Privacy & Cookies

Last updated 21 August 2026

Raut is a multi-tenant ERP and field-sales platform operated by Tari Africa Platforms Limited. Businesses use it to run their own sales operations, so most of the personal data in Raut is entered by those businesses about their own staff and trade customers.

For that data the customer company is the data controller and Tari Africa Platforms is the data processor: we hold and process it on their instructions. If you are a field rep, or a shop whose details appear in Raut, your first point of contact is the business you deal with.

What we collect

Raut collects what the platform needs to do its job, and no more. There is no advertising, no profiling and no third-party analytics: the console loads no external scripts, trackers or fonts.

Categories of personal data Raut stores
WhatSpecificallyWhy
AccountName, work email, phone number, role, the company and branch you belong to, and a hashed password.To sign you in, and to decide what you are allowed to see.
DeviceA device identifier, platform, model, app version, and when the device last synced.So a lost handset can be cut off without disturbing anyone else.
Trade customer recordsShop name, contact phone and email, physical address and town, GPS pin, credit limit, outstanding balance and free-text notes.Entered by the customer company to run its sales, credit and delivery operations.
Visits and salesScheduled, check-in and check-out times, the GPS position at check-in, the geofence verdict, orders, payments, invoices and expense claims.The operational record of the work performed.
PhotosImages captured during a visit, and the time they were taken.Proof of delivery, shelf condition, or a disputed order.
Audit logWho did what, to which record, when — with the IP address and the browser or app user agent of the request.Accountability, and investigating disputes or misuse.

Location data

Location is the most sensitive thing Raut handles, so it is worth being precise about it.

At check-in. When a field rep checks in at a customer, the app records the GPS position at that moment, and the server compares it against the customer’s stored pin or the territory boundary. The verdict — verified or not, and the distance — is stored on the visit. This happens only when the rep taps check-in.

Continuous tracking is off by default. A rep may switch on route tracking, which records periodic points: position, accuracy, speed, heading, battery level, and whether the device is moving. The app states plainly whether tracking is on. While it is off, no background positions are recorded.

Location is used to verify that field work happened where it was reported, and to sequence routes by distance. It is never sold, and never shared outside the company that employs the rep.

Cookies and local storage

Raut sets one cookie, and it is strictly necessary. There are no advertising or analytics cookies, which is why the platform shows no consent banner: there is nothing optional to consent to. Refusing the session cookie simply means you cannot sign in.

Cookies and browser storage used by Raut
WhatSpecificallyWhy
raut_sessionCookie. HTTP-only and same-site, so page scripts cannot read it. Holds your signed session.Strictly necessary — it is what keeps you signed in. Cleared when you sign out.
raut.themeBrowser local storage, not a cookie. Stores your light, dark or system preference.Remembers how you like the console to look. Contains no personal data.
App token storageMobile app only: access and refresh tokens, the device id and the last-sync time, in the app's private storage on the device.Keeps you signed in between shifts, and lets the app work with no signal. Removed when you sign out.

How it is used

To operate the service you or your employer signed up for: signing people in, enforcing what each role may see, recording sales and visits, verifying field activity, and keeping an audit trail. We also use it to keep the service secure and to diagnose faults.

We do not use your data to train models, build advertising profiles, or sell to anyone.

Who it is shared with

Between companies, never. Raut is multi-tenant: every record carries the company it belongs to, and that scope is derived from your signed-in session rather than from anything the browser or app sends. One company cannot read or write another’s data.

Within your company, access depends on your role and on which modules the company licenses. Data leaves the platform only where we are legally required to disclose it, or to the infrastructure provider hosting the service on our behalf.

The platform runs on a virtual private server in Europe. Where the SMS module is enabled, message content and recipient numbers are passed to the SMS provider your company configures.

How long it is kept

Operational records — customers, visits, orders, invoices, payments — are kept for as long as the customer company keeps its account. They are that company’s business records, and usually carry their own statutory retention period under tax law.

We do not currently run automated deletion of location history or audit logs; they are retained until the account is closed. If your company needs a defined schedule — discarding location points after 90 days, for instance — contact us and we will configure it.

Security

Traffic is encrypted in transit with TLS. Passwords are stored hashed, never in readable form. Sessions use short-lived access tokens with rotating, device-bound refresh tokens, so a stolen token has a narrow window and a replayed one is refused outright.

No system is perfectly secure. If you believe an account or a record has been accessed improperly, tell us, so we can investigate the audit trail.

Your rights

Under the Kenyan Data Protection Act 2019 you may ask to access, correct or delete your personal data, to object to or restrict how it is used, and to receive a copy in a portable form. You may also complain to the Office of the Data Protection Commissioner.

Because most data in Raut belongs to a customer company, we normally have to pass such requests to that company as the controller. Approaching them directly is usually quicker.

Contact

Tari Africa Platforms Limited, Nairobi, Kenya.
Privacy enquiries: phinetechltd@gmail.com — or use the contact form, which prefills what we need.

If we change how the platform handles personal data, we will update this page and the date at the top.