Privacy Policy

How we handle your data

Last updated 7 July 2026

Mikrosell Wine POS is operated by Mikrosell Systems (“we”, “us”), based in Nairobi, Kenya. This policy explains what data we collect from a business that registers on Mikrosell Wine POS and the staff it invites, why we collect it, and the rights available under Kenya’s Data Protection Act, 2019.

1. Who this applies to

This policy covers every business (“tenant”) registered on Mikrosell Wine POS, its owner, and every cashier the owner invites. If you’re a customer of one of our tenant businesses — for example, a shopper with a running credit balance at a wines & spirits retailer — your data is controlled by that business, not by us directly; see “Customer data recorded by a tenant” below.

2. Data we collect

Account & business data — business name, branch names and locations, owner and cashier phone numbers, names, and hashed PINs (never the PIN itself — see Security below).

Operational data your business creates — sales, stock levels and adjustments, supplier deliveries and balances, customer credit balances your staff record, expenses, and shift cash counts.

Billing data— subscription plan, invoice history, and M-Pesa transaction references from Safaricom’s Daraja API. We never see or store your M-Pesa PIN — that transaction happens entirely between you and Safaricom.

Device & usage data — login timestamps, the device a shift or sale was recorded from, and connectivity state (used to queue and sync offline sales safely).

3. Customer data recorded by a tenant

A business using Mikrosell Wine POS may record its own customers’ names, phone numbers, and running credit balances (“deni”). That business is the data controller for that information — we process it on their behalf, as their service provider, and don’t use it for our own purposes. Questions about that data should go to the business you interact with directly.

4. How we use data

  • To run the service: recording sales, tracking stock, generating reports, and producing receipts, delivery notes, and statements.
  • To send documents you explicitly choose to share — a receipt or statement shared to WhatsApp is sent only when a cashier or owner taps to share it.
  • To process subscription payments via M-Pesa STK Push and issue invoices.
  • To generate the AI-powered sales summaries and stockout predictions a business opts into — computed from that business’s own data only, never pooled across businesses.
  • To secure accounts: rate-limiting repeated failed PIN attempts and detecting unusual login activity.

5. Data isolation between businesses

Every business’s data is isolated at the database level, enforced independently by our application logic and by PostgreSQL row-level security policies — one business can never query another’s data, even in the event of an application bug. Platform staff supporting the software itself do not have standing access to any business’s sales or stock data.

6. Where data is stored, and security

  • Data is hosted with Neon (managed PostgreSQL) and encrypted in transit (TLS) and at rest.
  • PINs are hashed with bcrypt before storage — we cannot recover or view a staff member’s actual PIN.
  • Login sessions use short-lived access tokens with rotating refresh tokens; repeated failed PIN attempts lock an account for a cooldown period.
  • Voiding a sale, changing a price, or editing staff access requires re-entering the owner’s PIN and is permanently logged with who made the change and when.

7. Who we share data with

We don’t sell data, and we don’t share it with anyone for their own marketing purposes. We share the minimum necessary with:

  • Safaricom, to process M-Pesa payments and STK Push subscription billing.
  • Our hosting and infrastructure providers, solely to run the service.
  • WhatsApp, only when you or your staff actively choose to share a document through it.
  • Law enforcement or regulators, only where legally required.

8. Your rights

Under the Data Protection Act, 2019, you can ask us to:

  • Confirm what personal data we hold about you and provide a copy of it.
  • Correct inaccurate data.
  • Delete your data, subject to what we’re required to keep for tax, audit, or legal reasons.
  • Export your business’s full operational data at any time — Mikrosell Wine POS is built with no lock-in.

To exercise any of these, contact us using the details below.

9. Data retention

We keep operational data for as long as your subscription is active, plus a reasonable period after closure to satisfy tax and audit obligations under Kenyan law, after which it’s deleted unless you request earlier deletion and no legal obligation requires us to retain it.

10. Changes to this policy

If we make a material change, we’ll notify the account owner by SMS, email, or WhatsApp before it takes effect. Continued use of Mikrosell Wine POS after that notice means you accept the update.

11. Contact

Questions, requests, or complaints about this policy can be sent via WhatsApp to the number provided on our site, or by email to the address given at signup. We’ll respond within a reasonable time.