PamojaHub

Privacy Policy

Last updated: August 2026

1. Introduction

This Privacy Policy explains how PamojaHub, operated by Martin M Mutua ( "PamojaHub", "we", "us", or "our"), collects, uses, stores, and protects personal information when you use the PamojaHub website and services.

PamojaHub is cloud-based management software for Kenyan community groups such as Chamas, SACCOs, welfare groups, investment circles, and similar organizations. We help groups keep records of contributions, loans, payments, meetings, members, and shares.

Important: PamojaHub is management software, not a bank or payment processor. We do not hold group funds or store raw payment-card data.

2. Scope

This policy applies to:

  • Visitors to our website at https://www.pamojahub.com.
  • People who register for a PamojaHub account.
  • Group administrators and members who use PamojaHub to manage group records.
  • Anyone who contacts our support team.

This policy does not apply to third-party websites or services that we link to, such as Paystack's hosted checkout pages.

3. Who Operates PamojaHub

Operator: Martin M Mutua
Business contact address:
2609 FeatherStone Rd
Oklahoma City, OK 73120
United States
Website: https://www.pamojahub.com
Support and privacy email: support@pamojahub.com

PamojaHub is not registered as a separate legal entity (such as a corporation or LLC). The service is operated by Martin M Mutua as an individual business.

4. Information We Collect

4.1 Account information

When you create an account, we collect:

  • Full name
  • Email address
  • Password (handled by Supabase Auth; we do not store plaintext passwords)
  • Selected subscription plan
  • Optional profile information you choose to add, such as phone number, county, city, avatar, preferred language, preferred currency, and timezone

4.2 Authentication and security data

We use Supabase Auth for authentication. This includes:

  • User ID
  • Email verification status
  • Multi-factor authentication status (if you enable it)
  • Last sign-in time (as provided by Supabase Auth)

4.3 Group and membership information

Group administrators may create records that include personal information about group members, such as:

  • Names and contact details from the member's PamojaHub profile
  • Group role and membership status
  • Attendance records
  • Voting records (yes/no/abstain)
  • Financial records such as contributions, loans, repayments, and share transactions

Group administrators are responsible for ensuring they have the right to enter this information and for informing their members how the group uses PamojaHub.

4.4 Financial recordkeeping data

PamojaHub stores records of group financial activity entered by authorized users, including:

  • Contribution plans and obligations
  • Payment records and references
  • Loan applications, approvals, schedules, and repayments
  • Share purchases, transfers, and redemptions
  • Transaction references

We do not store raw payment-card numbers, CVV codes, bank passwords, or M-Pesa PINs. Subscription payments are handled by Paystack's hosted checkout.

4.5 Subscription and billing data

We store:

  • Selected plan and subscription status
  • Billing contact information
  • Paystack transaction references and payment status
  • Coupon redemptions and trial history

4.6 Support data

When you contact support, we collect:

  • Ticket subject, category, priority, and message history
  • Support attachments you upload
  • Your user ID so we can respond

4.7 Audit and security logs

We log certain actions for security and accountability, such as:

  • Membership changes
  • Role changes
  • Financial record changes
  • Group setting changes
  • Platform admin actions

These logs include the actor, affected entity, event type, timestamp, and limited metadata. We do not log IP addresses, device identifiers, or detailed browsing history.

4.8 Analytics and technical data

We use Vercel Analytics and Vercel Speed Insights to understand website performance and usage in aggregate. These services may collect page URLs, performance metrics, and browser type/device category in aggregate form.

We do not use advertising cookies, advertising pixels, or behavioral-tracking tools such as Meta Pixel or Google Analytics.

Our site may also receive performance data through Cloudflare if our site is served through Cloudflare's proxy. Please refer to Cloudflare's privacy policy for details.

5. Information Group Administrators Provide About Members

PamojaHub groups may include personal information about people who do not have their own PamojaHub accounts, or whose accounts are managed through a group invitation.

When a group administrator enters a member's email address or phone number to send an invitation, or records financial or governance information about a member, the administrator (and the group or organization they represent) is responsible for:

  • Having a lawful basis to collect and enter that information
  • Informing members that the group uses PamojaHub
  • Responding to member questions and requests about that data

For some purposes, PamojaHub may act as a service provider or processor for the group with respect to member data, while for other purposes (such as account management, security, and billing) PamojaHub acts as a controller. This is a legal characterization that should be confirmed with counsel.

6. Financial Recordkeeping Information

PamojaHub records financial activity that authorized group users enter. This includes contributions, loans, repayments, share transactions, and related balances.

PamojaHub does not hold group funds, manage group bank accounts, or move money between members. Real-world transfers happen outside the software. The accuracy of records depends on the users who enter them.

7. Governance Information

PamojaHub records group governance activity entered by authorized users, including meetings, attendance, resolutions, and votes.

8. Subscription and Payment Information

We store subscription plan selections, subscription status, renewal dates, Paystack transaction references, and payment status. We do not store raw card numbers or CVV.

9. Pamoja AI

PamojaHub includes an optional AI assistant feature powered by Groq.

What Pamoja AI does:

  • Reads authorized group data already calculated by PamojaHub
  • Explains that data in plain language, such as summarizing financial position or loan status
  • Respects role-based access controls, so users only see information they are allowed to see

What Pamoja AI does not do:

  • Change records or execute transactions
  • Approve loans or make financial decisions
  • Store your questions or responses
  • Replace group officers, bylaws, or professional advice

When you use Pamoja AI, your question and selected capability are sent to our server. The server builds a context from data you are authorized to access and sends it to Groq for processing. Prompts and responses are not persisted in PamojaHub's database.

Groq's own privacy and data practices apply to information processed by their service. We encourage you to review Groq's privacy policy.

10. Analytics and Technical Information

We use cookies and similar technologies that are necessary for the service to function, including authentication cookies managed by Supabase. We do not use advertising or behavioral-tracking cookies.

We use Vercel Analytics and Vercel Speed Insights to collect aggregate performance and usage data. These services do not identify you personally.

We use browser local storage for non-essential preferences such as sidebar state, dashboard widget visibility, onboarding dismissal, and theme preference. This data stays on your device.

11. How We Use Information

We use personal information to:

  • Provide and maintain the PamojaHub service
  • Authenticate users and protect accounts
  • Process subscription payments through Paystack
  • Enable group administrators to manage group records
  • Send transactional emails, such as invitations, payment confirmations, and support updates
  • Send occasional promotional emails about subscription coupons or features (you may opt out of promotional emails by using the unsubscribe link in those emails or by contacting us)
  • Maintain security, prevent fraud, and investigate misuse
  • Generate aggregate analytics to improve performance
  • Comply with legal obligations and enforce our Terms of Service

12. Legal Bases for Processing in Kenya

Under the Kenya Data Protection Act, 2019, we rely on the following lawful bases where applicable:

  • Performance of a contract: Processing necessary to provide your account and the services you subscribe to.
  • Legitimate interests: Security, fraud prevention, service improvement, and maintaining reliable group records.
  • Consent: Where required, such as accepting our Terms of Service and Privacy Policy during registration, or enabling optional features.
  • Legal obligation: Where we are required to retain or disclose information by applicable law.

The specific lawful basis for group-member data entered by administrators should be determined by the group or organization, because the group determines the purpose of that data.

13. How We Share Information

We do not sell personal information.

We share personal information only in the following circumstances:

  • With service providers: We use trusted third-party services to host, secure, analyze, email, process payments, and provide AI inference. These providers process data only to perform services on our behalf.
  • With group administrators: If you are a member of a group, the group's authorized administrators and officers can see the data they need to manage group records.
  • For legal reasons: We may disclose information if required by law, court order, or government request, or to protect our rights, users, or the public.
  • With your consent: When you explicitly ask us to share information.

14. Service Providers

Our current service providers include:

  • Supabase — authentication, database, file storage (may process data outside Kenya)
  • Vercel — hosting, analytics, speed insights (may process data outside Kenya)
  • Paystack — payment processing (may process data outside Kenya)
  • Resend — transactional and promotional email (may process data outside Kenya)
  • Groq — AI inference for Pamoja AI (may process data outside Kenya)

We select providers that offer appropriate technical and organizational safeguards, but we cannot guarantee that any third party's data practices will be identical to ours. We encourage you to review the privacy policies of these providers.

15. No Sale of Personal Information

PamojaHub does not sell personal information to third parties. We also do not share personal information for cross-context behavioral advertising.

16. Advertising / Behavioral Tracking

We do not use advertising pixels, retargeting, or behavioral-tracking services. We do not participate in cross-context behavioral advertising.

17. Data Retention

We retain personal information for as long as necessary to:

  • Provide the PamojaHub service
  • Fulfill the purposes described in this policy
  • Comply with legal obligations
  • Resolve disputes and enforce agreements
  • Maintain financial, governance, and audit records

When information is no longer needed for these purposes, we delete or anonymize it where possible. Some information may be retained in anonymized form for historical, statistical, or legal reasons. We do not make specific claims about backup purge schedules because those schedules depend on our hosting provider's practices.

18. Account Deletion and Historical Records

You may request deletion of your PamojaHub account. When we process a deletion request:

  • We deactivate your account and remove your access
  • We anonymize your profile information, replacing identifying details such as name, email, and phone with anonymized values
  • We set your group and organization memberships to removed status
  • We do not delete every historical record you contributed to, because groups rely on financial, governance, and audit history for accountability, dispute resolution, and legal compliance

These retained historical records may reference a preserved internal user identifier, but they will no longer identify you by name, email, or other personal details.

19. Security

We take reasonable measures to protect personal information, including:

  • HTTPS/TLS encryption for data in transit
  • Authenticated access controls
  • Role-based permissions within groups
  • Row-level security and group isolation in the database
  • Optional multi-factor authentication
  • Security headers to reduce common web attacks
  • Audit logging for important actions
  • Least-privilege principles for system access

However, no method of transmission or storage is completely secure. We cannot guarantee absolute security.

20. International Data Transfers

PamojaHub is operated from the United States, and our service providers may process or store data in countries other than your own, including outside Kenya.

We use technical and organizational safeguards, such as contracts with service providers, to help protect personal information when it is transferred internationally. The specific legal mechanism for transfers from Kenya should be confirmed with legal counsel.

21. Kenya Privacy Rights

Under the Kenya Data Protection Act, 2019, you may have the right to be informed about how your personal data is processed; access the personal data we hold about you; object to processing in certain circumstances; request correction of inaccurate or misleading data; request deletion of personal data where applicable law allows; request restriction of processing in certain circumstances; and lodge a complaint with the Office of the Data Protection Commissioner (ODPC).

These rights are subject to limitations and exceptions under Kenyan law. To exercise your rights, contact us at support@pamojahub.com.

22. Conditional U.S. State Privacy Rights

If you are a resident of a U.S. state with a consumer privacy law that applies to PamojaHub, you may have rights such as to know what personal information we collect, use, and share; request deletion; correct inaccurate information; opt out of the sale or sharing of personal information; limit the use of sensitive personal information; receive a copy of your personal information in a portable format; and non-discrimination for exercising your privacy rights.

Because PamojaHub does not sell personal information or share it for cross-context behavioral advertising, an opt-out link is not currently required.

23. California Privacy Information

If the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), applies to PamojaHub, California residents have additional rights. Whether the CCPA currently applies depends on factors such as our annual revenue, the number of California consumers whose personal information we process, and whether we derive revenue from selling personal information. These thresholds are not disclosed here because they depend on business metrics not included in this policy.

24. Children

PamojaHub accounts are intended for adults. The service is not directed to children under 18, and we do not knowingly permit children under 18 to create accounts. If we learn that a child under 18 has created an account without appropriate consent, we will take steps to delete or anonymize that account.

This does not prevent a lawful group from keeping records about its members, including members who are minors, where the group has authority to do so.

25. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a prominent notice on our website before the changes take effect. The "Last updated" date at the top of this policy shows when it was most recently revised.

26. Contact Us

If you have questions, concerns, or requests about this Privacy Policy or our handling of your personal information, please contact us at:

Martin M Mutua
Email: support@pamojahub.com
Business contact address:
2609 FeatherStone Rd
Oklahoma City, OK 73120
United States
Website: https://www.pamojahub.com

If you are in Kenya and wish to lodge a complaint, you may also contact the Office of the Data Protection Commissioner.

Effective August 21, 2026

Account deletion update

This update replaces any inconsistent description of the account-deletion process in Section 18 of this Privacy Policy. PamojaHub provides a public account-deletion page at /account-deletion, which is also linked from the Android app.

An eligible user must be signed in, verify the current account password, and explicitly confirm permanent deletion. PamojaHub performs the privileged deletion operation only on the server. Service-role credentials are not provided to the Android app or browser.

Deletion may be blocked until responsibilities that cannot safely disappear are resolved. Examples include ownership of a group or non-disposable organization, a pending, active, or defaulted loan, an outstanding contribution obligation, a positive share holding, protected subscription or billing responsibility, or being the last platform super administrator.

When deletion succeeds, the Supabase authentication identity is permanently deleted. Direct profile identifiers such as the user's name, original email address, phone number, avatar, county, and city are removed or pseudonymized, and personal notification, email-preference, and active WhatsApp identity/preference data that is not required for historical integrity is removed or disconnected.

PamojaHub may retain pseudonymized historical records where needed to preserve group, loan, contribution, share, payment, governance, security, billing, dispute, fraud-prevention, accounting, or audit integrity, or where retention is otherwise lawfully required. These records retain an internal historical identifier rather than the deleted user's usable sign-in identity.

Creating a later account with the same email address or phone number creates a new account identity. PamojaHub does not reconnect the new account to the deleted account's historical memberships, loans, contributions, or other records merely because contact information matches.

If an account cannot be deleted through the self-service flow, contact support@pamojahub.com. PamojaHub may require identity verification before assisting with a deletion request.

27. Ask PamojaHub — AI Customer Help Assistant

PamojaHub may provide a floating customer-help feature called Ask PamojaHub. Ask PamojaHub is an AI system, not a human customer-service representative. It is intended to answer questions about how to use PamojaHub using our published Help Center and user guides.

When you choose to send a question to Ask PamojaHub:

  • Your question is sent to PamojaHub's server for processing.
  • We may include limited context needed to give a relevant answer, such as your current group role and relevant excerpts from PamojaHub's Help Center.
  • The question and selected Help Center excerpts may be sent to our AI inference provider, Groq, to generate the answer.
  • PamojaHub does not intentionally persist Ask PamojaHub chat questions or generated answers in the PamojaHub application database in this version of the feature.
  • PamojaHub has enabled Groq's Zero Data Retention control for the inference APIs used by Ask PamojaHub. According to Groq's current documentation, this prevents customer inputs and outputs from being retained for system-reliability and abuse-monitoring purposes. Groq still collects usage metadata for service activity and performance; Groq states that this usage metadata does not contain customer inputs or outputs.

Ask PamojaHub is designed as a read-only help feature. It does not approve or execute payments, loans, votes, membership or role changes, subscription changes, password changes, account recovery, or other transactions. It is not used to make decisions that have legal or similarly significant effects on you.

Answers are limited according to the user's current context. Customer-facing Ask PamojaHub does not provide platform super-admin or internal operator instructions. Group officer guidance may be limited to users who hold the relevant active group role.

AI-generated answers can be incomplete or incorrect. Important information should be verified in the applicable PamojaHub screen, Help Center article, group rules, or with a human support representative. If Ask PamojaHub cannot find adequate support in the Help Center, it is designed to direct the user to human support rather than invent an answer.

Do not enter passwords, PINs, payment-card details, CVV codes, MFA codes, recovery codes, national identification numbers, or other secrets into Ask PamojaHub. If you need help with a sensitive or account-specific issue, use our Contact Support page instead.

Because AI services and applicable legal requirements may change, we may update this notice and our technical safeguards. Material changes will be handled in accordance with the Changes to This Policy section above.