Privacy notice
This is what we collect when you use GallantSMS, why we collect it, who else sees it, how long we keep it, and what you can ask us to do about it. It is written to meet section 29 of Kenya's Data Protection Act, 2019, and to be readable.
Last updated 17 September 2026.
Who we are
GallantSMS is run by GallantByte, Nairobi, Kenya. For anything about your data, write to geraldombuthia@gmail.com.
For the data you give us about yourself, we are the data controller. For the phone numbers and messages you send through the API, you are the controller and we are the data processor, acting on your instructions. The difference matters and is explained below.
What we collect about you
| What | When | Why |
|---|---|---|
| Name, email address, phone number, username, a password (stored as a hash, never as typed) | When you register | To run your account, sign you in, and reach you about it |
| The time, IP address, browser, operating system and device of each sign-in attempt, successful or not | Each time anyone tries to sign in to your account | So you can see who has been in your account, and so we can spot someone who should not be |
| The M-Pesa number you pay from, the amount, and Safaricom's receipt number | When you top up | To credit your account and to keep the financial record the law requires |
| Which API endpoint each of your keys called, when, with what result and how long it took | Each API request | So the API page can show you your usage and so we can find a problem when you report one |
| What you write to us | When you use the Support page or email us | To answer you |
| The templates you write | When you save one | To send them, and to review them before they go live |
We do not collect anything the table does not list. We do not buy data about you from anyone.
Messages you send
Every message you send through the API carries a recipient's phone number and a message text. Those belong to your customers, not to us. You decide to send them; we deliver them. Under the Act that makes you the controller and us your processor, which means:
- We use recipient numbers and message text for one thing: delivering the message and showing you whether it was delivered. Nothing else.
- It is your responsibility to have a lawful reason to message each recipient. Our templates are reviewed to keep the service transactional (confirmations, codes, receipts, alerts) rather than marketing, which is the kind of message people have agreed to by dealing with you.
- We keep the number and text for 365 days, then remove them from the record. The fact that a message was sent, its status and what it cost stay, because that is your bill.
- If someone contacts us about a message you sent, we will tell them who sent it and point them to you; we will not act on your data without your instruction, unless the law requires it.
- If we ever learn that recipient data has been exposed, we tell you within 48 hours.
If you received a message and want no more: go to /stop, verify your number with a code we text you, and block the sender that messaged you, or every sender on the platform. It takes effect at once. We keep only a fingerprint of your number on that list, never the number, and we do not tell the sender who blocked them. Promotional messages are not permitted on this service at all; if one reached you, tell us at geraldombuthia@gmail.com and we will act on it.
Why, and on what basis
The Act requires a lawful basis for each use. Ours are:
- Performance of a contract — running your account, delivering messages, taking payment, answering support. This covers almost everything above.
- Legal obligation — keeping payment records for the Kenya Revenue Authority, and answering lawful requests from authorities.
- Legitimate interest — recording sign-in attempts and API calls to keep accounts secure and the service working. We have weighed this against your privacy; the records are small, short-lived, and used for nothing else.
We do not rely on consent for any of this, because the service does not work without it and asking would be theatre. We do not send you marketing. The emails you get from us are about your account: a welcome, a password reset, a template decision, a support reply, a low balance.
How long we keep it
A job runs every day and removes what has passed its time. These are the rules it enforces; they are written in the code, not just here.
| Data | Kept for | Then |
|---|---|---|
| Recipient numbers and message text | 365 days | Removed from the record. Status, cost and timestamps stay. |
| Opt-out list (a fingerprint of the number, last four digits) | Until the person lifts the block | That is the point of it. |
| Emails we sent you | 365 days | Address and body removed; the send record stays. |
| Sign-in records | 90 days | Deleted. |
| Support conversations | 2 years after they are closed | Deleted. |
| Payment records | 7 years | Deleted. The law requires financial records to be kept this long. |
| Your account (name, email, phone) | While you have an account | Deleted when you ask us to close it, apart from what the payment rule above requires. |
Where it is stored
Our servers are run by our hosting provider. Backups are held with the servers. The SMS gateway and M-Pesa are in Kenya. Our email provider and Cloudflare operate outside Kenya; the data that reaches them is what the table above says, and they are bound by their own data protection obligations and our contracts with them.
Your rights
Under the Act you can ask us, and we will do it:
- To see the personal data we hold about you. We answer within seven days.
- To correct it. Name, email and phone you can change yourself on the Profile page.
- To delete it, by closing your account. We keep only what the payment rule requires.
- To object to a use, or to ask us to stop.
- To take it with you: a copy of your data in a form you can use elsewhere.
Ask through the Support page or by email to geraldombuthia@gmail.com. We will confirm it is you before acting. There is no charge.
If you are unhappy with how we handled a request you can complain to the Office of the Data Protection Commissioner. We would rather you told us first.
How we protect it
- Everything travels over HTTPS.
- Passwords are stored as bcrypt hashes. API keys are stored as hashes too; we cannot read them back, which is why a key is shown once.
- Sign-ins are rate limited and every attempt is recorded so you can see them.
- Our logs redact keys, passwords and payment details.
- Every action taken on your account from our admin console is recorded with who did it and why.
- If we discover a breach affecting you, we tell you and the Data Commissioner within 72 hours of finding it.
Changes
If this notice changes in a way that matters, we email account holders before it takes effect. The date at the top is the date of the current version.
Contact
GallantByte, Nairobi, Kenya
geraldombuthia@gmail.com · 0750815413