Privacy Policy
Last updated: August 2026. This policy explains how PAY N BROWSE handles personal data under the Kenya Data Protection Act, 2019.
What we collect
- Tenant accounts: name, email, phone number, business details, and activity logs.
- WiFi customers: the phone number used to pay, the M-Pesa receipt, the voucher purchased, and the connecting device's MAC address. We do not inspect or record customers' browsing traffic.
- Technical: IP addresses and security events, kept for abuse prevention.
How it is used
To deliver purchases (matching M-Pesa payments to vouchers), send voucher codes and service SMS, secure the platform, and meet legal obligations. Tenants may message their own customers; we require such messaging to comply with the Acceptable Use policy.
How it is protected
Credentials and payment secrets are encrypted at rest; phone numbers used for payment matching are additionally stored as one-way hashes; access is role-restricted and audited; security events are monitored.
Retention
Payment records are kept as required by tax and financial rules. Security events are kept 90 days, router health data 30 days, and notifications 90 days. Audit logs are kept 12 months.
Your rights
Under the DPA 2019 you may request access, correction, or deletion of your personal data, and complain to the Office of the Data Protection Commissioner. Contact us through your dashboard's support section or the address on our website.
Sharing
We share data only with processors needed to run the service (Safaricom for payments, our SMS provider for messages, hosting providers) and where the law requires. We do not sell personal data.