Privacy policy
How we collect, use and protect your personal data, and the rights you have over it under the Kenya Data Protection Act, 2019.
Last updated 28 August 2026
Who we are
Deals Poa (“we”) sells airtime, data, minutes and SMS bundles in Kenya and runs a referral programme. We are the data controller for the personal data described here. You can reach us at support@dealspoa.com or on 0795 593 984.
What we collect
We keep our collection to what each service actually needs.
- Buying a bundle:the M-PESA number being charged, the recipient's number when you buy for someone else, the bundle and price, and the M-PESA transaction reference. You do not need an account to buy.
- Referral account: your name, email address, phone number, and a securely hashed password. Optionally a profile photo and a separate withdrawal number.
- Earnings and payouts: the sales attributed to your referral link, commission earned, and withdrawal records.
- Security and service records: sign-in times, IP address, browser user-agent, one-time-code delivery records, and payment-provider callbacks.
We never see or store your M-PESA PIN, and we do not collect card details.
Why we use it, and on what basis
- To perform our contract with you: processing payments, delivering bundles, calculating commission, and paying withdrawals.
- To meet legal obligations: keeping financial and tax records, and preventing fraud.
- For our legitimate interests: securing accounts, debugging failed payments, and understanding which offers are used.
- With your consent: marketing emails, which you can withdraw at any time from your dashboard settings without affecting anything else.
Who we share it with
We do not sell your personal data. We share only what is necessary with:
- Safaricom (M-PESA): to charge payments and send withdrawals.
- Our SMS and email providers: to deliver one-time codes and account notices.
- Our hosting provider: which stores the database on our behalf.
- Authorities: where we are legally required to disclose.
Referrers see only masked buyer numbers (for example 0712 *** 678) — never a full customer number.
How long we keep it
- Transaction and payout records: seven years, as tax law requires.
- Account details: until you delete your account.
- One-time codes: minutes — only a hash is stored, never the code itself.
- Security logs: up to twelve months.
Your rights
Under sections 26 and 40 of the Data Protection Act, 2019 you have the right to be informed, to access your data, to correct it, to delete it, to object to processing, and to data portability.
- Access and portability: download everything we hold about you as a JSON file from your dashboard settings, at any time.
- Correction: update your name and withdrawal number in settings; email us for anything else.
- Deletion: request account deletion in settings. We erase your identifying details; financial records are kept in an anonymised form that can no longer be linked to you, because tax law requires us to retain them.
- Objection and withdrawal of consent: turn off marketing in settings at any time.
We respond to requests within 30 days. If you are unhappy with our response you may complain to the Office of the Data Protection Commissioner at odpc.go.ke.
How we protect it
Passwords are hashed with bcrypt and one-time codes are stored only as hashes. Sessions are held server-side and can be revoked. Access to production data is restricted, sensitive actions are logged, and changing your withdrawal number or making a withdrawal always requires a fresh one-time code.
Cookies
We use a strictly necessary cookie to keep you signed in, and a short-lived cookie to remember a referral code so the right person is credited for a sale. We use Google Analytics to understand overall site usage.
Changes
If we change this policy we will update the date above and, for material changes, ask you to review it again when you next sign in. The current version reference is 2026-08-dpa-v1.