Privacy Policy
Last updated: June 2025 | Effective immediately upon registration
🔒 Your privacy matters to us. This policy explains how KenyaVest collects, uses, and protects your personal information.
1. Information We Collect
When you use KenyaVest, we collect the following information:
- Account Information: Full name, email address, phone number (M-Pesa registered number)
- Transaction Data: Deposit amounts, withdrawal requests, investment plans, M-Pesa transaction IDs
- Device Information: Browser type, operating system, IP address, and usage logs
- Communications: Messages sent through our contact form or support channels
2. How We Use Your Information
We use your information to:
- Create and manage your investment account
- Process deposits and withdrawals via M-Pesa
- Send account verification and security OTP codes
- Calculate and credit daily ROI returns to your balance
- Administer the referral program
- Send important account notifications and updates
- Comply with anti-money laundering (AML) regulations
- Improve our platform services
3. Data Sharing
We do not sell your personal data to third parties. We may share data only in these limited circumstances:
- M-Pesa / Safaricom: To process mobile money transactions on your behalf
- Email Providers: To send you transactional emails (e.g., OTP verification via SendGrid)
- Legal Compliance: When required by Kenyan law, court orders, or regulatory authorities
- Security: To prevent fraud, abuse, or illegal activities on the platform
4. Data Security
We protect your data using industry-standard security measures:
- All passwords are hashed using bcrypt before storage — we never store plain-text passwords
- All API communications are encrypted using HTTPS/TLS
- Authentication tokens (JWTs) are signed and expire periodically
- Rate limiting and brute-force protection are applied on all login and OTP endpoints
5. Cookies & Local Storage
KenyaVest uses browser localStorage to store your authentication token securely on your device. This enables you to stay logged in between sessions. We do not use third-party tracking cookies or advertising cookies.
6. Data Retention
We retain your account information for as long as your account is active. Transaction records are retained for a minimum of 7 years to comply with Kenyan financial regulations. You may request deletion of your account by contacting us, subject to legal retention requirements.
7. Your Rights
Under Kenyan data protection laws, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate personal data
- Request deletion of your account and personal data (subject to legal requirements)
- Object to certain processing of your data
8. Children's Privacy
KenyaVest does not knowingly collect or solicit personal information from anyone under the age of 18. If we become aware that we have collected personal information from a minor, we will delete it immediately.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by updating the "Last updated" date at the top of this page. Continued use of the platform constitutes acceptance of the revised policy.
10. Contact Us
For questions, concerns, or requests regarding your personal data, please contact us at privacy@kenyavest.com or through the Contact form on our website.