This policy covers the FyberPay mobile app and the FyberPay web platform. It is written for two different readers: people who buy internet from a provider that runs on FyberPay, and the providers themselves.
FyberPay is billing and network management software used by internet service providers in Kenya. Two groups of people use it, and the difference matters for what happens to your data.
If you are a subscriber, your account was created by your internet provider, not by FyberPay. Your provider decides what to collect about you and why. FyberPay processes that data on their instructions, as their data processor. Questions about your account, your bill or your service belong with your provider first.
If you are an internet provider, FyberPay is your data processor for your subscribers' data, and your data controller for your own account, staff logins and platform billing.
About subscribers
About provider staff
Automatically, from the app
The app asks your device for three permissions and no others: internet access, and fingerprint or biometric access if you switch on the optional app lock.
Crash reports are sent to error tracking infrastructure that FyberPay hosts itself. They are configured not to include your IP address, request headers or screenshots of what was on your screen.
Data is used to run the service and nothing else. Specifically: to create and maintain your account, to issue invoices and record payments, to provision and suspend network access according to payment status, to send you the notices your provider configures such as invoice and reminder messages, to answer your support tickets, and to keep the software working.
We do not sell personal data. We do not share it with advertisers. We do not use it to build advertising profiles.
Some data has to reach other companies for the service to function. Each is used only for the purpose named, and only with the data that purpose requires.
Error tracking is hosted on FyberPay's own infrastructure rather than sent to a third-party crash reporting service.
No system is perfectly secure, and we do not claim otherwise. If we discover a breach affecting your personal data, we will notify affected users and the Office of the Data Protection Commissioner as the Data Protection Act requires.
Account and contact details are kept while the account is active. Billing records, invoices and payment records are kept for as long as Kenyan tax and accounting law requires them to be kept, which is longer than the account itself may last. Crash reports are deleted automatically after 30 days. Network session records are kept for the period your provider configures.
Under the Data Protection Act 2019 you may ask to see the personal data held about you, to have it corrected, to have it erased, to object to how it is being used, and to receive a copy of it.
Deleting your account
Subscriber accounts are created by internet providers, so ask your provider first; they can action it directly. You can also write to the address below and we will act on it.
When an account is deleted, personal details are erased or anonymised: name, email address, phone number and physical address. Financial records are not erased. They are retained in anonymised form, because an invoice and a payment are accounting records your provider is legally required to keep, and because an unpaid balance does not disappear when an account does. What is removed is the link between those records and you.
If you have an outstanding balance, deletion of your personal details does not cancel it. Settle it with your provider first.
The full steps are on the account deletion page.
For anything about your bill, your plan or your connection, contact your internet provider. They hold your account.
For privacy questions, data access requests or deletion requests, write to [email protected]. If you are not satisfied with our response, you may complain to the Office of the Data Protection Commissioner of Kenya.
Last Updated: 25 August 2026