Last updatedJuly 2026
Plain and short: it's your restaurant's data, we look after it, and we don't sell it. The detail is below.
This policy explains how Xenia handles data for the restaurants that use it and for the people who visit this website. Xenia is a restaurant point‑of‑sale service operated from Nairobi, Kenya.
We use your data to run the service for you: to take orders, process payments, produce KRA‑compliant receipts, generate your reports and provide support. We do not sell your data, and we do not share it with anyone except where it is needed to deliver the service or where the law requires it.
M‑Pesa payments are processed by Safaricom through the Daraja API. We pass the details needed to request and confirm a payment, and we record the result against the order. We do not store card numbers. Card payments, where used, are handled by the payment provider, not by us.
To keep your sales compliant, invoice data is shared with the Kenya Revenue Authority through eTIMS as required by law. This is a normal part of issuing a fiscal receipt and applies to every VAT‑registered business.
Your data is encrypted in transit, access is limited to the people who need it to support you, and we back up your data regularly. No system is perfectly secure, but we take reasonable, up‑to‑date measures to keep yours safe.
It is your business data, not ours. You can ask us for a copy of the data we hold about you, ask us to correct anything that is wrong, or ask us to delete it — except where we are obliged to keep certain records for tax, legal or security reasons. Just get in touch and we will sort it out.
We keep your data for as long as you use Xenia. If you decide to leave, tell us and we will help you export what you need and remove the rest, keeping only what the law requires us to hold on to.
If anything here is unclear, or you want to make a request about your data, email us at hello@byte.co.ke and a real person will get back to you.