Privacy Policy
Last updated: May 5, 2026
Turtle Rewards Limited (“we,” “our,” or “us”), a company registered in Kenya (PVT-3QUDQB5J) and a registered Data Processor with the Office of the Data Protection Commissioner (ODPC) under identification number 268-0990-5797, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, platform, mobile application, and related services (the “Service”). This policy complies with the Kenya Data Protection Act, 2019 and, where applicable, the EU General Data Protection Regulation (GDPR).
Highlights — the short version
A quick summary of how we handle your data. The rest of this policy is the legal detail; this box is a fair summary, not a replacement.
- Who we are: Turtle Rewards Limited, based in Mombasa, Kenya. Registered Data Processor (ODPC ID 268-0990-5797).
- What we collect: account details, loyalty activity (points, stamps, redemptions), device and usage data, and — for cashier or merchant accounts — business details. We do not collect payment card numbers (those go directly to our payment providers).
- Why we collect it: to run loyalty programs, process payments, send transactional and (where you opt in) marketing messages, prevent fraud, and improve the platform.
- Who we share it with: a fixed list of named sub-processors (Stripe, Pesapal, M-Pesa via Safaricom, Resend, Gupshup, HostPinnacle, OpenAI, Anthropic, Sentry, cloud-hosting providers — full list in section 3). We do not sell your personal data.
- Your rights: access, correct, delete, port, object, restrict — exercise any of them via your account settings or by emailing hello@turtlerewards.club.
- If something goes wrong: we notify affected users and the ODPC within 72 hours of confirming a personal data breach where required by law.
- Automated decisions: we use AI to suggest offers and detect fraud — you have the right to ask for a human review of any decision that significantly affects you.
1. Information We Collect
1.1 Information You Provide
- Account information: Name, email address, phone number, and password when you create an account.
- Business information: Business name, category, branch locations (including address and geo-coordinates), operating hours, and staff details.
- Customer loyalty data: Points balances, transaction history, stamp card progress, offer claims, referral activity, and VIP tier status.
- Profile data: Optional information such as date of birth, avatar image, language preference, and timezone.
- Communications: Messages sent via the WhatsApp bot, support tickets, and feedback survey responses.
- Payment information: Payment details are collected and processed securely by our payment processor, Pesapal. We store transaction references and amounts but do not store card numbers or mobile money PINs.
- Consent records: Your acceptance of Terms & Conditions, Privacy Policy, and marketing communication preferences, along with timestamps.
1.2 Information Collected Automatically
- Device and access data: IP address, browser type, operating system, and device information recorded in server logs.
- Location data: When you scan a QR code or redeem a product offer, your approximate location (latitude/longitude) and device information may be recorded.
- Usage data: Features used, pages visited, API calls made, and timestamps of interactions.
1.3 Feature-Specific Data Collection
- WhatsApp bot conversations: Messages you send to our WhatsApp assistant are stored for up to 180 days to provide conversational context. Message content is processed by OpenAI to generate responses. Flagged conversations may be reviewed by staff for quality improvement.
- Leaderboards: If a Business Owner enables leaderboards, your first name and achievement metrics (points, tier) may be visible to other customers enrolled in the same store.
- Referral invitations: If you refer someone by submitting their phone number or email, we send them a one-time invitation. You must have their permission to share their contact information. Referral contact data is deleted after 90 days if not acted upon.
- Feedback and surveys: Your survey responses are stored and associated with your account. Responses are visible to the Business Owner's staff and may be used for satisfaction scoring (e.g., NPS).
- Push notification tokens: If you enable push notifications, a device token (unique to your device) is stored and sent to Firebase (Google) for delivery. Tokens are deleted when you disable notifications or close your account.
- Support tickets: Ticket content (including any personal information in your description) is visible to the Business Owner's assigned staff. Tickets are retained for 2 years after resolution.
- Custom webhooks: If a Business Owner configures webhooks, your loyalty transaction data (name, transaction amount, timestamp) may be sent to the Business Owner's external servers in real time. The Business Owner is responsible for the security of their webhook endpoints.
- Campaign recipient data: Business Owners may export lists of campaign recipients (including names, contact details, and delivery status) as CSV files. The Business Owner is the Data Controller for exported data.
- Third-party integrations: When a Business Owner connects Shopify, WooCommerce, or a POS system, order data (customer email, purchase amount, date) is synced to the platform for loyalty points calculation.
- API access: API calls made using developer API keys are logged (endpoint, timestamp, IP address) for security purposes and retained for 90 days.
1.4 Information We Receive From Third Parties
We may receive information about you from third parties, including:
- Business partners: When you make a purchase at a participating business that uses Shopify, WooCommerce, or POS integrations, they share order data with us to award loyalty points.
- Other users: Other users may provide information about you when they refer you to the Service or share points with you.
- Service providers: We may receive delivery status information from our messaging providers (Gupshup, HostPinnacle, Resend) and payment status from Pesapal.
1.5 Cookies and Similar Technologies
We use the following cookies and tokens:
- Authentication tokens: A JSON Web Token (JWT) stored in your browser to maintain your login session. A refresh token is stored in a secure, HttpOnly cookie.
- Role cookie: A non-sensitive cookie indicating your account type (customer or business) for page routing purposes.
- Preference storage: Local storage entries for UI preferences such as dismissed tooltips and setup progress. These do not contain personal data.
We do not use third-party tracking cookies, advertising pixels, or analytics services such as Google Analytics.
2. How We Use Your Information
We process your information on the following legal bases under the Kenya Data Protection Act, 2019:
- Performance of contract: Operating the platform, processing loyalty transactions, managing subscriptions, and delivering features you use.
- Legitimate interest: Fraud detection and prevention, security monitoring, platform improvement, and aggregate analytics.
- Consent: Marketing communications via SMS, WhatsApp, email, and push notifications. You may withdraw consent at any time.
- Legal obligation: Tax reporting, responding to lawful government requests, and compliance with applicable regulations.
3. Data Sharing and Third-Party Processors
We do not sell your personal information. We share data with the following categories of third-party service providers, each bound by data processing agreements:
| Provider | Purpose | Data Shared |
|---|---|---|
| Pesapal Holdings | Payment processing (cards, mobile money — KE/UG/TZ/RW) | Name, email, phone, payment amount |
| Safaricom PLC (M-Pesa Daraja) | M-Pesa STK push and B2C disbursements | Phone number, payment amount, transaction reference |
| Stripe, Inc. | International card payments (where Pesapal not available) | Name, email, payment amount, billing address |
| Gupshup | WhatsApp Business messaging | Phone number, message content |
| HostPinnacle | SMS messaging (Kenya) | Phone number, message content |
| Resend | Transactional email delivery | Email address, email content |
| Firebase Cloud Messaging (Google) | Push notifications to mobile devices | Device tokens, notification content |
| OpenAI, OpCo, LLC | WhatsApp customer-support bot, AI-powered offer suggestions | Aggregated business metrics; bot conversation text (no individual customer PII) |
| Anthropic, PBC | AI-powered customer-segmentation and churn-prediction insights | Aggregated and anonymised behavioural metrics (no individual customer PII) |
| Functional Software, Inc. (Sentry) | Error tracking and performance monitoring | User ID, error stack traces, browser / device metadata, request URLs (PII redacted by default) |
| Cloud-hosting providers | Database, cache, file storage, application hosting | All platform data at rest and in transit (encrypted) |
We may also share data: with law enforcement when required by Kenyan law or court order; in connection with a merger, acquisition, or sale of assets (with advance notice to you); and with your explicit consent.
We update this list when we add or remove sub-processors. If we add a new sub-processor that processes Business Owner customer data, we notify Business Owners at least 14 days in advance via email and the platform notice area, so they have an opportunity to object before the change takes effect.
4. Data Controller and Data Processor Roles
Under the Kenya Data Protection Act, 2019:
- For Business Owners: We act as a Data Processor. You (the Business Owner) are the Data Controller for your customers' personal data. We process this data only on your instructions and as necessary to provide the Service.
- For Platform Users: We act as a Data Controller for your account information, payment data, and platform usage data.
Business Owners who require a formal Data Processing Agreement (DPA) may request one by contacting legal@turtlerewards.club.
5. Data Security
We implement appropriate technical and organisational measures to protect your information, including:
- Encryption of data in transit using TLS.
- Password hashing using bcrypt with industry-standard cost factors.
- Role-based access controls with multi-tenant data isolation.
- Regular security audits and vulnerability assessments.
- Fraud detection systems monitoring for anomalous transaction patterns.
- Audit logging of all administrative actions and data access.
While we strive to protect your information, no method of transmission over the internet is 100% secure. In the event of a data breach affecting your personal data, we will notify the ODPC within 72 hours and inform affected users without undue delay, as required by the Kenya Data Protection Act, 2019.
6. Your Rights
Under the Kenya Data Protection Act, 2019 (and GDPR where applicable), you have the following rights:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure: Request deletion of your personal data. We will anonymise your data within 30 days, subject to legal retention requirements.
- Right to data portability: Request a machine-readable export of your data in JSON format.
- Right to object: Object to processing of your data for direct marketing or based on legitimate interests.
- Right to withdraw consent: Withdraw marketing consent at any time through your account settings or by contacting us. Withdrawal does not affect the lawfulness of processing before withdrawal.
How to exercise your rights: You can manage notification preferences and request account deletion through your profile settings. For data export or other requests, contact legal@turtlerewards.club. We will respond within 30 days. You may also lodge a complaint with the Office of the Data Protection Commissioner at www.odpc.go.ke.
6b. Automated Decision-Making and AI Profiling
Some features of the Service use automated processing — including AI models from OpenAI and Anthropic — to analyse customer behaviour and make recommendations. The features that involve automated decisions or profiling are:
- Customer segmentation:we group customers into segments (such as “champions,” “at risk,” or “new”) based on visit frequency, spend history, and engagement. Business Owners use these segments to target campaigns. Segments do not restrict your access to the Service.
- Churn prediction: we score how likely a customer is to stop visiting a Business Owner. Business Owners may use these scores to prioritise win-back offers. Scores do not restrict your access to the Service.
- “Next best offer” suggestions: the platform suggests rewards a customer is likely to redeem. Business Owners decide whether to act on the suggestion.
- Fraud detection: we monitor transactions for patterns indicating fraud (rapid point accumulation, suspicious redemption sequences, duplicate accounts). When the system flags an account, a human reviewer investigates before any restriction is applied to the account.
Your right to human review. Under Article 22 of the GDPR (where it applies to you) and Section 35 of the Kenya Data Protection Act 2019, you have the right not to be subject to a decision based solely on automated processing — including profiling — that produces legal effects or similarly significantly affects you. If a fraud-detection action restricts your account, suspends points, or reverses a redemption, you may request that a human review the decision by contacting legal@turtlerewards.club. We will explain the reason for the action, allow you to provide additional context, and re-evaluate the decision.
We do not use AI to make decisions about loan approvals, insurance, employment, or other matters with binding legal effect on you outside the loyalty platform.
7. Marketing Communications
We will only send you marketing communications if you have given explicit opt-in consent during registration or through your account settings. Marketing messages may be delivered via SMS, WhatsApp, email, or push notification.
You can opt out at any time by: updating your notification preferences in your profile settings; clicking the unsubscribe link in marketing emails; replying STOP to SMS messages; or contacting us at legal@turtlerewards.club. Opting out of marketing does not affect transactional messages (e.g., OTP codes, point balance updates, security alerts).
8. Data Retention
We retain your personal data for as long as necessary to provide the Service and for the periods below:
- Account data: Retained while your account is active. Deleted or anonymised within 30 days of account closure.
- Transaction records: Retained for 7 years after the transaction date to meet tax and regulatory requirements under Kenyan law.
- Message logs: SMS, email, and WhatsApp delivery logs retained for 90 days. WhatsApp bot conversation history retained for 180 days.
- Audit logs: Administrative action logs retained for 3 years.
- Expired tokens: Authentication tokens are automatically purged daily.
Business Owners may configure a custom retention policy for inactive customer data through the compliance settings in their dashboard.
When you request account deletion, we will anonymise your data within 30 days. Residual copies may remain in encrypted backup systems for up to 90 days before being permanently purged.
9. International Data Transfers and Jurisdiction-Specific Rights
Our platform infrastructure is hosted on Railway (United States). Some of our third-party processors (OpenAI, Firebase, Resend) also process data in the United States. Where your personal data is transferred outside Kenya, we ensure appropriate safeguards are in place as required by the Kenya Data Protection Act, 2019, including contractual clauses that require the recipient to maintain equivalent data protection standards.
9.1 European Economic Area, United Kingdom, and Switzerland
Although we do not specifically direct our services at EU/EEA residents, we apply GDPR principles as a matter of best practice. If you are in the EU/EEA or UK, your data is transferred to Kenya and the US under contractual safeguards. You have all the rights listed in Section 6 above, and you may lodge a complaint with your local supervisory authority.
9.2 California, United States (CCPA/CPRA)
If you are a California resident:
- Right to know: You may request disclosure of the categories and specific pieces of personal information we have collected about you.
- Right to delete: You may request deletion of your personal information, subject to certain legal exceptions.
- No sale of data: We do not sell your personal information as defined by the CCPA/CPRA. We do not share your personal information for cross-context behavioral advertising.
- Non-discrimination: We will not discriminate against you for exercising your privacy rights.
To exercise CCPA/CPRA rights, use the data export and account deletion features in your profile settings, or contact legal@turtlerewards.club.
9.3 Other Jurisdictions
If your local data protection law provides rights beyond those listed here, we will honour them to the extent required. Contact legal@turtlerewards.club specifying your jurisdiction.
10. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected information from a person under 18, please contact us immediately at legal@turtlerewards.club and we will take steps to delete such information.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email and by updating the “Last updated” date at the top of this page. For significant changes that affect how we process your data, we will seek your renewed consent where required. Your continued use of the Service after any changes constitutes acceptance of the updated policy.
12. Contact Us
For privacy inquiries, data requests, or to exercise your rights under the Kenya Data Protection Act, 2019, contact us:
Turtle Rewards Limited
Data Processor — ODPC ID: 268-0990-5797
Beach Road Complex, Beach Road, Nyali
Kisauni District, Mombasa County, Kenya
P.O. Box 89026 Mombasa G.P.O.
Email: legal@turtlerewards.club
You may also contact the Office of the Data Protection Commissioner (ODPC) if you believe your data protection rights have been violated: www.odpc.go.ke