Kanyapong Family Welfare
Privacy policy
Effective 22 August 2026
This policy explains how Kanyapong Family Welfare handles personal information in the Kanyapong Family Welfare Android app and at kanyapong.online. The welfare is the data controller for information recorded in the service.
Information we collect
We collect information needed to operate the welfare: names, contact details, location, date or year of birth, gender, membership and family relationships, profile photographs, account and security records, notification tokens, contribution obligations, payment and receipt references, welfare activities, claims, approvals, and documents a user chooses to provide. Security records include the IP address and device or browser description used for sign-in and other protected actions.
The Android app can let a user choose or take a profile photograph. It does not request broad access to the device photo library. Push notification permission is used only to deliver welfare notices and account-related updates.
If fingerprint or face sign-in is enabled, the device performs the biometric check. The welfare does not receive or store biometric templates. The saved sign-in credential is protected by Android secure storage on that device.
How we use information
Information is used to verify and secure accounts, maintain the member and family register, administer contributions and welfare activities, record payments, issue receipts, assess eligibility, process claims, communicate with members, prevent fraud, resolve disputes, maintain an audit trail, and meet applicable legal obligations.
We do not sell personal information and the app does not contain advertising.
Service providers and sharing
Data is shared only when needed with authorized welfare officials and providers that operate hosting, database, file storage, email, push notifications, authentication, and payment processing. Payment details may be exchanged with Safaricom M-Pesa to initiate or reconcile a payment. Providers may process data only for the service they supply.
We may disclose information when required by law, to protect members or the service, or to investigate fraud or misuse.
Security and retention
The service uses encrypted network connections, access controls, session protection, audit logging, and restricted administrative permissions. No system can guarantee absolute security, but access is limited to what each role needs.
Active account data is kept while membership or service use continues. When an account deletion request is completed, login access, sessions, notification tokens, and data not needed for an ongoing purpose are deleted or anonymized. Financial, payment, governance, fraud-prevention, dispute, and audit records may be retained where necessary for legal, accounting, security, or legitimate record-keeping obligations. Retained records are restricted and removed or anonymized when that need ends.
Your choices and rights
You can review and update contact details in the app. You can disable notifications in Android settings and remove locally saved biometric sign-in from the app settings. You may ask to access, correct, or delete personal information, subject to records that must be retained for the reasons described above.
To request account and data deletion, use the account deletion page.
Contact
Questions and privacy requests can be sent to maildon254@gmail.com.