Privacy Policy
How Payzaapi handles, secures, and maintains user data across our processing engines.
Introduction
Data Privacy Commitment: Payzaapi ("we", "our", "us") operated via payzaapi.co.ke is committed to preserving the integrity and confidentiality of personal records belonging to business operators and end customers across our systems.
This Privacy Policy specifies the information collected when interfacing with Payzaapi infrastructure, our processing mechanisms, third-party disclosure protocols, and your statutory rights over stored records.
Payzaapi is operated by Payzaapi Technologies in Nairobi, Kenya, in strict adherence to the Kenya Data Protection Act, 2019 alongside applicable international regulatory standards.
Information We Collect
We log data provided directly during setup, telemetric data generated through platform consumption, and payload confirmation structures from integrated payment systems.
Payzaapi never intercepts or stores plain card primary account numbers (PAN), CVVs, or M-Pesa secret PINs. Sensitive monetary tokens are processed exclusively by PCI-DSS certified partners (Korapay, Tuma, PawaPay) under their isolated gateway protocols.
How We Use Your Data
Collected datasets serve operational, security, and administrative functions, including:
- Core Provisioning: Operating store modules, managing point-of-sale ledgers, and executing billing state changes.
- Automated Communications: Dispatching transaction receipts, transfer verifications, security alerts, and system notices.
- Security & Fraud Controls: Monitoring anomalies, detecting multi-account abuse, and auditing illegal transaction attempts.
- Operational Support: Resolving technical inquiries, handling ledger disputes, and maintaining platform uptime.
- Regulatory Compliance: Fulfilling statutory duties under Kenyan tax laws and financial compliance mandates.
- Interface Customization: Setting default regional currency views and localized dashboard preferences.
Payzaapi never sells, rents, or monetizes user or consumer datasets to third-party advertising networks.
Data Sharing
Information dispatches strictly occur with authorized infrastructure entities necessary to run the platform:
- Settlement Gateways: Korapay, Tuma, and PawaPay receive payload specs needed to verify payments and clear merchant disbursements.
- Email Relays: Isolated transactional mail routing nodes used strictly to deliver receipt and password resets.
- Cloud Infrastructure: Hardened server clusters and database nodes housing encrypted records in local compliance regions.
- Statutory Bodies: Disclosures executed only under formal legal summons, court warrants, or regulatory orders from Kenyan enforcement agencies.
All third-party processor partners operate under strict contractual data protection agreements limiting usage strictly to designated tasks.
Payment Data Security
PCI-DSS Compliant Operations: Payzaapi strictly enforces TLS 1.2+ encryption on all external interfaces and routes sensitive payment actions to certified processing infrastructure.
- All browser and API calls enforce encrypted HTTPS transmission (TLS 1.2+).
- M-Pesa STK push actions execute directly via partner API gateways — authorization PINs never pass through our application code.
- Card and direct bank clearing operates under Korapay PCI-DSS Level 1 infrastructure.
- Merchant payout bank account credentials are encrypted at rest using AES-256 database configurations.
Infrastructure Security
Multi-layered protective controls guard application state and system records:
- Password Hashing: Credentials hash via `bcrypt` with unique cryptographic salts.
- Token Rotation: Session identifiers rotate dynamically upon auth verification and auto-expire after inactivity windows.
- Rate Throttling: Brute-force rate limiting enforced on API endpoints, auth routes, and checkout actions.
- System Audit Trail: Immutable logging tracking administrative actions and balance state changes.
Retention Schedule
Datasets persist according to operational necessity and regulatory statutory timelines:
- Account Records: Preserved for 7 years post account closure to fulfill Kenyan financial audit regulations.
- Ledger Transactions: Retained for a minimum of 7 years for tax compliance verification.
- Support Log History: Preserved for 3 years.
- System Access Telemetry: Retained for 12 months for security threat auditing.
Statutory Rights
Under the Kenya Data Protection Act, 2019, registered users hold explicit statutory rights:
- Access Rights: Request structured copies of all personal and commercial records held in active storage.
- Rectification Rights: Request prompt updates to inaccurate or outdated entity information.
- Erasure Rights: Request account purging, subject to statutory tax and financial retention laws.
- Data Portability: Export commercial dataset copies in standard machine-readable JSON or CSV formats.
To exercise statutory data rights, transmit an inquiry to [email protected]. Responses issue within 30 days.
Cookies & Telemetry
Payzaapi uses functional state cookies necessary for software operations:
- Session State Cookies: Essential for maintaining authenticated access states. Expire automatically upon session exit.
- Security State Tokens: Anti-CSRF tokens validating inbound request signatures against cross-site exploitation.
- Preference Cookies: Storing local UI options and table layout state across logins.
We do not deploy third-party advertising or cross-site behavior tracker cookies.
Minors Protection
Payzaapi is exclusively built for business operations and legal commercial entities. We do not register accounts or collect data from individuals under 18 years of age. Accounts identified as belonging to minors are terminated immediately.
Policy Modifications
Material adjustments to data processing practices trigger a 30-day advance notice dispatched via email to registered primary contact addresses alongside dashboard notification banners.
Contact Channel
For inquiries regarding data privacy compliance, statutory requests, or infrastructure security: