Lawful basis, and only what is needed
Identity data is held because the law requires us to hold it, and we do not collect what we have no use for. The payer on a checkout gives a phone number and, optionally, a name.
Told at the point of collection
The hosted checkout says in plain language, where the payer can read it, that as the processor we record technical details of the visit to detect fraud and meet anti-money-laundering obligations. Not buried in a policy nobody opens.
Separated from the merchant
Those technical details are ours for fraud and compliance. They are not handed to the business being paid. A shop receives the payment and the name, if a name was given, and does not receive a profile of its customer.
Minimised in our own logs
Logging uses an allowlist rather than a denylist, so a field nobody has thought about yet cannot leak by default. Phone numbers, PINs, tokens and provider credentials are masked. This was a finding once and it is now the shape of the system.
Transferred out of Kenya, on a basis we will name
The database is in Ireland, the application in London, and verification documents in Western Europe, because the application and the database have to sit beside each other and there was no managed database near Nairobi we were willing to run money on. Account and transaction data moves on the necessity of the transfer for performing the contract, with each provider contractually bound to the standard the Act requires. An identity document is sensitive personal data and the threshold is higher, so that transfer rests on consent as well, asked for in the dashboard before anything is uploaded.
Rights, and who to ask
Access, correction, deletion and objection under the Act. Write to us and we will tell you what we hold and what we can and cannot remove, since some of it we are obliged to keep.