Privacy Policy

QuickSend Privacy Policy

Effective Date: June 1, 2026

Last Updated: June 1, 2026

1. Legal Status & Data Processing Definitions

This Privacy Policy sets out how QuickSend Invoice processes data in strict conformity with the Kenya Data Protection Act, 2019, and its attendant Data Protection (General) Regulations. Under these statutory definitions, QuickSend Invoice operates primarily as a 'Data Processor' with respect to client billing data uploaded by our users, and as a 'Data Controller' regarding the personal registration datasets collected directly from our registered merchants.

2. Comprehensive Scope of Data Collection

We collect explicitly itemized data parameters necessary for the performance of our contract with you. This data includes:

  • Merchant Administrative Personnel Identifiers: First Name, Last Name, verified business email channel, and secure access account credentials.
  • Merchant Corporate Identity Metrics: Trading name, physical shop or office location, operational postal code, contact business phone string, corporate logo image assets, and Kenya Revenue Authority (KRA) Personal Identification Number (PIN).
  • Client Transaction Records: End-customer structural identities, recipient WhatsApp phone numbers formatted for instant global delivery routes, itemized project line summaries, quantities, transactional values, and calculated value-added tax rates.

3. Precise Lawful Bases & Purpose of Processing

In accordance with Section 30 of the Data Protection Act, 2019, your datasets are logged exclusively under the lawful criteria of contractual performance and legitimate business interests. QuickSend uses this information to:

  • Compile, calculate, and render secure web-accessible and print-ready paper-style invoice documents.
  • Generate cryptographically unique, non-guessable URL link references (`quicksend.io/inv/uuidv4`) to prevent public directory parsing.
  • Facilitate instant delivery handoffs to the native WhatsApp messaging API system for end-client dispatch.
  • Update real-time interactive merchant dashboard metric summaries (Outstanding, Paid, and Sent totals).

4. Strict Data Retention & Purge Lifecycles

Operational profile configurations and relational invoice historical logs remain permanently saved within our secure database clusters to maintain continuous service availability. Should a registered merchant choose to explicitly delete their business profile via the dashboard account hub, all associated data tables, metadata rows, and cloud-stored logo image blobs will enter an immutable purge sequence, fully erasing the datasets from our primary database servers within exactly 30 days.

5. Statutory Data Subject Rights

As a data subject under the regulatory preview of the Office of the Data Protection Commissioner (ODPC) in Kenya, you maintain explicit legal privileges. You have the right to object to processing types, request absolute rectification of misstated business metadata, demand structural data portability via an exportable structured `.json` configuration file, or file official complaints with the ODPC regarding data management practices.