About this policy
This Privacy Policy explains how ShieldPay Kenya (“ShieldPay”, “we”, “us”) handles personal data in connection with the ShieldPay Finance System (the “Platform”), our bill payment automation service for Kenyan businesses.
It applies to our website, the Platform, our application programming interfaces, and our email, WhatsApp and telephone support. It should be read alongside the End User Licence Agreement.
We process personal data in accordance with the Data Protection Act, 2019 and the regulations made under it, and with the guidance of the Office of the Data Protection Commissioner.
We collect what we need to open your account, verify your business, execute the payments you instruct, keep an audit trail, meet our legal duties and support you. We do not sell personal data, ever. We do not use your payment history to advertise to you. We never collect your M‑Pesa PIN, card PIN or bank password.
Who we are
ShieldPay Kenya operates the Platform from Nairobi, Kenya. For the personal data described in this policy for which we are the data controller, we are the entity responsible.
- Data controller
- ShieldPay Kenya
- Privacy contact
- support@shieldpayfinance.com
- WhatsApp / Phone
- 0705 959 986
- Location
- Nairobi, Republic of Kenya
Controller and processor roles
Our role under the Data Protection Act depends on whose data is involved.
| Whose data | Our role | What that means |
|---|---|---|
| Your own account data | Controller | We decide why and how we process it (for example your name, email, phone number and security settings) and this policy governs it. |
| Data you upload about suppliers, employees and customers | Processor | Your business decides why and how it is processed. We act on your instructions. Your own privacy notice governs it, and you are responsible for having a lawful basis. |
| Website visitors and enquiries | Controller | We decide why and how we process it, for the purposes described below. |
Where we act as a processor, we process personal data only on your documented instructions, keep it confidential, apply the security measures described in section 12, assist you in responding to data subject requests, and delete or return it at the end of the engagement, subject to the retention rules in section 11.
What we collect
Identity and account data
- full name, username, email address and phone number;
- password, stored only as a salted cryptographic hash, and we never store it in a readable form;
- two-factor authentication configuration and recovery codes;
- profile details you choose to add, including a profile photograph;
- your role and status within each business you belong to, and the history of invitations you sent or accepted.
Business and verification data
- business name, trading name, registration or certificate number, KRA PIN, industry, size and address;
- business contact details and branch information;
- details of the accounts from which payments are made, including bank account and mobile money identifiers;
- documents you upload in support of verification.
Supplier and beneficiary data
- supplier or beneficiary name and contact details;
- payment details, including paybill, till, account and phone numbers, bank name and branch;
- verification status and history of changes to those details.
Transaction data
- bills, invoices, payment schedules, amounts, currencies, due dates and descriptions;
- payment status, references and receipts returned by a payment partner;
- who created, approved, rejected, executed or cancelled each payment, and when;
- documents and images you upload against a bill, including scanned invoices processed by optical character recognition.
Audit and security data
- a durable audit trail of actions affecting money, permissions and records;
- sign-in events, failed sign-in attempts and account lock-outs;
- IP address, device and browser type, operating system and approximate location derived from IP address;
- session and cookie identifiers.
Integration data
- access and refresh tokens for services you connect, such as QuickBooks Online or Zoho Books, held encrypted at rest;
- records synchronised between the Platform and those services;
- certificates and credentials used for electronic tax invoicing, held encrypted at rest.
Communications data
- messages you send us by email, WhatsApp, the website contact form or in-product support;
- notification preferences and delivery records;
- feedback, survey responses and support case history.
We do not collect or store your M‑Pesa PIN, your card PIN, your card number or your bank password. Mobile money confirmations are entered directly into the mobile network operator’s own system on your handset. We also do not deliberately collect sensitive personal data such as health, biometric, genetic, religious, ethnic or political information; please do not upload it.
How we collect it
- Directly from you: when you register, create a business, add a supplier, raise a bill, connect an integration, contact support or complete a form.
- From your colleagues: when a business owner or administrator invites you, or records information about you as a member.
- Automatically: through cookies, server logs and security telemetry as you use the Platform.
- From payment partners: transaction statuses, receipts, references and failure reasons returned to us by banks and mobile money operators.
- From services you connect: accounting records synchronised from QuickBooks Online, Zoho Books or a file you import.
- From public and third-party sources: business registry, tax registry and sanctions or politically-exposed-person screening data, where verification or compliance requires it.
Why we use it, and our lawful basis
Section 30 of the Data Protection Act requires a lawful basis for every processing activity. Ours are set out below.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Create and administer your account | Identity, account, business | Performance of a contract with you |
| Verify your identity and your business | Identity, business, verification documents | Legal obligation; legitimate interest in preventing fraud |
| Create, approve and execute payment instructions | Transaction, supplier, business account | Performance of a contract with you |
| Maintain the audit trail and enforce approval controls | Audit, identity, transaction | Legal obligation; legitimate interest in accountability and fraud prevention |
| Detect, investigate and prevent fraud, money laundering and abuse | Transaction, audit, security, screening | Legal obligation; legitimate interest in protecting our customers |
| Secure the Platform and your account | Security, device, session | Legitimate interest in information security |
| Generate tax records and submit electronic tax invoices | Transaction, business, supplier | Legal obligation; performance of a contract with you |
| Send service notifications, reminders and receipts | Identity, transaction, communications | Performance of a contract with you |
| Provide support and respond to enquiries | Communications, identity, account | Performance of a contract; legitimate interest in serving enquirers |
| Bill you and collect subscription fees | Identity, business, billing | Performance of a contract with you |
| Improve, troubleshoot and develop the Platform | Usage, security, aggregated data | Legitimate interest in improving our service |
| Send marketing about ShieldPay | Identity, contact | Consent, which you may withdraw at any time |
| Establish, exercise or defend legal claims | Any relevant data | Legal obligation; legitimate interest in defending our rights |
Where we rely on a legitimate interest, we have considered whether that interest is overridden by your interests, rights and freedoms, and we have concluded it is not. You may object to that processing, see section 13, and we will stop unless we have compelling grounds to continue or need the data for legal claims.
We do not sell personal data. We do not share it with advertising networks or data brokers, and we do not use your payment history to profile you for advertising.
Payment and mobile money data
ShieldPay is a software platform. We do not hold or custody funds. When a payment is approved and executed, we transmit the instruction to a licensed payment partner, such as Safaricom M‑Pesa, KCB Buni or PesaLink, which moves the money from your own account or wallet.
To do this, we share with the relevant payment partner only what that partner requires to process the transaction: typically the beneficiary identifier, the amount, a reference and the identifiers of the paying account. Each payment partner processes that data as an independent controller under its own privacy notice and its own regulatory licence, and we encourage you to read those notices.
Statuses, receipts, transaction references and failure reasons returned to us are stored against the payment so that you have a complete, reconcilable record. Where a payment requires confirmation on your handset, the PIN is entered into the mobile network operator’s system and never reaches ShieldPay.
Data about other people
Much of what a business puts on the Platform is personal data about other people: suppliers who are sole traders, employees being paid, landlords, contractors and customers.
Where you upload that data, your business is the data controller and we act as your processor. That means you are responsible for:
- having a lawful basis to collect and share that data with us;
- telling those people how their data is used, normally through your own privacy notice;
- keeping the data accurate and up to date; and
- responding to requests those people make about their data, and we will assist you promptly.
If you are a supplier, employee or other individual whose data appears on the Platform and you want to exercise a right, please contact the business that entered your details. If you do not know which business that is, write to us at support@shieldpayfinance.com and we will help you identify it or pass your request on.
Transfers outside Kenya
Some of our service providers (for example cloud hosting, email delivery and error monitoring) process data on servers outside Kenya.
Where personal data leaves Kenya we comply with sections 48 and 49 of the Data Protection Act. That means we transfer only where there is proof of appropriate safeguards, such as a written contract imposing standard data protection obligations on the recipient, or where the transfer is necessary for the performance of our contract with you, or where you have given explicit consent after being informed of the risks.
You may request details of the safeguards applying to a particular transfer by writing to support@shieldpayfinance.com.
How long we keep information
We keep personal data only for as long as we need it for the purpose it was collected, or for as long as the law requires, whichever is longer.
| Category | Retention period |
|---|---|
| Account and profile data | For the life of the account, then deleted or anonymised within 90 days of closure. |
| Transaction and payment records | At least 7 years from the end of the relevant tax year, to meet obligations under tax and record-keeping law. |
| Audit trail entries | At least 7 years, so the record of who authorised each payment remains available. |
| Anti-money-laundering and verification records | At least 7 years after the end of the business relationship. |
| Electronic tax invoice records | At least 7 years, in line with tax record-keeping requirements. |
| Security and access logs | Up to 24 months, or longer where needed for an active investigation. |
| Support communications | Up to 3 years from the last contact. |
| Marketing contact data | Until you withdraw consent, plus a suppression record so we do not contact you again. |
| Integration tokens | Deleted when you disconnect the integration or close the account. |
Where data must be retained for a statutory period after you close your account, we restrict access to it so that it is used only for the legal purpose that requires its retention. When a retention period ends, we securely delete the data or irreversibly anonymise it.
How we protect information
We apply technical and organisational measures appropriate to the sensitivity of payment data, including:
- Encryption in transit: all traffic to the Platform is protected with TLS, and connections are upgraded to a secure channel automatically.
- Encryption at rest: integration credentials, tokens and certificates are encrypted before they are stored.
- Password protection: passwords are stored only as salted cryptographic hashes, never in a readable form.
- Two-factor authentication: mandatory for anyone holding an owner, admin, finance manager or approver role.
- Role-based access control: each member sees only what their role allows, within their own business.
- Tenant isolation: every record is scoped to a business, and access is checked against your membership on every request.
- Separation of duties: the person who creates a payment cannot be the person who approves it.
- Brute-force protection: repeated failed sign-in attempts trigger progressive lock-out.
- Signed and replay-protected webhooks: inbound payment callbacks are cryptographically verified before they are acted on.
- Audit logging: every action affecting money or permissions is recorded with the actor and timestamp.
- Least privilege internally: our staff access customer data only where necessary for support, security or legal compliance, under confidentiality obligations and with that access logged.
No system can be guaranteed completely secure. You play an essential part: use a strong unique password, keep two-factor authentication enabled, never share credentials, and tell us immediately if you suspect a compromise.
Your rights
Under sections 26 and 34 to 40 of the Data Protection Act, you have the right to:
- be informed of the use to which your personal data is put, and this policy is part of how we do that;
- access the personal data we hold about you, and obtain a copy;
- correct data that is inaccurate, outdated, incomplete or misleading;
- request deletion of data we no longer have a lawful reason to keep;
- object to processing based on our legitimate interests, and to direct marketing at any time;
- restrict processing while a dispute about accuracy or lawfulness is resolved;
- data portability: receive your data in a structured, commonly used, machine-readable format, or have it transmitted to another provider where technically feasible;
- withdraw consent at any time where processing is based on consent, without affecting processing already carried out; and
- not be subject to a decision based solely on automated processing that significantly affects you.
Some rights are qualified. We may be unable to delete a transaction record we are legally required to retain, or to erase an audit entry that establishes who authorised a payment. Where we cannot fully meet a request, we will explain why.
How to exercise your rights
Many rights can be exercised directly in the Platform: you can view and correct your profile, manage notification preferences, disconnect integrations, and export your payment history and reports at any time.
For anything else, email support@shieldpayfinance.com with the subject line “Data protection request”, telling us which right you wish to exercise and enough detail for us to locate your records.
- We will acknowledge your request and may ask you to verify your identity, so that we do not disclose data to the wrong person.
- We will respond within thirty (30) days. If a request is complex we may extend that period, and we will tell you if we do.
- There is no fee for a request. We may charge a reasonable administrative fee only where a request is manifestly unfounded or excessive, or repetitive.
If your data was uploaded by a business using ShieldPay (for example because you are one of their suppliers), we will forward your request to that business, which is the controller of that data, and assist them in responding.
Marketing and communications
We distinguish between two kinds of message.
Service messages are part of the Platform and cannot be switched off entirely: payment approvals and results, security alerts, billing notices, and changes to these terms. You can, however, choose the channel for many of them in your notification settings.
Marketing messages: product news, tips and offers, are sent only with your consent. Every marketing email contains a one-click unsubscribe link, and you can withdraw consent at any time in your notification settings or by emailing us. Withdrawing consent does not affect service messages.
Automated processing
The Platform automates work for you: it generates payments from recurring schedules, matches suppliers, reads uploaded invoices using optical character recognition, retries failed payments, and flags anomalies such as a duplicate payment or a recently changed supplier account number.
These processes support your decisions; they do not replace them. No payment is executed without a human approval from a member holding approval authority, and no automated process makes a decision that produces a legal or similarly significant effect on you without human involvement.
Where a compliance screening flags a transaction or account, the outcome is reviewed by a person before we take any action that affects you, and you may ask for that review and contest the outcome.
Children
The Platform is a business tool intended for people aged eighteen (18) and over. We do not knowingly collect personal data from children. If you believe a child’s data has been provided to us, contact support@shieldpayfinance.com and we will delete it promptly, unless we are legally required to retain it.
Data breaches
We maintain procedures to detect, investigate, contain and report personal data breaches.
Where a breach presents a real risk of harm to the rights and freedoms of a data subject, we will notify the Office of the Data Protection Commissioner within seventy-two (72) hours of becoming aware of it, in line with section 43 of the Data Protection Act, and we will notify affected individuals without undue delay where the law requires it.
Where we act as your processor, we will notify you without undue delay after becoming aware of a breach affecting your data, and give you the information you need to meet your own notification obligations.
Changes to this policy
We review this policy regularly and may update it, for example when we add a feature, change a service provider, or when the law or regulatory guidance changes.
The current version is always published at this address, with the effective date and version number at the top of the page. Where a change is material, we will give at least thirty (30) days’ notice by email to the address on your account or by a prominent notice in the Platform before it takes effect. Where a change requires your consent, we will ask for it.
Complaints
If you are unhappy with how we have handled your personal data or a request, please tell us first at support@shieldpayfinance.com. We take complaints seriously and will investigate and respond.
You also have the right to lodge a complaint with the supervisory authority:
- Authority
- Office of the Data Protection Commissioner, Kenya
- Website
- www.odpc.go.ke
- info@odpc.go.ke
- Location
- Nairobi, Republic of Kenya
Contacting the Commissioner does not require you to contact us first, though we would appreciate the opportunity to put things right.
How to contact us
For any question about this policy, about the data we hold, or to make a data protection request, reach us here. We aim to acknowledge every privacy enquiry within one business day.
- Entity
- ShieldPay Kenya
- Privacy email
- support@shieldpayfinance.com
- WhatsApp / Phone
- 0705 959 986
- Location
- Nairobi, Republic of Kenya
This document forms part of the ShieldPay legal framework together with the End User Licence Agreement. Questions may be sent to support@shieldpayfinance.com or WhatsApp 0705 959 986.
↑ Back to top