JengaLedger Privacy Policy
4 August 2026
JengaLedger ("we", "us", "our") is operated by JengaLedger Technologies ("the Company"). This policy explains what personal data we collect through the JengaLedger mobile application and related services (the "Service"), why we collect it, how it is used and protected, and the rights you have over it under the Kenya Data Protection Act, 2019 ("the Act").
1. Who we are
- Data controller: JengaLedger Technologies
- Business location: Eldoret, Kenya
- Contact for privacy matters: admin@jengaledger.co.ke
- Data Protection Officer: JengaLedger Technologies has not appointed a dedicated Data Protection Officer. Privacy questions and data-subject requests may be sent to support@jengaledger.co.ke.
2. What personal data we collect
| Data | Collected when | Why |
|---|---|---|
| Full name | Registration | Identify your account and appear on documents you generate for your own customers |
| National ID number | Registration | Prevent duplicate accounts; required for certain regulatory/verification purposes. Stored encrypted (AES-256-GCM) — never in plain text, and never displayed back to anyone but you |
| Phone number | Registration | Login identity, SMS one-time codes (login, password reset, debt reminders you choose to send), and — if you register through USSD — your primary identifier on that channel |
| Business PIN / registration number (company accounts only) | Registration | Identify a registered business account distinctly from an individual one. Business PIN is stored encrypted |
| Your customers' names, phone numbers, and transaction records | As you use the app to record sales/debts/expenses | This is the core bookkeeping service you use JengaLedger for — this data belongs to your business relationship with your own customers, and we process it on your behalf as a data processor for that purpose, not for our own use |
| Payment records (M-Pesa/Pesapal transaction references) | When you pay for a subscription | Activate and track your subscription |
| Device identifiers (for offline-mode devices, where enabled) | Only if you opt into offline-mode device registration | Let your account work correctly without a network connection |
We do not collect your bank account numbers, card numbers, or M-Pesa PIN — the app never asks for these; do not enter them anywhere in JengaLedger.
3. How we use your data
- To provide the Service: recording your sales, expenses, debts, and generating documents (cards, statements, receipts) for your own customers.
- To communicate with you: SMS one-time codes, debt-reminder SMS you explicitly trigger, and in-app notifications.
- To process subscription payments, through one or more licensed payment channels depending on how you pay and how you installed the app — this may include a payment gateway (Pesapal), direct mobile money processing (Safaricom M-Pesa, via STK Push / Lipa na M-Pesa), Jenga (Equity/Finserve), or Google Play Billing.
- To maintain security: detecting fraud/abuse, rate-limiting, and investigating reported problems.
- We do not sell your personal data, or your customers' data, to any third party.
4. Who we share data with
| Third party | What they receive | Why |
|---|---|---|
| Pesapal | Payment amount, phone number, a merchant reference | Process your subscription payment when this channel is used |
| Safaricom (Daraja) | Payment amount, phone number, a merchant/checkout reference | Process your subscription payment directly via M-Pesa (Lipa Na M-Pesa Online / STK Push) when this channel is used |
| Africa's Talking | Your phone number, the SMS message text | Deliver OTP/notification SMS on our behalf |
| Amazon Web Services (AWS) | Encrypted database backups | Offsite backup storage — see docs/BACKUP_AND_RESTORE_RUNBOOK.md |
| Equity/Finserve (Jenga), once approved | Payment amount, phone number | An alternative subscription payment channel — not yet live |
| Google (Play Billing), once approved | Purchase tokens, package name | An alternative subscription payment channel for the Play Store build — not yet live |
We do not share data with anyone else, and never for advertising purposes.
5. How long we keep your data
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected. Account and profile information is retained while an account is active and is deleted or anonymised following a verified deletion request, except where continued retention is required by law, necessary to resolve disputes, prevent fraud or establish legal claims. Contact enquiries may be retained for up to 24 months, security and audit records for up to 12 months, and unverified deletion requests for up to 30 days. Records required for tax or accounting purposes may be retained for five years from the end of the relevant reporting period, or longer where an active legal or tax proceeding requires it.
- While your account is active: for as long as you use the Service.
- If you request deletion: your account profile (name, ID number, phone number,
business PIN) is anonymized after a grace period (see §7 and
docs/BACKUP_AND_RESTORE_RUNBOOK.md's sibling account-deletion documentation for the exact mechanism). Historical sales/expense/debt records are retained in anonymized form only, as required for accounting and tax record-keeping obligations under Kenyan law — see the retention periods above. - Backups: database backups are retained per the schedule in
docs/BACKUP_AND_RESTORE_RUNBOOK.mdand are themselves subject to the same anonymization once a deletion completes and a new backup is taken.
6. Your rights under the Kenya Data Protection Act, 2019
You have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data (via the app's own profile/settings screens, or by contacting support@jengaledger.co.ke).
- Request deletion of your account — see §7.
- Object to certain processing, and lodge a complaint with the Office of the Data Protection Commissioner (Kenya) if you believe your rights have been violated.
7. Requesting account deletion
You can request deletion of your JengaLedger account in either of two ways:
- In the app: Settings → Delete my account. You'll be asked to re-enter your password to confirm, and shown exactly what is retained and why before you confirm.
- On the web, if you no longer have the app installed: visit jengaledger.co.ke/account-deletion, enter the phone number your account is registered under, and confirm the one-time code sent by SMS.
Either way, deletion is confirmed immediately but takes effect after a documented grace period
(see docs/BACKUP_AND_RESTORE_RUNBOOK.md's account-deletion section) during which you
can still cancel the request by contacting support@jengaledger.co.ke.
8. Security
Sensitive fields (national ID number, business PIN) are encrypted at rest (AES-256-GCM).
Passwords are hashed, never stored in plain text. All traffic to our servers is encrypted in
transit (HTTPS/TLS). See docs/MONITORING_AND_INCIDENT_RESPONSE.md for how we monitor
for and respond to security incidents.
9. Changes to this policy
We will update the effective date above whenever this policy changes, and notify you in-app of material changes.
10. Contact us
Questions about this policy or your data: admin@jengaledger.co.ke