We can't find the internet
Attempting to reconnect
Something went wrong!
Hang in there while we get back on track
ECITIZEN Privacy Policy
Last Updated: December 06, 2025
INTRODUCTION
This is the privacy policy of ECITIZEN, a private limited liability company incorporated in the Republic of Kenya.
In case you wish to reach us to report any threat to or breach of your privacy or even to make any suggestions relating to such matters, and for any access requests, questions, or inquiries about how we use your Personal Information you may reach us at the below addresses:
By Email: privacy@ecitizen.com
By Post: ECITIZEN Limited,
P O Box 15140-00509,
NAIROBI
It is ECITIZEN's policy to respect your privacy regarding any information that we may collect while operating our website or when you are interacting with any of our products. This Privacy Policy applies to ECITIZEN (hereinafter, "us", "we", or "our website").
We respect your privacy and are committed to protecting personal identifiable information that you may provide to us through the Website or by any other means. We have adopted this policy ("Privacy Policy") to explain what information may be collected on our Website, how we use this Privacy Policy applies only to information we collect through the Website and does not apply to our collection of information from other sources.
POLICY STATEMENT
The Board of Directors and management of ECITIZEN are committed to compliance with all relevant Kenyan laws in respect of personal data, and the protection of the "rights and freedoms" of individuals whose information ECITIZEN collects and processes including, but not limited to, the Data Protection Act, 2019.
Accordingly, ECITIZEN has developed this policy to explain how we may collect, retain, process, share and transfer your personal data when you visit our or use our sites and services. This Policy applies to your personal data when you visit our sites or use our services that display or provide links to this Policy and does not apply to Sites and services that we do not own nor control, including the sites and services of other ECITIZEN users, where applicable.
This Policy is designed to help you obtain information regarding how we process your personal data, and aims to address all possible processing scenarios to aid you in making privacy choices while using our site and services. Where service offerings may vary by region, we may further inform you of product- or service-specific data collection through supplementary policies or notices provided before collection.
APPLICATION AND GUIDING PRINCIPLES
The Data Protection Act, 2019 and this policy apply to all of ECITIZEN's personal data processing functions, including those performed on customers', clients', employees', suppliers' and partners' personal data, and any other personal data the ECITIZEN processes from any source.
ECITIZEN has established objectives for data protection and privacy, which are guided by the following principles:
- Your personal data will always be processed in accordance with your right to privacy;
- Your personal data will be processed lawfully, fairly and in a transparent manner;
- We will collect your personal data for explicit, specified and legitimate purposes only and not further process them in a manner that is incompatible with those purposes;
- We will ensure that our processing of your personal data is adequate, relevant, limited to what is necessary in relation to the purposes for which it is processed;
- We will collect your personal data only after providing a valid explanation whenever information relating to your family or private affairs is required;
- We will ensure that your personal data accurate and, where necessary, kept up to date, and take every reasonable step to ensure that any inaccurate personal data is erased or rectified without delay when it comes to our attention;
- We will ensure that your personal data is kept in a form which identifies you for no longer than is necessary for the purposes which it was collected; and
- Ensure that your personal data is not transferred outside Kenya, unless there is proof of adequate data protection safeguards or with your consent.
This Privacy Policy describes your privacy rights regarding our collection, use, storage, sharing and protection of your personal information. It applies to ECITIZEN's services and all related sites, applications, services and tools regardless of how or from where you access or use them.
SCOPE AND CONSENT
You accept this Privacy Policy when you sign up for, access, or use our products, services, content, features, technologies or functions offered on our website and all related sites, applications, and services (for these purposes collectively referred to as the "ECITIZEN Services"). Should the need arise, we may amend this policy at any time by posting a revised version on our website. The revised version will be effective at the time of posting.
It is important for us to remind you of your rights under Kenyan Law. You have a right: (a) to be informed of the use to which your personal data is to be put; (b) to access your personal data in our custody; (c) to object to the processing of all or part of your personal data; (d) to the correction of false or misleading data; and (e) to deletion of false or misleading data about you.
WHAT PERSONAL DATA DO WE COLLECT?
"Personal data" means any information relating to an identified or identifiable natural person. You accept this Privacy Policy when you sign up for, access, or use our products, services, content, features, technologies or functions offered on our website and all related sites, applications, and services (collectively referred to as the "ECITIZEN Services").
Normally, you directly provide us with such data when you use ECITIZEN Services or interact with us. The information we collect may include the following:
Registration Information – When you register to use ECITIZEN Services by creating an Account, we will collect Personal Data as necessary to fulfill the services you request. Depending on the services you choose, we may require you to provide us with your name, national identification or passport number, email address or phone number to establish an Account. We may require you to provide us with additional Personal Data as you use our Services.
Transaction and experience information – When you use ECITIZEN Services or access our Sites, for example, to make purchases or pay for services provided by or from Ministries, Departments and Agencies of the government (MDAs), merchants, or to process payments, we collect information about the transaction, as well as other information associated with the transaction such as amount paid for products or services, nature of service paid for, MDA or merchant information, including information about the payment method used to complete the transaction, Device Information and Technical Usage Data.
Information that you choose to provide us to obtain additional Services or specific online Services – If you request or participate in an optional Site feature, or request enhanced Services, we may collect additional information from you. We will provide you with a separate notice at the time of collection, if the use of that information differs from the uses disclosed in this Privacy Policy. An example of this is an online survey, whether provided by us or a third party.
Personal Data about you if you use unbranded Services – certain Services are available without being required to log in to or establish an Account with ECITIZEN. For instance, we collect Personal Data when you are interacting with and making payments to MDAs and merchants, on their sites and checkout with ECITIZEN without logging into an account. For our unbranded payment services, your interaction is with the merchant, on their platform. If you are an Account holder, or create an Account at a later date, we may collect information about such unbranded transactions and associate them with your Account to improve your customer experience as an Account holder and for compliance and analytics purposes. If you are not an Account holder, we will collect and store all information you provide and use such information in accordance with this Privacy Policy.
Other information we collect related to your use of our Sites or Services – We may collect additional information from or about you when you communicate with us, contact our technical, maintenance and support, including customer support teams or respond to a survey.
RETENTION OF PERSONAL DATA
Where it is a requirement of the law, ECITIZEN will normally retain your personal data for as long as required by a relevant law (e.g. to ensure compliance with tax requirements); or if a relevant law no longer requires us to maintain Personal Information (or that period has elapsed), the Personal Information may then still be retained if required by any relevant contractual agreement or arrangement; and for Personal Information to which a relevant law or contractual agreement or arrangement does not apply, we will retain the Personal Information for as long as is required to manage our engagement and/or relationship with you plus a reasonable period afterwards.
If your Account is closed, we may take steps to mask Personal Data and other information, but we reserve our ability to retain and access the data for so long as required to comply with applicable laws. We will continue to use and disclose such Personal Data in accordance with this Privacy Policy
PROCESSING OF PERSONAL DATA
We may use your personal data for the following purposes:
Provision of our Services, including to:
- initiate a payment, pay for a service, goods or pay a bill;
- authenticate your access to an Account;
- communicate with you about your Account, the Sites, the ECITIZEN Services, or ECITIZEN; sending you information about our services that may interest you or help us to serve you better. If you do not want to receive these types of information, you can opt out at any time.
- perform Account application or Service provision and availability evaluations and compare information for accuracy and verification purposes.
- keep your Account and financial information up to date.
To manage our operational needs, such as monitoring, analyzing, and improving the ECITIZEN Services and the Sites' performance and functionality. For example, we analyze User behavior and perform research about the way you use the ECITIZEN Services.
To manage risk and protect the Sites, the ECITIZEN Services and you from fraud by verifying your identity. ECITIZEN's risk and fraud tools use Personal Data, Device Information, Technical Usage Data and Geolocation Information from our Sites and website that offer ECITIZEN Services to help detect and prevent fraud and abuse of the ECITIZEN Services.
To market to you ECITIZEN products and Services and the products and services of unaffiliated businesses. We may also process your Personal Data to uniquely tailor the marketing content and certain Services or Site experiences to better match your interests on ECITIZEN and other third-party websites.
HOW WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES
When you visit our Sites, use our Services, or visit a third-party website for which we provide online or digital Services, we may use cookies and other tracking technologies (collectively, "Cookies") to recognize you as a User and to customize your online experiences, the Services you use, and other online content and advertising; measure the effectiveness of promotions and perform analytics; and to mitigate risk, prevent potential fraud, and promote trust and safety across our Sites and Services.
ECITIZEN will not use cookies for any purposes not stated in this Policy. You can manage or delete cookies based on your own preferences.
You can clear all the cookies stored on your computer, and most web browsers provide the option of blocking cookies.
PROTECTION OF YOUR PERSONAL DATA
ECITIZEN takes the security of your personal data very seriously. We use appropriate physical, management, and technical measures to protect your personal data from unauthorized access, disclosure, use, modification, damage, or loss. The security measures include, but are not limited to:
- Implementing security measures in accordance with internationally recognized standards for information access management, firewalls, security monitoring and data encryption. Our security controls and mechanisms are continuously verified by an independent external auditor.
- We use cryptographic technologies for transaction security and integrity such as encryption, transmission of transaction information using HTTPS and Secure Socket Layer (SSL) technology and ensuring that post transaction no sensitive card information is stored on our systems.
- We maintain physical, electronic, and procedural safeguards in connection with the collection, storage, and disclosure of personal information.
- We will normally add additional layers of security, including the use of one-time passwords or pins (OTPs) for additional security and safety of your transactions and personal data.
While we are dedicated to securing our systems and Services, you are responsible for securing and maintaining the privacy of your password(s) and Account/profile registration information and verifying that the Personal Data we maintain about you is accurate and current.
YOUR RIGHTS
Depending on your location, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate or incomplete information
- Request deletion of your personal information
- Restrict or object to our processing of your information
- Request transfer of your information to another service provider
- Withdraw consent where processing is based on consent
CONTACT US
If you have any questions about this Privacy Policy, please contact us at:
Email: privacy@ecitizen.com
Phone: +254 XXX XXX XXX
Address: [Company Address]