RiverPen Technologies

Privacy Policy

Effective date: June 24, 2026

RiverPen Technologies ("RiverPen", "we", "us", or "our") is a sole proprietorship registered in Kenya and operating from Nyeri, Kenya.We respect your privacy and are committed to protecting your persoanal data.

This Privacy Policy explains how we collect, use, disclose, store, and protect personal data when you visit riverpen.com, contact us, purchase our digital products, order design or website services, use our software, or otherwise interact with us.

By using our website or Services, you agree to the collection and use of information in accordance with this Privacy Policy and applicable law, including the Data Protection Act, 2019 of Kenya.

Data Controller

The data controller responsible for your personal data is:

  • RiverPen Technologies
  • Nyeri, Kenya
  • Email: privacy@mail.riverpen.com
  • Website: https://www.riverpen.com

If you have questions about this Privacy Policy or wish to exercise your rights, contact us using the details above.

Information We Collect

We may collect the following categories of personal data:

Information you provide to us

  1. a)Full name.
  2. b)Email address.
  3. c)Phone number.
  4. d)Business or organization name.
  5. e)Billing information
  6. f)Payment references and transaction details.
  7. g)KRA PIN or tax-related details where needed for invoicing, recordkeeping, or legal compliance.
  8. h)Account credentials.
  9. i)Project briefs, files, and content you submit.
  10. j)Messages, support requests, and feedback.
  11. k)Any other information you choose to share with us.

Information collected automatically

  1. a)IP address.
  2. b)Browser type and version.
  3. c)Device information.
  4. d)Operating system.
  5. e)Referring URLs.
  6. f)Pages viewed and actions taken on our site.
  7. g)Session data.
  8. h)Log data.
  9. i)Cookie identifiers and similar tracking technologies.

Payment information

  1. a)If you make a payment, we may receive transaction details from our payment processors, including M-Pesa STK Push confirmations and payment status.
  2. b)We do not intentionally store full card details onour own systems unless a future payment provider requires it for processing.

Cookies and Similar Technologies

We use cookies and similar technologies to:

  1. a)Keep the website functioning properly.
  2. b)Authenticate users and maintain sessions.
  3. c)Remember preferences.
  4. d)Analyze traffic and improve performance.
  5. e)Detect fraud, abuse, or security issues.

You may control cookies through your browser settings and, where available, our cookie controls. If you disable cookies, some parts of the website may not work properly.

How We Use Personal Data

We use personal data for the following purposes:

  1. a)To provide and manage our Services.
  2. b)To process orders, payments, and refunds.
  3. c)To communicate with you about your inquiries, projects, purchases, and support requests.
  4. d)To deliver digital products, designs, websites, software, and related services.
  5. e)To create and manage accounts.
  6. f)To improve our website, products, and Services.
  7. g)To monitor and secure our systems.
  8. h)To detect and prevent fraud, abuse, and unauthorized access.
  9. i)To comply with legal, tax, accounting, eCitizen, KRA, and regulatory obligations.
  10. j)To send service updates and, where permitted, marketing messages.

Where required by law, we will ask fro your consent before sending marketing communications. You may opt out of marketing emails at any time.

Legal Bases for Processing

Where applicable, we process personal data on the following legal bases:

  1. a)Your consent.
  2. b)Performance of a contract.
  3. c)Compliance with legal obligations.
  4. d)Our legitimate business interests.
  5. e)Protection of our rights, property, users, and systems.

Sharing of Personal Data

We do not sell your personal data.

We may share personal data with:

  1. a)Hosting and cloud service providers.
  2. b)Payment processors and mobile money integration providers.
  3. c)Email and communication tools.
  4. d)Analytics and security providers.
  5. e)Professional advisors such as accountants, auditors, and lawyers.
  6. f)Law enforcement, regulators, courts, or government authorities where required by law.
  7. g)Third parties involved in a business transfer, merger, restructuring, or sale of assets.

We require third parties that process personal data on our behalf to use appropriate safeguards and to handle the data only for authorized purposes.

International Transfers

Because we serve customers in Kenya and globally, your personal data may be transferred to and processed in countries outside Kenya.

Where this happens, we take reasonable steps to ensure that appropriate safeguards are in place to protect your personal data. These safeguards may include contractual protections, security controls, and use of reputable service providers.

Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, including to:

  1. a)Provide the Services.
  2. b)Complete transactions.
  3. c)Handle disputes and claims.
  4. d)Meet tax, accounting, eCitizen, KRA, and legal obligations.
  5. e)Enforce our agreements.

Retention periods may vary depending on the type of data. For example, transaction, tax, and accounting records may need to be kept longer than support messages or marketing data.

Data Security

We use reasonable administrative, technical, and organizational safeguards to protect personal data. These measures may include:

  1. a)Access controls.
  2. b)Secure passwords and authentication.
  3. c)Encryption where appropriate.
  4. d)Secure hosting and infrastructure.
  5. e)Logging and monitoring.
  6. f)Limiting access to authorized persons only.

However, no method of transmission or storage is completely secure. We cannot guarantee absolute security.

Your Rights

Subject to applicable law, you may have the right to:

  1. a)Access your personal data.
  2. b)Correct inaccurate or incomplete data.
  3. c)Request deletion of your personal data.
  4. d)Restrict or object to certain processing.
  5. e)Withdraw consent where processing is based on consent.
  6. f)Request portability of data where applicable.
  7. g)Lodge a complaint with the relevant data protection authority.

To make a request, contact us at privacy@riverpen.com. We may need to verify your identity before responding.

Children's Privacy

Our Services are not directed to children under 18 years of age. We do not knowingly collect personal data from children without appropriate authorization. If we discover that we have collected personal data from a child without proper authorization, we will take reasonable steps to delete it.

Changes to This Privacy Policy

We may update this Privacy from time to time. When we do, we will post the updated version on this page and revise the Effective Date above.

Your continued use of our Services after any changes become effective means you accept the updated Privacy Policy, to the extent permitted by law.

Contact Us