Introduction
This Privacy Policy explains how Raven Tech Group (“Stride”, “we”, “us”) collects, uses, stores, and protects personal data when you visit getstride.co.ke, use the Stride operations platform at app.getstride.co.ke, or interact with us for sales and support.
Stride is a multi-tenant software-as-a-service platform for East African businesses — covering HR & payroll, finance, procurement, projects, legal, and industry-specific modules. Because we process employee, payroll, and financial records on behalf of customer organisations, this policy describes both our role as a data processor and the limited data we control directly as a data controller.
Controller and processor roles
When Stride is the data controller. We determine the purposes and means of processing for: website analytics and marketing enquiries; account registration and billing contact details for the subscribing organisation; platform security logs; and communications with prospective and existing customers.
When Stride is the data processor. For employee, applicant, payroll, finance, and operational data entered into a customer’s Stride tenant, the customer organisation is the data controller. We process that data only on documented instructions from the customer — to provide, secure, and support the subscribed services — and in accordance with our data processing terms and this policy.
If you are an employee or other individual whose employer uses Stride, please contact your employer (the controller) in the first instance for access, correction, or deletion requests relating to employment data. We will assist our customers in fulfilling those requests as required by contract and applicable law.
Data we collect
Depending on your relationship with Stride, we may process the following categories of personal data:
Customer organisation and billing contacts
- Name, work email, phone number, job title, and company details
- Subscription tier, billing history, and Paystack payment references (not full card numbers)
- Support tickets, demo requests, and correspondence with our team
Platform users (staff and administrators)
- Account credentials or SSO identifiers (Microsoft Entra ID, Google Workspace)
- Role, permissions, login timestamps, IP address, and device/browser metadata for security
- Audit logs of actions taken within the platform
Employee and workforce data (processor data)
- Identity and contact details, national ID or passport references, tax PIN, bank and M-Pesa payout details
- Employment records: job title, department, compensation, leave, attendance, performance, and disciplinary records
- Applicant and recruitment data where the ATS module is enabled
- Documents uploaded to the platform (contracts, IDs, payslips, letters)
Finance and operations data (processor data)
- Chart of accounts, invoices, expenses, approvals, vendor records, and payment instructions
- M-Pesa disbursement batches, reconciliation references, and statutory filing outputs (KRA, NSSF, SHIF, etc.)
- Procurement, asset, fleet, and project records linked to identifiable individuals where applicable
Website visitors
- Cookie and analytics data (where consent or legitimate interest applies)
- Contact form submissions and newsletter preferences
Purposes and lawful basis
We use personal data for the following purposes and lawful bases under the Kenya Data Protection Act, 2019:
| Purpose | Typical lawful basis |
|---|---|
| Providing and operating the Stride platform for subscribed customers | Contract performance; legitimate interest of the customer |
| Processing payroll, M-Pesa disbursements, and statutory compliance on customer instruction | Contract performance; legal obligation (where applicable) |
| Account security, fraud prevention, and incident response | Legitimate interest; legal obligation |
| Subscription billing via Paystack | Contract performance |
| Product support, onboarding, and service communications | Contract performance; legitimate interest |
| Marketing to prospective customers (demo requests, product updates) | Consent or legitimate interest with opt-out |
| Improving reliability, analytics, and product development (aggregated where possible) | Legitimate interest |
Where we rely on consent, you may withdraw it at any time without affecting processing already performed. Where we act as processor, the customer organisation determines the lawful basis for employee and operational data.
Sub-processors
We use carefully selected infrastructure and service providers to deliver Stride. Each sub-processor is bound by contractual data protection obligations consistent with this policy.
| Provider | Service | Data processed |
|---|---|---|
| Neon | Managed PostgreSQL database | All tenant application data at rest |
| Vercel | Application hosting, edge network, and deployment | Request logs, cached assets, environment configuration |
| Paystack | Subscription billing and payment processing | Billing contact details, transaction references, payment status |
| Microsoft / Google | Single sign-on (Entra ID, Google Workspace) | Authentication identifiers, name, and work email from identity provider |
| SMTP email provider | Transactional email (invites, payslips, notifications) | Recipient address, message content as configured by the customer |
We may update sub-processors from time to time. Enterprise customers may request prior notice of material sub-processor changes as set out in their agreement.
Your data subject rights
Under the Kenya Data Protection Act, 2019, data subjects have rights including access, rectification, erasure, restriction, objection, and data portability, subject to legal exceptions. You may also lodge a complaint with the Office of the Data Protection Commissioner (ODPC) in Kenya.
- Controller data (marketing, billing, your Stride admin account): contact us at privacy@getstride.co.ke.
- Employee or payroll data held in your employer’s tenant: contact your employer first; we will support them in responding within agreed timeframes.
We respond to verified requests without undue delay and within timelines required by applicable law, typically within 30 days unless an extension is permitted.
Retention
We retain personal data only as long as necessary for the purposes described above:
- Active subscription data: retained for the duration of the customer agreement and configured backup windows.
- Post-termination: customer may export data during a defined wind-down period; after that, tenant data is deleted from production systems within 90 days unless a longer period is required by law or agreed in writing.
- Billing and tax records: retained for at least seven (7) years as required for Kenyan tax and accounting purposes.
- Security and audit logs: typically 12–24 months, unless needed for an active investigation.
- Marketing contacts: until you unsubscribe or we no longer have a legitimate basis to contact you.
Security
We implement technical and organisational measures appropriate to the sensitivity of HR, payroll, and financial data, including:
- Encryption in transit (TLS) and encryption at rest for database storage
- Multi-tenant isolation with row-level security and role-based access controls
- Hashed credentials, optional SSO, and session management for staff and ESS portals
- Environment separation between production, staging, and internal demo sandboxes
- Access logging, least-privilege internal access, and periodic review of administrative permissions
- Backups and disaster-recovery procedures for database availability
No method of transmission or storage is completely secure. We require customers to maintain strong passwords, enable SSO where available, and configure appropriate internal access roles.
M-Pesa and payment data
Stride supports M-Pesa bulk salary disbursements and payment reconciliation as part of payroll and finance modules. When customers use these features:
- Mobile money payout instructions (phone numbers, amounts, batch references) are processed on the customer’s instruction and stored within their tenant.
- Stride does not store M-Pesa PINs or full mobile-money wallet credentials. Integration with payment rails is performed through authorised APIs and customer-configured accounts.
- Subscription payments for Stride itself are processed by Paystack. We do not store full payment card numbers on Stride servers; Paystack provides tokenised payment references and receipts.
Customers are responsible for ensuring they have a lawful basis and employee consent (where required) to collect and disburse payments via mobile money.
Data residency and cross-border transfers
Stride is designed for East African operations with regional data cells for Kenya (KE), Uganda (UG), and Tanzania (TZ). Customer tenant data is allocated to the cell selected at onboarding and remains logically segregated from other regions.
Some sub-processors (for example Vercel edge infrastructure and email delivery) may process limited metadata outside your selected cell. Where personal data is transferred outside Kenya, we implement appropriate safeguards — including contractual clauses and vendor security assessments — consistent with the Kenya Data Protection Act and ODPC guidance.
Enterprise customers may specify residency requirements in their order form. Cross-border transfers within a customer’s own multi-entity setup (for example Kenya and Uganda entities in one account) occur under the customer’s control and documented instructions.
Kenya Data Protection Act and ODPC
We align our processing practices with the Kenya Data Protection Act, 2019 and regulations issued by the Office of the Data Protection Commissioner (ODPC), including:
- Registering as a data controller/processor where required and maintaining required records of processing
- Processing personal data lawfully, fairly, and transparently with appropriate security measures
- Honouring data subject rights and supporting our customers in honouring rights for processor data
- Conducting data protection impact assessments for high-risk processing where appropriate
- Appointing a contact point for privacy enquiries and regulatory correspondence
You may contact the ODPC at odpc.go.ke if you believe your rights have been infringed and we have not resolved your concern.
Personal data breach notification
We maintain procedures to detect, investigate, and respond to suspected personal data breaches. If we become aware of a breach affecting personal data where we are the controller, we will notify the ODPC within seventy-two (72) hours where required and communicate to affected individuals without undue delay when the breach is likely to result in a high risk to their rights and freedoms.
Where we process data on behalf of a customer, we will notify the customer without undue delay after becoming aware of a personal data breach affecting their tenant, and provide reasonable assistance so the customer can meet its regulatory and contractual notification obligations.
Contact and Data Protection Officer
For privacy questions, data subject requests relating to controller data, or regulatory enquiries:
- Data Protection contact: privacy@getstride.co.ke
- General enquiries: hello@getstride.co.ke
- Postal address: Raven Tech Group, Nairobi, Kenya (full registered address available on request for contractual and regulatory correspondence)
This policy should be read together with our Terms of Service. We may update this policy from time to time; material changes will be posted on this page with an updated “Last updated” date.