Privacy Policy
Last updated: January 2024
1. Information We Collect
We collect: (a) Business information (name, registration, address, bank details), (b) Contact details (email, phone), (c) KYC documents (ID copies, certificates), (d) Transaction data (amounts, payment methods, timestamps), (e) Technical data (IP addresses, device info).
2. How We Use Information
We use collected data to: (a) Process payments and settlements, (b) Verify merchant identity (KYC), (c) Detect and prevent fraud, (d) Communicate about services, (e) Comply with legal obligations.
3. Data Sharing
We share data with: (a) Payment providers (Safaricom M-Pesa, card processors) to execute transactions, (b) Banks for settlement processing, (c) Law enforcement when required by law. We do NOT sell personal data to third parties.
4. Data Security
We implement industry-standard security measures including encryption, access controls, and secure infrastructure. Card data is handled in compliance with PCI-DSS standards.
5. Data Retention
Transaction records are retained for 7 years as required by financial regulations. KYC documents are retained for the duration of the merchant relationship plus 5 years.
6. Your Rights
You have the right to: (a) Access your data, (b) Correct inaccurate data, (c) Request deletion (subject to legal retention requirements), (d) Object to processing.
7. Contact
For privacy inquiries, contact privacy@digipay.co.ke.