Data Governance Framework

Privacy Policy

How Payzaapi handles, secures, and maintains user data across our processing engines.

Last Updated: 26 August 2026
Effective Date: 1 January 2025
01

Introduction

Data Privacy Commitment: Payzaapi ("we", "our", "us") operated via payzaapi.co.ke is committed to preserving the integrity and confidentiality of personal records belonging to business operators and end customers across our systems.

This Privacy Policy specifies the information collected when interfacing with Payzaapi infrastructure, our processing mechanisms, third-party disclosure protocols, and your statutory rights over stored records.

Payzaapi is operated by Payzaapi Technologies in Nairobi, Kenya, in strict adherence to the Kenya Data Protection Act, 2019 alongside applicable international regulatory standards.

02

Information We Collect

We log data provided directly during setup, telemetric data generated through platform consumption, and payload confirmation structures from integrated payment systems.

Account Identity
Merchant name, primary email address, mobile number, registered business name, country, and salt-hashed access passkeys.
Commercial Catalog
Product records, pricing structures, inventory units, digital invoices, order histories, and staff credentials.
Transaction References
Payload amounts, system reference strings, M-Pesa account phone numbers, and destination account payout details.
System Telemetry
Client IP address, browser signature, route access logs, session duration, and action timestamps.
Hardware Context
Device classification, underlying OS kernel version, and browser specifications for fraud prevention.
Support Records
Transmitted support tickets, system emails, and chat transcripts maintained for quality and compliance.

Payzaapi never intercepts or stores plain card primary account numbers (PAN), CVVs, or M-Pesa secret PINs. Sensitive monetary tokens are processed exclusively by PCI-DSS certified partners (Korapay, Tuma, PawaPay) under their isolated gateway protocols.

03

How We Use Your Data

Collected datasets serve operational, security, and administrative functions, including:

  • Core Provisioning: Operating store modules, managing point-of-sale ledgers, and executing billing state changes.
  • Automated Communications: Dispatching transaction receipts, transfer verifications, security alerts, and system notices.
  • Security & Fraud Controls: Monitoring anomalies, detecting multi-account abuse, and auditing illegal transaction attempts.
  • Operational Support: Resolving technical inquiries, handling ledger disputes, and maintaining platform uptime.
  • Regulatory Compliance: Fulfilling statutory duties under Kenyan tax laws and financial compliance mandates.
  • Interface Customization: Setting default regional currency views and localized dashboard preferences.

Payzaapi never sells, rents, or monetizes user or consumer datasets to third-party advertising networks.

04

Data Sharing

Information dispatches strictly occur with authorized infrastructure entities necessary to run the platform:

  • Settlement Gateways: Korapay, Tuma, and PawaPay receive payload specs needed to verify payments and clear merchant disbursements.
  • Email Relays: Isolated transactional mail routing nodes used strictly to deliver receipt and password resets.
  • Cloud Infrastructure: Hardened server clusters and database nodes housing encrypted records in local compliance regions.
  • Statutory Bodies: Disclosures executed only under formal legal summons, court warrants, or regulatory orders from Kenyan enforcement agencies.

All third-party processor partners operate under strict contractual data protection agreements limiting usage strictly to designated tasks.

05

Payment Data Security

PCI-DSS Compliant Operations: Payzaapi strictly enforces TLS 1.2+ encryption on all external interfaces and routes sensitive payment actions to certified processing infrastructure.

  • All browser and API calls enforce encrypted HTTPS transmission (TLS 1.2+).
  • M-Pesa STK push actions execute directly via partner API gateways — authorization PINs never pass through our application code.
  • Card and direct bank clearing operates under Korapay PCI-DSS Level 1 infrastructure.
  • Merchant payout bank account credentials are encrypted at rest using AES-256 database configurations.
06

Infrastructure Security

Multi-layered protective controls guard application state and system records:

  • Password Hashing: Credentials hash via `bcrypt` with unique cryptographic salts.
  • Token Rotation: Session identifiers rotate dynamically upon auth verification and auto-expire after inactivity windows.
  • Rate Throttling: Brute-force rate limiting enforced on API endpoints, auth routes, and checkout actions.
  • System Audit Trail: Immutable logging tracking administrative actions and balance state changes.
07

Retention Schedule

Datasets persist according to operational necessity and regulatory statutory timelines:

  • Account Records: Preserved for 7 years post account closure to fulfill Kenyan financial audit regulations.
  • Ledger Transactions: Retained for a minimum of 7 years for tax compliance verification.
  • Support Log History: Preserved for 3 years.
  • System Access Telemetry: Retained for 12 months for security threat auditing.
08

Statutory Rights

Under the Kenya Data Protection Act, 2019, registered users hold explicit statutory rights:

  • Access Rights: Request structured copies of all personal and commercial records held in active storage.
  • Rectification Rights: Request prompt updates to inaccurate or outdated entity information.
  • Erasure Rights: Request account purging, subject to statutory tax and financial retention laws.
  • Data Portability: Export commercial dataset copies in standard machine-readable JSON or CSV formats.

To exercise statutory data rights, transmit an inquiry to [email protected]. Responses issue within 30 days.

09

Cookies & Telemetry

Payzaapi uses functional state cookies necessary for software operations:

  • Session State Cookies: Essential for maintaining authenticated access states. Expire automatically upon session exit.
  • Security State Tokens: Anti-CSRF tokens validating inbound request signatures against cross-site exploitation.
  • Preference Cookies: Storing local UI options and table layout state across logins.

We do not deploy third-party advertising or cross-site behavior tracker cookies.

10

Minors Protection

Payzaapi is exclusively built for business operations and legal commercial entities. We do not register accounts or collect data from individuals under 18 years of age. Accounts identified as belonging to minors are terminated immediately.

11

Policy Modifications

Material adjustments to data processing practices trigger a 30-day advance notice dispatched via email to registered primary contact addresses alongside dashboard notification banners.

12

Contact Channel

For inquiries regarding data privacy compliance, statutory requests, or infrastructure security:

Payzaapi Technologies · Nairobi, Kenya
Open Contact Channel