Privacy Policy
Last updated: [add date when you publish this]
⚠️ This is a starting template, not legal advice. It covers the basics for a small Kenyan web-design business collecting contact-form info and running a client portal with Firebase + M-Pesa/card payments. Read it fully, adjust anything that doesn't match how you actually operate, and consider a quick review against Kenya's Data Protection Act 2019 before you rely on it.
What we collect
- Contact form submissions: name, phone, business name, and message.
- Client portal accounts: email, name, phone, and project/plan details, stored in Firebase.
- Payment activity: M-Pesa and card payments are processed by Safaricom (Daraja) and Paystack respectively — we do not store your card number or M-Pesa PIN. We do store payment amounts, status, and references to match invoices to your account.
How we use it
- To reply to enquiries and deliver the web design services you've requested.
- To run your client portal account and show your project status and payment history.
- To send project or payment updates via WhatsApp, email, or SMS.
Who we share it with
We don't sell your data. It's shared only with the services that make the portal and payments work: Firebase (Google) for accounts/data storage, Safaricom Daraja for M-Pesa, and Paystack for card payments — each governed by their own privacy policies.
Your rights
You can ask us to correct or delete your data at any time by messaging us on WhatsApp or email (contact details below). Deleting your portal account will remove your Firestore record; payment records may be retained where required for financial record-keeping.
Contact
Questions about this policy: vectuz9@gmail.com or WhatsApp +254 783 944 907.