Privacy Policy
Plain language summary: We collect the minimum data needed to run an invoicing service — your business details, invoices, and payment info. We share tax records with KRA when a live eTIMS workflow requires it. We use Convex-managed cloud infrastructure, which may process data outside Kenya under the safeguards described below. We will never sell your data. You can export or request deletion of your data at any time, subject to legal retention requirements.
1. Who We Are (Data Controller)
PesaStack Limited ("PesaStack," "we," "us") is the data controller for personal data processed through Risiti. We are a private limited company registered in the Republic of Kenya.
- Product: Risiti (getrisiti.com)
- Contact: hello@getrisiti.com
- Data Protection Officer: As required by Section 24 of the Kenya Data Protection Act, 2019, PesaStack will appoint a Data Protection Officer and register with the Office of the Data Protection Commissioner (ODPC). Until appointment, direct all data protection queries to hello@getrisiti.com.
This Privacy Policy applies to personal data processed through Risiti's websites, applications, merchant dashboard, APIs, webhooks, and support channels. For account administration, security, billing, and product operations, PesaStack acts as a data controller. Where an API Customer submits personal data about a Connected Business, buyer, seller, supplier, or other person for the purpose of providing the contracted Service, PesaStack processes that data on the API Customer's documented instructions, subject to applicable law. The API Customer is responsible for its lawful basis, required notices, authority, consent, and data-subject request handling.
2. What Data We Collect
2.1 Account & Business Data
- Business name and trading name
- KRA Personal Identification Number (PIN)
- Branch ID (if applicable)
- Director or authorized user names
- Phone number (used for login via OTP and SMS notifications)
- Email address (if provided)
- Business type and category
2.2 Invoice Data
- Invoice line items: item descriptions, quantities, unit prices, discount amounts
- Invoice totals, tax calculations, and applicable tax type codes
- Buyer details: buyer name, buyer KRA PIN (if provided), buyer phone number (if provided for SMS delivery)
- Invoice dates, invoice numbers, payment method codes
- KRA receipt numbers and QR code data returned by KRA after invoice submission
- Credit-note reasons and references to original invoices
- Item catalogue, supplier, purchase, and stock-movement information
- Buyer-initiated invoice requests, declarations, seller consent decisions, and audit events
- API request identifiers, idempotency references, API-key prefixes, response status, and webhook delivery records
Note: Invoice data is transmitted to KRA's eTIMS system as a core function of the Service. This is not optional — it is the reason Risiti exists.
2.3 Payment Data
- M-Pesa phone number used for payment
- M-Pesa CheckoutRequestID and MerchantRequestID (transaction identifiers)
- M-Pesa receipt numbers for completed payments
- Subscription plan, amount, and payment timestamps
We do not store your M-Pesa PIN, M-Pesa account balance, or any payment card details.
2.4 Usage Data
- Features used, pages visited, and interaction patterns within the app
- Error logs and crash reports (anonymized where possible)
- Session timestamps and general usage frequency
- Acquisition source, coarse country and region, browser family, operating-system family, device category, and landing page
- Form progression field names and elapsed time, but never the values typed into those fields
- A first-party pseudonymous browser fingerprint hash used with a random visitor identifier to preserve journey continuity, limit duplicate attribution, and connect a pre-signup journey to the account created in that browser. We do not store the underlying browser fingerprint components.
2.5 Device Data (Mobile App)
- Device type and model
- Operating system version
- App version
- Push notification token (if you enable push notifications)
2.6 SMS Delivery Data
- Recipient phone numbers for SMS delivery via Celcom Africa
- SMS delivery status (sent, failed)
We do not read, store, or process the content of any SMS messages you receive. SMS is outbound only.
3. How We Use Your Data
| Purpose | Legal Basis |
|---|---|
| To provide the invoicing service and transmit invoices to KRA via eTIMS | Contract performance + Legal obligation (Tax Procedures Act, 2015) |
| To process M-Pesa subscription payments | Contract performance |
| To send transactional SMS (invoice confirmations, payment receipts, KRA status) | Contract performance + Legitimate interest |
| To verify your identity via OTP at login | Contract performance + Security (legitimate interest) |
| To comply with Kenyan tax, financial, and data protection laws | Legal obligation |
| To improve the Service using minimized, pseudonymous analytics | Legitimate interest |
| To send renewal reminders and service announcements | Legitimate interest (you can opt out) |
| To send marketing communications about new features or offers | Consent (you can withdraw at any time) |
4. Who We Share Your Data With
PesaStack does not sell your data. Ever. We share data only with the parties listed below, and only to the extent necessary to provide the Service.
4.1 Kenya Revenue Authority (KRA)
Your invoice data is transmitted to KRA's eTIMS system via the OSCU API. This is the primary and mandatory function of Risiti. Sharing invoice data with KRA is required by Kenyan tax law. You cannot opt out of this and continue using the Service — it is the entire purpose of eTIMS invoicing.
4.2 Safaricom (M-Pesa)
When you make a subscription payment, your M-Pesa phone number and payment amount are shared with Safaricom's Daraja API to process the STK Push transaction. Safaricom's own privacy policy governs their handling of this data.
4.3 Celcom Africa (SMS)
Your phone number (and the phone numbers of invoice recipients, where provided) are shared with Celcom Africa solely for the purpose of delivering SMS notifications. Celcom Africa processes this data as a data processor on our behalf.
4.4 Convex (Cloud Infrastructure)
All Risiti data — including your business profile, invoices, and payment records — is stored on Convex cloud infrastructure in the hosting region configured for the relevant Risiti deployment. That region may be outside Kenya. See Section 5 on international data transfers.
4.5 Law Enforcement & Regulatory Bodies
We may disclose data to Kenyan law enforcement agencies, courts, the ODPC, or other regulatory bodies when required to do so by law, court order, or to protect the rights, property, or safety of PesaStack, our users, or the public.
5. International Data Transfers
Risiti may process or store personal data outside Kenya through its cloud and communications service providers. Hosting regions and subprocessors may change as infrastructure is maintained or improved.
Before an international transfer, PesaStack relies on an available lawful transfer basis and appropriate safeguards, such as contractual data-protection commitments, transfer necessity, or explicit consent, as applicable under Kenyan data-protection law. We assess providers and restrict their processing to the services they supply.
If you have concerns about international data transfers, contact us at hello@getrisiti.com.
6. Data Retention
- Active account data: Retained for the duration of your subscription and for 30 days after account closure to allow data export.
- Invoice and tax data: Retained for the applicable statutory period—ordinarily at least five years from the end of the relevant reporting period—and longer where another tax law, an amended assessment, investigation, or proceeding requires it. This may apply after account closure.
- Payment records: Retained for 7 years for financial record-keeping compliance.
- Usage and analytics data: Raw event logs are retained for up to 90 days, then deleted or converted to privacy-safe aggregates. Pseudonymous identity aliases may be retained while an account or waitlist relationship is active where needed for journey continuity and duplicate prevention.
- SMS delivery logs: Retained for 12 months.
- OTP verification records: Deleted within 24 hours of use.
7. Your Rights Under the Kenya Data Protection Act, 2019
As a data subject under the Kenya DPA 2019, you have the following rights:
To exercise any of these rights, email hello@getrisiti.com with the subject line "Data Rights Request." We will verify your identity before processing the request.
8. Security
PesaStack implements the following security measures to protect your data:
- Encryption in transit: All data transmitted between your device and our servers uses TLS 1.2 or higher.
- Encryption at rest: Data stored on Convex infrastructure is encrypted at rest.
- Access controls: Access to production data is restricted to authorized PesaStack personnel only, on a need-to-know basis.
- Authentication: Direct-user access uses phone OTP. Merchant workspace access uses verified email credentials and protected sessions. API access uses hashed, scoped, revocable keys whose plaintext is shown only when created.
- API safeguards: Merchant ownership checks, sandbox/live separation, production approval, minimum scopes, idempotency, payload limits, rate limits, request logging, key rotation and revocation, and account suspension are enforced server-side.
- No M-Pesa PIN storage: We never store, log, or transmit your M-Pesa PIN.
No security system is 100% impenetrable. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the ODPC as required by the Kenya Data Protection Act, 2019.
9. Children's Privacy
Risiti is a business tool intended for adults operating registered businesses in Kenya. We do not knowingly collect personal data from anyone under 18 years of age. If you believe a minor has created an account, contact us at hello@getrisiti.com and we will delete the account.
10. Cookies & Web Tracking
For details on how Risiti uses cookies and tracking technologies on the web app, see our Cookie Policy.
In summary: we use session storage for authentication and privacy-limited first-party analytics under legitimate interests to understand acquisition, engagement, reliability, and form progression. Visitors can opt out and browser Do Not Track is respected. We do not use Google Analytics, Google Ads tags, advertising pixels, session replay, exact location, IP addresses in analytics records, or form values in analytics events.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email or SMS at least 30 days before the changes take effect. The updated policy will always be available at getrisiti.com/privacy.
Your continued use of Risiti after the effective date of changes constitutes acceptance of the updated policy.
12. Contact & Complaints
For any privacy-related questions, requests, or complaints:
- Email: hello@getrisiti.com (subject: "Privacy")
- Website: getrisiti.com
- Company: PesaStack Limited, Nairobi, Kenya
If you are not satisfied with our response, you have the right to
contact the
Office of the Data Protection Commissioner (ODPC):
Website: odpc.go.ke · Email:
info@odpc.go.ke