Last updated: August 2026
Placeholder pending legal review. This policy is a good-faith draft prepared for Shiriki Connect's launch and has not yet been reviewed by a qualified data protection lawyer in Kenya or the EU. Do not treat it as final legal advice; it will be updated before general availability.
This policy applies to Shiriki (“we”, “us”), the church administrators and staff who use our platform (“church accounts”), and the individual church members whose records those accounts manage (“members”). Where a church is the data controller for its own members' information, Shiriki acts as a data processor on the church's behalf.
We collect and process the following categories of information:
We process member and financial data to operate the church management services a church account has subscribed to: recording and reconciling giving, maintaining member directories, sending church-authorized communications, running events, and generating financial reports for the church's own governance and audit needs. We do not sell member or giving data to third parties.
Giving transactions initiated via M-Pesa STK Push, PayBill, Airtel Money, USSD, or card are matched to a member record and giving category and retained as part of the church's financial ledger. These records are treated with the same sensitivity as banking records: access is restricted to admin roles explicitly granted financial permissions, and every view or export is written to an immutable audit log.
Financial and giving records are retained for at least seven years to support church financial audits and Kenyan tax record-keeping norms, unless a church requests earlier deletion where not otherwise required by law. Member profile data is retained for the life of the church account and deleted, or anonymized, within 90 days of a verified deletion request or account closure, subject to any records we are legally required to keep.
Shiriki is designed to operate consistently with Kenya's Data Protection Act, 2019 and the regulations issued by the Office of the Data Protection Commissioner (ODPC). This includes: processing personal data lawfully, fairly, and transparently; collecting data for specified, explicit purposes; minimizing data collected to what is necessary; and implementing appropriate technical and organizational security measures. Kenyan data subjects have the right to be informed of processing, access their data, correct inaccurate data, object to processing, and request deletion, subject to statutory retention requirements described above.
Members giving or registering from the European Union, the United Kingdom, or other jurisdictions with equivalent data protection law are additionally afforded the rights available under the General Data Protection Regulation (GDPR), including the right to access, rectify, erase, restrict, or port their personal data, and the right to lodge a complaint with a supervisory authority. Where diaspora giving data is transferred outside the EU/UK, we rely on standard contractual clauses or equivalent safeguards with our processors.
Access to the platform is phone-OTP only — there are no reusable passwords. Data is encrypted in transit (TLS) and at rest. Admin sessions use short-lived, rotating tokens. Every financial and member-record action is written to an immutable audit log. Access to production systems is restricted to authorized engineering staff under least-privilege principles.
To access, correct, or request deletion of your data, contact your church administrator directly (they control your member record), or email us at hello@shiriki.site and we will route your request to the relevant church account and respond within the timelines required by applicable law.
We will update this page as our practices evolve and as this policy completes formal legal review. We encourage church administrators to review it periodically.