Privacy Notice

mjengoPay Privacy Notice

This notice explains how mjengoPay handles personal data across the platform, including workforce operations, supplier records, and payment workflows.

Version 2026-06-15
Effective June 15, 2026

1. Scope of this Notice

This Privacy Notice explains how mjengoPay collects, uses, stores, shares, and protects personal data processed through the mjengoPay platform.

This Notice should be read together with the mjengoPay Business Terms of Service and any applicable data processing addendum or feature-specific privacy terms.

2. Data We Process

Depending on the feature used, mjengoPay may process account, workforce, supplier, payment, and security data.

  • Account and profile data such as names, phone numbers, email addresses, roles, company details, and login records.
  • Worker and supplier data such as names, contact details, ID information, photos, attendance records, pay rates, and payroll records.
  • Transaction and operational data such as wallet activity, approvals, audit logs, notices, device data, IP addresses, and support records.

3. Why We Process Data

mjengoPay processes data to deliver the service, secure the platform, support customers, run payment workflows, maintain records, and comply with law.

  • Account creation, authentication, role management, and access control.
  • Attendance, payroll, supplier payments, wallet routing, reporting, and analytics.
  • Fraud prevention, audit logging, incident response, troubleshooting, and legal compliance.
  • Operational notices, invoices, support communications, and service improvement.

4. Controller and Processor Roles

In many cases, the customer controls the worker, supplier, and operational data it chooses to enter into mjengoPay and acts as the data controller for that information.

mjengoPay may act as a processor when handling such data on the customer's behalf and may also act as an independent controller for account management, platform security, fraud prevention, support, compliance, billing, and service administration.

5. Sharing and Service Providers

mjengoPay may share data with trusted service providers and infrastructure partners where necessary to operate the service.

  • Cloud hosting and storage providers.
  • Payment, mobile money, banking, and messaging providers.
  • Analytics, monitoring, security, and customer support providers.
  • Professional advisers, auditors, regulators, or lawful authorities where required.

6. Cross-Border Processing and Security

Some mjengoPay providers or systems may process or store data outside Kenya. Where cross-border transfers occur, mjengoPay will use reasonable safeguards appropriate to the service and legal requirements.

mjengoPay uses administrative, technical, and organisational safeguards designed to protect personal data, but no online system can be guaranteed to be completely secure or uninterrupted.

7. Retention

mjengoPay retains data for as long as needed to provide the service and for reasonable periods afterward where necessary for legal, audit, security, backup, fraud-prevention, dispute, or operational reasons.

8. Rights and Requests

Where applicable law gives data subjects rights of access, correction, objection, deletion, restriction, portability, or complaint, requests can be directed to the relevant customer controller or to mjengoPay, depending on the role mjengoPay is performing for the data in question.

9. Bring Your Own Paybill (BYOP) Data

If your company uses Bring Your Own Paybill (BYOP) to pay from its own M-Pesa business account, mjengoPay processes additional data to connect to and operate that account on your instruction.

For BYOP, your company is the controller of its own M-Pesa account data and the worker and supplier data it pays. mjengoPay acts as your processor and authorised agent when it uses your credentials to initiate transactions you have authorised, and as an independent controller for the fee, audit, security, and tax records arising from providing the service.

  • M-Pesa API (Daraja) credentials you provide — consumer key and secret, passkey, initiator name, and security credential — which mjengoPay stores encrypted and uses only to perform the operations you authorise.
  • Your M-Pesa account operational data — shortcode, account balances, and the C2B, B2C, and B2B transaction flows and receipts mjengoPay observes — used to orchestrate payouts, collect mjengoPay's fees, reconcile, and report.
  • Payee data processed through your paybill, such as worker and supplier phone numbers, amounts, and payout outcomes.
  • Tax data such as your KRA PIN and the fee invoices/receipts mjengoPay issues on its service fee.
  • mjengoPay shares data with Safaricom (using your credentials, on your behalf, to execute the transactions you authorise) and with the Kenya Revenue Authority where required for tax-compliant receipting of mjengoPay's service fee.
  • On deactivation, suspension, or termination of BYOP, mjengoPay stops acting on your shortcode and deletes the stored credentials, retaining transaction and fee records only as needed for legal, audit, and tax purposes.

10. Contact

Privacy questions can be sent to hello@mjengopay.com.