Privacy Policy
Last updated: 17 August 2026
GOLD FISH TECHNOLOGY CO LIMITED (“we”, “us”, “FishPesa”) operates
the FishPesa mobile lending application (com.fishpesa.cash.secure) and website at fishpesa.com.
This Privacy Policy explains how we collect, use, store, share and protect your personal
information when you use our app or website.
We respect your privacy and comply with Google Play policies, the Kenya Data Protection Act, 2019,
and all applicable laws and regulations.
1. Who We Are
Data controller: GOLD FISH TECHNOLOGY CO LIMITED
Registered office: Timshack House, Ngong Road, Dagoreti District, Nairobi 00100, Kenya
Certificate of Incorporation: PVT-BB1OA9M3
KRA PIN / VAT: P052558388D
Website: fishpesa.com
Privacy enquiries: [email protected]
Customer support: +254 797 492 076 (Mon–Sat, 8:00 AM – 6:00 PM EAT)
2. Information We Collect
2.1 Information You Provide
When you register, complete your profile or apply for a loan, we may collect:
- Mobile phone number
- Full name, gender, date of birth and email address
- National ID number
- County, address and location details
- Employment status, occupation, monthly income and payday
- Education level and marital status
- Emergency contact name and phone number (selected or entered by you)
- Loan application details and repayment records
- Communications with our customer support team
2.2 Information Collected With Your Permission
When you explicitly authorise required permissions and submit a loan application, we may collect
additional data for eligibility assessment and fraud prevention:
- Device information — brand, model, OS version, Android ID, memory, screen size, language, time zone, emulator/root status and related technical signals
- Advertising identifier (GAID) — only after permission, for fraud prevention and analytics in compliance with platform policies
- SMS messages — only after you apply for a loan, to support eligibility assessment and risk control. We do not send SMS on your behalf without your action
- Phone state — basic device identification to prevent multi-device fraud during login and loan application
- Location — coarse location for risk assessment, only with your consent
- Installed applications — list of apps installed on your device, used for fraud prevention and environment risk evaluation
- Wi-Fi information — Wi-Fi RSSI / SSID / BSSID, used for device environment and risk evaluation
We will always request your permission before accessing or uploading any such data.
No data is uploaded to our servers unless you submit a loan application and grant the required permissions.
2.3 Credit Bureau Data
We may request data from external credit bureaus or financial institutions to enhance credit
assessment accuracy. Before making any such request, we will inform you of the provider involved
and obtain your separate authorisation. No external queries occur without your explicit consent.
3. How We Use Your Information
We use personal information for the following purposes:
- Identity verification and Know Your Customer (KYC) compliance
- Credit scoring, assessment and loan decisioning
- Loan disbursement and repayment processing via M-Pesa
- Repayment monitoring, collections and loan extension management
- Fraud detection, device authentication and risk management
- Customer support and dispute resolution
- Service improvement, statistical analysis and product development
- Compliance with legal, regulatory and accounting obligations in Kenya
- Marketing and promotional activities — only if you separately opt in; you may withdraw consent at any time
4. Legal Basis for Processing
We process your data based on:
- Contract performance — to provide lending services you request
- Legitimate interests — fraud prevention, security and service improvement
- Legal obligation — compliance with Kenyan law and regulatory requirements
- Consent — for optional processing such as marketing, credit bureau inquiries and sensitive permissions
5. M-Pesa Payments
Loan disbursement and repayment are processed through Safaricom M-Pesa.
We collect your M-Pesa mobile number, transaction amounts, reference numbers and payment status.
We never collect, store or request your M-Pesa PIN. All M-Pesa transactions
are confirmed on your Safaricom phone.
6. Data Sharing
We do not sell your personal data. We may share data only in these circumstances:
- With your explicit consent — for optional services or marketing you agree to
- Service providers — payment processors (M-Pesa/Safaricom), identity verification vendors, cloud hosting, analytics and fraud-detection partners, operating under strict confidentiality obligations
- Credit bureaus — only with your separate authorisation
- Legal requirements — court orders, law enforcement or regulatory requests, where we will notify you when legally permitted
- Security vendors — for fraud detection and incident response
7. Data Security & Storage
We implement appropriate technical and organisational measures to protect your data:
- In transit — industry-standard encryption (TLS/HTTPS)
- At rest — strong encryption algorithms on our servers
- Access control — only authorised personnel may access your data
- Data residency — data is transmitted to and stored on our secure servers. Specific retention periods are available upon request
8. Cookies and this Website
The FishPesa website at fishpesa.com is a static information site. We do not use advertising
cookies or third-party tracking pixels on this website. Your browser may send standard
technical data (such as IP address, browser type and pages visited) to our hosting provider
(Cloudflare) as part of normal web delivery and security.
9. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this
policy, including providing services, complying with legal obligations and resolving disputes.
When data is no longer needed, we securely delete or anonymise it.
10. Your Rights
Under the Kenya Data Protection Act, 2019, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data (subject to legal and contractual obligations)
- Withdraw consent for optional processing (e.g. marketing)
- Object to certain processing activities
- Lodge a complaint with the Office of the Data Protection Commissioner (ODPC)
You may exercise these rights through in-app settings or by contacting
[email protected].
Account deletion is available after all outstanding loans have been fully repaid.
11. Account Deactivation
When you request account closure:
- All outstanding loans must be fully repaid
- After confirmation, there is a 7-day grace period to cancel the closure by logging in again
- If you do not log in within 7 days, the account is permanently closed
12. Children
FishPesa is not intended for persons under 18 years of age. We do not knowingly collect
personal data from minors.
13. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top
will reflect the latest version. Continued use of the app after changes constitutes acceptance
of the updated policy.
14. Contact Us
For privacy enquiries or to exercise your data rights:
Email: [email protected]
Phone: +254 797 492 076
Address: Timshack House, Ngong Road, Dagoreti District, Nairobi 00100, Kenya