Privacy Policy
Last updated: December 2024
Pewang Company ("we", "our", or "us") operates the THIBITISHA mobile application. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our application.
Summary: We only read M-Pesa SMS messages to capture transaction data. We never read personal text messages, and your data is securely stored and never sold to third parties.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Business name
- Email address
- Phone number
- Login credentials (securely hashed)
1.2 SMS Data (M-Pesa Only)
Our app requires SMS permission to function. We ONLY read SMS messages from "MPESA" sender to extract:
- Transaction reference ID
- Payment amount
- Sender name
- Transaction timestamp
Important: We do NOT read, access, or store any personal text messages. Our SMS filter strictly limits reading to M-Pesa confirmation messages only.
1.3 Transaction Data
Transaction information extracted from M-Pesa messages is stored to provide our services, including:
- Transaction history
- Payment verification records
- Worker confirmation logs
1.4 Device Information
We may collect device information such as:
- Device type and model
- Operating system version
- App version
2. How We Use Your Information
We use the collected information to:
- Provide and maintain THIBITISHA services
- Process and display M-Pesa transactions
- Enable worker management and payment verification
- Send SMS notifications (with your consent)
- Improve our application
- Provide customer support
3. Data Storage and Security
Your data is stored securely using:
- Firebase Cloud Services (Google Cloud Platform)
- Encrypted data transmission (HTTPS/TLS)
- Secure authentication systems
- Local encrypted storage on your device
4. Data Sharing
We do NOT sell, trade, or rent your personal information to third parties.
We may share data with:
- Service Providers: Firebase (data storage), Paystack (payment processing), MobileSasa (SMS services)
- Legal Requirements: If required by law or to protect our rights
- Your Workers: Transaction data is shared with workers you authorize in the app
5. Your Rights
You have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request deletion of your account and data
- Disable SMS reading at any time in app settings
- Export your transaction data
6. SMS Permission Justification
THIBITISHA requires SMS permission because:
- M-Pesa transaction confirmations are delivered via SMS
- Automatic transaction capture is our core functionality
- There is no alternative API for personal M-Pesa accounts
- Real-time payment tracking requires SMS interception
7. Data Retention
We retain your data as long as your account is active. Upon account deletion:
- Account information is deleted within 30 days
- Transaction history may be retained anonymously for analytics
- Backup data is purged within 90 days
8. Children's Privacy
THIBITISHA is not intended for users under 18 years of age. We do not knowingly collect information from children.
9. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes via email or in-app notification.
10. Contact Us
If you have questions about this Privacy Policy, please contact us:
- Email: support@pewang.company
- Website: thibitisha.pewang.company
- WhatsApp: +254 711 164 069