Legal
Privacy Policy
Last updated: April 2025
TaxSimple Kenya ("we", "us") respects your privacy. This policy explains what data we collect, how we use it, and your rights.
1. Data We Collect
Account Data
When you register, we collect your name, email address, and password (hashed). If you sign in via Google, we receive your name and email from Google.
Usage Data
We collect information about how you use the Platform: pages visited, features used, calculator inputs, and session duration. This is used to improve the product.
Payment Data
Payments are processed by M-Pesa (Safaricom) and Stripe. We do not store full card numbers or M-Pesa PINs. We retain transaction IDs and amounts for billing records.
Tax Input Data
Income figures, expense categories, and other financial data you enter into calculators are stored to power your dashboard. We treat this data as highly sensitive.
Cookies
We use cookies and similar technologies. See our Cookie Policy for details.
2. How We Use Your Data
- Provide and improve the Platform
- Send service emails (receipts, deadline reminders)
- Personalise your experience
- Detect and prevent fraud
- Comply with legal obligations
We do not sell your personal data to third parties.
3. Data Sharing
We share data only with:
- Service providers who process data on our behalf (hosting, analytics, email delivery) under data processing agreements
- Consultants you explicitly choose to engage — only the information necessary for that engagement
- Law enforcement where required by Kenyan law
4. Data Retention
We retain your account data for as long as your account is active. If you delete your account, we remove personal data within 30 days, except where retention is required by law (e.g. financial records for 7 years under the Tax Procedures Act).
5. Security
We use industry-standard security measures: TLS encryption in transit, encrypted storage, access controls, and regular security reviews. No system is perfectly secure; we will notify you of any breach affecting your data as required by law.
6. Your Rights
Under Kenya's Data Protection Act 2019, you have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion ("right to erasure")
- Object to processing
- Data portability
To exercise any of these rights, email privacy@taxsimple.co.ke.
7. Children
TaxSimple is not directed at persons under 18. We do not knowingly collect data from minors.
8. Changes to This Policy
We will notify you of material changes via email or an in-app notice at least 14 days before they take effect.
9. Contact
Data Controller: TaxSimple Kenya
Email: privacy@taxsimple.co.ke