Privacy Policy

ShuleMeal Cards Platform

Last updated: 6 July 2026

Your Data is Protected

ShuleMeal is built with privacy-by-design principles. All student personal data is encrypted using AES-256 encryption at rest. Biometric data never leaves the student's device. We comply with the Kenya Data Protection Act, 2019 and the Constitution of Kenya (Article 31).

1. Introduction

ShuleMeal Tech Solutions ("ShuleMeal," "we," "us," or "our") operates the ShuleMeal Cards platform, accessible at shulemeal.co.ke and related services (the "Platform").

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Platform. We are committed to protecting the personal data of all users, including school administrators, teachers, accountants, students, and parents, in compliance with the following laws:

  • The Data Protection Act, 2019 (Kenya) — the primary legislation governing data processing in Kenya
  • The Constitution of Kenya, 2010 (Article 31) — the fundamental right to privacy
  • The Computer Misuse and Cybercrimes Act, 2018 (Kenya)
  • The Children Act, 2022 (Kenya) — protections for data relating to minors
  • The EU General Data Protection Regulation (GDPR) — where applicable to international users

2. Data Controller

For the purposes of the Data Protection Act, 2019, the data controller for information processed through the Platform is:

ShuleMeal Tech Solutions

Nairobi, Kenya

Email: privacy@shulemeal.co.ke

Each school that subscribes to ShuleMeal acts as a joint data controller for the student and staff data that the school inputs into the Platform.

3. Personal Data We Collect

We collect the minimum amount of personal data necessary to provide our services:

3.1 Student Data

Data CategoryDetailsEncryption
Full NameStudent's legal name as provided by the schoolAES-256 Encrypted
Admission NumberUnique school-assigned student identifierAES-256 Encrypted
Grade / StreamAcademic class informationPlaintext
Biometric DataWebAuthn credential identifiers only — actual fingerprint data is never stored on our serversBase64url Encoded
Meal Scan RecordsDate, time, meal type, and approval statusLinked to encrypted ADM

3.2 School Administrator Data

  • Username — chosen by the school during registration
  • Password — securely hashed using bcrypt (we never store or see your plain-text password)
  • School Name — the name of the subscribing institution
  • Contact Information — phone number and email provided during onboarding

3.3 Payment Data

  • Payment amounts and dates
  • Payment mode (Cash, M-Pesa, Bank Transfer)
  • M-Pesa transaction reference codes (where applicable)
  • Subscription status and billing cycle

3.4 Technical Data

  • Session tokens (JSON Web Tokens) for authentication
  • Locally cached offline roster data (stored in the browser's localStorage)
  • Audit logs of administrative actions (enrollment, renewals, deletions)

4. Protection of Children's Data

ShuleMeal processes data relating to minors (school students) as part of its core service. In accordance with the Children Act, 2022 and Section 33 of the Data Protection Act, 2019:

  • All student data is entered by authorised school staff — students do not directly input personal data
  • We apply the highest level of data protection to all student records through AES-256 encryption
  • Student data is only accessible to authorised personnel of the school that enrolled them
  • We do not use student data for marketing, profiling, or any purpose unrelated to the meal card service
  • Biometric data (fingerprints) is processed on the student's device hardware and never transmitted to our servers

5. How We Use Your Data

We process personal data for the following lawful purposes under Section 30 of the Data Protection Act, 2019:

PurposeLegal Basis
Issuing and verifying digital meal cardsPerformance of contract
Recording meal attendance and generating reportsLegitimate interest of the school
Processing and tracking fee paymentsPerformance of contract
Biometric verification as a fallback for lost cardsExplicit consent of the data subject
Managing school subscriptions and billingPerformance of contract
Maintaining audit trails for accountabilityLegitimate interest / Legal obligation

6. Biometric Data — Special Category

Under the Data Protection Act, 2019 (Section 44), biometric data is classified as sensitive personal data requiring additional safeguards. Our approach:

  • On-device processing: Fingerprint verification uses the WebAuthn/FIDO2 standard. The actual biometric template (fingerprint image/pattern) is processed entirely on the student's local device hardware (e.g., phone, laptop, or biometric scanner) and is never transmitted, stored, or accessible by ShuleMeal.
  • What we store: Only a cryptographic credential identifier and public key— these cannot be reverse-engineered to reconstruct a fingerprint.
  • Consent: Biometric enrollment is entirely optional and requires affirmative action by an authorised school administrator.
  • Deletion: Biometric credential data is permanently deleted when a student record is removed from the system.

7. Data Sharing and Disclosure

We do not sell, rent, or trade any personal data. We may share data only in the following circumstances:

  • With the subscribing school: School administrators and authorised staff can access their own school's student and payment data only
  • School data isolation: Each school's data is strictly isolated — no school can access another school's records
  • Legal compliance: Where required by a valid court order, subpoena, or directive from the Office of the Data Protection Commissioner (ODPC) of Kenya
  • Service providers: We may engage carefully vetted hosting providers who process data on our behalf under strict contractual data processing agreements

8. Data Security Measures

In compliance with Section 41 of the Data Protection Act, 2019, we implement appropriate technical and organisational measures:

Encryption at Rest

Student names and admission numbers are encrypted using AES-256-CBC with unique initialisation vectors

Password Hashing

All passwords are hashed with bcrypt and never stored in plaintext

HTTPS / TLS

All data in transit is protected by TLS encryption

School Isolation

Multi-tenant architecture with strict school-level data segregation

Session Security

Time-limited JWT tokens with automatic expiry

Audit Logging

All data modifications are logged with timestamps and user identifiers

9. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, in accordance with Section 39(3) of the Data Protection Act, 2019:

  • Active student records: Retained for the duration of the student's enrollment at the subscribing school
  • Payment records: Retained for the statutory period required by the Kenya Revenue Authority (KRA) for financial record-keeping (currently 5 years)
  • Meal scan records: Retained for the current academic year, with historical summaries archived
  • Archived records: Schools may archive expired student records; archived data remains encrypted
  • Account deletion: Upon termination of a school's subscription, all data is permanently deleted within 90 days unless a legal retention obligation applies

10. Your Rights Under the Data Protection Act

Under Sections 26–28 of the Data Protection Act, 2019, data subjects (students, parents, and school staff) have the following rights:

  • Right to be informed — to know what data we hold about you and how it is processed
  • Right of access — to request a copy of your personal data
  • Right to rectification — to request correction of inaccurate or incomplete data
  • Right to erasure — to request deletion of your personal data, subject to legal retention obligations
  • Right to object — to object to certain types of processing, including direct marketing
  • Right to data portability — to request your data in a structured, commonly used, machine-readable format

To exercise any of these rights, please contact your school's administration or email us directly at privacy@shulemeal.co.ke. We will respond within 30 days as required by law.

11. Cross-Border Data Transfers

Our servers may be hosted outside Kenya. In such cases, in compliance with Section 48 of the Data Protection Act, 2019, we ensure that:

  • The receiving jurisdiction provides adequate data protection safeguards
  • Appropriate contractual clauses and technical measures are in place to protect your data
  • Data transfers are necessary for the performance of the contract between the school and ShuleMeal

12. Cookies and Local Storage

ShuleMeal uses the following browser storage mechanisms:

  • Session Storage: Authentication state tokens that are cleared when the browser tab is closed
  • Local Storage: Offline roster cache (encrypted student identifiers) to enable meal scanning without an internet connection. This data is automatically refreshed and can be cleared by the user
  • No third-party tracking cookies: We do not use any advertising, analytics, or third-party tracking cookies

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to subscribing schools via their registered contact details. The "Last updated" date at the top of this policy will always reflect the most recent revision.

14. Complaints and Regulatory Contact

If you believe your data protection rights have been violated, you may lodge a complaint with:

Office of the Data Protection Commissioner (ODPC)

P.O. Box 40401-00100, Nairobi, Kenya

Website: www.odpc.go.ke

Email: complaints@odpc.go.ke

15. Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

ShuleMeal Tech Solutions — Data Protection Office

Email: privacy@shulemeal.co.ke

General Enquiries: info@shulemeal.co.ke