ShieldPay ShieldPay
Product How it works Pricing Integrations FAQs Contact
Sign in Start free trial
Product How it works Pricing Integrations FAQs Contact
Sign in Start free for 15 days
Privacy Policy

What we collect,
why we need it,
and your rights.

ShieldPay handles payment data for Kenyan businesses, so we take privacy seriously. This policy explains in plain language what personal data we collect, the lawful basis on which we process it, who we share it with, how long we keep it, and the rights the Data Protection Act, 2019 gives you.

Effective 1 September 2026
Last updated 1 September 2026
Version 1.0
Governing law Republic of Kenya
End User Licence Agreement Privacy Policy
Contents
  1. About this policy
  2. Who we are
  3. Controller and processor roles
  4. What we collect
  5. How we collect it
  6. Why we use it, and our lawful basis
  7. Payment and mobile money data
  8. Data about other people
  9. When we share information
  10. Transfers outside Kenya
  11. How long we keep information
  12. How we protect information
  13. Your rights
  14. How to exercise your rights
  15. Cookies and similar technologies
  16. Marketing and communications
  17. Automated processing
  18. Children
  19. Data breaches
  20. Changes to this policy
  21. Complaints
  22. How to contact us

About this policy

This Privacy Policy explains how ShieldPay Kenya (“ShieldPay”, “we”, “us”) handles personal data in connection with the ShieldPay Finance System (the “Platform”), our bill payment automation service for Kenyan businesses.

It applies to our website, the Platform, our application programming interfaces, and our email, WhatsApp and telephone support. It should be read alongside the End User Licence Agreement.

We process personal data in accordance with the Data Protection Act, 2019 and the regulations made under it, and with the guidance of the Office of the Data Protection Commissioner.

The short version

We collect what we need to open your account, verify your business, execute the payments you instruct, keep an audit trail, meet our legal duties and support you. We do not sell personal data, ever. We do not use your payment history to advertise to you. We never collect your M‑Pesa PIN, card PIN or bank password.

Who we are

ShieldPay Kenya operates the Platform from Nairobi, Kenya. For the personal data described in this policy for which we are the data controller, we are the entity responsible.

Data controller
ShieldPay Kenya
Privacy contact
support@shieldpayfinance.com
WhatsApp / Phone
0705 959 986
Location
Nairobi, Republic of Kenya

Controller and processor roles

Our role under the Data Protection Act depends on whose data is involved.

Whose dataOur roleWhat that means
Your own account data Controller We decide why and how we process it (for example your name, email, phone number and security settings) and this policy governs it.
Data you upload about suppliers, employees and customers Processor Your business decides why and how it is processed. We act on your instructions. Your own privacy notice governs it, and you are responsible for having a lawful basis.
Website visitors and enquiries Controller We decide why and how we process it, for the purposes described below.

Where we act as a processor, we process personal data only on your documented instructions, keep it confidential, apply the security measures described in section 12, assist you in responding to data subject requests, and delete or return it at the end of the engagement, subject to the retention rules in section 11.

What we collect

Identity and account data

  • full name, username, email address and phone number;
  • password, stored only as a salted cryptographic hash, and we never store it in a readable form;
  • two-factor authentication configuration and recovery codes;
  • profile details you choose to add, including a profile photograph;
  • your role and status within each business you belong to, and the history of invitations you sent or accepted.

Business and verification data

  • business name, trading name, registration or certificate number, KRA PIN, industry, size and address;
  • business contact details and branch information;
  • details of the accounts from which payments are made, including bank account and mobile money identifiers;
  • documents you upload in support of verification.

Supplier and beneficiary data

  • supplier or beneficiary name and contact details;
  • payment details, including paybill, till, account and phone numbers, bank name and branch;
  • verification status and history of changes to those details.

Transaction data

  • bills, invoices, payment schedules, amounts, currencies, due dates and descriptions;
  • payment status, references and receipts returned by a payment partner;
  • who created, approved, rejected, executed or cancelled each payment, and when;
  • documents and images you upload against a bill, including scanned invoices processed by optical character recognition.

Audit and security data

  • a durable audit trail of actions affecting money, permissions and records;
  • sign-in events, failed sign-in attempts and account lock-outs;
  • IP address, device and browser type, operating system and approximate location derived from IP address;
  • session and cookie identifiers.

Integration data

  • access and refresh tokens for services you connect, such as QuickBooks Online or Zoho Books, held encrypted at rest;
  • records synchronised between the Platform and those services;
  • certificates and credentials used for electronic tax invoicing, held encrypted at rest.

Communications data

  • messages you send us by email, WhatsApp, the website contact form or in-product support;
  • notification preferences and delivery records;
  • feedback, survey responses and support case history.
What we never collect

We do not collect or store your M‑Pesa PIN, your card PIN, your card number or your bank password. Mobile money confirmations are entered directly into the mobile network operator’s own system on your handset. We also do not deliberately collect sensitive personal data such as health, biometric, genetic, religious, ethnic or political information; please do not upload it.

How we collect it

  • Directly from you: when you register, create a business, add a supplier, raise a bill, connect an integration, contact support or complete a form.
  • From your colleagues: when a business owner or administrator invites you, or records information about you as a member.
  • Automatically: through cookies, server logs and security telemetry as you use the Platform.
  • From payment partners: transaction statuses, receipts, references and failure reasons returned to us by banks and mobile money operators.
  • From services you connect: accounting records synchronised from QuickBooks Online, Zoho Books or a file you import.
  • From public and third-party sources: business registry, tax registry and sanctions or politically-exposed-person screening data, where verification or compliance requires it.

Why we use it, and our lawful basis

Section 30 of the Data Protection Act requires a lawful basis for every processing activity. Ours are set out below.

PurposeData usedLawful basis
Create and administer your account Identity, account, business Performance of a contract with you
Verify your identity and your business Identity, business, verification documents Legal obligation; legitimate interest in preventing fraud
Create, approve and execute payment instructions Transaction, supplier, business account Performance of a contract with you
Maintain the audit trail and enforce approval controls Audit, identity, transaction Legal obligation; legitimate interest in accountability and fraud prevention
Detect, investigate and prevent fraud, money laundering and abuse Transaction, audit, security, screening Legal obligation; legitimate interest in protecting our customers
Secure the Platform and your account Security, device, session Legitimate interest in information security
Generate tax records and submit electronic tax invoices Transaction, business, supplier Legal obligation; performance of a contract with you
Send service notifications, reminders and receipts Identity, transaction, communications Performance of a contract with you
Provide support and respond to enquiries Communications, identity, account Performance of a contract; legitimate interest in serving enquirers
Bill you and collect subscription fees Identity, business, billing Performance of a contract with you
Improve, troubleshoot and develop the Platform Usage, security, aggregated data Legitimate interest in improving our service
Send marketing about ShieldPay Identity, contact Consent, which you may withdraw at any time
Establish, exercise or defend legal claims Any relevant data Legal obligation; legitimate interest in defending our rights

Where we rely on a legitimate interest, we have considered whether that interest is overridden by your interests, rights and freedoms, and we have concluded it is not. You may object to that processing, see section 13, and we will stop unless we have compelling grounds to continue or need the data for legal claims.

We do not sell personal data. We do not share it with advertising networks or data brokers, and we do not use your payment history to profile you for advertising.

Payment and mobile money data

ShieldPay is a software platform. We do not hold or custody funds. When a payment is approved and executed, we transmit the instruction to a licensed payment partner, such as Safaricom M‑Pesa, KCB Buni or PesaLink, which moves the money from your own account or wallet.

To do this, we share with the relevant payment partner only what that partner requires to process the transaction: typically the beneficiary identifier, the amount, a reference and the identifiers of the paying account. Each payment partner processes that data as an independent controller under its own privacy notice and its own regulatory licence, and we encourage you to read those notices.

Statuses, receipts, transaction references and failure reasons returned to us are stored against the payment so that you have a complete, reconcilable record. Where a payment requires confirmation on your handset, the PIN is entered into the mobile network operator’s system and never reaches ShieldPay.

Data about other people

Much of what a business puts on the Platform is personal data about other people: suppliers who are sole traders, employees being paid, landlords, contractors and customers.

Where you upload that data, your business is the data controller and we act as your processor. That means you are responsible for:

  • having a lawful basis to collect and share that data with us;
  • telling those people how their data is used, normally through your own privacy notice;
  • keeping the data accurate and up to date; and
  • responding to requests those people make about their data, and we will assist you promptly.

If you are a supplier, employee or other individual whose data appears on the Platform and you want to exercise a right, please contact the business that entered your details. If you do not know which business that is, write to us at support@shieldpayfinance.com and we will help you identify it or pass your request on.

When we share information

We share personal data only where there is a clear reason to, and only to the extent necessary.

RecipientWhy
Payment partnersBanks, mobile money operators and payment service providers, to execute the payments you instruct and to investigate disputes.
Other members of your businessSo colleagues can see the suppliers, bills, payments and audit entries relevant to their role.
Kenya Revenue AuthorityWhere you use electronic tax invoicing or generate tax reports, to meet your tax obligations.
Accounting integrationsQuickBooks Online, Zoho Books and similar services you have explicitly connected, to synchronise the records you have chosen to synchronise.
Infrastructure and service providersHosting, database, storage, email delivery, error monitoring and analytics providers, acting as our processors under written contract.
Professional advisersAuditors, lawyers, accountants and insurers, where necessary and under a duty of confidence.
Regulators and law enforcementThe Financial Reporting Centre, the Central Bank of Kenya, the Office of the Data Protection Commissioner, courts and law enforcement agencies, where required by law or a valid legal process.
A successor entityIn connection with a merger, acquisition, financing or sale of assets, subject to this policy continuing to apply.

Every processor we engage is bound by a written contract requiring them to process data only on our instructions, to apply appropriate security measures, and to return or delete data at the end of the engagement.

Where we are compelled to disclose data to an authority, we assess the request, disclose only what is legally required, and tell you unless the law prevents us from doing so.

Transfers outside Kenya

Some of our service providers (for example cloud hosting, email delivery and error monitoring) process data on servers outside Kenya.

Where personal data leaves Kenya we comply with sections 48 and 49 of the Data Protection Act. That means we transfer only where there is proof of appropriate safeguards, such as a written contract imposing standard data protection obligations on the recipient, or where the transfer is necessary for the performance of our contract with you, or where you have given explicit consent after being informed of the risks.

You may request details of the safeguards applying to a particular transfer by writing to support@shieldpayfinance.com.

How long we keep information

We keep personal data only for as long as we need it for the purpose it was collected, or for as long as the law requires, whichever is longer.

CategoryRetention period
Account and profile dataFor the life of the account, then deleted or anonymised within 90 days of closure.
Transaction and payment recordsAt least 7 years from the end of the relevant tax year, to meet obligations under tax and record-keeping law.
Audit trail entriesAt least 7 years, so the record of who authorised each payment remains available.
Anti-money-laundering and verification recordsAt least 7 years after the end of the business relationship.
Electronic tax invoice recordsAt least 7 years, in line with tax record-keeping requirements.
Security and access logsUp to 24 months, or longer where needed for an active investigation.
Support communicationsUp to 3 years from the last contact.
Marketing contact dataUntil you withdraw consent, plus a suppression record so we do not contact you again.
Integration tokensDeleted when you disconnect the integration or close the account.

Where data must be retained for a statutory period after you close your account, we restrict access to it so that it is used only for the legal purpose that requires its retention. When a retention period ends, we securely delete the data or irreversibly anonymise it.

How we protect information

We apply technical and organisational measures appropriate to the sensitivity of payment data, including:

  • Encryption in transit: all traffic to the Platform is protected with TLS, and connections are upgraded to a secure channel automatically.
  • Encryption at rest: integration credentials, tokens and certificates are encrypted before they are stored.
  • Password protection: passwords are stored only as salted cryptographic hashes, never in a readable form.
  • Two-factor authentication: mandatory for anyone holding an owner, admin, finance manager or approver role.
  • Role-based access control: each member sees only what their role allows, within their own business.
  • Tenant isolation: every record is scoped to a business, and access is checked against your membership on every request.
  • Separation of duties: the person who creates a payment cannot be the person who approves it.
  • Brute-force protection: repeated failed sign-in attempts trigger progressive lock-out.
  • Signed and replay-protected webhooks: inbound payment callbacks are cryptographically verified before they are acted on.
  • Audit logging: every action affecting money or permissions is recorded with the actor and timestamp.
  • Least privilege internally: our staff access customer data only where necessary for support, security or legal compliance, under confidentiality obligations and with that access logged.

No system can be guaranteed completely secure. You play an essential part: use a strong unique password, keep two-factor authentication enabled, never share credentials, and tell us immediately if you suspect a compromise.

Your rights

Under sections 26 and 34 to 40 of the Data Protection Act, you have the right to:

  • be informed of the use to which your personal data is put, and this policy is part of how we do that;
  • access the personal data we hold about you, and obtain a copy;
  • correct data that is inaccurate, outdated, incomplete or misleading;
  • request deletion of data we no longer have a lawful reason to keep;
  • object to processing based on our legitimate interests, and to direct marketing at any time;
  • restrict processing while a dispute about accuracy or lawfulness is resolved;
  • data portability: receive your data in a structured, commonly used, machine-readable format, or have it transmitted to another provider where technically feasible;
  • withdraw consent at any time where processing is based on consent, without affecting processing already carried out; and
  • not be subject to a decision based solely on automated processing that significantly affects you.

Some rights are qualified. We may be unable to delete a transaction record we are legally required to retain, or to erase an audit entry that establishes who authorised a payment. Where we cannot fully meet a request, we will explain why.

How to exercise your rights

Many rights can be exercised directly in the Platform: you can view and correct your profile, manage notification preferences, disconnect integrations, and export your payment history and reports at any time.

For anything else, email support@shieldpayfinance.com with the subject line “Data protection request”, telling us which right you wish to exercise and enough detail for us to locate your records.

  • We will acknowledge your request and may ask you to verify your identity, so that we do not disclose data to the wrong person.
  • We will respond within thirty (30) days. If a request is complex we may extend that period, and we will tell you if we do.
  • There is no fee for a request. We may charge a reasonable administrative fee only where a request is manifestly unfounded or excessive, or repetitive.

If your data was uploaded by a business using ShieldPay (for example because you are one of their suppliers), we will forward your request to that business, which is the controller of that data, and assist them in responding.

Cookies and similar technologies

We use a small number of cookies and similar browser technologies. We do not use advertising cookies and we do not permit third-party advertising trackers on the Platform.

TypePurposeCan it be disabled?
Strictly necessaryKeeping you signed in, remembering the business you are working in, and protecting forms against cross-site request forgery.No, the Platform cannot function without these.
PreferenceRemembering choices such as light or dark appearance. Stored in your browser’s local storage rather than sent to us.Yes, by clearing site data in your browser.
SecurityDetecting repeated failed sign-in attempts and other abuse.No. These protect your account.
AnalyticsUnderstanding aggregate usage so we can improve the Platform. Where used, data is aggregated and not used to identify you.Yes, through your browser settings.

Most browsers let you block or delete cookies. Blocking strictly necessary cookies will prevent you from signing in.

Marketing and communications

We distinguish between two kinds of message.

Service messages are part of the Platform and cannot be switched off entirely: payment approvals and results, security alerts, billing notices, and changes to these terms. You can, however, choose the channel for many of them in your notification settings.

Marketing messages: product news, tips and offers, are sent only with your consent. Every marketing email contains a one-click unsubscribe link, and you can withdraw consent at any time in your notification settings or by emailing us. Withdrawing consent does not affect service messages.

Automated processing

The Platform automates work for you: it generates payments from recurring schedules, matches suppliers, reads uploaded invoices using optical character recognition, retries failed payments, and flags anomalies such as a duplicate payment or a recently changed supplier account number.

These processes support your decisions; they do not replace them. No payment is executed without a human approval from a member holding approval authority, and no automated process makes a decision that produces a legal or similarly significant effect on you without human involvement.

Where a compliance screening flags a transaction or account, the outcome is reviewed by a person before we take any action that affects you, and you may ask for that review and contest the outcome.

Children

The Platform is a business tool intended for people aged eighteen (18) and over. We do not knowingly collect personal data from children. If you believe a child’s data has been provided to us, contact support@shieldpayfinance.com and we will delete it promptly, unless we are legally required to retain it.

Data breaches

We maintain procedures to detect, investigate, contain and report personal data breaches.

Where a breach presents a real risk of harm to the rights and freedoms of a data subject, we will notify the Office of the Data Protection Commissioner within seventy-two (72) hours of becoming aware of it, in line with section 43 of the Data Protection Act, and we will notify affected individuals without undue delay where the law requires it.

Where we act as your processor, we will notify you without undue delay after becoming aware of a breach affecting your data, and give you the information you need to meet your own notification obligations.

Changes to this policy

We review this policy regularly and may update it, for example when we add a feature, change a service provider, or when the law or regulatory guidance changes.

The current version is always published at this address, with the effective date and version number at the top of the page. Where a change is material, we will give at least thirty (30) days’ notice by email to the address on your account or by a prominent notice in the Platform before it takes effect. Where a change requires your consent, we will ask for it.

Complaints

If you are unhappy with how we have handled your personal data or a request, please tell us first at support@shieldpayfinance.com. We take complaints seriously and will investigate and respond.

You also have the right to lodge a complaint with the supervisory authority:

Authority
Office of the Data Protection Commissioner, Kenya
Website
www.odpc.go.ke
Email
info@odpc.go.ke
Location
Nairobi, Republic of Kenya

Contacting the Commissioner does not require you to contact us first, though we would appreciate the opportunity to put things right.

How to contact us

For any question about this policy, about the data we hold, or to make a data protection request, reach us here. We aim to acknowledge every privacy enquiry within one business day.

Entity
ShieldPay Kenya
Privacy email
support@shieldpayfinance.com
WhatsApp / Phone
0705 959 986
Location
Nairobi, Republic of Kenya

This document forms part of the ShieldPay legal framework together with the End User Licence Agreement. Questions may be sent to support@shieldpayfinance.com or WhatsApp 0705 959 986.

↑ Back to top
ShieldPay

Bill payment automation for Kenyan businesses. Powered by KCB Buni and Stanbic PesaLink. CBK-compliant infrastructure.

WhatsApp/Call: 0705 959 986  |  support@shieldpayfinance.com

Product Product How it works Pricing Integrations Contact
Account Sign in Create account FAQs
Legal Licence agreement Privacy policy

KCB Buni · Stanbic PesaLink · CBK compliant · Kenya DPA 2019

© 2026 ShieldPay Kenya. All rights reserved.