Quepay Privacy Policy
Last updated: 29 November 2025
QUEPAY LTD (“QuePay”, “we”, “us”, “our”) respects your privacy and is committed to protecting your personal data in full compliance with the Kenya Data Protection Act, 2019 and its Regulations.
This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you use:
- Our website: https://quepay.co.ke
- QuePay consumer mobile app (Android/iOS)
- QuePay merchant dashboard and merchant Android app
- QuePay hardware devices (Smart ATM Controller – PLC, embedded & handheld)
- NFC prepaid cards and QR payment services
1. Data Controller
QUEPAY LTD
Ground Floor, Chandaria Innovation Center
Kenyatta University, Thika Road, Nairobi, Kenya
Email: dpo@quepay.co.ke
We are in the process of registering with the Office of the Data Protection Commissioner (ODPC) as a Data Controller.
2. Personal Data We Collect
| Category | Examples | When Collected |
|---|---|---|
| Identity Data | Full name | Registration |
| Contact Data | Phone number, email address | Registration & use |
| Transaction Data | M-Pesa transaction records, amounts, timestamps | Every payment |
| Technical Data | Device ID (system-generated), IP address, app logs | App & hardware usage |
We do NOT collect: National ID, KRA PIN, biometric data, location data, or data belonging to children under 18.
3. How We Use Your Personal Data
- To create and manage your account
- To process payments and top-ups via M-Pesa
- To provide transaction receipts and statements
- To prevent fraud and ensure security
- To improve our services and generate anonymised analytics
- To comply with tax, anti-money laundering, and CBK regulations
- To send essential service notifications (e.g., payment confirmations)
We will only send marketing messages (SMS/email/WhatsApp) if you give explicit opt-in consent, which you can withdraw at any time.
4. Lawful Basis for Processing
- Performance of contract – to provide payment services
- Legal obligation – tax and AML record-keeping
- Legitimate interests – fraud prevention and service improvement
- Consent – marketing communications (optional)
5. Who We Share Your Data With
- Safaricom PLC – for M-Pesa payment processing (Kenya)
- DigitalOcean & AWS – secure cloud hosting (with Standard Contractual Clauses)
- Infobip – transactional SMS
- Google Analytics & Microsoft Clarity – anonymised usage insights
We never sell your data. We only share where necessary and under strict data processing agreements.
6. International Data Transfers
Some processors (DigitalOcean, AWS) are located in the USA. We only transfer data under ODPC-approved Standard Contractual Clauses and binding Data Processing Agreements to ensure the same level of protection as in Kenya.
7. Security & Retention
- Security: TLS 1.2+ encryption in transit, AES-256 at rest, MFA, regular penetration testing
- Retention: Transaction data kept for 7 years (legal requirement). All other data deleted 7 years after last activity.
8. Your Rights (Free of Charge)
You have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion (“right to be forgotten”)
- Restrict or object to processing
- Data portability
- Withdraw consent (for marketing)
Email your request to: dpo@quepay.co.ke
9. Data Breach Notification
In the unlikely event of a personal data breach that risks your rights, we will notify the ODPC within 72 hours and inform you without undue delay.
10. Cookies & Analytics
Our website and apps use anonymised analytics (Google Analytics, Microsoft Clarity) to improve user experience. No personal data is sent without consent.
11. Changes to this Policy
We may update this Privacy Policy from time to time. The latest version will always be posted here with the updated date.
12. Contact Us & Complaints
Data Protection Officer:
Email: dpo@quepay.co.ke
Phone: 0705 876 339
Address: Ground Floor, Chandaria Innovation Center, Kenyatta University, Thika Rd, Nairobi
If you are unhappy with how we handle your data, you may lodge a complaint with the
Office of the Data Protection Commissioner: complaints@odpc.go.ke
