Privacy Policy.

This policy covers the FyberPay mobile app and the FyberPay web platform. It is written for two different readers: people who buy internet from a provider that runs on FyberPay, and the providers themselves.

01Who this policy is for

FyberPay is billing and network management software used by internet service providers in Kenya. Two groups of people use it, and the difference matters for what happens to your data.

If you are a subscriber, your account was created by your internet provider, not by FyberPay. Your provider decides what to collect about you and why. FyberPay processes that data on their instructions, as their data processor. Questions about your account, your bill or your service belong with your provider first.

If you are an internet provider, FyberPay is your data processor for your subscribers' data, and your data controller for your own account, staff logins and platform billing.

02What we collect

About subscribers

  • Name, email address and phone number, so an account can exist and be reached.
  • Physical address and, where the provider records it, the coordinates of the premises being connected. This comes from the provider or their field staff, not from your phone.
  • Billing records: invoices, payments, amounts, dates, payment status and account balance.
  • Connection details needed to deliver service: your plan, subscription dates, PPPoE username where one is issued, and the router or device assigned to you.
  • Support tickets and messages you send to your provider through the app.
  • Network usage and session records collected from your provider's routers.

About provider staff

  • Name, work email address, phone number and role.
  • Sign-in records and actions taken in the platform, for audit purposes.

Automatically, from the app

  • Crash reports and diagnostics when something goes wrong: the error, the app version, your device model and your operating system version.

03What the mobile app does and does not do

The app asks your device for three permissions and no others: internet access, and fingerprint or biometric access if you switch on the optional app lock.

  • It does not request your location. Any coordinates attached to your account were entered by your provider, not read from your phone.
  • It does not read your contacts, photos, files, camera or microphone.
  • It contains no advertising and no third-party analytics. There is no advertising identifier and no ad network.
  • It never handles your card number. If you pay by card, the app opens your provider's payment page in your browser and the card details go to the payment processor, never through the app.
  • Your fingerprint or face is checked by your device and never leaves it. FyberPay never receives biometric data.
  • Your sign-in tokens are held in the device's own encrypted storage, the Android Keystore or the iOS Keychain.

Crash reports are sent to error tracking infrastructure that FyberPay hosts itself. They are configured not to include your IP address, request headers or screenshots of what was on your screen.

04How we use it

Data is used to run the service and nothing else. Specifically: to create and maintain your account, to issue invoices and record payments, to provision and suspend network access according to payment status, to send you the notices your provider configures such as invoice and reminder messages, to answer your support tickets, and to keep the software working.

We do not sell personal data. We do not share it with advertisers. We do not use it to build advertising profiles.

05Who else sees it

Some data has to reach other companies for the service to function. Each is used only for the purpose named, and only with the data that purpose requires.

  • Payment processors. Safaricom, for M-Pesa payment prompts and confirmations, and card processors where your provider offers card payment. They receive the phone number or payment details and the amount.
  • Messaging providers. SMS gateways and email providers, which receive your phone number or email address and the content of the message being sent to you.
  • Your internet provider. For subscriber data, they are the controller and can see your account in full.
  • Where the law requires it. A valid legal order, and nothing broader than that order.

Error tracking is hosted on FyberPay's own infrastructure rather than sent to a third-party crash reporting service.

06How it is protected

  • All traffic between apps, browsers, routers and FyberPay uses TLS.
  • Passwords are stored as Argon2 hashes. Nobody at FyberPay can read your password, because it is not kept.
  • Sensitive credentials that providers entrust to the platform, such as M-Pesa Daraja API keys, are encrypted at rest with AES-256 before they are written to the database.
  • Sign-in uses short-lived access tokens with separate refresh tokens that can be revoked.
  • Each provider's data is scoped to their own organisation, and requests are checked against that scope.

No system is perfectly secure, and we do not claim otherwise. If we discover a breach affecting your personal data, we will notify affected users and the Office of the Data Protection Commissioner as the Data Protection Act requires.

07How long we keep it

Account and contact details are kept while the account is active. Billing records, invoices and payment records are kept for as long as Kenyan tax and accounting law requires them to be kept, which is longer than the account itself may last. Crash reports are deleted automatically after 30 days. Network session records are kept for the period your provider configures.

08Your rights, and deleting your account

Under the Data Protection Act 2019 you may ask to see the personal data held about you, to have it corrected, to have it erased, to object to how it is being used, and to receive a copy of it.

Deleting your account

Subscriber accounts are created by internet providers, so ask your provider first; they can action it directly. You can also write to the address below and we will act on it.

When an account is deleted, personal details are erased or anonymised: name, email address, phone number and physical address. Financial records are not erased. They are retained in anonymised form, because an invoice and a payment are accounting records your provider is legally required to keep, and because an unpaid balance does not disappear when an account does. What is removed is the link between those records and you.

If you have an outstanding balance, deletion of your personal details does not cancel it. Settle it with your provider first.

The full steps are on the account deletion page.

09Contact

For anything about your bill, your plan or your connection, contact your internet provider. They hold your account.

For privacy questions, data access requests or deletion requests, write to [email protected]. If you are not satisfied with our response, you may complain to the Office of the Data Protection Commissioner of Kenya.

Last Updated: 25 August 2026