Kit Business

Privacy policy

How Kit Business handles data needed to provide, protect, and support a business workspace.

Effective and last updated: 17 August 2026

At a glance. Kit Business and SalesLive are business-management services. The apps do not contain third-party advertising SDKs and Kit does not use app data for cross-app advertising or tracking. Data is used to provide requested business features, secure accounts, complete integrations and transactions, meet legal obligations, and support the service.

1. Who this policy covers

Kit POS Uganda Limited (“Kit”, “we”, “us”, or “our”) operates the Kit Business and SalesLive applications and services at pos.kit.africa. This policy covers Kit Business for iOS and Android, whose bundle or package identifier is africa.kit.analytics, and SalesLive for macOS, whose bundle identifier is africa.kit.saleslive.

Kit is responsible for account administration, service security, billing, platform KYC, and direct communications. A business using Kit normally decides why its customer, supplier, employee, and transaction records are entered. For that workspace content, Kit processes data to provide the service to the business.

If you are a customer, supplier, or employee recorded in a Kit workspace, contact that business first about a workspace-specific request. Kit will assist the business where required.

2. Data Kit handles

  • Account and authentication data: name, username, email, phone number, password hash, Apple or Google identity reference, two-factor settings, verification events, session and device records.
  • Business and contact data: business identity and locations; customer, supplier, employee, and user details; addresses, tax identifiers, roles, permissions, notes, and CRM records.
  • Operational records: products, stock, sales, quotations, invoices, purchases, expenses, payments, accounting entries, payroll, projects, timesheets, reports, budgets, and audit history.
  • Financial, wallet, and KYC data: transaction amounts and status, wallet activity, payment destinations, provider references, reconciliation information, business-registration details, identity or eligibility evidence, tax information, and documents submitted for a requested service.
  • App-store subscription data: selected package and billing period, store product and plan identifiers, purchase and transaction references, subscription status and dates, account-binding evidence, and verification, renewal, cancellation, refund, or revocation events received from Apple App Store or Google Play.
  • User content: receipts, photographs, scans, files, support messages, and other content an authorised user chooses to submit.
  • Search and integration data: search terms and filters, tax-identification or fiscal-document queries, selected integration actions, and responses used to perform them.
  • Device, network, and security data: app and operating-system version, device type and name, an app-generated device identifier, IP address, user agent, push token and permission state, timestamps, security events, and operational error information.

Apple and Google sign-in and registration

If you choose Sign in with Apple, Apple processes the authorisation request and gives Kit a signed identity token and one-time authorisation code. After validating the signature, issuer, audience, expiry, device-bound nonce, and code exchange, Kit uses Apple's stable subject identifier (sub) as the primary external identity. Kit stores a hash of that stable subject, any Apple-provided email in encrypted form, and an encrypted Apple refresh token only to revoke the Apple grant during unlinking or account deletion.

Apple may provide a private relay address when you choose Hide My Email, and may provide your name and email only on the first authorisation. Kit accepts the relay address, does not try to reveal or replace it, does not treat email as the permanent Apple identity, and does not overwrite an existing Kit profile when Apple omits those fields later. Apple processes Sign in with Apple under Apple's privacy policy.

If you choose Google sign-in, Google gives the app a signed identity credential. Kit verifies the stable Google account identifier and verified contact information. Kit does not retain a Google access token or refresh token for this mobile flow.

If Kit cannot find an account for that verified Apple or Google identity, the app may offer to register a new account. Registration does not happen merely because a sign-in attempt was made. If you choose to continue, registration is bound to the verified provider identity and registered mobile device; Kit collects the business and contact details required by the Kit business-registration form, verifies your phone number, and records the visible package and monthly or yearly billing option you select.

Apple App Store and Google Play subscriptions

When you buy or restore a mobile subscription, Kit sends the minimum account-binding and purchase information needed to Apple or Google and verifies the purchase with that store before granting access. Kit keeps provider transaction and entitlement evidence needed to prevent replay or fraud, reconcile subscription access, process renewals, cancellations, refunds, and revocations, and resolve billing disputes. Kit does not receive your full card number from the app store.

Camera, files, biometrics, and notifications

The camera is requested only when you start a feature such as scanning an official Kit sign-in QR code or capturing a receipt or document. Photo and file access begins when you select content. Biometric checks are performed by iOS or Android; Kit receives only the success or failure result, not a face or fingerprint template.

Push notifications are optional. When enabled, Kit uses a device push token and Google Firebase Cloud Messaging, including Apple Push Notification service delivery on iOS, to deliver permitted alerts. Notification content is designed to avoid exposing business details before the app is opened and unlocked.

Optional diagnostics

The current production app configuration does not transmit optional product-interaction analytics or crash reports. If Kit enables such collection in a future build, the relevant disclosure and consent controls will be updated before collection. Normal service requests can still produce security and operational logs, including the source IP visible to the server.

3. How data is used

  • authenticate users, register accounts you expressly ask to create, verify phone numbers, enforce permissions and two-factor authentication, maintain sessions, and protect accounts;
  • provide and synchronise the business, inventory, sales, accounting, payroll, document, reporting, and permitted financial features requested by users;
  • perform payments, native-store purchase verification, KYC, messaging, tax, Apple or Google identity, push-notification, and other integrations a user or workspace chooses;
  • prevent fraud and misuse, investigate incidents, maintain audit trails, troubleshoot, back up, and recover the service;
  • send transaction, verification, security, support, deletion, and legally required communications; and
  • comply with tax, accounting, KYC/AML, payment, court, regulator, and other legal duties and resolve disputes.

Optional external AI features are used only when enabled for the workspace and invoked by an authorised user. The selected prompt, file, or minimum relevant business context may then be sent to the configured provider, such as OpenAI, Google Gemini, or Microsoft Azure OpenAI, to return the requested result. AI output is guidance and should be reviewed before use.

4. Who may receive data

Kit limits disclosure to what is reasonably necessary for the selected service, security, or law. Recipients may include:

  • authorised users and administrators of the relevant business workspace;
  • Apple for Sign in with Apple authorisation, token exchange and revocation, and for App Store subscription purchase, restoration, verification, renewal, cancellation, refund, and revocation events;
  • Google for chosen Google authentication, Google Play subscription purchase, restoration, verification and lifecycle events, and Firebase push infrastructure;
  • payment processors, mobile-network operators, banks, wallet or KYC partners, payees, billers, and fraud-prevention providers for a financial service you request;
  • the Uganda Revenue Authority and EFRIS for enabled taxpayer and fiscal-document functions;
  • email, SMS, WhatsApp, or other messaging providers when an authorised user requests a communication;
  • hosting, storage, backup, monitoring, cybersecurity, and support providers that operate the service for Kit;
  • the configured AI provider only when the optional feature described above is used; and
  • regulators, courts, law enforcement, professional advisers, auditors, or a successor where disclosure is lawfully required.

Service-provider protection. A third party that processes personal data for Kit is required to use it only for the agreed purpose and to provide the same or equal protection of user data described in this policy. Kit applies contractual, organisational, access, and data-minimisation controls appropriate to the service.

Some providers operate outside Uganda. Kit limits transferred data to the selected service and applies the safeguards required for the transfer. A bank, mobile network, tax authority, or other independently controlled service may also keep its own records under its law and privacy notice.

5. Security and data on your device

Kit uses secure transport, access controls, workspace and location boundaries, protected credentials, and monitoring. Supported offline record payloads and permission-scoped SalesLive cache data use protected app storage, while encryption keys and authentication secrets use platform secure credential storage.

Android cloud backup is disabled for Kit Business. On iOS and macOS, eligible app-container data may be included in a device or iCloud backup according to Apple and device settings, and Keychain-protected items can follow the operating system’s lifecycle, including persistence after an uninstall. Removing an app does not delete server records; use the account-deletion process for a server-side request.

Files exported or shared to another application leave Kit’s protected app storage and are then controlled by the selected destination. No online or device-storage method can guarantee absolute security, so protect devices, verification codes, recovery codes, and credentials.

6. Retention and deletion

Kit retains active account and workspace data while needed to provide the service and for the period required to complete transactions, maintain accurate records and audit trails, prevent fraud, resolve disputes, and meet legal duties. The period differs by record and jurisdiction.

  • Temporary mobile EFRIS lookup snapshots expire after about 10 minutes unless their result becomes part of a saved business or audit record.
  • Mobile sessions expire or are revoked under the configured security period. Signing out revokes the applicable server session and removes local authentication tokens.
  • A non-owner may delete their individual user profile immediately after the required confirmation. Kit revokes sessions and registered devices, removes linked Apple or Google identity data, and erases or anonymises profile and support data that is not required as part of shared business, audit, transaction, security, or legal records.
  • A business owner must use the business-wide deletion process. Only a business-wide deletion request has a seven-day cancellation period; it does not erase records immediately.
  • After processing, the active workspace and its database records are removed. Associated files and residual backup copies can remain after database deletion until separate file cleanup or protected backup rotation removes them; they are not available through the deleted workspace.
  • Limited records may be restricted and retained where required for tax, accounting, KYC/AML, payments, security, fraud prevention, disputes, court orders, regulators, or legal claims. They are deleted or anonymised when the applicable obligation or hold ends.
  • Deletion detaches the user from app-store purchaser linkage, but Kit may retain protected transaction, financial, replay-prevention, entitlement, and deletion-receipt evidence where needed for the business, security, legal obligations, or disputes.
Store subscriptions are managed separately. Deleting a Kit user profile or business does not cancel an Apple App Store or Google Play subscription and does not stop renewal. Billing, renewal, cancellation, and refund eligibility are controlled by the store under its rules. Manage or cancel the subscription in the Apple or Google store account used to purchase it.

For request instructions and a clearer explanation of the process, read Delete a Kit Business account.

For native purchase terms and official store-management links, read the Kit Business Mobile Terms and Store Billing Notice.

7. Your choices and rights

  • Use workspace roles and location permissions to limit access.
  • Control camera, photo, file, biometric, and notification permissions in Kit Business or SalesLive and in iOS, Android, or macOS settings.
  • Do not invoke optional AI, payment, KYC, messaging, tax, or other integrations you do not want to use.
  • Revoke devices and linked sessions, sign out, or clear local app storage where appropriate.
  • Manage or cancel a native mobile subscription in the Apple App Store or Google Play account used to purchase it.
  • Request access, correction, export, restriction, objection, or deletion where applicable, and withdraw consent for optional processing.

Kit verifies identity and workspace authority before disclosing, changing, exporting, or deleting protected records. Never email a password, one-time code, recovery code, or payment PIN.

To delete an account in SalesLive for macOS, open the profile menu, choose Delete account, confirm your identity again, and type the exact server-provided confirmation phrase. See the account-deletion instructions for the mobile, desktop, and web paths.

You may also complain to Uganda’s Personal Data Protection Office or another competent supervisory authority.

8. Contact Kit

Kit POS Uganda Limited
Plot 6 Semawata Place
Ntinda, Kampala, Uganda

Email: info@kit.africa
Phone: +256 759 948 200

Include “Kit Business privacy request” and identify the relevant workspace without sending unnecessary identity documents or account secrets.