Privacy Policy
Last updated 28 July 2026
MamasLedger ("we", "us") provides record-keeping and ordering tools for small food vendors, dukas and salons in Kenya, and the customer portal their customers use. This policy explains what personal data we collect, why, and the rights you have over it under Kenya's Data Protection Act, 2019 ("the DPA").
1. Who this applies to
Vendors and staff who register a business on MamasLedger, and customers a vendor adds to their own MamasLedger account (for example, to run a credit tab or send order confirmations).
For customer data, the vendor is the data controller — they decide to add a customer's details and what they're used for. MamasLedger acts as the data processor, providing the platform the vendor's data is stored and processed on.
2. What we collect
- Name, phone number, and a PIN (stored as a salted hash — never in plain text) for login
- Business details: shop name, address, business type, email (optional)
- Order, payment, and loyalty history recorded through the app
- For customers with a credit tab, a vendor may optionally record a national ID number and/or ID photo, at the vendor's discretion, for identity verification on credit
- Basic device/usage data (e.g. push notification tokens) needed to deliver alerts
We do not collect more than a vendor needs to run their business, and most fields above are optional.
3. How we use it
- To operate the account: logins, orders, payments, stock, and receipts
- To send order, payment, low-stock, and expiry notifications by push, SMS, or WhatsApp
- To let a vendor track customer tabs, loyalty points, and order history
- To keep the service secure and prevent abuse (e.g. rate-limiting login attempts)
We do not sell personal data, and we do not use it for third-party advertising.
4. Where data is stored
MamasLedger runs on Cloudflare's infrastructure (Workers, D1, and R2 storage), which may process data outside Kenya. Where that happens, we rely on Cloudflare's own security and data protection safeguards, and only transfer what's needed to operate the service.
5. Who can see it
A vendor and their staff can see the data for their own business only — never another vendor's. Staff access is further limited by role (e.g. a sales-only staff member cannot see financial reports). MamasLedger's own team can access data only to provide support or fix technical issues, and never for marketing purposes.
6. Your rights
Under the DPA, you can ask a vendor (or us, for vendor-account data) to:
- Confirm what personal data is held about you and access a copy
- Correct inaccurate or outdated data
- Delete data that's no longer needed, subject to legal/record-keeping requirements
- Object to or restrict certain processing
To exercise these rights, contact the vendor directly, or reach us at hello@mamasledger.com and we'll help route the request.
7. Data retention
We keep account and transaction data for as long as an account is active, plus a reasonable period after for legal, accounting, and dispute-resolution purposes. A vendor can request deletion of their business account and associated data at any time.
8. Security
PINs are never stored in plain text — they're hashed with a unique salt per account. Access to business data requires authentication, and sensitive actions (like large payment edits or stock write-offs) can require a second staff member's approval. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data against loss, misuse, or unauthorised access.
9. Changes to this policy
We may update this policy as the service evolves. Material changes will be reflected here with an updated date at the top of the page.
10. Contact us
Questions about this policy or how your data is handled? Reach us at hello@mamasledger.com or WhatsApp. You can also lodge a complaint with the Office of the Data Protection Commissioner (ODPC), Kenya, at odpc.go.ke.
