Privacy Policy

Last updated: January 2024

1. Information We Collect

We collect: (a) Business information (name, registration, address, bank details), (b) Contact details (email, phone), (c) KYC documents (ID copies, certificates), (d) Transaction data (amounts, payment methods, timestamps), (e) Technical data (IP addresses, device info).

2. How We Use Information

We use collected data to: (a) Process payments and settlements, (b) Verify merchant identity (KYC), (c) Detect and prevent fraud, (d) Communicate about services, (e) Comply with legal obligations.

3. Data Sharing

We share data with: (a) Payment providers (Safaricom M-Pesa, card processors) to execute transactions, (b) Banks for settlement processing, (c) Law enforcement when required by law. We do NOT sell personal data to third parties.

4. Data Security

We implement industry-standard security measures including encryption, access controls, and secure infrastructure. Card data is handled in compliance with PCI-DSS standards.

5. Data Retention

Transaction records are retained for 7 years as required by financial regulations. KYC documents are retained for the duration of the merchant relationship plus 5 years.

6. Your Rights

You have the right to: (a) Access your data, (b) Correct inaccurate data, (c) Request deletion (subject to legal retention requirements), (d) Object to processing.

7. Contact

For privacy inquiries, contact privacy@digipay.co.ke.