Privacy policy
Last updated: 12 August 2026
This policy explains what StokiTrack collects when you use our software, why we collect it, and what you can ask us to do with it. It is written to be read, not to be impressive. If anything here is unclear, email stokitrack@gmail.com and we will explain it plainly.
Who we are
StokiTrack Limited (StokiTrack) is the data controller for the information described here. We are based in Nairobi, Kenya.
What we collect
We collect three kinds of information.
1. Account information
- Your name, email address and phone number
- Your shop's name, business type and county
- A securely hashed version of your password, never the password itself
2. Business records you create
- Products, prices, stock levels and stock movements
- Sales, receipts and payment methods
- Staff shifts, including clock-in times and, if you allow it, location
- Questions you ask Stoki and the answers it gives
3. Payment information
When you pay by M-Pesa we store the transaction reference, the amount, the phone number charged and Safaricom's receipt number. We never see or store your M-Pesa PIN. You enter it on your own phone, directly with Safaricom.
What we do with it
- Run the service: track your stock, record your sales, manage shifts
- Take subscription payments and keep a record of them
- Let Stoki answer questions about your own shop
- Support you when something goes wrong
- Keep the service secure and detect abuse
We do not sell your business information to anyone. We do not share your sales figures with suppliers, competitors, or data brokers.
Stoki and your data
Stoki answers using your shop's own records. When you ask a question, the relevant figures are sent to our AI provider (Google, via the Gemini API) to generate the answer. We currently use Google's no-cost API tier, under which Google may review that data and use it to improve their products, including possible use in future model training. Stoki itself can only ever read the shop you are signed in to. Its access is restricted at the database level, not merely hidden in the interface.
Who else sees it
- Safaricom, to process M-Pesa payments
- Google (Gemini API), to generate Stoki's answers; see above
- Our hosting provider, to run the servers and database
- Google Analytics: anonymised usage statistics for our marketing pages, with IP anonymisation on
We may also disclose information where the law requires it, for example a lawful order from a Kenyan court or the Kenya Revenue Authority.
How long we keep it
Your business records are kept for as long as your account is active. If your subscription lapses, we keep the data so you can come back to it or export it. Ask us to delete your account and we will erase your data within 30 days, except records we are legally required to keep, such as tax records.
Your rights under the Data Protection Act, 2019
Kenyan law gives you the right to:
- Be told what data we hold about you
- Get a copy of it
- Correct anything that is wrong
- Ask us to delete it
- Object to how we use it
- Complain to the Office of the Data Protection Commissioner
To exercise any of these, email stokitrack@gmail.com. We respond within 30 days.
Keeping it safe
Passwords are hashed, connections are encrypted, and each shop's records are isolated at the database level so one business can never read another's. This is enforced by the database itself rather than by application code alone. No system is perfect; if a breach affects you, we will tell you and the Data Protection Commissioner as the law requires.
Cookies
We use a cookie to keep you signed in. The app cannot work without it. Our marketing pages use Google Analytics to count visits, with IP anonymisation enabled. We do not use advertising trackers.
Children
StokiTrack is for businesses. We do not knowingly collect information from anyone under 18.
Changes to this policy
If we change anything significant we will tell account holders by email. The date at the top always shows the current version.
Contact
Questions, requests or complaints: stokitrack@gmail.com or +254745831687.