Privacy Policy
Last updated: 27 August 2026
Xcobean Systems Limited ("Xcobean", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you use our website, client portal, mobile applications, and related services.
Table of Contents
- 1. Scope of This Policy
- 2. Data Controller
- 3. Data We Collect
- 4. How We Collect Data
- 5. How We Use Your Data
- 6. Legal Basis for Processing
- 8. Third-Party Services and Integrations
- 9. Data Sharing and Disclosure
- 10. Data Storage and Security
- 11. Data Retention
- 12. Your Rights
- 13. International Data Transfers
- 14. Children's Privacy
- 15. Changes to This Policy
- 16. Contact Us
Sections 7. Cookies and Tracking Technologies of the company document deal with enterprise services and are not reproduced here. The numbering above is the company numbering, so cross-references still line up. The complete document is at xcobean.co.ke/legal.
1. Scope of This Policy
This Privacy Policy applies to:
- Our Websites and Platforms: xcobean.co.ke and xcobean.com and all of their subdomains (including api, developers, payments, sign, vault, connect, links, pass, id and ai-gw), xs.ke and its subdomains (our one-time secret service), and notarize.africa
- Client Portal: our WHMCS-based client area for account management, billing, and service provisioning (including Apache CloudStack integration)
- Mobile Applications: the myxcobean and Xcobean ID mobile apps available on Google Play and the Apple App Store
- Communications: emails, live chat (Zoho SalesIQ), WhatsApp Business, Telegram, and phone calls
- Third-Party Integrations: services we use to deliver and improve our products
2. Data Controller
The data controller responsible for your personal data is:
Xcobean Systems Limited
11th Floor, Britam Towers, Nairobi, Kenya
Kigali Innovation City, Kigali, Rwanda
Email: privacy@xcobean.co.ke
Phone: +254 709 488 888 / +254 726 415 131 (Kenya)
Phone: +250 788 931 752 (Rwanda)
3. Data We Collect
3.1 Account Information
When you register for an account or purchase services, we collect:
- Full name, company name, and job title
- Email address and phone number
- Physical/postal address
- KRA PIN (for VAT compliance, where applicable)
- Username and password (hashed)
3.2 Authentication Data
Depending on the method you choose, we may process:
- Email/password credentials (passwords are stored as one-way hashes)
- Social login tokens (Google Sign-In, Apple Sign-In)
- Biometric authentication flags (Face ID, Touch ID, or fingerprint unlock is evaluated entirely by your device; we never receive or store your device's biometric templates). Face data collected during identity verification is described separately in Section 3.7
- FIDO2/WebAuthn passkeys (public key only; private key remains on your device)
- Two-factor authentication (2FA) recovery codes
3.3 Billing and Financial Data
- Invoices and payment history
- Payment method details (M-Pesa phone number, PayPal email, Pesapal transaction references)
- Credit notes and account balances
We do not store full credit/debit card numbers. Payment processing is handled by our third-party payment providers.
3.5 Device and Usage Data
- IP address and approximate geolocation
- Browser type, version, and operating system
- Device type and screen resolution
- Pages visited, time spent, and referral source
- Mobile app: device model, OS version, app version, unique device identifiers
3.6 Permissions (Mobile Apps)
The myxcobean and Xcobean ID apps may request the following device permissions:
- Camera: for scanning QR codes, scanning your identity document, and taking a selfie during identity verification (see Section 3.7)
- NFC: to read the secure chip inside your passport or national eID during identity verification (Xcobean ID)
- Notifications: to send service alerts and updates
- Biometric: for secure local authentication
Permissions are requested at the point of use and can be revoked through your device settings at any time.
3.7 Identity Verification and Face Data (Xcobean ID)
The Xcobean ID app offers an optional identity verification feature. It reads the secure chip inside your passport or national eID, then performs a short face check to confirm that you are the document's holder. This feature runs only when you choose to start it and only after you have reviewed a consent screen describing what will happen. If you use this feature, we process:
- Document chip data: the details stored on your document's chip: full name, document number, nationality, date of birth, document expiry, the machine-readable zone (MRZ), the chip's digital signatures, and the photograph stored on the chip
- A live selfie photograph: a single, standard two-dimensional photograph taken by the front camera during the face check
- A liveness result: a pass or fail indication that a live person, rather than a photo or a screen, completed the face check
Face data from the TrueDepth camera stays on your device. On iPhones with Face ID hardware, the liveness check uses Apple's TrueDepth camera (through Apple's ARKit face tracking) to confirm a real, three-dimensional face is present and to follow simple prompts such as turning your head and blinking. The depth information, facial geometry, and facial-expression values produced by the TrueDepth camera are processed solely on your device, in memory, for the duration of the check. They are never stored, never written to disk, and never transmitted off the device, and they are discarded the moment the check ends. The only items that leave your device are the standard two-dimensional selfie photograph and the pass or fail result.
Purpose. Your selfie is used for exactly one purpose: a one-to-one comparison against the photograph on your own identity document, to confirm you are the document's holder. We do not use face data to identify you among other people, we do not build or contribute to any facial-recognition database, and we do not use face data for advertising, analytics, profiling, or any other purpose.
Sharing. Face data is never shared with, sold to, or disclosed to any third party. The face comparison and liveness analysis are performed entirely on Xcobean's own systems, running on infrastructure we operate on Google Cloud Platform. No third-party facial-recognition or biometric service is involved. Google acts solely as our hosting infrastructure provider and has no access to this data for its own purposes.
Storage and retention. Your selfie is processed transiently for the comparison and is not retained once the check completes. The verified document details and the photograph from your document's chip are stored encrypted (AES-256-GCM, with keys held separately from the database) for as long as the verification remains active on your account. The face comparison produces a numeric similarity score, which we retain as part of the verification record.
Deletion. You can delete your identity verification, including the stored document details and document photograph, at any time from your Xcobean account page at id.xcobean.com (Account, then Remove identity verification), or by emailing privacy@xcobean.co.ke. Deletion takes effect immediately.
4. How We Collect Data
- Directly from you: when you register, place orders, submit tickets, fill in forms, or communicate with us
- Automatically: through cookies, analytics, and server logs when you use our website or apps
- From third parties: payment providers (transaction confirmations), social login providers (basic profile data), and public registries (WHOIS, company registries)
5. How We Use Your Data
We use your personal data to:
- Provision, manage, and support the services you purchase
- Process payments and issue invoices
- Communicate with you about your account, services, and support requests
- Send service notifications, maintenance alerts, and security advisories
- Send marketing communications (only with your consent; you can opt out at any time)
- Analyse website and app usage to improve our products and user experience
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations, including tax and regulatory requirements
- Enforce our Terms of Service and Acceptable Use Policy
6. Legal Basis for Processing
Under the Kenya Data Protection Act 2019 and, where applicable, the EU General Data Protection Regulation (GDPR), we process your data on the following bases:
- Contractual necessity: to perform our obligations under your service agreement
- Legitimate interests: to improve our services, prevent fraud, and maintain security
- Legal obligation: to comply with tax, accounting, and regulatory requirements
- Consent: for marketing communications and non-essential cookies (which you can withdraw at any time)
8. Third-Party Services and Integrations
We use the following third-party services, each of which has its own privacy policy:
8.1 Service Delivery
- WHMCS: client management, billing, and support ticketing
- Apache CloudStack: cloud infrastructure orchestration
8.2 Zoho Suite
- Zoho SalesIQ: live chat and visitor tracking
- Zoho PageSense: website analytics and A/B testing
- Zoho Marketing Automation: email marketing and lead nurturing
- Zoho Books: accounting and invoicing
- Zoho Desk: customer support management
- Zoho Sign: electronic document signing
- Zoho Assist: remote support sessions (initiated with your consent)
- Zoho Survey: customer satisfaction surveys
- Zoho Bookings: appointment scheduling
8.3 Google Services
- Google Analytics (GA4): website traffic analysis
- Google Workspace: email and collaboration (for internal operations)
- Google Sign-In / OAuth: social login for the mobile app
8.4 Payment Processors
- Xcobean Pay: our own payment aggregation platform, and the method most customers use. We handle the transaction record, settlement and reconciliation, and the payment itself is carried by one of the providers below depending on how you choose to pay
- M-Pesa (Safaricom): mobile money payments, including STK push, paybill and till
- Paystack: card and bank payment processing
- DPO Group: card and mobile money processing
- Pesapal: card and mobile money payments
- PayPal: international payments
- Bank transfer: where you pay us directly by bank transfer, your bank and ours process the payment. We receive the reference and remittance details
8.5 Communications
- WhatsApp Business API: customer messaging
- Telegram Bot: notifications and support
- Firebase Cloud Messaging: push notifications for the mobile app
8.6 Authentication
- Apple Sign-In: social login for iOS
- Google Sign-In: social login
- Firebase Authentication: mobile app user management
8.7 Infrastructure and Network
- Cloudflare: content delivery, DNS, DDoS mitigation, web application firewall and bot protection (Turnstile). Cloudflare sits in front of our websites and therefore processes the IP address and request metadata of every visitor
- Google Cloud Platform: hosting for this website, our API platform and our identity verification service
- Vultr: hosting for certain services
- Zabbix and Grafana: service monitoring and availability reporting
- Meilisearch: site and knowledge base search
- n8n: internal workflow automation
8.8 Artificial Intelligence Services
Some features send text to AI providers to generate a response. This includes our website assistant, our WhatsApp assistant and certain support and reporting tools in the client portal. We do not send payment details, passwords or identity verification data to these providers, and our agreements with them do not permit your data to be used to train their models. You can always reach a human instead by emailing info@xcobean.co.ke.
- Anthropic (Claude): assistant, support and content generation
- Google (Gemini): assistant and content generation
- OpenAI and xAI: assistant and content generation
- Our own AI gateway: some models run on infrastructure we operate ourselves, in which case no third party receives your text
8.9 Email Delivery
- ZeptoMail, Postmark, Resend, Amazon SES and Mailgun: delivery of transactional email such as invoices, service notifications and password resets. These providers process recipient email addresses and message content
- Microsoft 365 and Google Workspace: business email and collaboration
8.10 Electronic Signature
- DocuSeal and LibreSign: electronic signature services we operate on our own infrastructure
- Zoho Sign and Dropbox Sign: third-party electronic signature services, which process the name, email address, IP address and signature of each signatory
8.11 Communications and Telephony
- 3CX and our SIP carriers: voice telephony, call routing and, where you are notified, call recording
- Slack: internal alerting
9. Data Sharing and Disclosure
We do not sell your personal data. We may share data with:
- Service providers: third parties who process data on our behalf (as listed in Section 8), bound by data processing agreements
- Payment processors: to facilitate transactions you initiate
- Regulatory authorities: where required by Kenyan law (e.g., Kenya Revenue Authority, Office of the Data Protection Commissioner)
- Law enforcement: where legally compelled by a valid court order
- Business transfers: in the event of a merger, acquisition, or asset sale, with prior notice to affected users
10. Data Storage and Security
Where your data is stored depends on which service you use. We do not operate a single location, so rather than claim otherwise, here is the actual picture:
- Kenya: data held in our own Kenyan data centre and colocation facilities, including services we provide from local infrastructure
- Switzerland (Zurich): this website and our identity verification service, on infrastructure we operate in Google Cloud Platform's europe-west6 region
- United Kingdom (London): certain hosted and cloud services
- United States: certain third-party platforms we use to deliver and support our services
- Zoho's regional data centres: data held in the Zoho applications we use for customer relationship management, support, email and marketing
The safeguards described in Section 13 apply to any transfer outside Kenya. If your organisation requires data to remain in a particular country, tell us before you sign and we will confirm in writing where your data will sit for your specific service. We would rather agree that up front than have you assume it.
In all locations we implement appropriate technical and organisational measures, including:
- Encryption in transit (TLS 1.2+) and at rest
- Firewalls, intrusion detection, and DDoS mitigation
- Role-based access controls and multi-factor authentication for staff
- Regular security audits and vulnerability assessments
- Encrypted backups with tested restoration procedures
11. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this policy:
| Data Type | Retention Period |
|---|---|
| Account information | Duration of account + 2 years after closure |
| Billing and invoicing records | 7 years (Kenya tax law requirement) |
| Support tickets | Duration of account + 1 year |
| Website analytics | 26 months (GA4 default) |
| Server and access logs | 90 days |
| Marketing consent records | Duration of consent + 3 years |
| Identity verification record (document details and document photograph, encrypted) | Until you delete the verification or close your account |
| Identity verification selfie | Not retained; processed transiently during the check only |
| TrueDepth face data (depth information, facial geometry, expression values) | Never collected by our servers; processed on your device only and discarded when the check ends |
12. Your Rights
Under the Kenya Data Protection Act 2019 (and the GDPR for EU/EEA residents), you have the right to:
- Access: request a copy of the personal data we hold about you
- Rectification: request correction of inaccurate or incomplete data
- Erasure: request deletion of your personal data (subject to legal retention obligations)
- Data portability: receive your data in a structured, machine-readable format
- Restriction: request that we limit the processing of your data
- Objection: object to processing based on legitimate interests or direct marketing
- Withdraw consent: where processing is based on consent, withdraw it at any time without affecting prior processing
To exercise any of these rights, contact us at privacy@xcobean.co.ke. We will respond within 30 days.
You also have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC), Kenya.
13. International Data Transfers
Some of our third-party service providers (e.g., Google, PayPal, Firebase) may process data outside Kenya. Where this occurs, we ensure that appropriate safeguards are in place, including:
- Standard contractual clauses
- Adequacy decisions by the ODPC
- Binding corporate rules of the service provider
14. Children's Privacy
Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a minor, please contact us at privacy@xcobean.co.ke and we will promptly delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on this page with a revised "Last updated" date
- Sending an email notification for significant changes
- Displaying a prominent notice on our website or client portal
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Xcobean Systems Limited
11th Floor, Britam Towers, Nairobi, Kenya
Kigali Innovation City, Kigali, Rwanda
Privacy inquiries: privacy@xcobean.co.ke
General inquiries: info@xcobean.co.ke
Phone: +254 709 488 888 / +254 726 415 131 (Kenya)
Phone: +250 788 931 752 (Rwanda)
Website: xcobean.co.ke
Qootuma supplement
Last updated: 17 September 2026
Qootuma is a product of Xcobean Systems Limited, which is the data controller for everything described here. The company Privacy Policy above sets out how Xcobean handles personal data generally. This supplement says exactly what the Qootuma app collects, why, where it goes and how long it is kept, and where the two differ this supplement is the one that applies to your membership.
P1. What Qootuma holds about you
- Who you are: your name, your phone number in international format, an email address if you gave one, your country, your home city, your language, and, if you choose to add them, a short bio, your gender, your firm's name and your profile photograph.
- How you got in: the invitation code you used, who invited you, and the date you took the pledge together with the version of the terms you accepted.
- Your standing: your trust level and tier, who has said they know you, who has vouched for you and on what stated relationship, your ratings, badges, points and streaks.
- What you post and do: trips and car pools including the cities, dates, means of travel, number of seats and any map pins you drop, the classes of document you name, waves and connections, chat messages with their sent, delivered and read times, alerts, reports you make, and the steps of any handoff including the check-in word and the photograph of a sealed envelope if you take one.
- Safety details: the name and number of the emergency contact you choose to add.
- Money: a record of memberships and donations, with the amount, currency, provider and the provider's reference. Qootuma never receives or stores your card number.
- Technical: your device's push notification token, and the ordinary server records of requests to the service, which include an IP address.
P2. Matching your phone book, without sending it
Qootuma can tell you which of the people in your phone book are already members. Your contacts' phone numbers never leave your device. This is how it works, and it is worth reading once:
- You choose the contacts. On the phone the app opens the system contact picker, so nothing is read until you tap a name; in the browser it uses the same picker where the browser offers one.
- On your own device, each number is put into international format, joined to a secret word the server gives the app, and turned into a SHA-256 hash: a fixed sixty-four character fingerprint from which the original number cannot be worked back out. Email addresses are treated the same way.
- Only those hashes are sent. Not the numbers, not the names, not the rest of the phone book.
- The server compares them with the hashes of members' own numbers and tells you which matched. We keep the hashes, the fact that you consented, and the matches, so that we do not have to ask you again and so that a member can be told when someone already in their phone book joins.
- If you would rather your own arrival was not announced to the people who hold your number, switch that off in Settings. Deleting your account deletes your hashes.
P3. The profile photograph check
The circle only works if the face on a profile is a real face. When you set a profile photograph the app sends it to be checked automatically, and the check answers three questions and nothing more: is this a photograph of a real human face, is it one person, and is the face clear. A photograph that fails is refused and is not kept. If the check cannot be completed, the photograph is accepted and the team may look at it later.
That check is run by Google's Gemini model, acting as our processor, under a business key. The photograph is sent for that single question. It is not used to identify you, it is not compared with any other person, and it is not added to any database of faces. The photograph you set is then held on our own storage, and other members see it in the app exactly as you would expect.
P4. Verifying your identity
Identity verification is optional and it never starts on its own. There are two routes.
The chip. The app reads the machine-readable zone printed on your passport or national identity card with the camera, then reads the document's secure chip over NFC, then takes a live selfie. From the chip it reads the identity data group, the photograph the issuing state stored on it, and the document's security object, which carries the state's digital signatures. These, with the selfie, go to Xcobean's own identity platform, which confirms the chip is genuine and signed by the issuing country, compares the selfie with the chip photograph one to one, and judges whether a living person took it. No outside facial recognition service is involved.
- What is kept: the photograph from the chip, your selfie, the result of the three checks including the face similarity score and the issuing country, the type of document and its country, and a one-way keyed hash of the document number, which exists so that one document can verify only one account.
- What is not kept: the document number itself, your date of birth, the name and other fields held on the chip, and the chip's raw data and signatures. They are used for the check and then dropped.
- Face data from the phone's depth camera stays on the phone. Where the liveness check uses an iPhone's TrueDepth camera, the depth and facial-geometry values are worked out on the device, in memory, for the seconds the check takes. They are never written down and never sent. What leaves the device is the ordinary flat selfie and a pass or fail.
The manual route. If your document has no chip, or the phone cannot read it, you can send a photograph of the document and a selfie instead. Those two images are stored on our server and a member of the Qootuma team looks at them by hand to decide. Only that small team can open them.
Verification images and the verdict are kept while the verification stands on your account. They go when you delete your account. If you would rather they went sooner, once you have been verified, ask us at privacy@xcobean.co.ke and we will remove them and keep only the verification record itself.
P5. Messages, calls and the SOS button
- Messages between two connected members are stored on our servers so that both sides can read them on any device, with the times they were sent, delivered and read. They are not end-to-end encrypted. Staff do not read them as a matter of course, and will only open the messages on a connection where a report has been made about that connection or where the law requires it.
- Calls are carried by a media server that Xcobean operates. A call can only be placed inside an accepted connection, each call gets its own room and a token that expires within the hour, and calls are not recorded. What we keep is the fact that a call was placed, and when.
- SOS. If you press SOS we take the location your device offers at that moment, together with any note you type, and alert the Qootuma team so that somebody knows where you are. We hand you the emergency numbers for the country you are in and your own emergency contact. This is not an emergency service. Call the police.
P6. Location
Qootuma does not follow you about. There is no background location tracking, and the app does not report where you are unless you ask it to. Location appears in exactly three places: the map pins you choose yourself when posting a road trip or a car pool, the position sent when you press SOS, and the circle map, which plots members on their stated home city from a fixed list of city coordinates and not on any live position.
P7. What is kept on your device
A session cookie and a cross-site request forgery token so that you stay signed in safely, and a small flag for each first-time hint so the app does not show you the same tip twice. That is all. Qootuma runs no analytics, no advertising and no tracking of any kind, and it sets none of the analytics or marketing cookies described in the company policy.
P8. What other members can see
You choose, in Settings, between being visible to everyone in the network and being visible only to your contacts. Members who are not your contacts then see your name and must ask to connect, and you decide. Whoever can see you sees your photograph, your city, your trust tier and badges, the trips you have posted, and how many people you both know. Your phone number, your email address, your emergency contact and your verification documents are never shown to another member.
P9. Who else touches the data
Qootuma does not sell member data, and it is never handed to advertisers or data brokers. Outside Xcobean it reaches only these, each for one job:
- Google Cloud Platform, which hosts the service and its database in the Zurich region, and does not access the data for its own purposes
- Google's Gemini model, for the single profile-photograph question described in P3
- Apple, and on Android Google, to deliver push notifications to your device
- the payment provider you choose when you buy a membership or make a donation
- a regulator, a court or the police, where the law obliges us and on a valid demand
P10. How long it is kept
| What | How long |
|---|---|
| Your profile and everything attached to it | While your account is open |
| A deleted account | Thirty days, so a deletion made in error can be undone, then erased with your photographs and files |
| Contact hashes | Until you delete your account or turn contact matching off |
| Verification images and verdict | While the verification stands, or until you ask us to remove the images |
| Chip data groups and signatures, your document number, your date of birth | Never stored; used for the check and dropped |
| Depth and facial-geometry data from the phone's camera | Never leaves your device and is discarded when the check ends |
| Messages on a connection | While either member's account is open |
| Membership and donation records | Seven years, as Kenyan tax law requires |
| Server and access logs | Ninety days |
P11. Your rights, and how to use them
Under the Kenya Data Protection Act, 2019 you may ask us for a copy of what we hold about you, have anything wrong put right, have your data erased, receive it in a form you can take elsewhere, restrict or object to what we do with it, and withdraw a consent you gave. You can delete your account yourself from Settings at any moment; you do not need to ask us.
Write to privacy@xcobean.co.ke and we will answer within thirty days. If we have not put something right, you are entitled to complain to the Office of the Data Protection Commissioner in Kenya, and you should.
P12. Why we are allowed to hold it
- To give you the service you asked for: your profile, trips, connections, messages and membership.
- Because you consented, and you can take that back: contact matching, identity verification, your emergency contact, location when you press SOS, and push notifications.
- Because the circle has to stay safe: the trust record, the photograph check, reports and moderation, and the handoff trail. This is our legitimate interest and the interest of every other member.
- Because the law says so: payment and tax records.
Qootuma, a product of Xcobean Systems Limited
11th Floor, Britam Towers, Nairobi, Kenya
Data protection: privacy@xcobean.co.ke
Qootuma: hello@qootuma.com
Anything else: info@xcobean.co.ke
Phone: +254 709 488 888 / +254 726 415 131