Privacy
Last updated 3 October 2026
Written to be read. Short sections, plain sentences, and what it means in practice rather than which clause of which Act it derives from.
Last updated 3 October 2026
Written to be read. Short sections, plain sentences, and what it means in practice rather than which clause of which Act it derives from.
NOSTREL is a payment platform operated from Nairobi, Kenya. For the purposes of the Data Protection Act, 2019, we are the data controller for information about the businesses who use us and their staff, and we act as a processor for information about their customers that we handle in order to move a payment.
Write to [email protected] about anything on this page. It is read by a person.
We collect what is needed to verify you and to pay you: your registered business identity and the documents behind it, the people who ultimately own or control the company, the contact details of whoever uses the dashboard, and a destination for settlement.
We also keep the record of what you did: transactions, approvals, sign-ins and configuration changes. Several of those we are obliged to keep, which is why some of them cannot be deleted on request while the obligation lasts.
We do not sell any of it, we do not share it for advertising, and nobody is building a profile of you for anything other than fraud and compliance.
You gave a phone number, and optionally a name. We also record technical details of the visit, including the network address and information about the device, because we are obliged to detect fraud and to meet anti-money-laundering requirements. The checkout page says this in plain language at the moment you are there, rather than only here.
Those technical details are ours for that purpose. They are not handed to the business you paid. A shop receives the payment and the name, if you gave one. It does not receive a profile of you.
We never see your M-Pesa PIN. It is entered on your handset, in Safaricom's own prompt, and it does not pass through our systems or the merchant's.
To move the payment you asked us to move, which is the contract. To meet legal obligations under payments and anti-money-laundering law, which is not optional for either of us. And to detect fraud and secure the service, which is a legitimate interest and the reason the technical details above are collected at all.
We do not use any of it for advertising, profiling unrelated to fraud, or automated decisions that produce a legal effect on you.
Outside Kenya, and it is worth being specific rather than reassuring. Our database is in Ireland, the application that serves it runs in London, and verification documents are stored in Cloudflare's Western Europe region. The payment itself moves on Safaricom's rails in Kenya, and Safaricom holds its own record of it.
The reason is latency and the absence of a suitable managed database closer to home: the application and the database have to sit beside each other, because a single payment does several round trips between them, and the ones available near Nairobi were not ones we were willing to run money on. We would rather say that than imply a choice we did not make.
The Act allows a transfer out of Kenya on several bases, and which one applies depends on what is being transferred. For ordinary account and transaction data we rely on the necessity of the transfer for performing the contract, together with contractual protections that bind each provider to the standard the Act requires. Verification documents are different: an identity document is sensitive personal data, and sensitive personal data may be transferred only with consent as well as those safeguards. So we ask for it, in the dashboard, before any document is uploaded, showing the same wording we then store alongside the agreement so there is a record of what was agreed to rather than merely that something was.
None of this is data a Kenyan localisation rule requires to stay in the country. If that changes, or if where any of it lives changes, this page changes with it.
Transaction and verification records are kept for the period payments and anti-money-laundering law requires, which is measured in years rather than months and is not ours to shorten. Operational logs are kept for a short window and then discarded, and they are written through an allowlist, so a field nobody has thought about yet cannot end up in them by default.
When an obligation ends and we have no other reason to hold something, we delete it.
Access to what we hold about you, correction of anything wrong, deletion where no obligation requires us to keep it, objection to processing based on legitimate interests, and a copy in a portable form.
Write to [email protected]. We will tell you what we hold, what we can remove and what we are obliged to keep and why. If you are unhappy with the answer, you can complain to the Office of the Data Protection Commissioner.
The date at the top is the date it last changed. If something changes materially for people already using the service, we will say so rather than relying on you to re-read a page you read once.
A real person reads it and answers specifically. If we are holding something we should not be, we would rather you told us.