Last Updated: September 19, 2026
1. Introduction
Welcome to SWIFT-WALLET ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our M-Pesa payment processing platform and services.
By using SWIFT-WALLET services, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.
This Privacy Policy applies to all users of SWIFT-WALLET, including businesses, developers, and end-users who interact with our payment processing services.
2.1 Personal Information
We collect personal information that you provide directly to us, including:
- Account Information: Name, email address, phone number, business name, and contact details when you create an account
- Identity Verification: Government-issued identification documents, business registration certificates, and KYC (Know Your Customer) documentation
- Payment Information: Bank account details, M-Pesa Paybill numbers, Till numbers, and other payment channel information
- Communication Data: Records of correspondence, support tickets, and feedback you provide to us
2.2 Transaction Data
When processing payments through our platform, we collect:
- Transaction amounts, currency, and payment references
- Customer phone numbers and names for M-Pesa STK Push transactions
- Transaction status, timestamps, and confirmation codes
- Payment channel information (Paybill, Till Number, or Bank Settlement)
- Callback and webhook data related to payment status updates
2.3 Technical Information
We automatically collect certain technical information when you use our services:
- API Usage Data: API keys, request logs, response codes, and endpoint usage statistics
- Device Information: IP addresses, browser type, device identifiers, and operating system information
- Usage Analytics: Pages visited, features used, time spent on platform, and navigation patterns
- Error Logs: Technical error messages, debugging information, and system performance metrics
2.4 Cookies and Tracking Technologies
We use cookies, web beacons, and similar tracking technologies to:
- Maintain your session and authentication state
- Remember your preferences and settings
- Analyze website traffic and user behavior
- Improve our services and user experience
3. How We Use Your Information
We use the collected information for the following purposes:
3.1 Service Provision
- Process and facilitate M-Pesa payments and transactions
- Manage your account and provide customer support
- Authenticate API requests and ensure secure access
- Send payment confirmations, receipts, and transaction notifications
- Route payments to appropriate channels (Paybill, Till Number, or Bank)
3.2 Business Operations
- Verify your identity and comply with KYC requirements
- Detect and prevent fraud, abuse, and security threats
- Conduct risk assessments and compliance monitoring
- Generate invoices, reports, and financial statements
- Manage subscriptions, billing, and payment processing
3.3 Communication
- Send important service updates, security alerts, and policy changes
- Respond to your inquiries, support requests, and feedback
- Provide marketing communications (with your consent) about new features and services
- Notify you about account activity and transaction status
3.4 Improvement and Analytics
- Analyze usage patterns to improve our platform and services
- Develop new features and enhance existing functionality
- Conduct research and statistical analysis
- Monitor system performance and optimize infrastructure
4. Data Sharing and Third Parties
We do not sell your personal information. We may share your information in the following circumstances:
4.1 Service Providers
We share information with trusted third-party service providers who assist us in operating our platform:
- Safaricom M-Pesa: To process payments and facilitate STK Push transactions
- Cloud Hosting Providers: For secure data storage and infrastructure management
- Payment Processors: For payment gateway services and transaction processing
- Email Service Providers: For sending transactional and marketing emails
- Analytics Services: For website analytics and performance monitoring
4.2 Legal Requirements
We may disclose your information if required by law or in response to:
- Legal processes, court orders, or government requests
- Regulatory compliance and financial reporting obligations
- Protection of our rights, property, or safety
- Investigation of fraud, security breaches, or illegal activities
4.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections.
4.4 With Your Consent
We may share your information with third parties when you explicitly consent to such sharing.
5. Data Security and Storage
We implement industry-standard security measures to protect your information:
5.1 Security Measures
- Encryption: All data in transit is encrypted using TLS/SSL protocols. Sensitive data at rest is encrypted using AES-256 encryption
- Access Controls: Strict access controls and authentication mechanisms limit access to personal information to authorized personnel only
- API Security: API keys are hashed and stored securely. All API requests are authenticated and rate-limited
- Network Security: Firewalls, intrusion detection systems, and regular security audits protect our infrastructure
- Regular Updates: We regularly update our systems and apply security patches to address vulnerabilities
5.2 Data Storage
Your data is stored on secure servers located in Kenya. We retain your information for as long as necessary to provide our services and comply with legal obligations.
5.3 Data Breach Notification
In the event of a data breach that may affect your personal information, we will notify you and relevant authorities as required by law, typically within 72 hours of becoming aware of the breach.
6. Your Rights
Under the Kenyan Data Protection Act, 2019, and applicable data protection laws, you have the following rights:
6.1 Right of Access
You have the right to request access to the personal information we hold about you, including:
- What personal data we process
- Why we process it
- Who we share it with
- How long we retain it
6.2 Right to Correction
You can request correction of inaccurate or incomplete personal information. We will update your information promptly upon verification.
6.3 Right to Deletion
You may request deletion of your personal information, subject to legal and regulatory requirements that may require us to retain certain data.
6.4 Right to Object
You have the right to object to processing of your personal information for direct marketing purposes or based on legitimate interests.
6.5 Right to Data Portability
You can request a copy of your personal data in a structured, machine-readable format for transfer to another service provider.
6.6 Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
6.7 Exercising Your Rights
To exercise any of these rights, please contact us using the information provided in the "Contact Us" section below. We will respond to your request within 30 days.
7. Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience on our platform:
7.1 Types of Cookies
- Essential Cookies: Required for the platform to function properly, including authentication and session management
- Analytics Cookies: Help us understand how visitors interact with our website and improve user experience
- Preference Cookies: Remember your settings and preferences for future visits
- Marketing Cookies: Used to deliver relevant advertisements and track campaign effectiveness (with your consent)
7.2 Managing Cookies
You can control cookies through your browser settings. However, disabling certain cookies may affect the functionality of our platform. Most browsers allow you to:
- View and delete cookies
- Block cookies from specific sites
- Block all cookies
- Set notifications when cookies are set
8. Data Retention
We retain your personal information for different periods depending on the type of data and purpose:
- Account Information: Retained for the duration of your account and up to 7 years after account closure for legal and regulatory compliance
- Transaction Records: Retained for 7 years as required by financial regulations and tax laws
- API Logs: Retained for 90 days for security and debugging purposes
- Marketing Data: Retained until you unsubscribe or withdraw consent
- KYC Documents: Retained for 5 years after account closure as required by anti-money laundering regulations
After the retention period, we securely delete or anonymize your personal information in accordance with our data destruction policies.
9. International Data Transfers
Your personal information is primarily stored and processed in Kenya. However, we may transfer data to service providers located outside Kenya for:
- Cloud hosting and infrastructure services
- Email delivery and communication services
- Analytics and performance monitoring
When transferring data internationally, we ensure appropriate safeguards are in place, including:
- Standard contractual clauses approved by data protection authorities
- Adequacy decisions recognizing the recipient country's data protection laws
- Binding corporate rules for multinational service providers
10. Children's Privacy
SWIFT-WALLET services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately, and we will take steps to delete such information.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of significant changes by:
- Posting the updated policy on our website with a new "Last Updated" date
- Sending an email notification to registered users
- Displaying a prominent notice on our platform
Your continued use of our services after such changes constitutes acceptance of the updated Privacy Policy. We encourage you to review this policy periodically.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
SWIFT-WALLET Privacy Team
Email: [email protected]
Address: [Your Business Address], Kenya
Phone: [Your Contact Number]
For data protection inquiries or to exercise your rights, you can also contact our Data Protection Officer at [email protected]
13. Compliance and Legal Framework
SWIFT-WALLET is committed to compliance with applicable data protection laws and regulations:
13.1 Kenyan Data Protection Act, 2019
We comply with the Data Protection Act, 2019, which governs the processing of personal data in Kenya. This includes:
- Lawful, fair, and transparent processing of personal data
- Collection for specified, explicit, and legitimate purposes
- Data minimization and accuracy
- Appropriate security measures
- Respect for data subject rights
13.2 Financial Regulations
As a payment processing platform, we comply with:
- Central Bank of Kenya regulations
- Anti-Money Laundering (AML) requirements
- Know Your Customer (KYC) obligations
- Payment service provider licensing requirements
13.3 GDPR Principles
While primarily serving Kenyan businesses, we apply GDPR principles where applicable, including:
- Privacy by design and by default
- Data protection impact assessments
- Appointment of a Data Protection Officer
- Regular security audits and compliance reviews
Thank you for trusting SWIFT-WALLET with your payment processing needs. We are committed to protecting your privacy and ensuring the security of your data.