Privacy Policy
Effective Date: July 1, 2026 • Compliant with Kenya Data Protection Act, 2019 (ODPC)
1. Introduction & Our Role
UshirikaApp (“we”, “our”, or “us”) is committed to protecting your personal data. This Privacy Policy explains how we collect, process, store, and share information across our web dashboard, mobile applications, and payment integrations.
Under the Kenya Data Protection Act, 2019 and guidelines from the Office of the Data Protection Commissioner (ODPC), when a church or ministry uses UshirikaApp to manage its congregation, the church acts as the Data Controller (determining the purpose of data processing), and UshirikaApp acts as the Data Processor (processing data on behalf of the church).
2. Information We Collect
We collect personal information required to deliver effective congregation and financial management services:
- Standard Personal Data: Full name, email address, telephone number, physical address, profile photographs, and ministry group participation.
- Sensitive Personal Data: In the course of church operations, the platform records financial contribution history (tithes, offerings, pledges) and religious membership/affiliation. Under Kenyan law, this information is classified as Sensitive Personal Data and is processed strictly with explicit user consent or for legitimate non-profit organizational purposes.
- Technical & Usage Data: IP addresses, browser types, device identifiers, mobile operating systems, and interaction metrics used for platform security and performance optimization.
3. How We Use Your Information
We process personal and sensitive data solely for the following purposes:
- To provide, maintain, and secure the UshirikaApp platform and mobile apps.
- To facilitate seamless online donations and split-payment settlements via Paystack.
- To enable church leadership to communicate with members via SMS, email, and push notifications regarding events, prayers, and sermons.
- To generate anonymized, aggregated demographic and financial analytics for church leadership.
4. Payment Processing & Data Sharing
We do not sell, rent, or trade personal data to third-party advertisers. Information is shared only with necessary operational sub-processors:
- Payment Gateway (Paystack): Financial transactions are processed securely by Paystack. When you make a contribution, your payment details (card numbers, M-Pesa phone numbers) are transmitted directly to Paystack in compliance with PCI-DSS standards. We only store transaction reference numbers and contribution amounts.
- Cloud & Communication Providers: We use secure cloud infrastructure (e.g., Supabase, PostgreSQL databases with strict Row-Level Security) and communication gateways to send OTPs and service notifications.
5. Account Deletion & Data Retention Policy (Google Play & ODPC)
We employ strict Row-Level Security (RLS) policies and end-to-end encryption in transit. You have the right to request the deletion of your account and associated personal data at any time:
A. Member & Individual Account Deletion
- In-App Deletion: Inside the UshirikaApp mobile app, navigate to Profile → Delete Account.
- Web / Email Request: You can also request individual account deletion by emailing our Data Protection Officer at geraldg652@gmail.com with the subject line “Account Deletion Request”.
- Consequences & Ledger Preservation: Upon deletion of an individual member account, your profile, OTP credentials, and group memberships are immediately deactivated and permanently detached from active records. In compliance with Kenyan accounting and tax laws, financial records of contributions you previously made are preserved in the church financial ledger for audit compliance; however, your personal identifiable connection is permanently removed (attributed as Anonymous Donor).
B. Church Organization Account Deletion (For Administrators)
- Admin Request: Church Administrators (acting as Data Controller for their workspace) who wish to delete their entire Church Organization account and terminate their subscription must send a formal request from their registered administrative email to geraldg652@gmail.com with the subject line “Organization Account Deletion Request”.
- Consequences for Members: Deletion of a Church Organization workspace is permanent and irreversible. It immediately deactivates the organization and terminates platform access for all branch administrators, staff, and congregation members connected to that church, de-linking their accounts from the organization's branches and community groups.
- Statutory Ledger Retention: Per Kenyan tax, anti-money laundering (AML), and financial reporting laws, historical organizational transaction ledgers and settlement records must be retained for audit compliance prior to final organization-level data purging.
6. Your Rights Under Kenyan Law
In accordance with the Data Protection Act, 2019, you have the right to:
- Be Informed: Know how and why your personal data is being processed.
- Access & Portability: Request a copy of your personal data stored on our platform.
- Correction: Request the correction of inaccurate or incomplete personal data.
- Erasure (Right to be Forgotten): Request deletion of your personal data, subject to legal and financial retention requirements.
- Withdraw Consent: Opt out of non-essential communications or withdraw consent for specific processing activities.
7. Contact & ODPC Inquiries
To exercise your data protection rights or report a privacy concern, please contact your local church administrator (your Data Controller) or reach out directly to our Data Protection Officer at geraldg652@gmail.com.
You also have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) in Nairobi, Kenya, if you believe your data rights have been infringed.