Privacy Policy

LendTrack — Personal Lending Management

Effective Date: 1 March 2026  •  Last Updated: 1 March 2026

1. Who We Are

LendTrack (“we”, “our”, or “us”) is a personal lending management application developed and operated by Agilecode, based in Nairobi, Kenya. The app is available on Android and on the web at lendtrack.agilecode.co.ke.

For any privacy-related questions, contact us at: sales@agilecode.co.ke

2. What Data We Collect

2.1 Account Data Collected at registration

2.2 Loan & Financial Data Created by you

This data is your own records — we store it securely on our servers solely so you can access it across your devices.

2.3 Contact Data Optional — on-device only

When you use the “Import from Contacts” feature on the Add Borrower screen, the app reads your device contacts to pre-fill the borrower form. This data is:

You will be prompted for permission before any contact access. You may deny or revoke this permission at any time; the app will continue to function normally without it.

2.4 Payment Data

When you subscribe via M-Pesa, the payment is processed directly by Safaricom using their Daraja API. We receive and store:

We do not receive or store your M-Pesa PIN or any card/bank credentials.

2.5 Device Data Push notifications

We use a Firebase Cloud Messaging (FCM) token to send you payment-due reminders. This token is a random device identifier assigned by Google Firebase; it does not personally identify you. We do not collect analytics, crash reports, or usage statistics beyond what Firebase provides for message delivery.

2.6 Authentication Data

3. How We Use Your Data

PurposeData Used
Providing the app (loan tracking, repayments, schedules) Account data, loan & financial data
User authentication Email address, Google Sign-In token
Processing your M-Pesa subscription Phone number, M-Pesa receipt
Sending payment-due reminders FCM device token
Customer support Name, email address
We do not sell, rent, or share your personal data with any third party for marketing purposes.

4. Data Storage & Security

5. Third-Party Services

ServicePurposePrivacy Policy
Google Firebase Push notifications (FCM) firebase.google.com/support/privacy
Google Sign-In Optional authentication policies.google.com/privacy
Safaricom Daraja (M-Pesa) Subscription payments safaricom.co.ke/data-privacy-statements

6. Data Retention

DataRetention Period
Account data Until you delete your account
Loan & borrower records Until you delete them or your account
M-Pesa payment receipts 7 years (legal / accounting requirement)
FCM tokens Refreshed automatically by Firebase; deleted when account is deleted

7. Your Rights

You have the right to:

8. Changes to This Policy

We may update this privacy policy when we add new features or as legal requirements change. We will notify you of significant changes via an in-app notification and by email to your registered address. The Last Updated date at the top of this page will always reflect the most recent revision.

9. Contact Us

If you have any questions, concerns, or requests regarding your privacy:

CompanyAgilecode
Emailsales@agilecode.co.ke
Websitelendtrack.agilecode.co.ke
LocationNairobi, Kenya