Privacy Policy

Last updated: July 25, 2026

KifiyaCheck ("KifiyaCheck", "we", "us") provides a payment-verification and cash-sale-logging tool for merchants in Ethiopia. This Privacy Policy explains what information we collect from business owners and staff who use the platform (together, "you"), why we collect it, how long we keep it, and the choices you have. It applies to the KifiyaCheck web application and its API, not to any third-party site it links to or verifies against (such as a bank's or telecom operator's own receipt page).

1. Information we collect

Account & business information

  • Business name, and - for owners only - a description/location if later added.
  • Your name, and at least one way to reach you: phone number, email address, a Google account identifier, or a Telegram account identifier. You are never required to provide all four - only enough to secure and recover your account.
  • A password hash if you sign in with a password (we never store your actual password).
  • A profile photo, only if you sign in with Telegram and it supplies one.
  • Your role (owner or staff) and active/inactive status within your business.

Payment & transaction information

  • The receiving payment accounts you register for your business (e.g. your own CBE or Telebirr account numbers) - never a customer's card or account details.
  • Payment references you scan, photograph, or type in to verify a payment (e.g. a CBE or Telebirr transaction reference or receipt URL), and the verification result: amount, payer/receiver account (as shown on the provider's own public receipt), timestamp, and outcome (verified, duplicate, invalid, unmatched, or too old to confirm).
  • Cash sale entries you log manually: amount and an optional note.
  • Rejected or suspicious verification attempts (duplicate references, receipts for an account you haven't registered, or receipts too old to safely confirm), kept separately from confirmed transactions so we can show you fraud-prevention statistics.
  • Subscription and billing history: which plan and billing cycle you're on, payment proofs you submit for a paid plan (amount, reference, which of our own receiving accounts you paid into), and who on your team initiated each renewal.

Receipt scanning

When you scan a QR code or photograph a receipt to extract a payment reference, image processing (QR decoding and OCR text recognition) happens locally in your browser - the photo itself is never uploaded to or stored on our servers. Only the text reference you confirm (and, if you edit an OCR-suggested value, your edited version) is sent to us to be verified.

Technical & usage information

  • IP address and browser user-agent, used for rate-limiting (preventing abuse of login, OTP, and verification endpoints) and to secure refresh-token sessions.
  • Session cookies: an httpOnly refresh-token cookie that keeps you signed in, and a readable CSRF token cookie that protects state-changing requests. We do not use third-party advertising or tracking cookies.
  • Your language preference (English or Amharic).
  • Support and feedback messages you submit, and reports you file from the Verify screen.

2. How we use this information

  • To create and secure your account, and to tell owners and staff apart within a business.
  • To verify a payment reference against the issuing bank or telecom operator's own public receipt system, confirm it was paid to one of your registered accounts, and detect duplicate, reused, invalid, or suspiciously old submissions.
  • To record confirmed transactions and cash sales as your business's sales log.
  • To enforce the limits of your subscription plan (daily verification/cash-log quota, staff seats, payment-account slots, and history retention window) and to show you accurate usage and analytics.
  • To process subscription renewals and confirm payment proofs you submit for a paid plan.
  • To send you account-critical email: email-address verification codes, password-reset links, and staff-invite verification codes. We do not send marketing email.
  • To respond to feedback, support requests, and reported issues.
  • To detect and prevent abuse - including reused free-trial attempts, credential-stuffing, and session hijacking.

3. Who we share information with

We do not sell your data. We share the minimum necessary with:

  • Google and Telegram- only if you choose "Continue with Google" or "Continue with Telegram", to authenticate you. We receive your name, email (Google), and profile photo (Telegram) - nothing else from those accounts.
  • CBE and Telebirr- the payment reference you submit is looked up against that provider's own publicly accessible receipt page to confirm it is genuine. We do not have accounts with, or privileged access to, either provider - see Section 8.
  • Our email delivery provider - to send verification codes and password-reset links on our behalf.
  • Our database and infrastructure providers - to host the application and store data securely. They do not use your data for their own purposes.
  • Other members of your own business - an owner can see all staff activity and transactions in the business; staff see only their own logged transactions and shared business-wide settings (payment accounts, subscription status).
  • We may disclose information if required by law, to investigate fraud, or to protect the rights, safety, or property of KifiyaCheck, our users, or the public.

4. How long we keep information

  • Transaction and verification-attempt records are kept for a number of days set by your subscription plan (currently 7 / 30 / 90 days on Basic / Pro / Premium) and are automatically deleted after that window by a daily maintenance job. Aggregated, non-identifying daily statistics (counts and totals, not the underlying transactions) are kept indefinitely so your longer-term analytics stay accurate even after raw rows age out.
  • Payment proofs for subscription billing are kept permanently, even if the related business is later deleted, for our own financial record-keeping - with the business name preserved as a label but no longer linked to a live, active business.
  • A minimal trial-eligibility record (which identifiers you registered with - not your other account data) is kept permanently and independently of your business account, solely to prevent the same person from claiming more than one free trial by deleting and re-registering a business.
  • If you delete your business, your account, staff accounts, transactions, subscriptions, and payment accounts are permanently deleted, except for the payment proofs and trial-eligibility record described above.
  • If a staff member is removed or leaves, their account is deleted (or, if they have transaction history, deactivated and stripped of access) - their past transactions remain on the business's record, attributed to them by name.

5. Your choices & rights

  • You can review and update your name and business name at any time in Settings.
  • You can change or remove your password (if you have one), and see which sign-in methods are active on your account.
  • An owner can permanently delete the entire business and all its data (subject to Section 4). Staff can remove their own account at any time.
  • You can switch your interface language between English and Amharic at any time.
  • You can ask us what data we hold about you, or ask us to delete it where we are not required to keep it (e.g. for billing or fraud-prevention records), by contacting us - see the bottom of this page.

6. Security

Passwords are never stored in plain text - only a one-way cryptographic hash. Sessions use short-lived access tokens plus a rotating refresh token; if we detect a previously used refresh token being replayed (a sign of a stolen token), we immediately end that entire session family and require signing in again. Login and sensitive endpoints are rate-limited, and we don't reveal whether a phone number or email is registered when a login or password-reset attempt fails, to prevent account enumeration. No method of transmission or storage is perfectly secure, but we work to protect your information using industry-standard practices.

7. Camera & QR/OCR scanning permission

The Verify screen asks for camera access only when you choose to scan a receipt QR code or photograph a receipt for text recognition. That access is used solely for that purpose, in the moment; as noted in Section 1, the image itself stays on your device and is never uploaded.

8. Third-party verification is outside our control

KifiyaCheck verifies a payment reference by checking the publicly accessible receipt page that the issuing bank or telecom operator (currently the Commercial Bank of Ethiopia and Telebirr) already makes available for that transaction. We do not have accounts with, or any special access to, these providers' systems - we read the same public information a customer could look up themselves. Those providers may change, rate-limit, restrict, or temporarily or permanently block access to their public receipt pages at any time, entirely outside our control, which can prevent verification from completing. This is also described in our Terms of Service.

9. Children

KifiyaCheck is a business tool intended for adult merchants and their staff. It is not directed at, and we do not knowingly collect information from, children.

10. Changes to this policy

We may update this Privacy Policy from time to time as the product changes. We'll update the "Last updated" date above, and for material changes we'll make reasonable efforts to notify you in-app or by email.

Questions about this document? Contact us at kifiyacheck@elyasdev.com, or use Help & Support inside the app.