Last updated: 4 August 2026
Privacy Policy
Veira AI ("Veira", "we", "our", or "us") provides point-of-sale and business management software for businesses in Kenya. This Privacy Policy explains what data we collect, how we use it, and your rights under the Kenya Data Protection Act, 2019. Related: Terms of Service · Cancellation.
Who is responsible for what
- Veira is the data controller for your Veira account, billing, and how the platform is run (hosting, security, support).
- Your business is the data controller for customer and staff records you enter in Veira (for example loyalty phones). You decide what to collect and how long to keep it, subject to Kenyan law.
What data we collect
- Account data: name, email, phone, business name, and credentials (or OAuth identifiers from Google or Apple).
- Transaction data: sales, amounts, payment methods, timestamps, and receipt metadata.
- Business data: products, inventory, staff, customers, expenses, and settings you enter in the app.
- Device data: device type, operating system, app version, and diagnostic logs when needed for support.
- Usage data: features used and session activity to improve reliability and security.
- Location: we do not collect precise GPS location for core POS features.
- Payment card data: not stored on Veira servers; card and M-Pesa flows are handled by Paystack or your configured processor.
How we use your data
- To provide the Veira POS service, including offline sync and multi-branch operations.
- To generate KRA eTIMS fiscal receipts where you have enabled compliance (legal requirement when configured).
- To send business summaries via WhatsApp or email when you opt in.
- To improve product performance, security, and support.
We do not sell your personal or business data to advertisers or data brokers.
How we protect data
- Encrypted communications (HTTPS/TLS) for data transmitted between your devices and Veira.
- Sensitive customer contact details are protected when stored; only your authorised staff can access them in the app.
- Payment and integration secrets are protected at rest.
- Access inside your account is role-based (for example owner vs cashier).
- Each business's data is isolated from other businesses; Veira staff use a separate admin process with logging.
Data sharing
- KRA (Kenya Revenue Authority): fiscal data required for eTIMS when you connect your credentials.
- Payment Partners: Payment information is processed by Paystack and any other payment service providers you choose to integrate with. Where payments are made using M-Pesa, the transaction is processed through the applicable payment provider rather than Veira.
- Microsoft Azure: Application hosting and databases are hosted on Microsoft Azure. Data is currently stored in the South Africa North region unless otherwise notified or agreed.
- Messaging: WhatsApp / email providers only when you enable notifications.
- Apple / Google: only when you choose Sign in with Apple or Google (authentication tokens, not ongoing access to your shop data).
Data retention
- Account profile data: while your account is active, plus up to 90 days after a deletion request for recovery/abuse checks.
- Transaction and fiscal records: up to 7 years where required for tax and audit purposes.
- Customer records you store: until you delete them or close your account (subject to fiscal retention rules).
Where deletion is requested, certain information may continue to be retained where required by Kenyan law, including fiscal, tax, and accounting records.
To request export or deletion, use Settings → Delete account (owners), or email [email protected].
International data transfers
Some of your data may be processed or stored outside Kenya. Where this occurs, Veira takes reasonable steps to ensure appropriate safeguards are in place in accordance with applicable data protection laws.
Your rights
Under Kenyan law you may request access, correction, deletion, or portability of your personal data. We will respond within a reasonable period. You may also lodge a complaint with the Office of the Data Protection Commissioner (Kenya).
Cookies
We use essential cookies for authentication and session security. We do not use advertising cookies on the business app.
Security incidents
If we become aware of a personal data breach that risks your rights, we will notify affected businesses without undue delay (aiming for within 72 hours where required). Contact: [email protected].
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Where changes are material, we will notify you through the Veira application, by email, or by updating the "Last updated" date above. Your continued use of the Services after the effective date constitutes acceptance of the updated Privacy Policy.
Contact
Data Controller: Veira AI
Email: [email protected]
Address: Westlands, Nairobi, Kenya