Privacy policy
DeniBook (“we,” “us,” or “our”) helps shopkeepers track credit sales, payments, and SMS reminders. This policy describes what personal information we collect, why we collect it, how we protect it, and the choices you have. It applies to the DeniBook app at denibook.com and related services.
1. Information we collect
Depending on how you use DeniBook, we may collect:
- Account information: your name, email address, and/or phone number (used for sign-in with one-time codes).
- Business information: shop name, store location, M-Pesa paybill or till number you choose to save, and business profile details.
- Customer records you enter: customer names, phone numbers, notes, and reminder preferences.
- Transaction records: credit sales, payment amounts and dates, balances, adjustments, and related notes.
- SMS reminder data: reminder message content sent through the service, delivery status, timestamps, and related logs when you use SMS features.
- Team and access data: staff invites, roles, and activity tied to shops you own or join.
- Subscription and billing data: plan type, bundle dates, M-Pesa payment references you submit for Pro/Business plans, and SMS top-up purchases.
- Support messages: information you send through our contact form or support channels.
- Technical and security data: device/browser type, IP address, sign-in and OTP request logs, and similar data needed to secure the service.
- On your device: DeniBook may store a copy of your shop data locally (for example in your browser’s storage) so the app works offline and syncs when you are back online.
You choose what business and customer data to enter. You are responsible for having a lawful basis to collect and use your customers’ information (for example their phone numbers for SMS reminders).
2. Why we collect it
We use personal information to:
- Authenticate you with email or phone one-time passcodes (OTP).
- Provide the app — credit books, dashboards, reports, team access, and settings.
- Sync your data across devices and keep your records up to date when you sign in.
- Send SMS reminders on your behalf to customer phone numbers you provide.
- Process subscriptions and SMS top-ups, and verify M-Pesa payments where applicable.
- Provide customer support and respond to your requests.
- Protect security, prevent fraud and abuse, and enforce our terms.
- Improve reliability through aggregated, non-identifying usage statistics.
3. How data is stored and protected
- Data is transmitted over encrypted connections (HTTPS/TLS) between your device and our servers.
- Cloud data is hosted using Supabase (database and authentication) with access controls and industry-standard protections.
- Access to production data is limited to authorized personnel who need it to operate and support the service.
- We use technical and organizational measures appropriate to the sensitivity of the data, but no method of transmission or storage is 100% secure.
4. Third-party services
We use trusted providers to run DeniBook. They process data only as needed to deliver the service:
- Supabase — authentication, database, and file storage.
- Vercel — application hosting and delivery.
- Resend — transactional email (sign-in codes, contact form, and service notifications).
- Africa’s Talking (or another SMS provider you configure, such as Celcom) — outbound SMS for OTP and payment reminders.
- Meta (Facebook) Pixel — on our marketing pages and sign-up flow only, to measure advertising performance. This does not apply to in-app shop data you enter after sign-in.
We do not use a separate crash-reporting SDK in the production app at this time.
5. Data sharing
We do not sell your personal information.
We may share information only in these situations:
- Service providers listed above, under contracts that require them to protect your data and use it only to operate DeniBook.
- SMS delivery: when you send a reminder, the customer’s phone number and message content are passed to our SMS provider to deliver the text.
- Legal requirements: if required by law, court order, or to protect rights, safety, and security.
- Business transfer: if we are involved in a merger or acquisition, subject to notice where required by law.
6. Data retention
- We keep your account and shop data for as long as your account is active and as needed to provide the service.
- When you delete your account, we remove profile and shop data as described on our account deletion page. Some records (such as payment receipts, SMS delivery logs, or security logs) may be retained for a limited period for legal, accounting, or fraud-prevention reasons, then deleted or anonymized.
- Backup copies may exist for up to 30 days before being purged in the ordinary course of operations.
7. Your rights and choices
Depending on where you live, you may have the right to access, correct, export, or delete your personal data.
- Access and export: view and export your shop data from within the app (Settings → Export).
- Correction: update your profile, business, and customer records in the app.
- Deletion: request account deletion — see denibook.com/delete-account.
- Contact us: email info@denibook.com or use the in-app contact form.
8. Children
DeniBook is intended for adults running a business. It is not directed to children under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
9. International use
DeniBook is operated from Kenya and may process data in countries where our service providers host infrastructure. By using the service, you understand your information may be processed in those locations with appropriate safeguards.
10. Changes to this policy
We may update this policy from time to time. We will post the revised policy on this page and update the “last updated” date below. Continued use of DeniBook after changes means you accept the updated policy.
11. Contact us
DeniBook
Email: info@denibook.com
Website: https://denibook.com
In-app: Contact form