Your Data is Protected
ShuleMeal is built with privacy-by-design principles. All student personal data is encrypted using AES-256 encryption at rest. Biometric data never leaves the student's device. We comply with the Kenya Data Protection Act, 2019 and the Constitution of Kenya (Article 31).
1. Introduction
ShuleMeal Tech Solutions ("ShuleMeal," "we," "us," or "our") operates the ShuleMeal Cards platform, accessible at shulemeal.co.ke and related services (the "Platform").
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Platform. We are committed to protecting the personal data of all users, including school administrators, teachers, accountants, students, and parents, in compliance with the following laws:
- The Data Protection Act, 2019 (Kenya) — the primary legislation governing data processing in Kenya
- The Constitution of Kenya, 2010 (Article 31) — the fundamental right to privacy
- The Computer Misuse and Cybercrimes Act, 2018 (Kenya)
- The Children Act, 2022 (Kenya) — protections for data relating to minors
- The EU General Data Protection Regulation (GDPR) — where applicable to international users
2. Data Controller
For the purposes of the Data Protection Act, 2019, the data controller for information processed through the Platform is:
Each school that subscribes to ShuleMeal acts as a joint data controller for the student and staff data that the school inputs into the Platform.
3. Personal Data We Collect
We collect the minimum amount of personal data necessary to provide our services:
3.1 Student Data
| Data Category | Details | Encryption |
|---|---|---|
| Full Name | Student's legal name as provided by the school | AES-256 Encrypted |
| Admission Number | Unique school-assigned student identifier | AES-256 Encrypted |
| Grade / Stream | Academic class information | Plaintext |
| Biometric Data | WebAuthn credential identifiers only — actual fingerprint data is never stored on our servers | Base64url Encoded |
| Meal Scan Records | Date, time, meal type, and approval status | Linked to encrypted ADM |
3.2 School Administrator Data
- Username — chosen by the school during registration
- Password — securely hashed using bcrypt (we never store or see your plain-text password)
- School Name — the name of the subscribing institution
- Contact Information — phone number and email provided during onboarding
3.3 Payment Data
- Payment amounts and dates
- Payment mode (Cash, M-Pesa, Bank Transfer)
- M-Pesa transaction reference codes (where applicable)
- Subscription status and billing cycle
3.4 Technical Data
- Session tokens (JSON Web Tokens) for authentication
- Locally cached offline roster data (stored in the browser's localStorage)
- Audit logs of administrative actions (enrollment, renewals, deletions)
4. Protection of Children's Data
ShuleMeal processes data relating to minors (school students) as part of its core service. In accordance with the Children Act, 2022 and Section 33 of the Data Protection Act, 2019:
- All student data is entered by authorised school staff — students do not directly input personal data
- We apply the highest level of data protection to all student records through AES-256 encryption
- Student data is only accessible to authorised personnel of the school that enrolled them
- We do not use student data for marketing, profiling, or any purpose unrelated to the meal card service
- Biometric data (fingerprints) is processed on the student's device hardware and never transmitted to our servers
5. How We Use Your Data
We process personal data for the following lawful purposes under Section 30 of the Data Protection Act, 2019:
| Purpose | Legal Basis |
|---|---|
| Issuing and verifying digital meal cards | Performance of contract |
| Recording meal attendance and generating reports | Legitimate interest of the school |
| Processing and tracking fee payments | Performance of contract |
| Biometric verification as a fallback for lost cards | Explicit consent of the data subject |
| Managing school subscriptions and billing | Performance of contract |
| Maintaining audit trails for accountability | Legitimate interest / Legal obligation |
6. Biometric Data — Special Category
Under the Data Protection Act, 2019 (Section 44), biometric data is classified as sensitive personal data requiring additional safeguards. Our approach:
- On-device processing: Fingerprint verification uses the WebAuthn/FIDO2 standard. The actual biometric template (fingerprint image/pattern) is processed entirely on the student's local device hardware (e.g., phone, laptop, or biometric scanner) and is never transmitted, stored, or accessible by ShuleMeal.
- What we store: Only a cryptographic credential identifier and public key— these cannot be reverse-engineered to reconstruct a fingerprint.
- Consent: Biometric enrollment is entirely optional and requires affirmative action by an authorised school administrator.
- Deletion: Biometric credential data is permanently deleted when a student record is removed from the system.
7. Data Sharing and Disclosure
We do not sell, rent, or trade any personal data. We may share data only in the following circumstances:
- With the subscribing school: School administrators and authorised staff can access their own school's student and payment data only
- School data isolation: Each school's data is strictly isolated — no school can access another school's records
- Legal compliance: Where required by a valid court order, subpoena, or directive from the Office of the Data Protection Commissioner (ODPC) of Kenya
- Service providers: We may engage carefully vetted hosting providers who process data on our behalf under strict contractual data processing agreements
8. Data Security Measures
In compliance with Section 41 of the Data Protection Act, 2019, we implement appropriate technical and organisational measures:
Encryption at Rest
Student names and admission numbers are encrypted using AES-256-CBC with unique initialisation vectors
Password Hashing
All passwords are hashed with bcrypt and never stored in plaintext
HTTPS / TLS
All data in transit is protected by TLS encryption
School Isolation
Multi-tenant architecture with strict school-level data segregation
Session Security
Time-limited JWT tokens with automatic expiry
Audit Logging
All data modifications are logged with timestamps and user identifiers
9. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, in accordance with Section 39(3) of the Data Protection Act, 2019:
- Active student records: Retained for the duration of the student's enrollment at the subscribing school
- Payment records: Retained for the statutory period required by the Kenya Revenue Authority (KRA) for financial record-keeping (currently 5 years)
- Meal scan records: Retained for the current academic year, with historical summaries archived
- Archived records: Schools may archive expired student records; archived data remains encrypted
- Account deletion: Upon termination of a school's subscription, all data is permanently deleted within 90 days unless a legal retention obligation applies
10. Your Rights Under the Data Protection Act
Under Sections 26–28 of the Data Protection Act, 2019, data subjects (students, parents, and school staff) have the following rights:
- Right to be informed — to know what data we hold about you and how it is processed
- Right of access — to request a copy of your personal data
- Right to rectification — to request correction of inaccurate or incomplete data
- Right to erasure — to request deletion of your personal data, subject to legal retention obligations
- Right to object — to object to certain types of processing, including direct marketing
- Right to data portability — to request your data in a structured, commonly used, machine-readable format
To exercise any of these rights, please contact your school's administration or email us directly at privacy@shulemeal.co.ke. We will respond within 30 days as required by law.
11. Cross-Border Data Transfers
Our servers may be hosted outside Kenya. In such cases, in compliance with Section 48 of the Data Protection Act, 2019, we ensure that:
- The receiving jurisdiction provides adequate data protection safeguards
- Appropriate contractual clauses and technical measures are in place to protect your data
- Data transfers are necessary for the performance of the contract between the school and ShuleMeal
12. Cookies and Local Storage
ShuleMeal uses the following browser storage mechanisms:
- Session Storage: Authentication state tokens that are cleared when the browser tab is closed
- Local Storage: Offline roster cache (encrypted student identifiers) to enable meal scanning without an internet connection. This data is automatically refreshed and can be cleared by the user
- No third-party tracking cookies: We do not use any advertising, analytics, or third-party tracking cookies
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to subscribing schools via their registered contact details. The "Last updated" date at the top of this policy will always reflect the most recent revision.
14. Complaints and Regulatory Contact
If you believe your data protection rights have been violated, you may lodge a complaint with:
Office of the Data Protection Commissioner (ODPC)
P.O. Box 40401-00100, Nairobi, Kenya
Website: www.odpc.go.ke
Email: complaints@odpc.go.ke
15. Contact Us
For any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
ShuleMeal Tech Solutions — Data Protection Office
Email: privacy@shulemeal.co.ke
General Enquiries: info@shulemeal.co.ke