or defend legal claims.
Backups may retain deleted information temporarily until the relevant backup rotation expires. We seek to prevent information that has been deleted from active systems from being restored for ordinary business use.
13. How we protect personal data
We use reasonable administrative, technical and organizational measures appropriate to the type of information and the risks involved. These measures can include:
- access controls and authenticated staff accounts;
- password hashing for client and administrative accounts;
- CSRF and form-security controls;
- spam and abuse detection;
- secure payment hand-off to a payment provider instead of storing full card details in our normal booking records;
- role-based access to business systems;
- HTTPS where the website is deployed with a valid security certificate;
- software updates, backups and operational monitoring; and
- limiting information shared with suppliers to what is reasonably necessary.
No internet, email, cloud or electronic-storage system can be guaranteed to be completely secure. You should avoid sending full card numbers, passwords or unnecessary sensitive documents through ordinary email, social media or public messaging channels.
14. Data breaches and security incidents
If we become aware of a personal-data breach, we will investigate the incident, take reasonable steps to contain and remediate it, assess the risk to affected individuals and keep appropriate records. Where applicable law requires notification to the Office of the Data Protection Commissioner or affected data subjects, we will seek to make the required notification within the applicable legal framework.
15. Your data-protection rights
Under Kenyan data-protection law, and subject to applicable conditions and exemptions, you may have rights including:
- the right to be informed about how your personal data is used;
- the right to request access to personal data we hold about you;
- the right to ask us to correct inaccurate or misleading personal data;
- the right to object to certain processing;
- the right to request deletion or erasure in appropriate circumstances;
- the right to request restriction of processing in appropriate circumstances;
- the right to data portability where the applicable legal conditions are met; and
- the right to withdraw consent where processing is based on consent.
The Office of the Data Protection Commissioner provides additional information about data-subject rights in Kenya.
To protect you and other clients, we may need to verify your identity before providing access, correcting account information or deleting data. A request may also be limited where we must retain information to comply with law, complete a transaction, prevent fraud, protect another person's rights or establish, exercise or defend legal claims.
16. Children and family travel
Our website and client-account services are not intended for children to use independently. Family safari enquiries and bookings should normally be made by a parent, guardian or responsible adult.
When a child is travelling, we may need limited information such as the child's name, age, date of birth, passport details, dietary needs or other information required to calculate the correct tariff and arrange accommodation, flights, park entry, permits or border formalities. We expect the adult making the booking to have authority to provide this information.
We do not intentionally use children's travel information for unrelated marketing.
17. Marketing communications
We may send travel ideas, safari information, offers or other marketing communications where you have requested them, consented to receive them, or where another lawful basis permits the communication.
You can ask us to stop direct marketing at any time by replying to the relevant message, using any unsubscribe option provided, or contacting us using the methods listed at the end of this policy. Stopping marketing does not prevent us from sending operational messages about an active enquiry, booking, payment, trip or account.
18. Third-party websites, social media and external services
Our website may link to external websites such as wildlife authorities, airlines, hotels, payment providers, social-media platforms, mapping services or travel resources. Once you follow an external link, the destination website's privacy policy and terms apply to its collection and use of information.
Our social-media pages are also hosted by third-party platforms. Information you post publicly on those platforms may be visible to others. For privacy requests, passport information, payment information or other sensitive matters, please use our email, telephone or website contact channels rather than a public social-media comment.
19. Photographs, videos, website content and copyright
The website contains written content, photographs, videos, graphics, logos, maps and other media. Some of this material is created or owned by Olengugih Safaris. Other material may be provided by hotels, lodges, camps, tourism partners, photographers, destination partners, media libraries, licensed providers or other third parties.
Some images and other media displayed on this website are subject to third-party copyright and remain the property of their respective copyright owners. Their appearance on this website does not mean that the material is in the public domain or that visitors are free to copy, republish, sell, edit or commercially reuse it.
Unless a page expressly states otherwise, you should not reproduce, download for republication, distribute, modify or commercially use website photographs, text, logos, itineraries or other protected content without permission from Olengugih Safaris and, where applicable, the underlying copyright owner.
If you are a copyright owner or authorized representative and believe material on our website has been used incorrectly, please contact us with the page URL, a description of the material, your contact details and evidence of ownership or authority. We will review a properly supported request and take appropriate action where necessary.
If you appear in an identifiable photograph or video and have a privacy concern about its use, you may also contact us using the methods below.
20. Automated processing
The website may automatically calculate totals, rooming quantities, package prices, form risk scores or other operational values based on information entered into the system. These automated calculations support booking and administrative workflows.
We do not currently intend to make decisions based solely on automated processing that produce legal or similarly significant effects on a traveller without appropriate human involvement. Material booking changes, supplier confirmations and customized travel decisions may be reviewed by our team.
21. Accuracy of your information
Please provide accurate and complete information, particularly names, passport details, dates of birth, telephone numbers, email addresses, flight details and other information that affects travel arrangements. Incorrect traveller information can lead to denied boarding, rejected permits, rooming problems, incorrect park charges or other disruptions.
If your information changes after booking, contact us as soon as possible so that we can determine whether suppliers must also be notified.
22. Changes to this Privacy Policy
We may update this policy when our website, technology, suppliers, payment methods, legal obligations or business practices change. The current version will be published on this page with a revised "Last updated" date.
Material changes may also be communicated through the website, account area, email or another appropriate method where necessary.
23. How to contact Olengugih Safaris about privacy
If you want to exercise a privacy right, correct information, ask how your data is being used, withdraw marketing consent, report a privacy concern, raise a copyright concern or make another data-protection request, you may contact Olengugih Safaris through any of the following methods:
- Email: info@olengugihsafaris.com
- Telephone: +254 717 210 198
- Website contact form: olengugihsafaris.com/contact
- Office: Venus Complex, 5th Floor, Room No. 4501, Norther Bypass, Ruiru, Kiambu County, Kenya
When making an access, correction, deletion or other rights request, please provide enough information for us to identify the relevant account, enquiry or booking. For security, we may ask for reasonable proof of identity. Please do not send unnecessary passport scans or payment-card details unless we specifically tell you they are required through an appropriate channel.
24. Complaints to the Office of the Data Protection Commissioner
We encourage you to contact us first so that we have an opportunity to investigate and resolve a concern. You also have the right to contact Kenya's Office of the Data Protection Commissioner (ODPC) about a data-protection complaint.
Information about complaints and current ODPC contact channels is available at odpc.go.ke/file-a-complaint. The ODPC currently lists its head office at Britam Tower, Hospital Road, Upper Hill, Nairobi, and publishes current email and telephone contact details on its official website.
This Privacy Policy is intended to explain how Olengugih Safaris handles personal information in clear practical terms. If a specific law, court order, regulatory requirement or binding contractual obligation conflicts with this policy, the applicable legal requirement will take precedence.
Related company and contact information
For more information about the company behind this website, read About Olengugih Safaris. If you have a privacy request, correction request or another question about information held in connection with an enquiry or booking, use our contact page and choose an appropriate private contact method.