Privacy Policy

Last updated: March 15, 2026

1. Who We Are

CashTrace is a product of Kigs Apex LLP, a Kenya-registered limited liability partnership with its principal office in Nairobi, Kenya. In this policy, "we", "us", and "our" refer to Kigs Apex LLP.

Contact: info@kigsapexsolutions.com | +254 768 335 829

2. Information We Collect

Information you provide

  • Account details: name, email address, phone number, company name
  • Business data: invoices, payment records, customer information you upload
  • Documents: invoice PDFs, M-Pesa screenshots, bank statements uploaded for OCR processing
  • Communications: messages you send via contact forms or email

Information collected automatically

  • Device and browser information (IP address, browser type, operating system)
  • Usage data (pages visited, features used, timestamps)
  • Cookies and similar technologies (see Section 8)

3. How We Use Your Information

  • To provide and maintain the CashTrace platform and its features
  • To process invoices and payments through OCR and our matching engine
  • To send collections reminders on your behalf (email and SMS)
  • To respond to your enquiries and provide customer support
  • To improve our platform, including training our matching algorithms
  • To prevent fraud and ensure platform security
  • To comply with legal obligations under Kenyan law

4. How We Share Your Information

We do not sell your personal information. We may share data with:

  • Service providers: Google Cloud Platform (hosting, OCR via Cloud Vision API, file storage), Resend or Gmail (email delivery), Africa's Talking (SMS delivery)
  • Authorised users: Accountants you invite to view your business data within CashTrace
  • Legal authorities: When required by Kenyan law, court order, or government regulation

5. Data Protection & Security

We implement appropriate technical and organisational measures to protect your data:

  • Encryption in transit (TLS/HTTPS) and at rest
  • Hosted on Google Cloud Platform with enterprise-grade security
  • Role-based access controls within the platform
  • Multi-tenancy isolation — your business data is never accessible to other businesses
  • Full audit logging of all data access and modifications
  • Regular security reviews and updates

6. Data Retention

  • Account data: Retained for the duration of your account and up to 24 months after account closure
  • Business data: Invoices, payments, and match records retained for the duration of your account
  • OCR data: Raw OCR output stored alongside the corresponding record for audit purposes
  • Audit logs: Retained for a minimum of 7 years as required for financial record-keeping
  • Contact submissions: Retained for up to 24 months

7. Your Rights

Under the Kenya Data Protection Act, 2019, you have the right to:

  • Access your personal data held by us
  • Rectify inaccurate or incomplete data
  • Delete your personal data (subject to legal retention requirements)
  • Restrict processing of your data
  • Data portability — receive your data in a structured, machine-readable format
  • Object to processing of your data for specific purposes
  • Withdraw consent at any time where processing is based on consent

To exercise any of these rights, contact us at info@kigsapexsolutions.com. We will respond within 30 days.

8. Cookies

We use the following types of cookies:

  • Essential cookies: Required for platform functionality (authentication, session management)
  • Analytics cookies: Google Analytics — aggregated and anonymised usage data
  • Functional cookies: Remember your preferences (e.g., timezone, display settings)

Persistent cookies last between 30 days and 2 years. You can manage cookies through your browser settings.

9. Children's Privacy

CashTrace is a business tool and is not directed to individuals under 18 years of age. We do not knowingly collect personal information from minors.

10. ODPC Compliance

CashTrace is committed to full compliance with the Kenya Data Protection Act, 2019 and regulations issued by the Office of the Data Protection Commissioner (ODPC).

Our commitments

  • Lawful processing: We process personal data only where we have a lawful basis — consent, contractual necessity, legal obligation, or legitimate interest
  • Purpose limitation: Data is collected for specified, explicit, and legitimate purposes and not processed in a manner incompatible with those purposes
  • Data minimisation: We collect only the data necessary for the purposes stated in this policy
  • Accuracy: We take reasonable steps to ensure data is accurate and up to date
  • Storage limitation: Data is kept only for as long as necessary (see Section 6)
  • Integrity & confidentiality: Appropriate security measures are in place (see Section 5)
  • Accountability: We maintain records of processing activities and can demonstrate compliance

Data Protection Officer

For data protection enquiries, complaints, or to exercise your rights under the Act, contact our Data Protection Officer at info@kigsapexsolutions.com.

Filing a complaint

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Office of the Data Protection Commissioner:

11. Cross-Border Data Transfers

Your data may be processed on servers located outside Kenya (Google Cloud Platform). Where data is transferred outside Kenya, we ensure appropriate safeguards are in place in accordance with the Data Protection Act, 2019, including ensuring the receiving jurisdiction provides adequate data protection or implementing appropriate contractual safeguards.

12. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email or an in-app notification. Continued use of CashTrace after changes constitutes acceptance of the updated policy.

13. Governing Law

This privacy policy is governed by and construed in accordance with the laws of Kenya, including the Data Protection Act, 2019. Any disputes shall be subject to the exclusive jurisdiction of the courts of Kenya.