Legal
Privacy Policy
Effective 5 August 2026 · Version 1.0
This Privacy Policy explains how EcoPay360 (“EcoPay360”, “we”, “us”), a product in the Ecosys360 family, collects, uses, shares, and protects personal data when you use pay.ecosys360.com, our dashboard, APIs, and related services (the “Service”).
It should be read together with our Terms of Use. By creating an account or using the Service, you acknowledge this Policy. Where consent is required by law, we will ask for it (including the signup acceptance checkbox).
Primary law: We design our practices around the Kenya Data Protection Act, 2019 (KDPA) and guidance from the Office of the Data Protection Commissioner (ODPC). If you are in the EU/EEA/UK or certain US states, additional rights described below may also apply.
1. Who we are
EcoPay360 operates the Service at pay.ecosys360.com. For privacy requests, contact privacy@ecosys360.com.
Roles. For account, billing, security, and product operation data about merchants and users of our dashboard, EcoPay360 is typically the data controller. For personal data of your end customers that you send through our APIs (for example MSISDNs for STK Push), you are typically the controller and EcoPay360 processes that data on your instructions as a processor / service provider, except where we must process it for our own legal, security, or billing obligations.
2. Scope
This Policy covers:
- Visitors to our marketing site and documentation
- Users who create EcoPay360 accounts and workspaces
- API and webhook traffic associated with your integration
- Subscription billing interactions
It does not cover third-party websites you link to, or Safaricom’s own processing of M-Pesa customer data under Safaricom’s policies.
3. Personal data we collect
3.1 Data you provide
| Category | Examples | Purpose |
|---|---|---|
| Account identity | Name, email address, password (stored hashed) | Create and secure your account |
| Organization | Workspace / business name, billing email | Tenant administration |
| Settlement config | Paybill / Till / bank shortcodes and account numbers (platform Lipa passkey stored encrypted for STK) | Route STK settlement to your destination |
| API & webhooks | API key metadata, webhook URLs, signing secrets | Authenticate and deliver events |
| Billing | Plan selection, phone number used for subscription STK, payment status | Charge and activate subscriptions |
| Support | Messages and attachments you send us | Customer support |
3.2 Data processed when you use payments features
When you initiate STK Push or receive callbacks, we may process:
- Payer MSISDN (phone number)
- Amount, currency (typically KES), account reference, transaction description
- Merchant request IDs, checkout request IDs, M-Pesa receipts
- Success / failure codes and result descriptions from Safaricom
- Webhook delivery status and retry metadata
We do not store full card PAN/CVV. EcoPay360 does not hold customer funds; settlement is to your connected shortcode.
3.3 Data collected automatically
- Technical logs: IP address, user agent, timestamps, request paths, error diagnostics
- Security & abuse prevention: signup rate limits, disposable-email checks, trial-claim history, Redis-backed cooldowns
- Session data: authentication cookies / session tokens via Better Auth
- Product usage: feature use within the dashboard needed to operate quotas and reliability (not sold for advertising)
3.4 Data we do not intentionally collect
- Precise GPS location
- Contacts from your device address book
- Biometric templates
- Children’s data (see Section 12)
- Health information
4. How we use personal data
| Purpose | Examples | Legal basis (KDPA / GDPR-style) |
|---|---|---|
| Provide the Service | Accounts, STK orchestration, webhooks, dashboard | Contract; legitimate interests |
| Billing & subscriptions | STK subscription payments, renewals, receipts | Contract; legal obligation (tax/accounting) |
| Security & fraud | Rate limits, abuse detection, incident response | Legitimate interests; legal obligation |
| Communications | Transactional email (activation, billing reminders) | Contract; legitimate interests |
| Product improvement | Aggregated reliability metrics | Legitimate interests |
| Legal compliance | Respond to lawful requests; enforce Terms | Legal obligation; legitimate interests |
| Marketing (if any) | Product updates you opt into | Consent (where required) |
5. Sharing and processors
We share personal data only as needed to run the Service:
- Safaricom / Daraja: MSISDN, amount, and STK parameters required to initiate and confirm Lipa Na M-Pesa Online requests
- Infrastructure processors: hosting, PocketBase (application data), Redis (rate limits / cooldowns), email/SMTP providers for transactional mail
- Your webhook endpoints: transaction event payloads you configure us to send
- Professional advisers under confidentiality (legal, accounting) when needed
- Authorities when required by law or to protect rights, safety, and security
- Business transfers: in a merger, acquisition, or asset sale, with notice where required
We do not sell personal data. We do not share personal data for cross-context behavioral advertising in the CCPA/CPRA sense. If that changes, we will update this Policy and provide required opt-outs.
6. International transfers
EcoPay360 is oriented to Kenya. Infrastructure or processors may store or process data in other countries. Where we transfer personal data from Kenya or another jurisdiction with transfer restrictions, we use appropriate safeguards (for example contractual protections and access controls) consistent with applicable law. Contact privacy@ecosys360.com for transfer questions.
7. Retention
We retain personal data only as long as needed for the purposes above:
- Account data: for the life of the account, then deleted or anonymized within a reasonable period after closure, unless law requires longer retention
- Transaction & billing records: typically retained for accounting, dispute, and fraud-prevention periods (often up to 7 years where financial record-keeping applies)
- Security logs: shorter operational windows unless needed for investigations
- API keys: metadata until you revoke them; secrets are stored hashed / encrypted as designed
8. Security
We implement technical and organizational measures appropriate to the risk, including:
- TLS encryption in transit
- Hashed passwords and session-based authentication
- Encryption of platform Lipa credentials at rest on connected accounts
- Access controls, rate limiting, and abuse prevention
- Webhook signing and callback authenticity controls where implemented
No method of transmission or storage is 100% secure. Report suspected vulnerabilities to security@ecosys360.com.
9. Your rights
Depending on your location, you may have the right to:
- Access personal data we hold about you
- Correct inaccurate data
- Request deletion / erasure
- Restrict or object to certain processing
- Data portability (where applicable)
- Withdraw consent where processing is consent-based
- Lodge a complaint with a supervisory authority
Kenya: You may complain to the Office of the Data Protection Commissioner (ODPC). EU/UK: You may complain to your local supervisory authority. California / similar US state laws: You may have rights to know, delete, correct, and opt out of “sale”/“sharing”; we do not sell personal information as described in Section 5.
To exercise rights, email privacy@ecosys360.com from your account email (or with enough detail to verify identity). We aim to respond within thirty (30) days, or sooner if required by law. We may need to retain certain data for legal, security, or billing reasons.
10. Account and data deletion
You may request account deletion by contacting support@ecosys360.com or privacy@ecosys360.com. We will delete or anonymize personal data we control that is not required for legal retention, fraud prevention, or dispute resolution. Processor obligations for end-customer data you control may require your instructions as controller.
11. Cookies and similar technologies
We use cookies and similar technologies that are:
- Strictly necessary — authentication sessions, security, load balancing
- Preferences — for example theme (light/dark) where stored locally
We do not currently use third-party advertising cookies. If we introduce analytics or marketing cookies that are not strictly necessary, we will update this Policy and, where required, obtain consent.
12. Children’s privacy
The Service is directed to businesses and adult professionals. It is not intended for children under 18. We do not knowingly collect personal data from children. If you believe a child has provided data, contact us and we will take appropriate steps to delete it.
13. Automated decision-making
We use automated rules for security and abuse prevention (for example rate limits and disposable-email blocking). These decisions affect access to trials or APIs but are not used for credit scoring of individuals. You may contact us to contest an erroneous block.
14. Breach notification
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify affected users and/or the ODPC (and other regulators where required) in accordance with applicable law, including KDPA timelines.
15. Changes to this Policy
We may update this Privacy Policy by posting a new version with a revised effective date. Material changes may be highlighted in the dashboard or by email. Continued use after the effective date means you acknowledge the updated Policy, except where consent is required.
16. Contact
| Topic | Contact |
|---|---|
| Privacy requests | privacy@ecosys360.com |
| Security | security@ecosys360.com |
| Support | support@ecosys360.com |
| Service | https://pay.ecosys360.com |
| Kenya regulator | Office of the Data Protection Commissioner (ODPC) |