PesaFii Privacy Notice
Version 1.0.0
Effective date: 21 August 2026
Last updated: 21 August 2026
1. About PesaFii and who we are
PesaFii is a hotspot billing and network management platform developed and operated by Agrinal Enterprises Limited in Uganda.
The platform helps WiFi and internet service businesses sell internet packages and vouchers, accept Mobile Money payments, manage MikroTik routers and monitor sales and network activity. In this Privacy Notice, businesses using PesaFii are referred to as hotspot operators or tenants. “PesaFii”, “we” and “us” mean Agrinal Enterprises Limited operating the PesaFii platform.
Our roles differ depending on whose data is involved. For the accounts of hotspot operators, their staff and their sales agents, we decide how the platform works and process that data to provide the service. For the customers of a hotspot (the people who buy WiFi access at a shop, hotel or public hotspot), the hotspot operator runs the WiFi service, and PesaFii provides the technology that authenticates devices, processes payments and keeps records on the operator's behalf. Where data protection law distinguishes between a “data controller” and a “data processor”, our classification for each category of data is subject to legal review. This notice describes what actually happens rather than asserting a legal label.
Contact details are in the Contact us section. Privacy contact: privacy@pesafii.net.
2. Scope of this notice
This notice explains what personal data the PesaFii platform collects, where it comes from, why it is processed, who it is shared with, how long it is kept, and the choices and rights you have. We process personal data in accordance with applicable data protection laws, including the Uganda Data Protection and Privacy Act, 2019 and its regulations.
It covers the PesaFii web dashboard, the PesaFii mobile app, the public PesaFii website, and the hotspot captive portal pages (the sign-in page you see when you connect to a participating WiFi hotspot). It does not cover the practices of hotspot operators outside the platform, of mobile network operators, or of other websites you visit after you are connected to the internet.
This notice deals with personal data only. The separate PesaFii Terms of Service, available at pesafii.net/terms, sets out the contractual terms on which the platform is provided, including account rules, acceptable use, fees and payouts, liability and termination. Where this notice describes a data practice and the Terms describe the same activity as a service obligation, both apply.
3. Who this notice applies to
Different people interact with PesaFii in different ways, and we process different data about each group:
- Hotspot operators (account owners): the business owners and administrators who create a PesaFii account.
- Team members and staff: people an account owner adds to help run the business, with specific roles and permissions.
- Sales agents: people who sell vouchers on behalf of a hotspot operator through the agent portal.
- Hotspot customers: people who connect to a participating WiFi hotspot and buy internet access with Mobile Money or a voucher. Hotspot customers do not create PesaFii accounts; see the dedicated section below.
- Mobile Money senders and payout recipients: people whose Mobile Money numbers are used to pay for packages, or to receive withdrawals and transfers requested by a hotspot operator.
- People who contact support: anyone who reaches out to us or to a hotspot operator through the platform's support features.
4. Personal data we collect
Account and identity data (operators, staff and agents)
- Username, email address and phone number provided at sign-up or when a team member or agent is added.
- Password, stored only as a cryptographic hash. We cannot read your password.
- Role, permissions and the business (tenant) the account belongs to.
- Email verification and one-time codes (stored hashed) used to confirm your email or authorise sensitive actions.
- Withdrawal PIN, stored only as a cryptographic hash, together with attempt counters and temporary lock information.
- Two-factor authentication status and an encrypted authenticator secret, where enabled for wallet payouts.
- Sign-in and session details: device identifier, browser type (user agent), IP address, and session tokens (stored hashed) for each signed-in device.
Hotspot customer data
- Mobile Money phone number entered on the captive portal to buy a package.
- Verified account-holder name returned by the payment provider's account-name lookup. This name is used internally for transaction records; see the Mobile Money section.
- Voucher codes and the hotspot login credentials behind them.
- Device MAC address and assigned IP address, provided automatically by the hotspot router.
- Connection records: session start and stop times, the router/hotspot the device connected through, and the amount of data transferred.
- Package purchased, payment amount, payment status and payment references.
Payment and wallet data
- Mobile Money numbers and verified account-holder names for payments, withdrawals and transfers.
- Transaction amounts, fees, statuses, timestamps, narratives and provider transaction references.
- Wallet balances and transaction history for each business.
- Payment notifications received from the payment provider, including the sending IP address and message content, kept for reconciliation and dispute handling.
Network and technical data
- Router details managed by the operator: router name, hardware identifiers, public IP address and the physical location label the operator sets.
- RADIUS authentication and accounting records generated when devices connect: usernames, device MAC addresses, assigned IPs and session statistics.
- Bandwidth and router health measurements collected from routers for monitoring dashboards.
- Audit records of significant account actions, including who acted, when, from which IP address and browser.
- Error and diagnostic reports from our own applications. These are first-party only; see Cookies and browser storage.
5. How we collect personal data
- Directly from you, when you create an account, add team members or agents, configure routers and payout numbers, enter a phone number or voucher code on a captive portal, or contact support.
- Automatically from hotspot routers: MikroTik routers and the RADIUS authentication system generate connection records (MAC address, IP address, session times, data usage) whenever a device connects to a participating hotspot.
- From the payment provider: when a Mobile Money payment, name verification or payout is processed, the provider returns transaction statuses, references and the registered account-holder name.
- Automatically from your browser or device: sign-in security data such as IP address, browser type and a device identifier, and error reports from our own applications.
- From other users: for example, when an account owner adds your email or phone number as a team member or agent, or enters a recipient number for a payout.
6. How we use personal data
- Creating, securing and administering PesaFii accounts, team roles and agent access.
- Authenticating sign-ins and protecting accounts, wallets and withdrawal PINs against unauthorised use.
- Operating hotspot access: authenticating devices, enforcing purchased packages, and disconnecting expired sessions.
- Creating, selling and redeeming vouchers and internet packages.
- Processing Mobile Money payments, withdrawals and transfers, and verifying account-holder names before money is sent.
- Calculating fees, maintaining wallets, and keeping accurate transaction and accounting records.
- Preventing duplicate, mistaken or fraudulent transactions, and investigating abuse.
- Showing hotspot operators their own sales, customer, session and network reports.
- Monitoring router health, bandwidth and service quality.
- Providing customer and technical support.
- Maintaining security and audit logs of significant actions.
- Complying with legal obligations, including financial record-keeping, and responding to lawful requests.
- Improving the reliability of the service using our own error and performance reports.
PesaFii does not use personal data for third-party advertising, does not sell personal data, and does not run third-party marketing or advertising trackers in the product.
7. Lawful grounds for processing
We rely on the grounds recognised by applicable data protection law, including the Uganda Data Protection and Privacy Act. In summary:
- Performance of a contract: processing needed to provide the PesaFii service you or your business signed up for, including operating hotspot access and processing the payments you initiate.
- Legal obligation: keeping financial and transaction records, and responding to lawful requests from authorities.
- Legitimate interests: securing the platform, preventing fraud and abuse, keeping audit trails, and improving reliability, balanced against your rights and interests.
- Consent: where the law requires it for a specific processing activity. Where we rely on consent, you may withdraw it, and withdrawing does not affect processing already carried out.
The precise mapping of each processing activity to a lawful ground is subject to review by Ugandan counsel before this notice is finalised.
8. Hotspot customers: what you should know
If you connect to a WiFi hotspot that runs on PesaFii, you do not need a PesaFii account. Depending on how you use the hotspot, the platform may process:
- the Mobile Money phone number you enter to buy a package;
- the registered account-holder name for that number, returned by the payment provider so the sale is recorded against the correct payer. This name is used internally for transaction and sales records and is not published;
- the package you bought, the amount paid and the payment status;
- your voucher code, if you use one;
- your device's MAC address and assigned IP address, and the times your device connected and disconnected;
- the router/hotspot you connected through and how much data your device used.
This information is used to authenticate your device, deliver the internet access you paid for, reconcile your payment, support you if a payment succeeds but access fails, prevent abuse and fraud, and give the hotspot owner accurate sales and network reports. The hotspot owner you bought access from can see the sales and connection records for their own hotspot.
The captive portal sign-in page links to this notice. Connection records are generated by the hotspot equipment as a necessary part of providing internet access.
9. Mobile Money and payment information
PesaFii uses a licensed Ugandan payment service provider (Yo! Uganda) to process Mobile Money transactions on the MTN and Airtel networks. When a payment, payout or transfer is processed, we share with the payment provider the information needed to execute it: the phone number to charge or pay, the amount, a short payment narrative and our transaction reference. The provider returns transaction statuses and references. Where we use its account-name verification service, it also returns the name registered to a Mobile Money number.
We use name verification to reduce the risk of sending money to a wrong number and to keep honest transaction records. Verified names are stored with the related transaction records. We do not receive or store Mobile Money PINs. The payment provider and mobile network operators process your data under their own terms and privacy notices, which we do not control.
10. Router, device and network data
To provide hotspot access, the platform necessarily processes technical identifiers: device MAC addresses, assigned IP addresses, router identifiers, session times and data volumes. These records are produced by the hotspot router and the RADIUS authentication system whenever a device connects. They make it possible to grant the access that was paid for, enforce package limits, and detect problems or abuse.
Routers are managed by the hotspot operator. Router management traffic between PesaFii and routers travels over an encrypted tunnel. PesaFii does not monitor the content of your browsing; connection records concern the session (when, which device, how much data), not the pages you visit.
11. How we share personal data
- With your hotspot operator: operators and the staff they authorise see the customer, sales, session and network records of their own business. PesaFii's multi-tenant design is intended to keep each business's data separate from other businesses.
- With the payment provider: as described in the Mobile Money section, to process payments, verify names and execute payouts.
- With service providers who host our infrastructure: see the next section.
- Within the platform: a small number of PesaFii platform administrators can access data across businesses for operations, support and billing oversight.
- For legal reasons: where required by applicable law, regulation or a lawful request, or to protect the rights, safety and integrity of the service and its users.
We do not sell personal data and we do not share it with advertisers or data brokers.
12. Service providers and processors
The platform runs on the following categories of providers, based on the current production setup:
- Managed cloud database and backend hosting: the platform database runs on a managed PostgreSQL service (Supabase), and the backend runs on cloud infrastructure.
- Web hosting: the public website and dashboard are served through a cloud web-hosting platform (Vercel).
- Payment services: Yo! Uganda is used for Mobile Money collections, payouts and account-name verification.
- Email delivery: an email (SMTP) provider used to send account verification codes and service emails.
- Network infrastructure: a virtual private server that operates the encrypted tunnel connecting hotspot routers to the platform.
- Fonts: the sign-in page loads the Inter typeface from Google Fonts, which means your browser requests a file from Google when that page opens.
Where a category is listed without a company name, the specific vendor is confirmed at deployment and will be identified, together with the applicable data processing terms, before this notice is finalised. We take reasonable steps to use providers that offer appropriate data protection commitments.
13. International and cross-border processing
PesaFii serves businesses in Uganda, and payments are processed in Uganda by a Ugandan provider. However, parts of our infrastructure are provided by international cloud companies, including the managed database, web hosting, email delivery and fonts. Data handled by those providers may be stored or processed on servers outside Uganda.
The exact hosting locations are being confirmed as part of finalising this notice. Where personal data is transferred outside Uganda, we will take the measures required by the Uganda Data Protection and Privacy Act for such transfers, and this section will be updated with the confirmed details.
14. Data retention
We retain personal data for as long as reasonably necessary for the purposes described in this notice, including providing the service, maintaining transaction and accounting records, resolving disputes and supporting customers, keeping the platform secure, and complying with legal obligations.
- Transaction, payment and wallet records are kept as part of the platform's financial records.
- Connection and session records are kept to support billing, troubleshooting and abuse prevention.
- Administrator accounts that remain unused for a prolonged period may be automatically removed, along with their sign-in sessions.
- Security records such as one-time codes and expired sessions are invalidated after use or expiry.
A formal retention schedule with specific periods per record type is being prepared, and this section will be updated once it is approved. Where law requires records to be kept for a minimum period, that period prevails.
15. Security
We use technical and organisational safeguards appropriate to the nature of the data we process, including:
- encrypted (HTTPS) connections to the platform, and encrypted tunnels between the platform and hotspot routers;
- passwords, withdrawal PINs and one-time codes stored only as cryptographic hashes;
- encryption of stored infrastructure secrets and two-factor authentication secrets;
- two-factor authentication and PIN confirmation, with attempt limits and lockouts, for wallet payouts;
- role-based permissions, per-business data scoping and server-side ownership checks on every request;
- rate limiting and brute-force protection on sign-in and public endpoints;
- revocable per-device sessions, and audit logging of significant actions;
- duplicate-transaction protection on money movements.
No system can guarantee absolute security. If we become aware of a personal data breach that requires notification, we will notify affected people and the relevant authority in accordance with applicable law.
16. Cookies and browser storage
The PesaFii dashboard does not set third-party advertising or analytics cookies, and does not use third-party tracking. It primarily uses your browser's local storage (localStorage and sessionStorage), not cookies, for things the service needs to work:
- Authentication and security: your sign-in tokens, a device identifier used to bind your session to your device, and your basic account profile, so you stay signed in.
- Application state: your selected router, dashboard date ranges, saved search filters and short-lived cached dashboard data.
- Preferences: your light/dark theme choice.
Account-specific values are cleared when you sign out. The hotspot captive portal page does not store credentials in your browser. The platform also sends first-party error and performance reports from the dashboard to our own servers, never to a third-party analytics service, to keep the service reliable.
17. Your privacy rights
Subject to applicable law, you have the right to:
- be informed about how your personal data is processed (this notice);
- request access to the personal data we hold about you;
- request correction of inaccurate or incomplete data;
- request deletion or blocking of data where the law allows. Some records, such as financial and transaction records, must be retained for legal and accounting reasons;
- object to processing for direct marketing (PesaFii does not currently conduct direct marketing);
- not be subject to solely automated decisions with significant legal effects, where the law provides this right;
- lodge a complaint with the data protection authority (see Complaints below).
To exercise these rights, contact privacy@pesafii.net. We may need to verify your identity before acting on a request, and requests are subject to applicable legal limitations. If your request concerns data held about you as a customer of a specific hotspot, we may work with that hotspot operator to resolve it.
18. Children and minors
PesaFii is intended for use by businesses and network administrators, and platform accounts are not directed at children. Public hotspot services may in practice be accessed by users of different ages; hotspot operators are responsible for ensuring that their use of PesaFii, and the way they offer WiFi access, complies with applicable requirements concerning minors. This section is subject to legal review.
19. Automated decision-making
PesaFii does not use personal data for automated profiling or solely automated decisions producing significant legal effects. The platform does apply automated operational rules that are necessary to provide and secure the service. Examples include disconnecting a session when a purchased package expires, temporarily locking a wallet PIN after repeated failed attempts, and rate-limiting repeated sign-in attempts. These are deterministic service and security rules, and this description is subject to legal review.
20. Account closure and data deletion
If you want to close a PesaFii account or request deletion of personal data, contact privacy@pesafii.net. We will action requests subject to the retention obligations described above. In particular, transaction and financial records connected to payments, wallets and payouts must be retained even after an account is closed. Administrator accounts that remain unused for a prolonged period may also be removed automatically.
21. Changes to this notice
We may update this notice as the service, our providers or the law change. The “Last updated” date at the top shows the current version, and material changes will be highlighted on this page. Continued use of the service after an update means the updated notice applies.
22. Contact us
Controller/operator: Agrinal Enterprises Limited, Uganda
Address: Buwambo Kiti, Uganda
Privacy contact: privacy@pesafii.net
Legal notices and other enquiries: legal@pesafii.net
23. Complaints and the data protection authority
If you have a concern about how your personal data is handled, please contact us first at privacy@pesafii.net so we can try to resolve it.
You also have the right to lodge a complaint with Uganda's Personal Data Protection Office (PDPO), the authority established under the Data Protection and Privacy Act. The PDPO's current contact details are available from its official website; please verify them there, as they are maintained by the PDPO and not by PesaFii.