Legal

Privacy Policy

How the Tillio Africa point-of-sale platform collects, uses, shares, and protects personal data — in line with the Kenya Data Protection Act, 2019.

Last updated · 7 September 2026Jurisdiction · Republic of KenyaKenya Shilling (KES) pricing
01

Introduction

This Privacy Policy explains how the Tillio Africa point-of-sale platform (the "Service") collects, uses, shares, and protects personal information. We process personal data in line with the Data Protection Act, 2019 ("DPA") and other applicable laws of the Republic of Kenya.

The operator (as defined in the Terms & Conditions) provides the Service and processes personal data in the ways described below. Where your business records data about its own customers, your business acts as the data controller of those records and we process them on your instructions.

02

Who this policy applies to

This policy applies to anyone who interacts with the Service, including:

  • (a)Visitors to our public pages who browse product information.
  • (b)People who submit a workspace request.
  • (c)Workspace Owners and Users (staff) who sign in to use the Service.
  • (d)The end-customers whose details business Owners record, such as names, phone numbers, and KRA PINs.
03

Information we collect

We collect the data needed to run the Service and to operate your workspace.

  • (a)Workspace and account data — business name, first and last names, email address, phone number, city, and preferred workspace URL, submitted when you request or administer a workspace.
  • (b)Business records — products, prices, stock levels, sales, purchase orders, suppliers, customer profiles (including KRA PINs where you capture them), loyalty balances, and reports.
  • (c)Payment data — M-Pesa transaction references, the customer's phone number, and amounts. These are processed through Safaricom's Daraja API and we do not store card numbers or M-Pesa PINs.
  • (d)Usage and technical data — device and browser type, IP address, operating system, timestamps, and the features or pages you use, collected for security and reliability.
  • (e)Communications — the message you include with a workspace request and any support correspondence.
04

How we use information

We use the information we collect for the following purposes.

  • (a)To review and process workspace requests and to communicate the outcome.
  • (b)To provision, operate, and administer workspaces, including authentication and access control.
  • (c)To provide the point-of-sale, inventory, customer, loyalty, eTIMS, and reporting features you use.
  • (d)To originate M-Pesa payment requests, match payments to sales, and generate receipts.
  • (e)To send service notices, contract and renewal messages, and relevant updates.
  • (f)To keep the Service secure, detect abuse or fraud, and investigate technical incidents.
  • (g)To comply with legal obligations, including KRA eTIMS reporting and statutory record-keeping.
05

Our legal basis for processing

Under the DPA, we need a lawful basis to process personal data. We rely on the following.

  • (a)Consent — for example, when you submit a workspace request.
  • (b)Performance of a contract — operating your workspace and providing the Service under the Annual Contract.
  • (c)Legal obligation — tax and regulatory obligations, including KRA eTIMS reporting and record-keeping under Kenya tax law.
  • (d)Legitimate interests — keeping the Service secure, reliable, and well supported, provided your rights do not override our interests.
06

Data retention

We keep personal information only as long as needed for the purposes in this policy and to meet legal requirements.

  • (a)Workspace and account data — for as long as your workspace is active, plus a reasonable period afterwards to administer contracts and handle disputes.
  • (b)Tax records, including sales and eTIMS data — for at least five years as required under Kenya tax legislation.
  • (c)Workspace request data — until the request is reviewed, then for a reasonable retention period before deletion.
  • (d)Payment references — for reconciliation and as required by financial regulation.
  • (e)Backups — retained on a scheduled basis; material you delete from the active Service is removed from backups in line with each backup's retention cycle.
07

Sharing and disclosure

We do not sell personal data. We share it only in the circumstances below.

  • (a)Our operator team, who review workspace requests and support tenants, under confidentiality obligations.
  • (b)Service providers who help operate the Service, such as hosting and email delivery, under contracts that restrict how they may use your data.
  • (c)Safaricom, to process M-Pesa payments, subject to Safaricom's own privacy practices.
  • (d)The Kenya Revenue Authority and other regulators, where required to comply with the law or a lawful request.
  • (e)Other parties only with your consent, or where required by a court order or competent authority.
08

M-Pesa and payment data

M-Pesa payments are initiated through Safaricom's Daraja API and completed on the customer's phone.

  • (a)We send a payment request to Safaricom containing the amount, the phone number, and a reference, and receive a confirmation back.
  • (b)We do not see or store M-Pesa PINs or card details. Payment data such as the customer's phone number and transaction reference is recorded so you can reconcile sales.
  • (c)Safaricom processes this data under its own terms and privacy notice, which you should review when you register payments.
09

KRA eTIMS and fiscal compliance

Where the eTIMS feature is enabled and you have registered with KRA, fiscal invoice data is transmitted to the Kenya Revenue Authority.

  • (a)This transmission is required by law and cannot be declined once the feature is enabled for your workspace.
  • (b)Your business controls its tax settings, rates, and fiscal configuration. We process fiscal data on your behalf as a service provider.
  • (c)Fiscal records are treated in line with the retention period in this policy.
10

How we protect data

We apply reasonable technical and organisational measures to protect personal data.

  • (a)Encryption for data in transit, and hashing of credentials at rest.
  • (b)Role-based access control, so staff only see what their role requires.
  • (c)Access logging and monitoring of the platform, with staff access to tenant data limited to what is needed to support you.
  • (d)Procedures to handle and report security incidents.
11

Your rights

Under the Data Protection Act, 2019, you have the following rights in relation to personal data we hold about you.

  • (a)Access — ask whether we hold your data and receive a copy of it.
  • (b)Correction — ask us to correct inaccurate or incomplete personal data.
  • (c)Deletion — ask us to erase personal data where there is no longer a legal basis to keep it.
  • (d)Restriction and objection — ask us to restrict processing or object where our basis is legitimate interests.
  • (e)Data portability — receive your personal data in a structured, machine-readable format where technically feasible.
  • (f)Withdrawal of consent — withdraw consent for any processing done on the basis of consent, at any time.
  • (g)Complaint — complain to the Office of the Data Protection Commissioner (ODPC) if you believe your rights have been breached.
12

How to exercise your rights

To exercise any of the rights above, contact our operator and identify the workspace or request you are referring to.

  • (a)We may ask you to verify your identity before responding to a request.
  • (b)We will respond within the period required by the DPA and keep you informed where a request takes longer.
  • (c)Where your business is the controller of records — for example customer profiles you entered into your Workspace — the Workspace Owner is best placed to act on those records, and we will cooperate with the Owner on request.
13

Cookies and technical data

We keep the Service simple. We rely on local storage for essentials such as sign-in tokens and preferences.

  • (a)Essential storage is required for the Service to work, such as authentication tokens and user preferences, and needs no separate consent.
  • (b)Logs of technical activity, including IP addresses and feature usage, are retained for security and reliability, not to profile you.
  • (c)If we introduce analytics or advertising tools in future, we will update this policy and obtain consent where the law requires it.
14

Children's privacy

The Service is intended for businesses and is not directed at children under 18.

  • (a)We do not knowingly collect personal data from children.
  • (b)If you believe a child has provided us with personal data, contact us and we will take reasonable steps to remove it.
15

Changes to this policy

This policy may be updated as the Service evolves or the law changes.

  • (a)We will post the updated policy on this page and update the "Last updated" date.
  • (b)Material changes will be communicated in advance, for example through the request status page or the contact details we have for your workspace.
  • (c)Continued use of the Service after a change takes effect constitutes acceptance of the updated policy.
16

Contact

For privacy questions, data subject requests, or feedback on this policy, contact our operator.

  • (a)Use the contact details on your Annual Contract, or the contact information shared when your workspace request is reviewed.
  • (b)You may also raise a privacy matter using the workspace request status page.
  • (c)If you are not satisfied with our response, you may lodge a complaint with the Office of the Data Protection Commissioner.