Last updated:
Privacy Policy
How SenteRail collects, uses, shares, secures, and retains personal data in a payments context.
This Policy is drafted for a payments and financial infrastructure context in East Africa. It is intended to support SenteRail's onboarding, payment orchestration, fraud controls, redress handling, regulated-partner relationships, and record-keeping duties while recognizing the rights of data subjects under the data protection law of each country we serve. SenteRail is incorporated in Uganda and is preparing to operate in Kenya; the country-specific section below sets out which law and which regulator apply to you.
Because SenteRail can act in different data roles depending on the product and the transaction flow, we explain those roles in practical terms below rather than using a single simplified label for every use case.
Merchant-specific data handling terms are set out in our Merchant Data Processing Addendum.
Scope and application
This Privacy Policy explains how SenteRail collects, uses, stores, shares, secures, and retains personal data in connection with our websites, hosted checkouts, merchant onboarding, merchant and operator portals, APIs, plugin tools, support channels, fraud controls, tax and reconciliation tools, and related services.
This Policy applies to merchants, merchant staff, operators, developers, partner users, payers, website visitors, support contacts, job applicants, and other individuals whose personal data is processed in connection with SenteRail. It should be read together with our Terms of Service and any service-specific notices or data processing terms that we provide for particular products.
Who we are and our role
SenteRail is the trading name used for SenteRail Technologies Company Limited, a private company limited by shares incorporated in Uganda (URSB Registration No. 80034644601118; registered office Kampala, Uganda). For purposes of this Policy, "SenteRail", "we", "us", and "our" refer to SenteRail Technologies Company Limited and the services we operate through https://senterail.com.
Depending on the context, SenteRail may act as a data collector, data controller, or data processor. In many cases, merchants remain responsible for their own customer relationship and customer notices, while SenteRail acts as a service provider or processor for payment enablement. In other cases, SenteRail acts as an independent controller where we determine the purposes and means of processing for fraud prevention, account security, transaction monitoring, complaint handling, audit, legal retention, sanctions screening, tax compliance, or regulatory reporting.
Categories of personal data we collect
We may collect and process the following categories of personal data:
- identity and profile data, including names, trading names, legal names, usernames, job titles, photographs, signatures, and account identifiers;
- contact data, including email addresses, telephone numbers, physical addresses, and support contact details;
- onboarding and due diligence data, including company registration documents, beneficial ownership details, director information, settlement account details, tax information, sanctions screening results, and verification outputs;
- identity verification data, including National ID, passport, or driving permit images, NIN or other identity document numbers, date of birth, document expiry dates, document barcode or machine-readable-zone checks, liveness results, face-match results, and manual-review decisions;
- payment and transaction data, including payer names, phone numbers, transaction references, channel data, merchant references, receipts, invoice references, amounts, timestamps, provider responses, settlement records, reconciliation status, and redress history;
- technical and device data, including IP address, browser type, operating system, device identifiers, session data, logs, API metadata, webhook delivery data, cookies, and usage analytics;
- communications and support data, including emails, call notes, ticket history, complaint files, fraud reports, and copies of communications with merchants, customers, regulators, or providers;
- risk and security data, including authentication events, failed login attempts, behavioral signals, fraud indicators, blacklist data, and incident investigation materials.
Job applications
When you apply for a role, we collect the name, email address, CV, supporting documents, work links and answers you submit, including any location and availability details you choose to provide. We use these details to review your application and contact you about the opportunity.
Application details and documents are sent to our team through our notification and email services. Please include only information relevant to the role; do not upload identity documents or financial records. Contact us using the details below with questions about your application data.
How we collect personal data
We collect personal data from several sources, including:
- directly from you when you sign up, apply, contact us, or use the Services;
- from your device camera when you choose to complete identity verification, including live photos of the front and back of your identity document and a selfie or liveness check;
- from merchants or business users who submit customer or team data through the Services;
- from payment providers, banks, mobile money operators, identity providers, and tax systems;
- from fraud, sanctions, device, risk, and public-source checks that support legal and compliance obligations;
- automatically from your device and browser when you visit or interact with our platforms.
Purposes of processing and lawful grounds
We process personal data for purposes that include:
- creating and administering accounts, invitations, authentication, and access controls;
- onboarding merchants, verifying authority, and performing customer due diligence;
- verifying members, payers, merchants, principals, and authorised users by comparing identity document photos, barcode or machine-readable details where present, selfie or liveness evidence, and available identity or sanctions sources;
- routing, processing, validating, reconciling, settling, and supporting payment transactions;
- issuing receipts, generating records, and operating tax or fiscalization workflows;
- preventing, detecting, investigating, and responding to fraud, abuse, and security incidents;
- meeting legal, regulatory, audit, accounting, tax, AML, and reporting obligations;
- handling support requests, complaints, disputes, refunds, reversals, and redress matters;
- improving platform reliability, analytics, service design, and operational resilience;
- communicating service notices, policy changes, security alerts, onboarding requirements, and relevant marketing where permitted.
Depending on the context, our lawful grounds may include your consent, performance of a contract, steps taken at your request before entering a contract, compliance with a legal obligation, fraud prevention, network and information security, protection of legitimate interests, establishment or defense of legal claims, and other grounds permitted under applicable Ugandan law.
Identity photos, barcodes, and biometric checks
Some SenteRail onboarding flows require a live photo of the front and back of your identity document. If the back of the document includes a machine-readable barcode, we may read it to compare the name, date of birth, document number, NIN, expiry date, or similar identity details against the visible front of the document and the information provided by you, your SACCO, merchant, or partner institution.
Some identity documents may embed fingerprint, portrait, or other biometric data inside the barcode. SenteRail designs this check to discard embedded biometric bytes before storage. We do not store fingerprint templates or embedded barcode portraits from the barcode result. We may store the document photo, extracted identity details, match outcome, confidence scores, reviewer decision, and audit record needed for onboarding, fraud prevention, dispute handling, and legal retention.
Selfies, liveness checks, and face-match outputs are used to confirm that the person presenting the document is live and appears to match the document photo. These checks may be performed by SenteRail or by identity verification service providers acting under appropriate data-protection terms. If you do not want to provide the required identity photos or liveness evidence, the relevant onboarding or verification flow may not be able to continue.
Merchant and customer data roles
When a merchant uses SenteRail to collect payments, send payment links, or generate hosted checkout experiences, the merchant typically remains responsible for the underlying sale, customer relationship, product disclosures, refund policy, and any merchant-facing privacy notice that is required for the merchant's own business.
SenteRail may process payer and customer data on the merchant's behalf to deliver the payment workflow, but SenteRail may also process the same or related data as an independent controller where necessary for fraud prevention, sanctions screening, account security, complaint handling, dispute resolution, legal retention, transaction auditability, regulator cooperation, or enforcement of our Terms.
Cross-border processing and transfers
SenteRail may process or store personal data in Uganda or in other jurisdictions where we or our service providers operate infrastructure or support services. Where data is transferred across borders, we take steps to ensure that the transfer is legally permitted and protected by contractual, operational, technical, or organizational safeguards appropriate to the risk and to applicable law.
Where a regulator, partner institution, or law requires local handling, in-country retention, or localized access arrangements for certain payment or identity data, we may restrict processing locations or implement additional controls for those datasets.
Security safeguards and incident response
We implement reasonable administrative, technical, and organizational safeguards designed to protect personal data against unauthorized access, misuse, alteration, loss, destruction, and unlawful disclosure. These safeguards may include access control, role separation, logging, encryption in transit and at rest where appropriate, secret management, audit trails, rate limiting, device and session controls, and incident detection and response processes.
No method of transmission, storage, or processing is completely secure. If we become aware of a personal data breach or other compromise requiring notice under applicable law, we will take appropriate containment and remediation steps and provide notice to affected persons or authorities where legally required.
Retention of personal data
We keep personal data only for as long as necessary for the purposes described in this Policy, unless a longer retention period is required or permitted by law, regulation, partner rule, court order, audit need, complaint handling requirement, or legitimate business necessity.
For payment systems, transaction evidence, AML and due diligence records, complaints and redress records, and other regulated financial records, retention periods may extend to at least ten years where required by Ugandan law or by a lawful preservation request. When retention is no longer justified, we may delete, anonymize, aggregate, or securely archive the data.
Your rights and choices
Subject to applicable law and lawful restrictions, you may have the right to request access to personal data we hold about you, request correction of inaccurate or incomplete data, request blocking, erasure, or destruction of unlawfully processed data, object to certain processing, require us to stop processing for direct marketing, and request review of certain decisions taken solely by automated means.
We may ask for proof of identity and enough information to locate the relevant data before acting on a request. Where the request is valid and no lawful exemption applies, we will respond within the time required by the law that applies to you. Response deadlines differ between countries, so the shorter of the applicable periods is the one we work to.
To exercise your rights, contact Contact our team. You may also complain to the data protection authority for your country — see country-specific information below for the authority that supervises your data.
Automated decision-making and profiling
We may use rules, scoring, and automated or semi-automated systems to assess risk, detect fraud, route transactions, flag suspicious activity, enforce rate limits, verify identity signals, and prioritize manual review. These systems help protect consumers, merchants, SenteRail, and our payment ecosystem from abuse and losses.
Where a decision that significantly affects you is based solely on automated processing and applicable law gives you a right to contest or seek reconsideration, you may contact us to request human review or further explanation, subject to lawful confidentiality and fraud-control limits.
Children and sensitive use cases
SenteRail's core services are intended for businesses, business representatives, and persons capable of entering binding arrangements. We do not knowingly solicit or target children for merchant account creation. If we learn that we have collected personal data unlawfully or without the required basis, we may delete or restrict that data and take any other action required by law.
Where a merchant uses SenteRail in a context involving schools, healthcare, savings groups, SACCOs, or other sensitive environments, that merchant must ensure that its own collection and disclosure of personal data is lawful and appropriate for the relevant context.
Country-specific information
SenteRail is incorporated in Uganda and is preparing to operate in Kenya. Which country's data protection law protects you depends on where you are, not on where we are. Both are set out below.
Uganda
If you are in Uganda, the Data Protection and Privacy Act, 2019 applies to the personal data we hold about you, and the Personal Data Protection Office (PDPO) supervises it.
You can complain to us first, and you can complain to the Personal Data Protection Office in Uganda if you are not satisfied with how we handled it.
SenteRail Technologies Company Limited is incorporated in Uganda, so this is the framework our own records and retention practices are built around.
Kenya
If you are in Kenya, the Data Protection Act, 2019 applies to the personal data we hold about you, and the Office of the Data Protection Commissioner (ODPC) supervises it.
You can complain to us first, and you can complain to the Office of the Data Protection Commissioner in Kenya if you are not satisfied with how we handled it.
Your rights under Kenyan data protection law apply to you whatever law governs your contract with us.
Personal data you give us may be processed in Uganda, where SenteRail is incorporated. Where Kenyan law sets conditions on moving personal data outside Kenya, we handle it on that basis.
SenteRail operates in Uganda and is preparing for Kenya. If you are reading this from anywhere else, tell us where you are based and we will explain which of these terms apply to you.
Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our business, products, partners, legal obligations, security practices, or data processing activities. The updated version becomes effective when posted, unless a later date is stated.
If a change is material, we may provide additional notice through the website, dashboard, email, or another reasonable method before or when the change takes effect.
Contact and complaints
For privacy questions, data subject requests, security concerns, or complaints about the handling of personal data, contact Contact our team.
We may request additional information to verify identity, protect other persons' data, and ensure that requests are handled lawfully and securely.