Privacy Policy
1. Who we are
TickBalance is operated by RIYO Ventures Limited, a private limited company incorporated in Kenya (registration no. PVT-7LUQL29), with its registered office at Riyo Place, Kirongothi Street, Eastleigh, P.O. Box 71909 – 00622, Nairobi, Kenya. In this policy "we", "us" and "TickBalance" mean RIYO Ventures Limited.
We are the data controller for information about people who create or use TickBalance accounts. Where a business uses TickBalance to message its own customers on WhatsApp, that business is the controller of its customers' data and we act as its data processor: the business decides why its customers' data is used, and we only act on its instructions. Section 2 sets out which group you are in.
We process personal data in accordance with the Kenya Data Protection Act, 2019 and, where it applies, the EU/UK General Data Protection Regulation.
2. Who this policy covers
This policy applies to three groups of people:
- Account holders — staff of businesses that sign up to TickBalance and use the app at app.tickbalance.com.
- Message recipients — customers of those businesses who receive or send WhatsApp messages through TickBalance. If you are a message recipient, the business that messaged you decides why your data is processed; contact that business first, and us if you need help reaching them.
- Visitors to tickbalance.com.
3. Data we collect
3.1 Information you give us
- Account details — name, work email address, mobile number, job title, password (stored only as a salted hash).
- Business details — legal name, registration number, address, tax identifiers, and identity or ownership documents where the law or our payment partners require them.
- Financial instructions — bank account and mobile-money details you enter for deposits, withdrawals and transfers, and the details of counterparties you pay.
- Support communications — anything you send us by email, in-app chat or WhatsApp.
3.2 Information generated when you use TickBalance
- Transaction data — wallet balances, deposits, withdrawals, transfers, currency-exchange quotes and trades, references, timestamps, and who recorded each entry.
- Technical data — IP address, device and browser type, operating system, log-in times, pages viewed, error logs, and the approximate location inferred from your IP address.
- Audit trail — who did what and when inside a business workspace, kept for your own compliance and ours.
3.3 WhatsApp messaging data
When a business connects a WhatsApp Business Account to TickBalance, we process:
- Meta asset identifiers — the business's WhatsApp Business Account ID, phone number ID, Meta business portfolio ID, and an access token that lets TickBalance send messages on the business's behalf.
- Recipient phone numbers and the WhatsApp profile name a recipient has chosen to share.
- Message content and metadata — the text, media and template parameters of messages sent and received, message IDs, timestamps, and delivery, read and failure statuses.
- Opt-in records — when and how a recipient agreed to receive messages, and any opt-out (for example replying STOP).
3.4 Information from other sources
- Meta Platforms — asset identifiers and status notifications for connected WhatsApp Business Accounts, delivered through the WhatsApp Business Platform.
- Banks and payment providers — where we have integrated one, confirmation of deposits, settlement of withdrawals, and exchange rates.
- Identity and sanctions screening providers — where we use one and are required to verify a business or its owners.
We do not collect special categories of personal data (such as health, religion or biometric data) and ask you not to send them to us.
4. How we use data
| Purpose | Data used | Legal basis |
|---|---|---|
| Provide the TickBalance service: run wallets, execute deposits, withdrawals, transfers and FX, keep the audit trail | Account, business, financial and transaction data | Performance of our contract with the business |
| Send WhatsApp messages on a business's behalf, record the replies it receives, and answer STOP, START and BALANCE automatically | WhatsApp messaging data | Contract with the business; the business relies on the recipient's opt-in |
| Verify businesses, screen for fraud, money laundering and sanctions, and meet reporting duties | Business details, identity documents, transaction data | Legal obligation; legitimate interest in preventing fraud |
| Secure the platform, detect abuse, debug and monitor performance | Technical data, logs | Legitimate interest in keeping the service safe |
| Respond to support requests | Support communications, account data | Contract; legitimate interest |
| Tell you about changes to the service, security notices and, with your consent, new features | Account contact details | Legal obligation for service notices; consent for marketing |
We do not sell personal data, use message content for advertising, or build profiles of message recipients across different businesses.
5. WhatsApp messaging
TickBalance sends and receives WhatsApp messages through the WhatsApp Business Platform (Cloud API) operated by Meta Platforms, Inc. and its affiliates ("Meta"). The following applies specifically to that feature.
- Each business uses its own account. Businesses connect a WhatsApp Business Account that they own under their own Meta business portfolio. TickBalance does not pool businesses onto a shared number.
- Meta processes messages to deliver them. Message content and recipient phone numbers pass through Meta's infrastructure, which is hosted outside Kenya. Meta handles that data under the WhatsApp Business Data Processing Terms and the WhatsApp Privacy Policy. Messages are encrypted in transit between Meta's servers and the recipient's WhatsApp app; Meta and TickBalance can each see the content at their respective ends in order to deliver and display it.
- Opt-in is required. Businesses may only message people who have agreed to receive messages from them, in line with the WhatsApp Business Messaging Policy. Recipients can withdraw consent at any time by replying STOP, blocking the business number in WhatsApp, or contacting the business.
- Templates are pre-approved. Messages that start a conversation use templates reviewed by Meta. Template text and the variables filled into it are stored with the message record.
- Access tokens are protected. Tokens that let TickBalance act on a business's WhatsApp account are encrypted at rest, scoped to that business, and deleted when the business removes the connection or its workspace is closed.
- Automated replies. A few keywords are answered automatically: STOP and START set your messaging preference, and — only where the business has switched this on — BALANCE returns the balance of the single account registered to your number. Anything else receives one fixed reply pointing you to the business. We do not disclose a balance when more than one account matches your number.
- Retention. Message content is retained for as long as the business keeps its TickBalance account, or until it asks us to delete it, unless a shorter period is agreed in its contract. Delivery and status metadata is kept with the audit trail.
If you received a WhatsApp message through TickBalance and want it to stop, reply STOP to the message. To have your data deleted, contact the business that sent it, or write to us at privacy@tickbalance.com and we will pass your request to the business and help make sure it is honoured. See section 11.
6. Who we share data with
- Meta Platforms — to send and receive WhatsApp messages (section 5).
- Banks, mobile-money operators and payment processors — where we have integrated one, to execute deposits, withdrawals, transfers and currency exchange.
- Cloud hosting and infrastructure providers — who store and process data on our behalf under contracts that restrict them to our instructions.
- Identity, fraud and sanctions-screening providers — where verification is required.
- Professional advisers and auditors — under confidentiality obligations.
- Regulators, law enforcement and courts — where the law requires it or to protect our rights, our users or the public.
- A buyer or successor — if RIYO Ventures Limited is sold or merges, subject to this policy continuing to apply.
Within a business workspace, other users of that workspace can see transaction data and WhatsApp conversations according to the roles the business assigns.
7. International transfers
We are based in Kenya. Some providers listed in section 6 — in particular Meta and cloud hosting providers — process data in the United States, the European Union and other countries. Where personal data leaves Kenya we rely on the transfer conditions in section 48 of the Data Protection Act, 2019: appropriate safeguards such as contractual data-protection terms, the recipient's own adequate protections, or your consent where no other basis applies.
8. How long we keep data
| Data | Kept for |
|---|---|
| Account and business details | Life of the account, then up to 90 days to allow reactivation, then deleted or anonymised |
| Transaction records and audit trail | 7 years after the transaction, as required by Kenyan financial and tax law |
| WhatsApp message content | Life of the business's account, or until the business asks us to delete it |
| WhatsApp opt-in and opt-out records | As long as the business may message the recipient, plus 2 years as evidence of consent |
| Technical logs | Up to 12 months |
| Support communications | 3 years after the case is closed |
9. Security
All traffic to tickbalance.com, app.tickbalance.com and our APIs is encrypted with TLS. Data is encrypted at rest. Access inside RIYO Ventures Limited is limited to staff who need it, protected by multi-factor authentication and logged. Webhooks from Meta are verified with a signature before we accept them. No system is perfectly secure; if we discover a breach that affects you we will notify you and the Office of the Data Protection Commissioner as the law requires.
10. Your rights
Under the Data Protection Act, 2019 (and the GDPR where it applies) you have the right to:
- be told how your data is used — this policy;
- access the personal data we hold about you and receive a copy;
- correct data that is inaccurate or incomplete;
- delete your data — see section 11;
- object to processing based on legitimate interests, and to any direct marketing;
- restrict processing while a dispute is resolved;
- port data you gave us to another provider in a machine-readable format;
- withdraw consent at any time where consent is the basis for processing;
- complain to the Office of the Data Protection Commissioner in Kenya, or to your local supervisory authority.
To exercise any right, email privacy@tickbalance.com. We respond within 30 days and may ask you to verify your identity first. Exercising these rights is free of charge.
11. Deleting your data
Anyone whose data we hold can ask for it to be deleted, at no cost, from anywhere in the world, whether or not they hold a TickBalance account. There are three ways:
- By the workspace owner — the owner of a business workspace can ask us to close the workspace and delete its data (its users, its WhatsApp connection and its message history) by emailing us from the owner's registered email address.
- By email — write to privacy@tickbalance.com with the subject "Data deletion request". Tell us the email address, phone number or business name the data relates to.
- On WhatsApp — reply STOP to any message you received through TickBalance and no further messages will be sent. To have your number and conversation history removed from the sending business's TickBalance workspace, contact that business or email us.
What happens next. We confirm receipt within 3 business days and complete the deletion within 30 days. We delete account details, message content, opt-in records, technical data and any stored access tokens, and we revoke TickBalance's connection to the affected WhatsApp Business Account. We keep only what the law obliges us to keep — transaction records for 7 years under Kenyan financial regulation — and hold that data in a restricted archive used for nothing else.
Data held by Meta. Deleting data from TickBalance does not delete copies WhatsApp keeps on its own systems. WhatsApp's own retention and deletion practices are described in the WhatsApp Privacy Policy; a business can delete its WhatsApp Business Account from its Meta business portfolio at any time.
12. Cookies
tickbalance.com uses no tracking or advertising cookies. app.tickbalance.com uses strictly necessary cookies and local storage to keep you signed in and remember your preferences. We do not use third-party analytics that identify you.
13. Children
TickBalance is a business service and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
14. Changes to this policy
We will post any changes on this page and update the effective date at the top. If a change materially affects how we use your data we will notify account holders by email at least 14 days before it takes effect.
15. Contact
RIYO Ventures Limited
Riyo Place, Kirongothi Street, Eastleigh
P.O. Box 71909 – 00622, Nairobi, Kenya
Email: privacy@tickbalance.com