Script Pay

Privacy Policy

Effective date: August 28, 2026

This is a working draft prepared for Script Pay's launch and has not yet been reviewed by counsel. Treat it as a starting point, not a final compliance document, until it has been.

1. Who we are

Script Pay (Online M-Pesa payments for businesses) is a payment-orchestration platform that lets Kenyan businesses ("merchants", "tenants") accept M-Pesa payments via Safaricom's Daraja API. This policy explains what personal data we collect from merchants and their customers, why, and what rights you have over it.

2. Information we collect

Account data: name, email address, password (stored as a salted hash, never in plain text), and business details (business name, M-Pesa shortcode) provided when you register or onboard a tenant.

Transaction data: when a payment is initiated, we process the payer's phone number (MSISDN), the payment amount, and the resulting transaction status — this data comes from and is settled by Safaricom's Daraja API; we do not independently collect it from any other source.

Technical data: IP address, browser/device information, and error diagnostics collected automatically via Sentry when something goes wrong. Payment amounts and phone numbers are deliberately excluded from what we send to Sentry — see Section 6.

3. How we use this information

  • To create and secure your account, and authenticate your sessions.
  • To initiate, process, and reconcile M-Pesa payments on your behalf.
  • To detect, investigate, and prevent fraud, abuse, or security incidents.
  • To provide support and respond to your requests.
  • To meet legal and regulatory obligations, including those under Safaricom's own merchant terms.

4. Legal basis for processing

We process personal data under Kenya's Data Protection Act, 2019, on the bases of: performance of a contract (processing a payment you or your customer initiated), legitimate interest (fraud prevention, service security), and legal obligation (regulatory recordkeeping).

5. Who we share data with

We do not sell personal data. We share it only where necessary to provide the service:

  • Safaricom (Daraja API): the actual M-Pesa payment processor — every STK Push, Paybill, or Till transaction is executed by Safaricom, not by us.
  • Sentry: our error-monitoring provider, receiving scrubbed diagnostic data only (see Section 6).
  • Hosting/infrastructure providers that run our servers and database, bound by their own data-processing terms.

6. What we deliberately don't share

Our error-reporting pipeline is built to exclude payment-sensitive data by design: when an API error is reported to Sentry, only the error message, HTTP status code, and which form fields failed validation are included — phone numbers and payment amounts are never forwarded, even inside validation error details.

7. Data retention

We retain account and transaction records for as long as your account is active and for a reasonable period afterward to meet accounting, audit, and regulatory obligations. You can request deletion of your account data as described in Section 9, subject to records we're legally required to keep.

8. How we protect your data

  • Session access tokens are held in memory only, never in browser storage.
  • Session refresh tokens are stored in httpOnly cookies, inaccessible to page scripts.
  • State-changing requests are protected against cross-site request forgery (CSRF).
  • Passwords are hashed, never stored or logged in plain text.
  • All traffic is encrypted in transit (HTTPS).

9. Your rights

Under the Data Protection Act, 2019, you have the right to access, correct, or request deletion of your personal data, to object to or restrict certain processing, and to lodge a complaint with the Office of the Data Protection Commissioner (Kenya). To exercise any of these rights, contact us using the details below.

10. Cookies

We use a small number of strictly necessary cookies to keep you signed in: an httpOnly session cookie, and a non-httpOnly cookie carrying a CSRF token that our app reads to protect state-changing requests. We do not use third-party advertising or tracking cookies.

11. Children's privacy

Script Pay is intended for businesses and is not directed at children. We do not knowingly collect personal data from minors.

12. Changes to this policy

We may update this policy as the service evolves. Material changes will be reflected by updating the effective date above; continued use of the service after a change constitutes acceptance of the revised policy.

13. Contact us

Questions about this policy or your data can be directed to scripttagg@gmail.com or +254 797 162 262.