← Back to Tuition Manager

Privacy Policy

Last updated: August 10, 2026

1. Who this applies to

This Privacy Policy explains how TECHZONE MALL LTD("Tuition Manager," "we," "us") collects, uses, and protects personal data through the Tuition Manager platform, in line with Kenya's Data Protection Act, 2019.

TECHZONE MALL LTD is in the process of registering as a data controller/processor with Kenya's Office of the Data Protection Commissioner (ODPC), as required under the Act.

2. A note on children's data

Tuition Manager is used by students who may be under 18. A minor may not create their own account. Instead, an account for a minor is created strictly using the parent or legal guardian's own name, phone number, and email -- never the minor's -- and that parent/guardian registers, manages, and pays for bookings on the minor's behalf. Creating an account for a minor in this way is itself the parent/guardian's informed consent, on the minor's behalf, to the collection and processing described in this Policy, in line with the Act's requirements for processing a child's personal data. If you believe a minor has created an account directly, contact us and we will investigate and remove it.

3. What we collect

  • Identity and contact details: name, phone number, email address, and (for teachers/reviewers) national ID or equivalent identification and qualification documents submitted during verification.
  • Account activity: bookings, classes attended, reviews, messages related to support cases, and payments/commissions.
  • Payment references: M-Pesa transaction references and amounts. We do not collect or store your M-Pesa PIN, and we never see or store full card numbers -- payment happens through M-Pesa directly.
  • Technical data: login timestamps and basic device/browser information, for account security (e.g. detecting suspicious sign-ins).

4. How we use it

  • To create and run your account, match students with teachers, and process bookings and payments.
  • To verify teacher identity and qualifications before they may teach.
  • To send account, booking, payment, and payout notifications by email.
  • To calculate and pay referral commissions to Salespeople, and teacher/reviewer earnings.
  • To investigate support cases, disputes, and policy violations, and to maintain an audit trail of account and payment changes for security and accountability.
  • To meet our legal and tax obligations.

5. Who we share it with

We don't sell personal data. We share it only where necessary to run the Service:

  • Safaricom/M-Pesa -- to process your payment. We receive a payment reference and status back, not your PIN.
  • Brevo -- our email delivery provider, used to send account and transaction emails (verification codes, booking confirmations, receipts, payout notices). Brevo processes the recipient address and message content needed to deliver that email.
  • Teachers and reviewers -- see the information about a booking needed to teach or assess that class (e.g. a student's name and the class details), not a student's payment or verification documents.
  • Verifiers/administrators -- teacher verification documents are visible only to verification staff and the teacher who submitted them, never publicly.
  • Law enforcement or regulators, where legally required.

6. How long we keep it

We keep account and transaction data for as long as your account is active, and for a further period afterward as needed for tax, audit, and legal record-keeping obligations (financial and audit records are generally kept longer than other account data, since Kenyan tax law requires this). Teacher verification documents are retained only for as long as needed for verification and compliance purposes.

7. Your rights

Under the Data Protection Act, 2019, you can:

  • Ask what personal data we hold about you, and get a copy of it.
  • Ask us to correct inaccurate data.
  • Ask us to delete data we no longer have a legal basis to keep (we may be required to retain some financial/audit records regardless -- see Section 6).
  • Object to certain processing, and withdraw consent where consent is the basis for processing.
  • Lodge a complaint with the Office of the Data Protection Commissioner (ODPC) if you believe we've mishandled your data.

To exercise any of these, contact us at the email in Section 9.

8. Security

Passwords are never stored in plain text. Sensitive fields such as meeting access links are encrypted at rest. Access to teacher verification documents and payment/payout data is restricted by role, and material account and financial changes are logged in an internal audit trail. No system is perfectly secure, but we take reasonable technical and organizational measures to protect your data.

9. Contact

Questions about this Policy, or to exercise your rights above: tzdigitalstores@gmail.com.

10. Changes to this Policy

We may update this Policy from time to time. We'll update the date at the top of this page when we do.