PRIVACY POLICY
Your information in Vendora.
Effective 7 October 2026. This policy explains how Lyco Technologies handles information when you use the Vendora Android app, related account and merchant services, connected merchant websites and myvendora.co.ke. The information processed depends on the features you use and the permissions you grant.
1. Information processed
- Account details: Firebase Authentication account identifier, name and email address. Email verification and sign-in provider status are also used to secure account access. For new accounts, the accepted policy version, policy links and first acceptance timestamp are recorded.
- Merchant profile: merchant and business name, merchant contact phone number and email, profile settings and supported workflow configuration.
- Local SMS and transaction records: Vendora can process supported incoming SMS messages for its payment workflow. SMS intake and related transaction records may be stored locally on the device. Do not assume every SMS or all local records are copied to the cloud.
- Transaction contact details: records may include a customer's airtime recipient number and, for applicable online orders or payment flows, payer phone details. The payer and recipient can be different people or numbers. Online order views may mask recipient details.
- Device and activity details: a generated app installation identifier, merchant session version, device name/model/manufacturer/type, installed app version and build number, and event types and timestamps such as app open, sign-in/out, online status and automation state. These details support device session ownership, account security and merchant activity reporting.
- Payment and support details: payment references, payer information and status needed to check a service purchase or connected merchant order, plus information you choose to send to support.
2. On-device processing and permissions
Vendora uses phone features to support SMS intake and USSD automation. You control Android permission prompts and can change or revoke granted permissions in Android settings. The app may keep local records on the device so parts of your workflow remain available without an internet connection. Anyone with access to your unlocked device may be able to see information available there; use the device's security controls and avoid sharing it with people who should not see your business records.
3. Firebase and connected cloud services
Vendora uses Firebase Authentication for account access and Firebase cloud services for selected merchant profiles, transaction and activity records, payment references, account and device session state, synchronization, administration and payment confirmation. This means information needed for those connected features may be sent from the app to cloud services. Cloud processing is distinct from local records, and updates may be delayed when a device is offline. Firebase is provided by Google and may process information under its own service and privacy terms.
4. Merchant websites and credentials
If you request or use a connected online merchant website, information you provide for website setup and online orders may be processed to review, configure and operate that service. Online site requests can include a contact email and site or business details; online orders can include payer and airtime recipient phone numbers, amount, merchant and payment status. A merchant may provide payment connection credentials such as a consumer key and secret, passkey, short code, Till or PayBill details, or an optional eTop key. These credentials are kept in server-only records for the connection and are not intended to be exposed in public website content or returned to storefront pages. Do not place credentials, M-PESA PINs or other secrets in public forms or ordinary support messages.
The eTop production adapter is currently disabled while provider integration is pending. An eTop credential field does not mean an eTop order is being submitted or fulfilled.
5. Why information is used
Information is used to provide and maintain the features you request, authenticate accounts, process merchant workflows, keep business records, confirm service payments, protect the service, respond to support requests and meet applicable legal obligations.
6. Service providers and sharing
Information may be handled by providers needed to operate Vendora, including Firebase/Google for authentication and cloud records; GitHub Pages for this public website; Cloudflare for DNS and, where used, connected website delivery; mobile network operators, including Safaricom, for SMS, USSD and mobile payment services; and payment or hosting providers used for a connected merchant service. Daraja is Safaricom's API service used for relevant M-PESA online payment flows. A provider receives information needed for the feature or transaction you use and applies its own terms and privacy information. The eTop production connection is pending and disabled; Vendora does not currently send live orders to eTop. Information may also be disclosed where required by law or needed to protect the service, users or another person's rights. Private merchant records are not published on this public website.
7. Retention and security
Information is kept for as long as reasonably needed for the purpose for which it is processed, service operation, account support, security, resolving disputes or applicable legal requirements. Retention can differ between records on your phone, Firebase and a connected provider. We do not state one fixed deletion deadline for all records. We use access controls and service-specific safeguards, but no internet transmission or storage system can be described as risk-free.
8. Your choices and data rights
You can control Android permissions through your device settings, manage information you enter in the app where those features allow, and contact us to request access, correction, objection or deletion of personal information, or to ask a question about its use. Requests are handled subject to identity verification, applicable law, technical limits and any lawful need to retain particular records. A local copy may remain on a device until it is removed there, even if a cloud record is changed. These rights are described by the Office of the Data Protection Commissioner.
9. Children
Vendora is a business tool for merchants and is not designed as a service for children. If you believe a child has provided personal information to Vendora, contact support so the matter can be reviewed.
10. This public website
This site does not provide account sign-in, merchant record access, package prices or a merchant credential upload form. It checks official VendoraWeb release metadata from GitHub when the download section loads. GitHub, Cloudflare and the website host may process ordinary connection and security information when you visit or use a connected domain. Links to WhatsApp, email, GitHub and other services take you to those providers, whose policies apply to your use of them.
11. Contact and updates
For privacy requests or questions, email support@myvendora.co.ke or contact Vendora support on WhatsApp. We may ask for information to identify your account and confirm that you are authorized to make the request. This policy may be updated as the service changes; the current version and effective date appear on this page.