Privacy Policy

Version: V1.0

Effective Date: March 24, 2026

Dear User (hereinafter referred to as “Customer”, “User”, or “You”), we fully recognize the importance of your personal information and appreciate your trust in us. L Pesa is the official loan service application owned and operated by LOAN PLUS DIGITAL CREDIT PROVIDER LIMITED (hereinafter referred to as “we”, “L Pesa”, or the “Platform”). We take the protection of your privacy and the confidentiality of your personal information very seriously. In accordance with the Kenya Data Protection Act, 2019, the General Data Protection Regulation (GDPR), the App Review Guidelines, and other relevant laws, regulations, and supervisory policies, we have formulated this “L Pesa Privacy Policy” (hereinafter referred to as “this Policy” or “this Privacy Policy”). This Policy explains how L Pesa collects, stores, protects, uses, and discloses your information, as well as outlines your rights.

Please read this Policy carefully before use. By starting to use L Pesa, you acknowledge that you have understood and agree to the contents of this Policy.

Relevant device permissions are not enabled by default. For important permissions, we will seek your explicit consent again via a separate pop-up window when you access the corresponding business function. After a permission is granted, you can disable it at any time through your device settings. Your refusal to grant a permission will not affect the normal use of other unrelated business functions.

This Privacy Policy will help you understand the following:

1.What Information We Collect and Why

2.How We Use Your Information

3.We Share and Disclose Your Information

4.Data Security and Storage

5.Your Data Rights

6.Cookies and Tracking Technologies

7.Children’s Privacy

8.Policy Updates

9.How to Contact Us

1.What Information We Collect and Why

1.1 Information You Provide Directly

  • Registration and Identity Verification: Your Kenyan mobile phone number, used to create your account and for login verification.
  • Loan Application and Credit Assessment: Your name, national ID, date of birth, gender, marital status, education level, employment status, monthly income, address, phone number, email address, and emergency contacts. This information is used to verify your identity, assess your creditworthiness, and determine suitable loan amounts and terms for you. This is a core requirement for providing our services.
  • Payment Information: Your bank account or mobile money wallet details, used to disburse loans and collect repayments.
  • Emergency Contacts: The names and phone numbers of two emergency contacts you provide. You must obtain their consent in advance. We will only attempt to contact them if we are unable to reach you and it involves important account security or debt-related matters, and we will not disclose specific details of your loan.
  • Customer Service and Dispute Resolution Data: When you contact us or raise a dispute, we need to collect and process information necessary to address your matter, verify your identity, and respond to you. In accordance with Kenyan regulations, customer support records are retained for 30 days before deletion.

1.2 Information We Collect Automatically

Device and Log Information: Your device model, operating system version, unique identifiers, location information, and usage logs. This is used to safeguard account security, prevent fraud, and diagnose technical issues.

1.3 Information Obtained from Third Parties

Credit Reference Bureau (CRB): With your authorization, we will query your credit report from a licensed Kenyan CRB to assess your credit history.

Anti-Fraud Service Providers: To enhance security, we may obtain risk indicator information from partners to assist in identity verification and fraud prevention.

1.4 Device Permissions (We only request when necessary)

We will separately seek your consent and explain the purpose when first requesting a device permission. You can also check and manage the status of each permission via your device’s “Settings” > “Permission management”. Granting a permission represents your authorization for us to collect and use the corresponding personal information. Disabling a permission revokes that authorization; we will no longer collect such information and the related service or function will become unavailable. However, disabling a permission does not affect information processing activities previously conducted based on your authorization. For functions requiring specific permissions, we will re-seek your consent via an in-app prompt. If you agree, we will obtain the permission and provide the service; if you refuse, we will be unable to offer that specific service.

Location Information (Approximate Location)

  • Purpose of Use: To confirm you are logging in from within Kenya and to assist in anti-fraud and geographic risk assessment.
  • Data Collected: The device’s approximate geographic location information (city-level latitude and longitude).
  • Usage Scenario: Permission is requested when you log into your account or submit a loan application. It is only accessed while the app is in use.
  • Data Protection: Location information is encrypted via the HTTPS protocol, transmitted, and stored on our secure servers (https://lpesaios.loanplus.co.ke/). We will never share such data with third parties without your explicit consent.

Camera Permission

  • Purpose of Use: To photograph your ID document and perform real-time liveness detection (selfie) to complete the legally required Know Your Customer (KYC) process and prevent fraud.
  • Data Collected: Photograph(s) of your ID document and real-time facial image frames for liveness detection.
  • Usage Scenario: Called only when you actively enter the identity verification process and click the “Take ID Photo” or “Perform Liveness Check” button.
  • Data Protection: All image data is encrypted via the HTTPS protocol, transmitted, and stored on our secure servers (https://lpesaios.loanplus.co.ke/). Original biometric images are used solely for real-time verification and are not stored as templates long-term. ID photos are encrypted and retained for the period required by law. We will never share such data with third parties without your explicit consent.

Photo Album

  • Purpose of Use: To allow you to select and upload a pre-saved ID photo from your phone’s gallery for identity verification, or to voluntarily upload images related to a customer service inquiry to help resolve issues.
  • Data Collected: Only the specific one or few images you manually select and confirm for upload. We do not scan or access your entire photo gallery.
  • Usage Scenario: Called when you choose “Upload from Gallery” during identity verification or click “Upload Image” in a customer service chat window.
  • Data Protection: Uploaded images are encrypted via the HTTPS protocol, transmitted, and stored on our secure servers (https://lpesaios.loanplus.co.ke/). They are stored and regularly purged according to their purpose (e.g., identity verification or customer service records). We will never share such data with third parties without your explicit consent.

Emergency Contacts (Access to Contacts)

  • Purpose of Use: For fraud prevention, account security verification, or as part of final collection efforts. Contact is attempted only if we are unable to reach you for an extended period concerning debt matters.
  • Data Collected: Only the names, phone numbers, and relationship to you of the 2 specific contacts you manually select. We do not upload, read, or store your entire contact list.
  • Usage Scenario: Called only on the loan application form when you click “Select from Contacts” for emergency contacts. You must ensure you have obtained the contact’s consent before providing their information to us.
  • Data Protection: Selected contact information is encrypted via the HTTPS protocol, transmitted, and stored on our secure servers (https://lpesaios.loanplus.co.ke/). It is stored solely as the emergency contact data you provided, subject to equivalent security protections. We will never share such data with third parties without your explicit consent.

Device Information

  • Purpose of Use: To generate device security identifiers and for risk analysis, safeguarding your account security, preventing fraud, and resolving technical issues.
  • Data Collected: Includes device name, model, IMEI, IMSI, MAC address, serial number, hardware/software specifications, IP address, operational status, and usage patterns. We do not access sensitive identifiers restricted by iOS.
  • Usage Scenario: Collected automatically when you install, launch the app, or perform key transactions (e.g., login, submit loan application, repayment).
  • Data Protection: This information is processed using de-identification techniques, encrypted via the HTTPS protocol, transmitted, and stored on our secure servers (https://lpesaios.loanplus.co.ke/). We will never share such data with third parties without your explicit consent.

Usage Tracking

  • Purpose of Use: To analyze application performance, troubleshoot crashes, and understand feature usage to improve the product experience.
  • Data Collected: Anonymous interaction events (e.g., page views, button clicks), performance data (e.g., loading times), and error reports (e.g., crash logs). This data does not contain your personally identifiable information.
  • Usage Scenario: Collected automatically during your use of the app.
  • Data Protection: All data is anonymized before collection. It is encrypted via the HTTPS protocol, transmitted, and stored on our secure servers (https://lpesaios.loanplus.co.ke/). We will never share such data with third parties without your explicit consent.

2.How We Use Your Information

We use your information primarily for the following core purposes:

  • Credit Assessment and Loan Provision: To analyze your application and financial information, calculate credit scores, make responsible lending decisions, and manage your account.
  • Verification and Fund Disbursement: To verify your identity and payment account information, ensuring the secure disbursement of funds.
  • Security and Anti-Fraud: To detect and prevent fraudulent activities, protecting your account from unauthorized access.
  • Service Optimization: To analyze anonymized usage data (e.g., feature clicks, performance errors) to fix issues and improve app stability and user experience.
  • Legal and Regulatory Compliance: To fulfill statutory obligations such as anti-money laundering and KYC (Know Your Customer), and to respond to lawful requests from regulatory authorities.
  • Communication with You: T o contact you regarding important matters such as loan status and service updates.

3.How We Share and Disclose Your Information

We are committed to maintaining the confidentiality of your personal information in accordance with relevant laws, regulations, and supervisory provisions. We do not share your personal information with any company, organization, or individual, except in the following circumstances:

  • With your prior explicit authorization or consent.
  • Service Providers: With partners who provide us with services such as cloud storage, payment processing, identity verification, and SMS delivery. They must protect your data strictly in accordance with our contracts.
  • Credit Reference Bureau (CRB): As required by law, we report your loan application record and performance (including any default information) to CRBs, which may affect your future credit score.
  • Legal Requirements: When disclosure is necessary to comply with laws, regulations, court orders, or government demands.

We only share your personal information for lawful, legitimate, necessary, specific, and explicit purposes, and we only share the personal information necessary to provide the service. We do not sell your personal data. In the event of a merger, acquisition, asset sale, or bankruptcy, we will notify you and ensure the recipient is committed to protecting your information in a manner consistent with this Policy.

4.Data Security and Storage

  • Security Measures: We implement industry-recognized administrative, technical, and physical safeguards designed to protect your data from unauthorized access, disclosure, alteration, or destruction. These measures include, but are not limited to: encrypting data in transit using SSL/TLS (HTTPS); applying strong encryption to data at rest (stored on our secure servers); enforcing strict role-based access controls; and conducting regular security vulnerability scans and penetration tests.
  • Data Storage: The personal data we collect is primarily stored on L Pesa servers (https://lpesaios.loanplus.co.ke/). In limited circumstances, to provide global support or use specific international service providers, data may be transferred outside Kenya. In such cases, we will ensure adequate protection through legal mechanisms such as Standard Contractual Clauses (SCCs).
  • Data Retention: We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Policy, or as required to comply with legal obligations (e.g., Kenyan tax law requires retaining financial records for up to 7 years), resolve disputes, or enforce our agreements. Data for inactive accounts will be securely anonymized or deleted after the minimum period required by law. User account information will be anonymized or securely deleted within a reasonable period after you actively close your account, following necessary legal and compliance reviews. Customer service communication records are typically retained for 30 days for review after your issue is resolved, after which they are deleted.
  • Security Incident Response: Despite our measures, in the unfortunate event of a personal information security incident, we will immediately activate our contingency plan to contain the impact. If the incident poses a high risk to your rights and freedoms, we will, in accordance with the Kenya Data Protection Act, 2019, promptly notify you via your primary contact method on file (SMS or in-app notification). We will inform you of the nature of the incident, its potential impact, the measures we have taken, and recommendations for steps you can take to protect yourself. We will also report serious security incidents to the Office of the Data Protection Commissioner (ODPC) as required by law.

5.Your Data Rights

In accordance with the Kenya Data Protection Act, 2019, you have the following rights:

  • Right to be Informed: To know how we process your data.
  • Right of Access: To access your personal information and request a copy of the personal data we hold about you.
  • Right to Rectification: To request correction of inaccurate or incomplete personal data.
  • Right to Erasure: To request deletion of your personal data, especially when it is no longer necessary or you withdraw your consent.You can submit a deletion request via the online customer service feature in the L Pesa app, by email to privacy@L Pesa.co.ke, or by calling our customer service hotline (+254 207 905 952).
  • Right to Object to Processing: To object to data processing based on legitimate interests or for direct marketing.
  • Right to Restriction of Processing: To request restriction of processing your data under specific circumstances.
  • Right to Data Portability: T o receive your data, which you provided to us, in a structured, commonly used, and machine-readable format.
  • Right to Withdraw Consent: To withdraw your consent to personal information processing or permission authorization at any time.
  • Right to Close Account: You can log into the L Pesa App, navigate to 【My】->【Account & Security】, find the “Delete Account” option and follow the instructions. Alternatively, submit a closure request via the customer service email privacy@L Pesa.co.ke or by calling our customer service hotline (+254 207 905 952).
  • Important Reminder: Before closing your account, please ensure all loans and related fees have been settled. After account closure, we will stop collecting your information, but information retained based on legal and regulatory requirements will continue to be stored.

We will respond to your request to exercise these rights within 30 days of receipt. To ensure security, we may need to verify your identity before processing your request.

6.Cookies and Tracking Technologies

Our official website may use cookies to improve your browsing experience and analyze traffic. You can manage cookie preferences through your browser settings. Third-party tracking is subject to their respective privacy policies.

7.Children’s Privacy

Our services are strictly for Kenyan residents aged 18 years and above. We do not knowingly collect information from minors. If we become aware of such collection, we will promptly delete the relevant data.

8.Policy Updates

To provide you with better service and due to business development needs, we reserve the right to update this Policy from time to time. We may update this Policy periodically. In the event of material changes, we will notify you via an in-app push notification or a notice on our website. If you disagree with the modifications made by L Pesa to this Privacy Policy, you have the right to immediately stop using the related products and services provided by L Pesa. Your continued use of our services after the updated Policy takes effect constitutes your acceptance of the revised Privacy Policy.

9.How to Contact Us

If you have any questions, requests, or complaints regarding this Policy or your personal information, please contact us through the following channels:

Dedicated Data Protection Email: privacy@L Pesa.co.ke

Customer Service Hotline: +254 207 905 952

If you are dissatisfied with our response, you have the right to lodge a complaint directly with the Office of the Data Protection Commissioner (ODPC) of Kenya.