Skip to content
GistCrypt
Legal

Privacy policy

Effective 27 Sep 2026

Template — to be reviewed by a qualified lawyer before launch. Edit in Admin → Pages.

Who we are

GistCrypt ("we") operates gistcrypt.com and related services. We act as a data controller for information collected on this website.

Information we collect

  • Details you give us: name, email, phone, company, country, and messages you send through forms.
  • Account and order information: purchases, invoices, subscriptions and support requests.
  • Payment metadata: transaction references, amounts and status. We never receive or store card numbers, CVV codes, PINs or payment passwords — payments are processed by licensed payment providers.
  • Usage information: pages viewed and actions taken, recorded only with your consent where required.

How we use it

To respond to enquiries, provide products and services, process orders and payments, send transactional emails, improve the website and — with your consent — send marketing.

Legal bases

Contract, legitimate interests, legal obligations and consent, in line with the Kenya Data Protection Act, 2019 and, where applicable, the EU/UK GDPR.

Sharing

With payment providers, email and hosting providers acting on our instructions, and authorities where the law requires. We do not sell personal data.

International transfers

Where data leaves Kenya we apply appropriate safeguards.

Retention

We keep data only as long as necessary for the purposes above and for statutory record-keeping.

Your rights

Access, correction, deletion, objection, restriction, portability and withdrawal of consent. Contact us to exercise them. You may also complain to the Office of the Data Protection Commissioner (Kenya).

Security

Encryption in transit, access control, audit logging and regular backups.

Contact

See the contact page.