Who We Are
Data Controller: yokasre Consulting Limited, a company incorporated in Kenya, operating Jimanage — a mobile point of sale and business management application available at jimanage.yokasre.com.
Contact address: Nairobi, Kenya. For all data-related enquiries, contact us via our contact page.
This policy applies to the Jimanage mobile application, the Jimanage website at jimanage.yokasre.com, and any associated services we provide.
Data We Collect
We collect data in the following categories depending on how you use Jimanage:
| Category | Examples | Source |
|---|---|---|
| Account & identity data | Name, phone number, email address, role | Provided by you on registration |
| Business data | Business name, type, location, number of employees | Provided by you when setting up a business |
| Transaction data | Sales records, invoices, payment amounts, payment methods (cash, M-Pesa, credit), items sold | Generated by you using the app |
| Inventory data | Product names, prices, quantities, purchase orders, stock movements | Entered by you or your employees in the app |
| Financial data | Expenses, debtor and creditor records, profit and loss data | Entered by you in the app |
| Employee data | Employee names, phone numbers, roles, sales activity | Entered by the business admin |
| Customer data | Customer names, phone numbers, credit balances (where recorded for debtor tracking) | Entered by the business admin or employees |
| Device & usage data | Device type, operating system version, app version, session logs, error reports | Automatically collected on app use |
How We Use Your Data
We use your data only for the purposes for which it was collected. Specifically:
- To provide the Jimanage service — processing your transactions, managing inventory, generating reports, and all core app functions.
- To maintain your account — authentication, account recovery, and managing business and employee access.
- To provide customer support — responding to queries, resolving technical issues, and onboarding assistance.
- To send service communications — subscription status, billing notifications, important product updates, and security alerts. We do not send marketing communications without your consent.
- To improve the product — analysing aggregated, anonymised usage data to improve features, fix bugs, and optimise performance.
- To comply with legal obligations — as required by Kenyan law, including the Data Protection Act 2019, Kenya Revenue Authority regulations, and other applicable legislation.
We will not use your data for automated decision-making that produces legal or similarly significant effects without your explicit consent.
Legal Basis for Processing
Under the Kenya Data Protection Act 2019, we process your personal data on the following legal grounds:
- Performance of a contract — processing is necessary to deliver the Jimanage service you have subscribed to.
- Consent — where you have given specific consent, such as for optional communications or integrations.
- Legitimate interests — to operate and improve the product, prevent fraud, and ensure security, where these interests are not overridden by your rights.
- Legal obligation — where processing is required to comply with Kenyan law or a lawful order of a regulatory or judicial authority.
Data Sharing & Disclosure
We do not sell, rent, or trade your personal data. We may share data only in the following limited circumstances:
- Service providers — trusted third-party vendors who assist us in operating Jimanage, such as cloud hosting providers, analytics services, and communication platforms. All such providers are contractually bound to process data only on our instructions and to maintain appropriate security measures.
- M-Pesa & payment integrations — where you have enabled M-Pesa integration, transaction data necessary to process payments is shared with Safaricom PLC via their API. This is governed by Safaricom's terms and your own M-Pesa agreement.
- Within your business — your business data, transaction records, and employee records are accessible to the admin accounts you designate and the employee roles you configure.
- Legal requirements — we may disclose data if required by law, a court order, or a lawful directive from a regulatory authority such as the Office of the Data Protection Commissioner (ODPC), Kenya Revenue Authority, or law enforcement agencies, provided we verify the legitimacy of such requests.
- Business transfers — in the event of a merger, acquisition, or sale of the business, your data may be transferred as part of that transaction. You will be notified in advance of any such transfer and provided an opportunity to delete your account.
We do not transfer personal data outside Kenya unless adequate data protection safeguards are in place as required under Section 48 of the DPA 2019.
Data Storage & Security
Your data is stored on secure servers located in Kenya or within jurisdictions that meet adequate data protection standards. We implement technical and organisational measures to protect your data, including:
- Encryption of data in transit (TLS/HTTPS) and at rest
- Access controls and role-based permissions within the application
- Regular security assessments and monitoring
- Secure password hashing and authentication practices
- Staff training on data protection obligations
While we take all reasonable steps to protect your data, no system is completely secure. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the ODPC as required by the DPA 2019.
Data Retention
We retain your data for as long as your account is active or as necessary to provide the service. Specifically:
- Account and business data — retained for the duration of your subscription and for 3 years after account closure to meet legal and accounting obligations.
- Transaction and financial records — retained for 7 years in compliance with Kenya's Tax Procedures Act, 2015 and applicable accounting regulations.
- Employee and customer data — retained as long as your account is active. Deleted within 90 days of account closure or earlier upon request.
- Device and usage logs — retained for up to 12 months for debugging and security purposes.
When data is no longer required, we securely delete or anonymise it in a manner that prevents reconstruction.
Your Rights Under the DPA 2019
As a data subject under Kenya's Data Protection Act 2019, you have the following rights. You may exercise these by contacting us via our contact page:
- Right to be informed — you have the right to know what data we hold about you and how it is used. This policy fulfils that obligation.
- Right of access — you can request a copy of the personal data we hold about you, which we will provide within 21 days.
- Right to rectification — you can request that we correct inaccurate or incomplete data about you.
- Right to erasure — you can request deletion of your personal data, subject to our legal retention obligations.
- Right to data portability — you can request your data in a structured, machine-readable format.
- Right to object — you can object to certain types of processing, including direct marketing.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC), P.O. Box 41079-00100, Nairobi, Kenya — www.odpc.go.ke.
Cookies & Website Tracking
Our website at jimanage.yokasre.com uses cookies and similar technologies to:
- Keep you logged in during a session (strictly necessary cookies)
- Remember your preferences
- Analyse website traffic in aggregate form (analytics cookies)
You can control cookies through your browser settings. Disabling non-essential cookies will not affect your ability to use the core Jimanage application.
The Jimanage mobile application itself does not use browser cookies. It uses secure local storage on your device for offline functionality, and communicates with our servers over encrypted connections.
Children's Privacy
Jimanage is a business management application intended for adults operating businesses. We do not knowingly collect personal data from persons under the age of 18. If you believe a minor has registered on our platform, please contact us immediately and we will take prompt action to delete the relevant account and data.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the law, our practices, or the features of Jimanage. We will notify you of material changes by:
- Posting the updated policy on this page with a revised effective date
- Sending a notification via the Jimanage app or by email/SMS if you have provided contact details
Your continued use of Jimanage after changes are posted constitutes acceptance of the revised policy. If you do not agree with changes, you may close your account by contacting us.
Current version: 1.0 | Effective date: 1 July 2026
Contact & Complaints
For any questions about this Privacy Policy, to exercise your data rights, or to raise a concern:
- Contact form: Contact Form
- Website: jimanage.yokasre.com
- Data controller: yokasre Consulting Limited, Nairobi, Kenya
We take all data protection queries seriously and will respond within 21 days. Where your concern is not resolved to your satisfaction, you may escalate to the Office of the Data Protection Commissioner (ODPC) at www.odpc.go.ke.