MajiPoint Privacy Policy

Effective date: 8 September 2026 · Last updated: 8 September 2026

This Privacy Policy explains how Qtech Dynamics, the owner and operator of MajiPoint ("MajiPoint", "we", "us", or "our"), collects, uses, stores, protects, and otherwise processes personal information when you use the MajiPoint website, web application, and related services.

MajiPoint is committed to handling personal information responsibly and in accordance with applicable Kenyan data-protection laws, including the Data Protection Act, 2019 and applicable regulations and guidance.

1. Who We Are

MajiPoint is owned and operated by Qtech Dynamics, a company registered in Kenya.

For personal information that MajiPoint collects and processes for its own purposes, MajiPoint/Qtech Dynamics acts as the Data Controller.

For personal information that a MajiPoint customer enters into the platform about its own customers, employees, or other individuals, the customer may determine the purposes and means of processing. In those circumstances, the customer may be the relevant Data Controller and MajiPoint may process the information as a service provider/data processor on the customer's behalf.

This distinction is important because MajiPoint does not determine why a water-refill business collects information about its own customers or employees.

2. Contact

For privacy and data-protection questions or requests, contact:

Qtech Dynamics / MajiPoint — Email: hello@majipoint.co.ke

3. What Personal Information We Collect

Depending on how you use MajiPoint, we may collect the following categories of information.

3.1 Account and business information — when a business creates a MajiPoint account, we may collect:

  • business name
  • owner or manager name
  • email address
  • telephone number
  • business address
  • account credentials
  • subscription information
  • information necessary to provide and administer the service

3.2 Employee information — customers may enter information about employees or authorised users, including:

  • name
  • telephone number
  • email address
  • account information
  • activity associated with the account
  • other information the customer chooses to enter

3.3 Customer information — MajiPoint customers may enter information relating to their own customers, including:

  • customer name
  • telephone number
  • address
  • purchase history
  • refill history
  • amounts paid
  • credit information
  • debt information
  • other business records entered by the customer

The customer is responsible for ensuring that it has a lawful basis for collecting and using this information.

3.4 Technical and usage information — when you use MajiPoint, we may automatically collect information such as:

  • IP address
  • browser type
  • device type
  • operating system
  • application or browser information
  • login information
  • access times
  • pages or application areas accessed
  • general usage information
  • security logs
  • error information
  • information about how users interact with the platform

We use this information primarily for security, analytics, troubleshooting, service improvement, and platform administration.

3.5 Payment information — MajiPoint subscription payments are currently made through an M-Pesa Buy Goods and Services Till Number. MajiPoint does not currently operate as a financial institution or payment processor for customers' own business transactions.

MajiPoint does not require or intentionally store customers' M-Pesa transaction credentials, PINs, or other sensitive authentication information. Subscription-payment information may be used to determine whether a customer's subscription is active.

4. Information We Do Not Intentionally Collect

MajiPoint does not currently require users to upload documents, photographs, identity documents, or other files as part of normal platform operation.

MajiPoint also does not intentionally request sensitive personal information such as health information or biometric information for normal use of the service.

Customers should not enter unnecessary sensitive personal information into MajiPoint.

5. How We Use Personal Information

We may process personal information for the following purposes:

  • creating and managing accounts
  • providing MajiPoint services
  • authenticating users
  • processing subscriptions
  • managing customer support
  • providing receipts and business communications
  • facilitating WhatsApp communications
  • maintaining security
  • detecting fraud and abuse
  • troubleshooting technical problems
  • monitoring service performance
  • understanding how users interact with MajiPoint
  • improving and developing the platform
  • maintaining backups
  • providing reports and functionality requested by customers
  • complying with legal obligations
  • enforcing our Terms of Service
  • resolving disputes
  • communicating service updates
  • sending marketing communications where permitted
  • other lawful purposes reasonably related to operating MajiPoint

6. Lawful Basis for Processing

Where applicable, MajiPoint relies on one or more lawful grounds for processing personal information, including:

  • performance of a contract
  • compliance with a legal obligation
  • legitimate interests
  • consent, where consent is appropriate or required
  • protection of rights and interests
  • other lawful grounds recognised by applicable law

Where we rely on consent, the individual may withdraw consent where permitted by law. Withdrawal of consent does not affect processing that occurred lawfully before withdrawal.

7. Customer-Entered Information

MajiPoint customers may use the platform to store information about their own customers and employees. In these circumstances, the customer is responsible for determining:

  • what information is collected
  • why it is collected
  • whether collection is necessary
  • the lawful basis for collection
  • how individuals are informed
  • how long the information should be retained
  • how requests from those individuals should be handled

MajiPoint processes such information primarily to provide the functionality requested by the customer.

8. Data-Subject Rights

Subject to applicable law and any relevant exceptions, individuals may have rights including:

  • the right to be informed about processing
  • the right to access personal information
  • the right to request correction of inaccurate information
  • the right to request deletion where legally applicable
  • the right to object to certain processing
  • the right to request restriction of certain processing
  • the right to data portability where applicable
  • the right to withdraw consent where processing relies on consent
  • the right to lodge a complaint with the relevant data-protection authority

Requests may be submitted to hello@majipoint.co.ke.

Where the request relates to information entered into MajiPoint by a business customer, we may direct the individual to that business where the business is the relevant Data Controller.

9. Verifying Requests

To protect personal information, MajiPoint may need to verify the identity or authority of an individual making a data request.

We will not request unnecessary identification information.

Where a request is made on behalf of another person, we may request reasonable evidence of authority.

10. Cookies and Similar Technologies

MajiPoint uses cookies and similar technologies. These technologies may be used for:

  • authentication
  • maintaining sessions
  • security
  • remembering preferences
  • application functionality
  • understanding usage
  • diagnosing technical issues
  • analytics

MajiPoint does not intentionally use advertising or behavioural-marketing cookies.

Some cookies may be necessary for the website or application to function properly and cannot be disabled without affecting functionality.

11. Google Analytics

MajiPoint uses Google Analytics to understand how users interact with the website and application. Google Analytics may collect information about:

  • pages or screens visited
  • approximate usage patterns
  • device and browser information
  • session information
  • traffic sources
  • other analytics information

We use analytics information to understand platform usage, identify problems, improve the user experience, and make informed product decisions. Google may process information in accordance with its own policies and terms.

MajiPoint does not use Google Analytics for behavioural advertising through MajiPoint.

12. WhatsApp

MajiPoint may integrate with WhatsApp to allow businesses to send communications such as:

  • receipts
  • debt reminders
  • payment-related communications
  • customer notifications
  • other business communications initiated by the customer

WhatsApp is a separate third-party service and has its own privacy practices.

MajiPoint does not control how WhatsApp processes information once information is transmitted to or otherwise processed by WhatsApp.

Customers are responsible for ensuring that their use of WhatsApp through MajiPoint complies with applicable privacy and communications laws.

13. Third-Party Service Providers

MajiPoint uses third-party technology providers to help provide and operate the service. These may include providers for:

  • database infrastructure
  • application hosting
  • analytics
  • communications
  • messaging
  • payments
  • security
  • backups
  • cloud infrastructure
  • other technical services

Such providers may process personal information only as reasonably necessary to provide the relevant service. MajiPoint seeks to use appropriate contractual and technical safeguards when engaging service providers.

14. Infrastructure Providers

MajiPoint uses Supabase as part of its database and application infrastructure.

Supabase may process or store information necessary to provide the MajiPoint service.

MajiPoint does not provide third-party service providers with unrestricted access to customer information for their own independent commercial purposes.

15. International Data Transfers

Because MajiPoint relies on cloud-based and third-party technology services, personal information may in some circumstances be processed or stored outside Kenya.

Where applicable, MajiPoint will take reasonable steps to ensure that international transfers or processing are carried out in accordance with applicable Kenyan data-protection requirements.

16. Data Security

MajiPoint implements reasonable technical and organisational safeguards designed to protect personal information. Current measures include, where applicable:

  • password hashing
  • HTTPS/SSL
  • encryption
  • role-based access controls
  • database and infrastructure security controls
  • backups
  • access controls
  • security monitoring and maintenance

No electronic transmission or storage system can be guaranteed to be completely secure.

Users should protect their passwords and notify MajiPoint promptly if they suspect unauthorised access.

17. Data Breaches and Security Incidents

If MajiPoint becomes aware of a suspected personal-data breach or significant security incident, we will take reasonable steps to:

  1. investigate the incident;
  2. contain or mitigate its effects;
  3. identify affected information where reasonably possible;
  4. implement appropriate remedial measures;
  5. assess legal and regulatory notification requirements; and
  6. make notifications where required by applicable law.

We may communicate with affected customers or individuals where appropriate.

18. Data Retention

MajiPoint retains personal information only for as long as reasonably necessary for the purposes for which it was collected, unless a longer retention period is required or permitted by law.

For customers who terminate their MajiPoint account, customer account and business data may generally be retained for 30 days following termination. After that period, information may be permanently deleted.

Exceptions may apply where information must be retained:

  • to comply with legal obligations
  • for accounting or tax purposes
  • to establish, exercise, or defend legal claims
  • to investigate fraud or security incidents
  • to enforce agreements
  • where another lawful basis for retention exists

19. Data Deletion

Where deletion is requested and legally applicable, MajiPoint will take reasonable steps to delete the relevant information.

Deletion may not be immediate where:

  • the information is required for a legitimate legal purpose
  • deletion would interfere with legal obligations
  • the information is contained in secure backups awaiting scheduled deletion
  • another lawful exception applies

20. Anonymised and Aggregated Information

After information has been sufficiently anonymised so that it can no longer reasonably be used to identify an individual or business, MajiPoint may retain and use aggregated or anonymised information. Such information may be used for:

  • analytics
  • product development
  • market analysis
  • business intelligence
  • performance benchmarking
  • research
  • reporting
  • improving MajiPoint

MajiPoint will not treat information as anonymised merely because obvious identifiers have been removed if the information can reasonably be used to re-identify an individual.

21. Marketing Communications

MajiPoint may send customers communications about:

  • new features
  • service updates
  • promotions
  • products
  • events
  • educational materials
  • other MajiPoint-related information

Where marketing communications require consent, MajiPoint will obtain the appropriate consent.

Customers may opt out of marketing communications using the unsubscribe mechanism provided or by contacting MajiPoint.

Opting out of marketing does not prevent MajiPoint from sending essential service communications, including security notifications, account notices, payment notices, or other operational communications.

22. Business Names and Logos

MajiPoint may request permission from customers to use their business name or logo in:

  • customer lists
  • marketing materials
  • case studies
  • presentations
  • websites
  • social media
  • other promotional materials

MajiPoint will not assume permission solely because a business uses the platform.

23. Children's Data

MajiPoint is intended for users aged 18 years and above.

We do not knowingly design MajiPoint to collect personal information directly from children.

If we become aware that an account has been created by a person under 18, we may take appropriate steps to terminate or restrict the account.

24. Account Security

Users are responsible for maintaining the security of their MajiPoint credentials. Users should:

  • use strong passwords
  • avoid sharing passwords
  • log out from shared devices
  • restrict employee access appropriately
  • notify MajiPoint of suspected unauthorised access

Businesses are responsible for managing employee access to their own MajiPoint accounts.

25. Data Portability and Export

MajiPoint may provide functionality allowing customers to export their business data.

Where a customer requests data export, MajiPoint will provide available information in a reasonably usable format where technically feasible and legally permissible.

Export rights do not transfer ownership of MajiPoint software or intellectual property.

26. Changes to This Privacy Policy

MajiPoint may update this Privacy Policy from time to time. Changes may be made to reflect:

  • changes to the service
  • new functionality
  • changes in law
  • changes to technology
  • changes to third-party services
  • improvements to our privacy practices

Where changes are material, we will provide reasonable notice through the website, application, email, or another appropriate method. The updated policy will become effective on the date indicated at the beginning of the policy.

27. Complaints

If you believe that MajiPoint has processed your personal information improperly, we encourage you to contact us first so that we can investigate and attempt to resolve the issue.

Privacy complaints should be directed to hello@majipoint.co.ke.

Nothing in this section prevents an individual from exercising their rights or submitting a complaint to the Office of the Data Protection Commissioner (ODPC) or another competent authority.

28. Data Protection Registration

MajiPoint/Qtech Dynamics intends to maintain any registrations, licences, or other regulatory requirements applicable to its activities as a data controller or processor under Kenyan law.

Where applicable, details of relevant registrations may be updated in this Privacy Policy.

29. Legal Basis and Compliance

This Privacy Policy is intended to operate consistently with applicable Kenyan data-protection legislation, including:

  • the Data Protection Act, 2019
  • the Data Protection (General) Regulations, 2021
  • the Data Protection (Registration of Data Controllers and Data Processors) Regulations, 2021
  • other applicable data-protection regulations and guidance

Where another jurisdiction's data-protection law applies to a particular processing activity, MajiPoint will take reasonable steps to comply with applicable mandatory requirements.

30. Contact Us

For privacy questions, requests, complaints, or data-protection matters:

Qtech Dynamics / MajiPoint — Email: hello@majipoint.co.ke

End of Privacy Policy