Karibu ← Back to home

Privacy Policy

How Karibu handles hotel-staff account data and guest data processed on behalf of hotels.

Effective 17 August 2026 · Version 2026-08-17 · English is the official language of this policy.

Two roles, not one. For your hotel’s guests, the hotel is the data controller and Karibu (Obliqque Software) is the processor. For your Karibu account (staff logins, billing, product analytics), Karibu is the controller. This page covers both. It does not replace a guest-facing notice that your hotel should publish on its own site.

1. Who we are

Karibu is a cloud hotel property-management system operated by Obliqque Software, trading as Karibu. Website: https://karibuapp.com. Privacy requests: karibuapplic@gmail.com.

Karibu is a B2B product for hotels and their staff. We do not knowingly offer accounts to children under 16.

2. The data we process

A. Account and usage data (Karibu is controller)

B. Hotel operations data (hotel is controller; Karibu is processor)

When you use Karibu to run the hotel, you instruct us to store data such as:

The hotel decides why that data is collected (a stay, a bill, a public page). Karibu processes it only to provide the service, on the hotel’s instructions, as described in the Terms of Service (processor clause). The hotel must have a lawful basis for collecting guest data and must answer guest requests.

3. Why we process it (lawful bases)

PurposeBasis
Create and authenticate staff accountsContract
Provide the PMS (reservations, billing, rooms, reports)Contract
Store guest records for the hotelHotel’s instructions (we are processor); hotel’s own basis toward guests
Charge subscriptions and keep tax recordsContract and legal obligation
Security, abuse prevention, error diagnosis (Sentry)Legitimate interests
Product analytics cookiesConsent (cookie banner)
Optional marketing emailConsent — we do not send marketing unless you opt in

4. Where data lives and who can see it

Application data is stored in Supabase Postgres in the European Union (AWS eu-west-1). Each hotel’s rows are isolated with database row-level security tied to the signed login token. Another hotel cannot read yours.

We do not sell personal data. We do not use guest records to advertise to those guests.

5. Sub-processors

ProviderRoleRegion
Supabase, Inc.Database, authentication, edge functionsEU (eu-west-1)
Google (Firebase Hosting)Static site hosting and CDNGlobal CDN
Stripe, Inc.Subscription paymentsUSA / EU
ResendTransactional email (welcome, reset, booking confirmations)USA
Functional Software, Inc. (Sentry)Error monitoringEU ingest
Formspree, LLCPublic contact formUSA
Cloudflare, Inc. (Turnstile)Bot check on the public booking formGlobal

WhatsApp messages, if you enable them, go through the hotel’s own WhatsApp number — not a Karibu inbox. Flutterwave may appear in the codebase for a possible future payment path; the live product bills through Stripe.

6. Cookies and similar storage

Strictly necessary storage keeps the product working (login session, active hotel, language, offline cache, CSRF/spam locks). We do not use advertising cookies.

NamePurposeType
Supabase auth tokenSigned login sessionEssential
karibu_session / karibu_hotel_idStaff UI session and hotel contextEssential
karibu_lang / karibu_landing_langLanguageFunctional
karibu_consentYour cookie choiceEssential
karibu_terms_*Staff acceptance of current Terms/Privacy versionEssential
karibu_hero_variantLanding-page variantFunctional
_karibuEventsIn-memory / local product events if analytics allowedAnalytics (consent)

On first visit we show a banner. You can accept analytics or reject it. Rejecting does not block login, booking, or the public hotel page. You can change your mind by clearing site data for karibuapp.com.

7. How long we keep data

Unused hotels may be warned and then removed under the inactivity rules in the Terms. Export your data before you leave if you need a copy.

8. Your rights

Depending on where you live (including GDPR, DRC Loi 2023 on data protection, Kenya Data Protection Act 2019, and similar African and EU rules), you may request access, correction, deletion, restriction, portability, or objection, and you may withdraw consent.

Hotel staff / billing contacts: email karibuapplic@gmail.com from the address on the account. We aim to respond within 30 days.

Hotel guests: ask the hotel. We will help the hotel locate or delete records in Karibu when they instruct us, unless law requires us to keep them.

You may also complain to your local data-protection authority. California residents: we do not sell or “share” personal information as those terms are used in the CCPA/CPRA.

9. Security

No online service is perfectly secure. Tell us promptly at the email above if you suspect unauthorised access.

10. International transfers

Primary database storage is in the EU. Some sub-processors (Firebase CDN, Stripe, Resend, Formspree) operate in the United States or globally. Where GDPR applies, we rely on the provider’s appropriate safeguards (for example Standard Contractual Clauses).

11. Changes

Material changes will be posted on this page with a new effective date. For hotel staff, a new policy version may require you to accept again before using the app. Continued use after that acceptance is agreement to the updated policy.

12. Contact

Obliqque Software · Karibu
karibuapplic@gmail.com