1. Scope and our role
This policy applies to Connect Mobile's website, purchase journeys and related support channels. It should be read with any privacy notice shown during an application.
Connect Mobile acts as a data controller for personal data where we decide why and how it is processed. A merchant or other service provider may separately act as a controller for its own services or legal duties and should provide its own privacy information.
2. Data-protection principles
We aim to process personal data lawfully, fairly and transparently in line with Kenya's Data Protection Act, 2019 and other applicable requirements.
- Collect data for specific and legitimate purposes.
- Use only data that is adequate, relevant and reasonably necessary.
- Take reasonable steps to keep data accurate and current.
- Retain data only for as long as it is needed or legally required.
- Protect confidentiality, integrity and availability through appropriate safeguards.
- Remain accountable for how personal data is handled.
3. Personal data we may collect
The information collected depends on how you use the service and the purchase plan you choose.
- Identity data, such as name, date of birth, photograph and national ID or passport details.
- Contact and profile data, including phone number, email address, physical address and preferred language.
- Application and payment data, such as income information, mobile-money or bank records, affordability information and instalment activity.
- Device and technical data, including IP address, browser, cookies, device identifiers, IMEI, serial number, SIM information and device-management status where applicable.
- Transaction data, including selected devices, deposits, payment references, instalment status and merchant information.
- Communications, complaints, consent records and customer-support history.
- Fraud-prevention, identity-verification and other legally permitted assessment information.
4. How we collect data
We may collect data directly from you when you browse, complete a form, submit an application, make a payment or contact support. With an appropriate legal basis, data may also come from merchants, payment providers, identity-verification services, fraud-prevention services, publicly available records or your device.
Where access to device, payment or third-party information requires consent or another specific authorization, the relevant request will explain what is needed before access occurs.
5. Why we use personal data
We process personal data only where we have a lawful basis, including performance of a contract, steps requested before a contract, compliance with law, legitimate interests that do not override your rights, or consent where required.
- Display and administer device-ownership and purchase journeys.
- Verify identity and assess eligibility and affordability.
- Create and manage accounts, orders, devices, instalments and customer support.
- Prevent, detect and investigate fraud, misuse, security incidents and financial crime.
- Manage and release devices where device-management terms apply.
- Meet accounting, reporting, regulatory and legal obligations.
- Improve service reliability, accessibility and customer experience.
- Send service messages and, with the required choice or consent, relevant marketing.
6. Automated assessment
Automated tools or profiling may support identity, fraud, eligibility or affordability assessments. Where a decision produces a significant legal or similar effect, you may have a right under applicable law to information about the decision and to request human review. The notice presented during the application should explain the available review process.
7. Who may receive data
We do not sell personal data. We may share it only where reasonably necessary, lawful and protected by appropriate arrangements.
- The merchant supplying the selected device.
- Payment, identity-verification, communications, cloud, security and device-management providers.
- Authorized verification, reporting or recovery providers where lawful.
- Professional advisers, auditors, insurers and potential successors to a service, subject to confidentiality.
- Courts, regulators, law enforcement or public authorities where disclosure is legally required or permitted.
8. International transfers
If personal data is processed outside Kenya, we will take steps required by applicable law to ensure an appropriate level of protection. These may include adequacy safeguards, contractual protections, consent where appropriate, and controls over access and onward transfer.
9. Retention
We retain personal data for only as long as reasonably necessary for the purpose collected, the purchase relationship, dispute resolution, fraud prevention and legal, tax, accounting or regulatory duties. Retention periods differ by record type. When data is no longer required, it will be securely deleted, anonymized or placed beyond use.
10. Security
We use proportionate technical and organizational measures designed to prevent accidental loss, unauthorized access, alteration or disclosure. Measures may include access controls, encryption, logging, staff confidentiality, supplier review and incident-response procedures. No internet service can guarantee absolute security, so protect your credentials and never share passwords, PINs or one-time codes.
11. Your data-protection rights
Subject to applicable law and limited exceptions, you may have the right to be informed; access your personal data; request correction or deletion; object to or restrict processing; receive portable data; withdraw consent; and request review of certain automated decisions.
You may also complain to Kenya's Office of the Data Protection Commissioner. We encourage you to contact us first so we can investigate and respond. We may verify your identity before fulfilling a request and will not ask for information beyond what is reasonably needed.
12. Cookies and website data
We may use essential cookies or similar technologies needed for security, preferences and website operation. If optional analytics or advertising technologies are introduced, we will provide appropriate information and choices before using them where required.
13. Children
Connect Mobile's purchase services are not directed to children, and applicants must meet the minimum legal age stated for the relevant plan. If we learn that children's data was collected without a lawful basis or required authorization, we will take appropriate steps to remove or protect it.
14. Changes and contact
We may update this policy when our services, partners or legal obligations change. The current version and effective date will remain available on this page.
To ask a privacy question or exercise a data-protection right, email support@connectmobile.co.ke or use the Contact Us page. Include ‘Privacy request’ in the subject line and do not email passwords, PINs or one-time codes.
Last updated: 9 August 2026