Privacy notice

This is what we collect when you use GallantSMS, why we collect it, who else sees it, how long we keep it, and what you can ask us to do about it. It is written to meet section 29 of Kenya's Data Protection Act, 2019, and to be readable.

Last updated 17 September 2026.

Who we are

GallantSMS is run by GallantByte, Nairobi, Kenya. For anything about your data, write to geraldombuthia@gmail.com.

For the data you give us about yourself, we are the data controller. For the phone numbers and messages you send through the API, you are the controller and we are the data processor, acting on your instructions. The difference matters and is explained below.

What we collect about you

WhatWhenWhy
Name, email address, phone number, username, a password (stored as a hash, never as typed)When you registerTo run your account, sign you in, and reach you about it
The time, IP address, browser, operating system and device of each sign-in attempt, successful or notEach time anyone tries to sign in to your accountSo you can see who has been in your account, and so we can spot someone who should not be
The M-Pesa number you pay from, the amount, and Safaricom's receipt numberWhen you top upTo credit your account and to keep the financial record the law requires
Which API endpoint each of your keys called, when, with what result and how long it tookEach API requestSo the API page can show you your usage and so we can find a problem when you report one
What you write to usWhen you use the Support page or email usTo answer you
The templates you writeWhen you save oneTo send them, and to review them before they go live

We do not collect anything the table does not list. We do not buy data about you from anyone.

Messages you send

Every message you send through the API carries a recipient's phone number and a message text. Those belong to your customers, not to us. You decide to send them; we deliver them. Under the Act that makes you the controller and us your processor, which means:

  • We use recipient numbers and message text for one thing: delivering the message and showing you whether it was delivered. Nothing else.
  • It is your responsibility to have a lawful reason to message each recipient. Our templates are reviewed to keep the service transactional (confirmations, codes, receipts, alerts) rather than marketing, which is the kind of message people have agreed to by dealing with you.
  • We keep the number and text for 365 days, then remove them from the record. The fact that a message was sent, its status and what it cost stay, because that is your bill.
  • If someone contacts us about a message you sent, we will tell them who sent it and point them to you; we will not act on your data without your instruction, unless the law requires it.
  • If we ever learn that recipient data has been exposed, we tell you within 48 hours.

If you received a message and want no more: go to /stop, verify your number with a code we text you, and block the sender that messaged you, or every sender on the platform. It takes effect at once. We keep only a fingerprint of your number on that list, never the number, and we do not tell the sender who blocked them. Promotional messages are not permitted on this service at all; if one reached you, tell us at geraldombuthia@gmail.com and we will act on it.

Why, and on what basis

The Act requires a lawful basis for each use. Ours are:

  • Performance of a contract — running your account, delivering messages, taking payment, answering support. This covers almost everything above.
  • Legal obligation — keeping payment records for the Kenya Revenue Authority, and answering lawful requests from authorities.
  • Legitimate interest — recording sign-in attempts and API calls to keep accounts secure and the service working. We have weighed this against your privacy; the records are small, short-lived, and used for nothing else.

We do not rely on consent for any of this, because the service does not work without it and asking would be theatre. We do not send you marketing. The emails you get from us are about your account: a welcome, a password reset, a template decision, a support reply, a low balance.

Who we share it with

Only who is needed to run the service, and only what they need:

WhoWhat they getWhy
HostPinnacle (SMS gateway, Kenya)Recipient number and message textThey carry the message to the mobile network
Safaricom (M-Pesa)Your M-Pesa number and the amountTo take your payment
Our hosting providerEverything, at rest, on the servers that run GallantSMSThey run the machines
Our email providerYour email address and the emails we send youTo deliver account emails
CloudflareYour IP address when you load our pages; email addressed to usDNS, and routing of our incoming email

We do not sell data, share it with advertisers, or hand it to anyone else, unless a court or an authority with the legal power to demand it does so, in which case we will tell you if we are allowed to.

How long we keep it

A job runs every day and removes what has passed its time. These are the rules it enforces; they are written in the code, not just here.

DataKept forThen
Recipient numbers and message text365 daysRemoved from the record. Status, cost and timestamps stay.
Opt-out list (a fingerprint of the number, last four digits)Until the person lifts the blockThat is the point of it.
Emails we sent you365 daysAddress and body removed; the send record stays.
Sign-in records90 daysDeleted.
Support conversations2 years after they are closedDeleted.
Payment records7 yearsDeleted. The law requires financial records to be kept this long.
Your account (name, email, phone)While you have an accountDeleted when you ask us to close it, apart from what the payment rule above requires.

Where it is stored

Our servers are run by our hosting provider. Backups are held with the servers. The SMS gateway and M-Pesa are in Kenya. Our email provider and Cloudflare operate outside Kenya; the data that reaches them is what the table above says, and they are bound by their own data protection obligations and our contracts with them.

Your rights

Under the Act you can ask us, and we will do it:

  • To see the personal data we hold about you. We answer within seven days.
  • To correct it. Name, email and phone you can change yourself on the Profile page.
  • To delete it, by closing your account. We keep only what the payment rule requires.
  • To object to a use, or to ask us to stop.
  • To take it with you: a copy of your data in a form you can use elsewhere.

Ask through the Support page or by email to geraldombuthia@gmail.com. We will confirm it is you before acting. There is no charge.

If you are unhappy with how we handled a request you can complain to the Office of the Data Protection Commissioner. We would rather you told us first.

How we protect it

  • Everything travels over HTTPS.
  • Passwords are stored as bcrypt hashes. API keys are stored as hashes too; we cannot read them back, which is why a key is shown once.
  • Sign-ins are rate limited and every attempt is recorded so you can see them.
  • Our logs redact keys, passwords and payment details.
  • Every action taken on your account from our admin console is recorded with who did it and why.
  • If we discover a breach affecting you, we tell you and the Data Commissioner within 72 hours of finding it.

Cookies

One cookie, sessionId, which keeps you signed in. It is needed for the dashboard to work and is not used to track you. There is no analytics, advertising or third-party tracking on this site.

Changes

If this notice changes in a way that matters, we email account holders before it takes effect. The date at the top is the date of the current version.

Contact

GallantByte, Nairobi, Kenya
geraldombuthia@gmail.com · 0750815413