Back

Privacy Policy

A phone number, and what your group can see.

Your identity with us is a phone number — no documents, no email, no trackers. The parts that matter most are section 5, on what other members can see, and section 11, on what we cannot delete.

Version 1.0.0-draft · Last updated 28 August 2026
Draft — not yet in force. This document is a structural draft awaiting legal review. Bracketed items are placeholders.

1. About this policy

Nanatec Limited ("we", "us", "our"), a company incorporated in Kenya with its registered office at Kasarani Mwiki Road, P.O. Box 38001–00100, Nairobi, Kenya, is responsible for the personal information described here. We operate the Chama app, website and related services (the "Platform").

This policy explains what we collect, why, who can see it, how long we keep it, and what you can ask us to do. It applies to members of the Platform. Our Terms of Service govern everything else about using it.

We process your information under Kenya’s Data Protection Act, 2019, on the lawful bases set out in section 4. If you are unhappy with how we have handled your information, you may complain to the Office of the Data Protection Commissioner.

2. The short version

  • Your identity with us is a phone number. We do not collect identity documents, and we never ask for your national ID or passport.
  • We do not email members, we set no cookies, and the app carries no analytics, no trackers and no third-party scripts of any kind.
  • Your group sees your money. Every member of a group can see every other member's contributions, loans and repayments in that group. That is what a shared ledger is.
  • We never sell your information, and advertisers never receive your financial activity.
  • The ledger is permanent. Financial records cannot be deleted, including on request. Read section 11 before you join a savings group.

3. What we collect

What you give us:

Phone number
Your identity on the Platform. Verified by SMS code at registration.
Display name
What other members of your groups see.
PIN
Stored only as a cryptographic hash, never as text, never logged, and never recoverable — a forgotten PIN is reset, never retrieved.
Group activity
Which groups you belong to, when you joined, your roles, and when you left.
Contributions, loans and repayments
Amounts, dates, and status. For a loan: the amount, term, interest, guarantors, repayment schedule, and the purpose you type, which is free text and stored as written.
Declared payments
The amount, method, payment reference, date, any remarks you write, and optionally a photo of your receipt.
Votes
In an election, which candidate you chose. Votes are recorded against your membership — see section 5.
Announcements
Anything you post to a group, kept even after it is removed from view.
Invitations you send
The phone number of the person you invite.

What we create about you. Ledger entries recording each confirmed money movement; your position in a group's cycle; notification records of what we sent you and whether we were able to send it; a login session record; and a one-way reference used for advertising counts (section 7).

What we receive from others. When you pay by mobile money, Safaricom sends us a confirmation — the payment reference, the amount, the status, and the phone number that paid. When we send money to you, the confirmation also carries the name your number is registered under with M-Pesa. We store each confirmation message as it arrives, in full, so the record of what the provider actually told us cannot drift.

What we do not collect:

  • No identity documents. No national ID, passport, or KYC file. Ever.
  • No email address. Members are never emailed; email is used only for our own staff.
  • No mobile-money credentials. Your M-Pesa PIN is entered on your own phone, to Safaricom, and never reaches us.
  • No location data and no contact list. The app asks for neither. When you attach a receipt, your phone shows you its own picture chooser and only the single image you pick is sent — and we strip the embedded metadata, including any GPS coordinates, before it leaves your device.
  • No cookies, no analytics, no advertising trackers, no third-party scripts. Not on the app, not on our website. Fonts on our website are served from our own servers, so even loading a page tells no one else you visited.
  • No device fingerprinting. We do not build a profile of your hardware or browser.

What our servers record about requests. Our web server keeps standard access logs: the IP address a request came from, the time, the page or endpoint requested, the response, the page you came from, and your browser’s user-agent string. This is what lets us diagnose a fault or spot an attack. It is not linked to your account.

4. Why we use your information

  • To run your groups — memberships, roles, cycles, contributions, loans, payouts and share-outs.
  • To keep the ledger accurate — recording, verifying and reconciling money movements, and matching provider confirmations to entries.
  • To move money — passing your phone number and the amount to the mobile-money provider so a payment can be collected or a payout sent.
  • To tell you what is happening — codes to sign in, and messages about your groups and your money.
  • To keep the Platform secure — verifying your number, protecting your account, and investigating abuse or fraud.
  • To keep the Platform free — showing advertising as described in section 7.

We do not profile you, score you, or build any picture of your creditworthiness. The only automatic limits are the ones your own group set — such as the cap on what you may borrow against your savings. Every decision about a loan is made by people in your group. We do not sell your information to anyone.

Our lawful bases. Under the Data Protection Act, 2019 we must have a lawful basis for each use. Ours are:

Running your account and your groups, recording the ledger, moving money on your group’s instruction
Performance of the contract between you and us — you cannot use the Platform without these.
Sending you sign-in codes and messages about your groups and your money
Performance of the contract, since a shared ledger you are not told about does not work.
Verifying your number, limiting abuse, keeping access logs, investigating fraud
Our legitimate interests in keeping the Platform secure and usable, balanced against your interests.
Showing advertising and counting how often an advert was seen
Our legitimate interests in funding a service that is free to members, using group-level context only and never your financial activity.
Keeping ledger and audit records permanently
Our legitimate interests, and the interests of the other members of your group, in an accurate and complete financial history that no single participant can alter.
Responding to a court order or a lawful request from an authority
Compliance with a legal obligation.

You can object to processing based on our legitimate interests. Where we agree, we will stop; where we do not, we will tell you why. Note that objecting to the ledger record is the one case we cannot accommodate — see section 11.

5. Who can see your information

Other members of your groups — read this part carefully. A shared ledger only works if the group can see it. Within each group you belong to, every other active member can see:

  • your display name and your roles;
  • every ledger entry attributable to you — what you contributed, what you borrowed, what you repaid, any penalty charged to you, and the payment reference on each;
  • your loan history in that group, including whether you are behind;
  • the payments you declare. Your group’s chairperson, admins and treasurer see each declaration in full — the amount, the reference, any remarks you wrote, and the reason if it was rejected. Other members do not see your declarations;
  • any receipt photograph you attach, which your group’s officials open when they review your payment. A receipt photo is usually a screenshot of your mobile-money message, which typically shows your phone number, your balance, and who else you have paid. Do not attach anything you would not hand to your group’s officials.

Group admins additionally see the phone number of every person with an outstanding invitation to the group, including people who never responded.

Your phone number is not otherwise shown to other members. But note that a receipt photo often reveals it, and that an internal account identifier of yours is visible to fellow members.

Across groups — nothing. A member of one of your groups learns nothing about your other groups. Every request is scoped to the groups you are actually an active member of.

Our staff. Our support and administrative staff can see member records — including phone numbers and display names — group memberships and contributions, and the ledger. They use this to answer support questions and to investigate fraud and abuse. Staff cannot alter a posted ledger entry; suspending an account or a group requires an administrator to re-authenticate, and those actions are recorded permanently.

Nobody else. We do not share your information with anyone outside the Platform except the service providers in section 6, and where a court or the law requires it.

6. Service providers

Three kinds of company are involved in delivering the service. Each receives only what it needs.

Safaricom (M-Pesa). To collect a payment or send you money, we pass your phone number, the amount, and a short reference identifying what the payment is for. Safaricom operates M-Pesa under its own terms and its own privacy policy. We do not send your name, and we hold no M-Pesa credentials of yours.

Advanta (SMS). To text you, we pass your phone number and the message text. That message may contain a sign-in code, or a short line about your group — for example that a contribution was received, or that a payment was not accepted and why. Message content travels as ordinary SMS, which is not encrypted; anyone with access to your handset can read it.

An email relay. Our staff receive sign-in codes by email through a mail provider. No member email is ever sent, because we hold no member email addresses.

Our own infrastructure. The database, file storage and servers are ours, operated by us on machines we control rather than on a third-party cloud platform.

There is no analytics vendor, no advertising network, no error-tracking service, no credit bureau, and no AI service in this list, because we use none.

7. Advertising

The Platform is free because financial institutions pay to show offers on it.

Advertising and your money are kept apart. The advertising component reads advertising records only. It does not read your ledger, your balances, your loans or your repayment history, and no advertiser can obtain them.

Targeting is coarse. An advertiser can ask to reach a type of group, or a region. It cannot ask to reach you.

What advertisers get is counts — how many times an advert was shown and clicked. Those counts are recorded against a one-way reference derived from your account identifier, not against your name or number. That reference is stable over time, so it links your own advertising events to one another; it is not disclosed to advertisers.

Advertisers never receive your phone number, your name, your group's records, or any financial information about you. We do not sell member data, to advertisers or to anyone.

8. What the app stores on your phone

The app keeps some data in your browser's storage so it works offline and does not ask you to sign in constantly:

  • Your sign-in tokens and your own profile — your account identifier, display name and phone number.
  • The app's own files — pages, styles and images, so it opens without a network. Your financial data is not stored in this cache.
  • Your theme choice and whether you dismissed the install prompt.

We set no cookies. Signing out clears your tokens and your saved profile, phone number included. Clearing your browser’s storage for the app removes everything above.

9. How long we keep things

Ledger entries
Permanently. They are append-only and cannot be deleted — see section 11.
Your account, name and phone number
For as long as the account exists. There is no automatic deletion.
Group memberships, including ended ones
Permanently, as part of the group's record.
Loans, contributions, votes, announcements
Permanently, including announcements removed from view.
Declared payments and receipt photographs
Permanently, including rejected and cancelled ones.
Mobile-money confirmations from Safaricom
Permanently.
Codes we text you (registration, PIN reset)
Deleted automatically 5 minutes after they are issued.
Login sessions
Deleted automatically 30 days after you signed in — renewing does not extend it.
Duplicate-request records
Deleted automatically after 24 hours.
Rate-limiting counters
Deleted automatically at the end of each 1-hour window. The counter is keyed by your IP address or account id.
Phone numbers of people invited who never joined
Retained indefinitely, whether the invitation lapsed, was declined, or was accepted.
Web-server access logs
[REVIEW — set and state a period]

10. How we protect your information

  • In transit, everything is encrypted with TLS 1.2 or 1.3, with modern cipher suites and HSTS enabled.
  • Your PIN is stored only as a cryptographic hash. We cannot read it, and neither can our staff.
  • Sign-in codes are stored hashed, never as text, and expire in minutes.
  • Sessions rotate. If a stolen session token is replayed after it has been rotated, we revoke the whole session. Resetting your PIN revokes every device’s session, which takes effect on each device within fifteen minutes.
  • Paying, recording and disbursing money need your PIN again, through a short-lived re-authentication, even while you are signed in.
  • Roles are checked on every request against current group membership, so a removal or an election takes effect immediately rather than whenever a token expires.
  • Provider credentials administered by our staff are sealed with strong encryption under a key held outside the database, so a copy of the database alone does not yield them.
  • Receipt photographs are stored in a private bucket and reachable only through a signed link that expires in two minutes.
  • We do not answer whether a phone number is registered. The sign-in and PIN-reset flows return the same response either way.

No system is perfectly secure. If a breach affects your information, we will tell you and the Office of the Data Protection Commissioner within 72 hours.

11. Your rights, and the limits of them

Where the Data Protection Act, 2019 applies, you have rights over your information — typically to see it, to correct it, to object to some uses, and to ask for it to be deleted. Write to info@chama.ke and we will respond within the period that law requires.

We must be straight with you about deletion.

What we can change: your display name.

What we cannot delete: entries in a group’s ledger, and the record of actions taken on the Platform. A shared financial record that any one participant can selectively erase is not a financial record — the other members of your group relied on those entries when they lent you money or accepted your contribution, and their interest in an accurate history does not end when you leave. This is a real limit on your right of erasure, and you accept it by joining a savings group.

What this means in practice: leaving a group ends your participation; it does not remove your history in it. Closing your account stops you using the Platform; your group's ledger keeps the entries that name your membership.

If you were invited but never joined, you have no account and no history — write to info@chama.ke and we will remove your number.

12. Children

The Platform is not for anyone under 18. We do not knowingly collect information from children. If you believe a child has registered, tell us at info@chama.ke and we will suspend the account so it can no longer be used.

13. Changes to this policy

We may update this policy. Every version carries a version number and a date. If a change materially affects how we use your information, we will say so when we publish it.

14. Contact

Nanatec Limited, Kasarani Mwiki Road, P.O. Box 38001–00100, Nairobi, Kenya. Privacy: info@chama.ke. Data protection contact: info@chama.ke. Support: info@chama.ke or +254 759 530195.

If you are not satisfied with our response, you may complain to the Office of the Data Protection Commissioner.

Version 1.0.0-draft · Last updated 28 August 2026.