PaidFastPrivacy Policy

PaidFast Privacy Policy

Last updated: 3 July 2026

1. Introduction

PaidFast is a product of ProductSuch Limited ("ProductSuch", "PaidFast", "we", "us", or "our"). ProductSuch Limited provides PaidFast, an invoicing and payment collection platform for small and medium-sized businesses (the "Service"). References to "PaidFast" in this Policy mean ProductSuch Limited, trading as PaidFast. This Privacy Policy explains what personal data we collect, how we use and share it, how long we keep it, and the rights you have.

This Policy applies to:

  • Account holders — businesses and their users who register for and use PaidFast; and
  • Portal users / end customers — people who receive invoices, reminders, receipts, or payment links from a PaidFast account holder, or who use the PaidFast customer payment portal.

Important — our two roles. For data about account holders and their use of the Service, ProductSuch Limited is the data controller. For the customer records, contact details, and invoice data that an account holder uploads or generates (for example, their customers' names, phone numbers, and amounts owed), the account holder is the data controller and PaidFast acts as a data processor on their instructions. If you are an end customer with questions about how a business that invoices you handles your data, please contact that business first; we will assist them in responding.

2. Data We Collect

2.1 Data you provide

  • Account and profile data: name, email address, password (stored only as a salted hash), and profile image where you sign in with Google or another identity provider.
  • Organization data: business name, country, currency, tax profile and tax identification numbers, branch details, invoice templates, and numbering preferences.
  • Customer records (processed on behalf of account holders): your customers' names, email addresses, phone numbers (including WhatsApp numbers), tax identification details, payment terms, and communication channel preferences.
  • Invoice and transaction data: invoices, quotations, statements, credits, line items, taxes, discounts, notes, payment records, receipts, and reconciliation data.
  • Billing data: your subscription plan, billing history, and payment references. Card and mobile money credentials are collected directly by our payment providers (for example Pesapal or Stripe); we do not store full card numbers or mobile money PINs.
  • Communications: messages you send to us (for example support requests) and messages sent through the Service, including WhatsApp messages used to create draft invoices.

2.2 Data collected automatically

  • Usage and log data: IP address, device and browser information, pages viewed, actions taken, timestamps, and error logs.
  • Message delivery data: delivery status of emails and WhatsApp messages sent through the Service.
  • Cookies and similar technologies: we use strictly necessary cookies for authentication and session management (for example sign-in sessions and portal sessions). Where we use non-essential cookies or analytics, we will ask for consent where required by law.

2.3 Data from third parties

  • Identity providers: if you sign in with Google, we receive your name, email address, and profile image from Google.
  • Payment providers: payment confirmations, references, amounts, and payer identifiers (such as a mobile money phone number) from providers like M-Pesa/IntaSend, Airtel Money, Pesapal, Stripe, and PayPal, used to reconcile payments against invoices.
  • Messaging platforms: delivery and inbound message data from the WhatsApp Business Platform (Meta).
  • Connected systems: customer, invoice, and payment records from accounting or ERP systems the account holder chooses to connect.

2.4 Security tokens

To protect accounts and documents we generate verification tokens, password reset tokens, document access tokens, and one-time passcodes (OTPs). These are stored hashed and expire automatically.

3. How We Use Personal Data

We use personal data to:

  1. Provide the Service — create and manage accounts and organizations; create, send, and track invoices and related documents; generate PDFs and payment links; operate the customer payment portal.
  2. Collect payments — initiate and reconcile payments through the payment providers chosen by the account holder, and issue receipts.
  3. Send communications — deliver invoices, quotations, payment reminders, receipts, OTP codes, verification emails, and service notices by email and WhatsApp.
  4. Support compliance features — validate or submit invoice data to government e-invoicing systems (for example Kenya's eTIMS) where the account holder enables such features.
  5. Operate integrations — synchronize data with third-party accounting/ERP systems as configured by the account holder.
  6. Bill our customers — manage subscriptions, process plan payments, apply coupons, and enforce plan limits.
  7. Secure and improve the Service — authenticate users, detect and prevent fraud, abuse, and spam; debug, monitor, and improve performance and features.
  8. Comply with law — meet legal, tax, accounting, and regulatory obligations, and respond to lawful requests from authorities.

Legal bases

Where laws such as the Kenya Data Protection Act, 2019 or the EU/UK GDPR apply, we rely on: performance of a contract (providing the Service you signed up for); legitimate interests (securing and improving the Service, preventing fraud, business communications); legal obligation (tax, accounting, and regulatory requirements); and consent where required (for example certain cookies or marketing messages). Where we act as a processor, we process personal data on the documented instructions of the account holder.

We do not sell personal data, and we do not use Customer Content to train advertising profiles.

4. How We Share Personal Data

We share personal data only as described below:

  • Payment providers (for example IntaSend/M-Pesa, Airtel Money, Pesapal, Stripe, PayPal) — to process invoice payments and subscription billing.
  • Messaging and delivery providers — email delivery services and the WhatsApp Business Platform (Meta) — to deliver invoices, reminders, receipts, and OTPs.
  • Government and tax authorities — invoice data submitted to e-invoicing systems (for example the Kenya Revenue Authority's eTIMS) where the account holder enables compliance features, or where we are legally required to disclose.
  • Connected systems — accounting/ERP platforms the account holder explicitly connects, per the sync settings they configure.
  • Infrastructure and service providers — hosting, database, storage, monitoring, and customer support providers who process data on our behalf under contractual confidentiality and data protection obligations.
  • Identity providers — Google, when you choose Google sign-in.
  • Legal and safety — where required by law, legal process, or to protect the rights, safety, or property of PaidFast, our users, or the public.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.

Each account holder's data is logically separated by organization; other PaidFast customers cannot access your data.

5. International Transfers

PaidFast is based in Kenya and is expanding to serve businesses in other countries over time. As we do, personal data may be transferred to, stored, and processed in Kenya and in other countries where we, our account holders, or our infrastructure and service providers operate — which may have different data protection laws than your own country. Where personal data is transferred outside your country, we take steps required by applicable law — such as transferring to jurisdictions with adequate protection, using appropriate contractual safeguards, or obtaining consent where required (including the requirements of the Kenya Data Protection Act, 2019 on transfers outside Kenya, and equivalent requirements in other markets where we operate).

6. Data Retention

We keep personal data only as long as necessary for the purposes above:

  • Account and organization data: for the life of the account and a reasonable period afterwards to allow reactivation and export.
  • Invoices, payments, and receipts: retained for the period required by tax and accounting laws in the relevant market (commonly 5–7 years), even after account closure.
  • Security tokens and OTPs: short-lived and deleted or invalidated after expiry or use.
  • Logs: retained for a limited period for security and troubleshooting, then deleted or anonymized.

When an account is closed, we delete or anonymize Customer Content within a reasonable period, except where retention is required by law or for the establishment or defense of legal claims. Account holders can request export of their data before deletion.

7. Security

We apply technical and organizational measures appropriate to the risk, including:

  • Encryption of data in transit (HTTPS/TLS);
  • Passwords stored only as salted hashes; OTPs, session tokens, and document access tokens stored hashed with automatic expiry;
  • OTP-protected access to sensitive customer portal documents;
  • Access controls that scope data to each organization;
  • Least-privilege access for our personnel and contractual obligations on our processors.

No system is perfectly secure. If we become aware of a personal data breach that affects you, we will notify you and the relevant authority (for example the Office of the Data Protection Commissioner in Kenya) where and when required by law.

8. Your Rights

Depending on your jurisdiction (including under the Kenya Data Protection Act, 2019 and the GDPR where applicable), you may have the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate or incomplete data;
  • Delete your data, subject to legal retention obligations;
  • Object to or restrict certain processing;
  • Portability — receive your data in a structured, commonly used format;
  • Withdraw consent at any time, where processing is based on consent, without affecting prior processing;
  • Complain to a supervisory authority, such as the Office of the Data Protection Commissioner (Kenya).

To exercise these rights, contact us using the details in Section 12. If we process your data as a processor for a PaidFast account holder (for example, you are a customer of a business that invoices you through PaidFast), we may redirect your request to that business and assist them in responding.

You can opt out of non-essential messages by using the unsubscribe or opt-out mechanism in the message or by contacting the business that sent it. Transactional messages necessary to the Service (such as OTPs and payment receipts) may still be sent.

9. Children

The Service is intended for business use by adults. We do not knowingly collect personal data from children under 18. If you believe a child has provided us personal data, contact us and we will delete it.

10. Third-Party Services

The Service links to and interoperates with third-party services (payment providers, WhatsApp/Meta, Google, government systems, accounting/ERP platforms). Those services process personal data under their own privacy policies, which we encourage you to review. We are not responsible for the privacy practices of third parties.

11. Changes to This Policy

We may update this Policy from time to time. Material changes will be notified through the Service or by email before they take effect, and the "Last updated" date above will be revised. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.

12. Contact Us

For privacy questions, requests, or complaints, contact:

ProductSuch Limited (trading as PaidFast) A company registered in Kenya Registered address: Nairobi, Kenya Email: info@productsuch.com

If you are in Kenya, you may also lodge a complaint with the Office of the Data Protection Commissioner (ODPC). If you are in another country, you may have the right to lodge a complaint with your local data protection authority.

Terms of Service·Back to PaidFast