Privacy Policy

Hisabi — Privacy Policy

What we do with your data across the web app, Hisabi Till and Hisabi Mkononi — in plain language, under the Kenya Data Protection Act, 2019.

Last updated: September 7, 2026

1. Who we are

Hisabi is bookkeeping software for small businesses in Kenya. It is run by Hisabi Limited, a company registered in Kenya (company number PVT-271JPL7E, registered office Kigali Street, Jamia Mall, CBD, Starehe District, Nairobi - 00101).

This policy explains what we do with data, under the Kenya Data Protection Act, 2019. For anything in it, write to support@hisabi.io.

It covers the web app at app.hisabi.io, the Hisabi Till app, the Hisabi Mkononi app, the public menu pages we host for restaurants, and this website.

2. Two kinds of data, and who is responsible for each

Some data is about you as a Hisabi user — your name, your email, your login. We decide how that is handled, so we are the data controller for it.

Most of what sits in Hisabi is your business’s own records: your customers, your suppliers, your staff, your sales. You decide what to put in and what to do with it. You are the controller for that; we only hold and process it on your instructions.

That distinction matters. If one of your customers asks you to delete their details, that request is yours to answer, and the tools to do it are in the app.

3. What we collect

Your account: your name, email address, password (stored only as a hash, never in readable form), and an internal user ID.

Your business records: sales, invoices, quotes, bills, expenses, payments, debts, stock, items and prices, suppliers, customers, staff, payroll and payslips — whatever you enter or import.

Details of other people that you enter: names and phone numbers of your customers, suppliers and staff. Till PINs are stored as hashes, never as the digits themselves.

Device and technical data: an identifier the app generates for each phone or till when you first open it, sync timestamps, and error logs. On the web we also see the usual IP address and request timestamps.

Website visitors: hisabi.io uses Vercel Analytics and Speed Insights to count visits and measure page speed. This is on the marketing website only. The Till and Mkononi apps contain no analytics of any kind.

Diners using a QR menu: if a restaurant turns on ordering, the diner types a name and a table code, picks dishes and can leave a note. No account, no phone number, no payment details.

4. What we do not collect

No advertising identifiers, no ad networks, no tracking for marketing. We show no ads and we do not sell or rent data to anyone, ever.

No location tracking. The apps ask for no location permission.

No access to your phone’s contacts or messages. The Till can record an M-Pesa confirmation only when a cashier pastes one in by hand; the app never reads your SMS inbox.

The Till uses the camera to read barcodes. Frames are processed on the phone and discarded. No photo is stored or sent anywhere.

No card numbers or bank details for payments. Hisabi does not take payments.

5. What we use it for

Running the service: keeping your books, working out VAT, withholding tax and payroll, and syncing your tills and phones with your account.

Sending things you ask us to send: a WhatsApp receipt to a customer, a statement, a payment reminder, a payslip to a member of staff.

Keeping accounts safe: verifying logins, tying a till to one business, spotting misuse.

Supporting you when you write in, and telling you about changes that affect your account.

Meeting our own legal obligations in Kenya.

6. Our legal grounds (Data Protection Act, 2019)

Contract: nearly everything we do is to provide the service you signed up for.

Consent: optional extras, such as sending a receipt to a customer’s WhatsApp number.

Legal obligation: records we are required to keep, and requests we are required to answer.

Legitimate interest: security, fraud prevention and improving the product.

7. WhatsApp messages

Hisabi can send receipts, statements, reminders and payslips over WhatsApp. This only happens when you choose to send one.

To deliver a message, the recipient’s phone number and the contents of that message are passed to Meta, which runs WhatsApp. Meta handles it under its own terms.

Before a cashier sends a receipt, the Till asks for the customer’s number and requires the cashier to confirm the customer agreed to receive it. Please make sure that is true — it is your responsibility as the sender.

8. Who else touches the data

We use a small number of suppliers to run Hisabi. They act on our instructions and may not use the data for their own purposes.

Supabase — the database, sign-in system and file storage that Hisabi runs on.

Vercel — hosting for the web app and this website.

Meta Platforms — delivery of WhatsApp messages you choose to send.

SendGrid — delivery of emails such as sign-in confirmations and password resets.

Google — for restaurants that link a Google listing to their menu, we ask Google’s Places service for the venue’s public star rating. We send only the identifier of the listing. No customer or diner data is sent to Google.

We also disclose data if a Kenyan court, regulator or law requires it. We will tell you when we are allowed to.

9. Where the data lives

Your data is stored on servers in the European Union, which is outside Kenya.

The Data Protection Act allows this where the data is properly protected. Our suppliers are bound by written contracts, hold recognised security certifications, and are subject to data protection law at least as strict as Kenya’s.

10. How long we keep it

While your account is open, we keep your records so the app works — you need last year’s figures to run this year’s books.

When you delete your account, we delete it. That is a real deletion, straight away, not a hidden or deactivated account: every business you own is removed along with all of its records and its audit log, and your login is removed too. Details are at hisabi.io/delete-account.

The one thing that stays is work you did inside a business you did not own. If you were staff somewhere, the sales you rang up belong to that business’s books, so they remain with that business and your name can still appear on them.

Where a specific law requires us to hold something for a period, we keep only what the law names, for only as long as it says.

11. Keeping it safe

Everything travels over an encrypted connection. The phone apps refuse unencrypted traffic outright.

Data is encrypted at rest by our hosting provider.

Every business is separated at the database level, not just in the app. One business cannot read another’s rows even if the app were to ask for them.

Staff see only what their role allows. PINs and access tokens are stored as hashes.

No system is perfect. We would rather say so than promise otherwise, so please export copies of records you cannot afford to lose. Every report in Hisabi can be exported.

12. Your rights

Under the Data Protection Act you can ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use, object to processing, take your data elsewhere, or withdraw consent you gave earlier.

Write to support@hisabi.io. We will reply within 7 days and deal with the request within 30 days.

If you are unhappy with how we handled it, you can complain to the Office of the Data Protection Commissioner in Nairobi.

13. Children

Hisabi is a business tool and is not intended for anyone under 18. We do not knowingly collect data about children. If you think we have, tell us and we will remove it.

14. Changes to this policy

We will update this page when the product changes. If a change materially affects you, we will tell you by email or in the app before it takes effect.

The date at the top always shows when it last changed.

15. Contact

Hisabi Limited, Kigali Street, Jamia Mall, CBD, Starehe District, Nairobi - 00101, Kenya.

Email support@hisabi.io for any privacy question or request.