Privacy Policy

Last updated: 12 July 2026

Zeno ("we", "us", "the Service") is an accounting and payments platform for Kenyan businesses. This policy explains what personal data we collect, why, and the rights you have under the Data Protection Act, 2019 (Kenya) and its regulations. It applies to business owners and staff who use Zeno, and to their customers whose details are processed through the Service.

1. Who is responsible for your data

For account data of businesses using Zeno, we act as data controller. For the customer and supplier records a business keeps inside Zeno (names, phone numbers, invoices, payments), that business is the data controller and we act as its data processor. Contact for all data matters: privacy@zeno.com.

2. What we collect

  • Account data — name, email, phone, business details, KRA PIN, login credentials.
  • Business records — contacts, invoices, bills, payroll, ledger entries entered by the business.
  • Payment data — M-Pesa and Kopo Kopo transaction details received via payment gateways: payer phone number, name, amount, receipt numbers. We never see or store M-Pesa PINs.
  • Receipt access data — when a customer uses a receipt link or the customer portal: the phone number they verify, one-time codes (stored hashed), and access sessions.
  • Technical data — device/browser information and logs needed to keep the Service secure.

3. Why we process it (lawful basis)

  • To provide the Service — bookkeeping, invoicing, payments, receipts (performance of contract).
  • To meet legal duties — tax record-keeping under Kenyan law, including KRA requirements (legal obligation).
  • To send transactional messages — payment receipts and verification codes by SMS or email (legitimate interest / contract).
  • To secure the Service — fraud prevention, audit logs (legitimate interest).

We do not sell personal data. We do not use it for third-party advertising.

4. Who we share it with

  • Safaricom (M-Pesa Daraja) and Kopo Kopo — to process payments you initiate or receive.
  • Advanta — to deliver SMS receipts and verification codes.
  • Resend — to deliver email receipts and notifications.
  • Supabase — our database and authentication host.

Some providers store data outside Kenya (including the EU and US). Where data leaves Kenya we rely on providers with appropriate safeguards, consistent with sections 48–49 of the Data Protection Act.

5. How long we keep it

Financial records are kept for at least five (5) years as required by Kenyan tax law, even after an account closes. Portal verification codes expire after 10 minutes; portal sessions after 30 days. Other personal data is deleted or anonymised when no longer needed.

6. How we protect it

  • Encryption in transit (HTTPS) and at rest; payment gateway credentials additionally encrypted with AES-256.
  • Verification codes stored only as one-way hashes.
  • Role-based access controls inside each business account.
  • Receipt links use unguessable random tokens; the customer portal requires phone verification.

7. Your rights

Under the Data Protection Act, 2019 you may:

  • ask what personal data we hold about you and get a copy (access);
  • correct inaccurate data (rectification);
  • ask for deletion where the law allows (erasure) — note tax records must be retained per section 5 above;
  • object to or restrict certain processing;
  • receive your data in a portable format.

Write to privacy@zeno.com. We respond within a reasonable time and at no cost, as the Act requires. If unsatisfied, you may complain to the Office of the Data Protection Commissioner (ODPC) www.odpc.go.ke.

8. Customers of businesses using Zeno

If a business you paid uses Zeno, your phone number and payment details were provided to us by that business or by the payment network to issue your receipt. Direct your requests to that business first; we assist them in fulfilling your rights.

9. Changes

We will post any changes here and update the date above. Material changes will be notified inside the Service.