- We collect what it takes to run a wallet and a payment: your email, your name and country once you verify, your balance, and payment records. There is no password.
- Checkout shows the company name. Your name is not shown to the buyer or written to a public ledger.
- We do not sell personal information. We do not run advertising trackers. We do not offer sign-in with Google or any other company.
- We share only what a payment needs: the payment result with the company, and a withdrawal with the method you chose.
- You can ask to see, correct, export, or delete your information by writing to us.
01About this notice
This Privacy Notice explains how Nuru Shillings (“Nuru”, “we”, “us”) collects, uses, shares, protects, and keeps personal information when you visit our website, open an account, hold a balance, pay a company, withdraw, or connect the payments API.
It should be read with the Terms of Service, which set the rules of the product, and the Security page, which describes the controls around accounts, keys, and payments.
02Who is responsible
Nuru Shillings is responsible for the personal information described in this notice (the “controller” in data-protection law). You can reach us at norashillings@benuru.com for privacy questions and at supportnorashillings@benuru.com for help with an account or a payment.
When a company accepts Nuru inside its own platform, that company is a separate controller for the information it collects in its own website, app, account system, or marketing list. Its own privacy notice applies to that information.
03Who this notice covers
- Visitors who read this website without an account.
- Wallet holders who buy, hold, spend, or withdraw Nuru Shillings.
- Companies named on a checkout, and the people who act for them.
- Developers who hold an API key and receive webhooks.
- People who contact us by email.
04Information you give us
When you open an account
- Your email address. We send a one-time sign-in link to it; there is no password.
- A one-way hash of each sign-in link, the IP address that asked for it, and when it was used. We keep the hash, never the link itself.
- A one-way hash of your session, and when it expires.
- The time you joined and the time you last signed in.
When you verify
- The name on the account and your country. Verification is free and done once before live money moves.
- If the details do not match, or the law requires it, we may ask for more information. We will tell you why when we ask.
When you contact us
- Your email, its contents, and any payment id you include, so we can answer and keep a record of the request.
05Information created by payments
Every payment produces a record with these fields:
| Field | What it holds |
|---|---|
| id | The payment id, for example pay_1042 |
| status | pending, paid, or refunded |
| mode | test (Sandbox) or live |
| fee | The 1% fee the company pays on the payment |
| amount and unit | The amount in NSH, for example 1800 and NSH |
| company | The company name the buyer saw at checkout |
| chain | private — the record is not written to a public ledger |
| reference | The order id the company supplied |
A wallet also keeps its balance and the activity that changed it: money added, a payment sent, a refund received, or a withdrawal, with the method used (PayPal, a card, or M-Pesa). A refund record points back to the original payment id. We do not need your home address to take a payment.
If you use Business tools, we also keep a one-way hash and the last four characters of each API key, the https webhook URL you saved for Sandbox and for Live, and the events sent to that URL with their delivery result. A live payment also records the wallet that paid it.
06Information collected automatically
- Technical data. When your browser loads a page, our servers receive standard request data such as your IP address, browser type, and the page requested. We use it to deliver the page, keep the Service secure, and investigate abuse.
- Browser storage. The site sets one sign-in cookie and stores two small preferences in your browser. See section 17.
- Fonts. This website loads the Inter and IBM Plex Mono typefaces from Google Fonts. Your browser therefore sends a request, including your IP address, to Google when a page loads. This is not a sign-in and does not give Google your Nuru account.
We do not use advertising cookies, cross-site tracking pixels, or third-party analytics that build a profile of you.
07Information from others
- Payment methods. PayPal, your card issuer, or your mobile-money provider tells us whether money you added or withdrew succeeded, failed, or was reversed.
- Companies. A platform tells us the amount, the unit, the company name, and its own reference when it creates a payment.
08How we use information and why
| Purpose | Information | Legal basis |
|---|---|---|
| Open your account and sign you in | Email, sign-in link hash, session hash | Contract |
| Verify you before live money moves | Name, country | Contract; legal obligation |
| Add money, pay, refund, and withdraw at 100 NSH = 1 USD | Balance, payment records, method | Contract |
| Show the company name and return the result to the platform | Payment record | Contract |
| Charge the 1% fee and return it on a refund | Payment record | Contract |
| Send webhooks to the developer’s https endpoint | Event id, type, payment id, reference, status | Contract |
| Prevent fraud, scripted sign-ups, and abuse | IP address, request limits, technical data, activity | Legitimate interests; legal obligation |
| Answer support requests and complaints | Email, payment id | Contract; legitimate interests |
| Send notices about the Terms, fees, or security | Contract; legal obligation | |
| Meet accounting, tax, and lawful requests | Payment records, verification | Legal obligation |
We do not use your information to decide credit, set prices for you personally, or show you advertising.
09What other people can see
- The buyer at checkout sees the company name and the amount. They do not see another customer’s name.
- The company receives the payment result: id, status, amount, unit, company, chain, and the reference it supplied. It does not receive your whole wallet, your balance, or your other payments.
- The public sees nothing. Payments are settled on a private chain and are not published on a public ledger.
10When we share information
We share personal information only in these cases:
- With the company you pay — the payment result listed in section 09.
- With your payment method — PayPal, your card issuer, or your mobile-money provider receives what it needs to process money you add or withdraw, such as the amount and the account, card, or phone number you gave.
- With service providers who host, secure, or send email for the Service, under a written contract that allows them to use the information only to provide that service to us.
- With authorities when the law that applies to Nuru requires it, or to respond to a lawful order. Where the law allows, we tell you first.
- To protect people and the Service — to investigate fraud or a breach of the Terms, or to protect the safety of a person.
- In a business transfer — if Nuru is merged or acquired, the new owner must honour this notice. We will tell you before your information is subject to a different notice.
11What we never do
- We do not sell or rent personal information, balances, payment references, company names, or email addresses.
- We do not share your information for advertising.
- We do not publish payments on a public ledger.
- We do not offer sign-in through Google or any other company.
- We never ask you to forward a sign-in link or to share your secret API key, your M-Pesa PIN, or your card security code.
12International transfers
Nuru is a worldwide service, so your information may be processed in a country other than your own. When we transfer personal information across borders, we use safeguards required by the applicable law, such as contractual protections with the recipient, and we only transfer what the purpose needs.
13How long we keep it
| Information | How long |
|---|---|
| Account details | While the account is open, then up to 2 years to handle disputes |
| Verification name and country | While the account is open, then as long as the law requires |
| Payment and refund records | While the account is open, then as long as accounting and financial law requires |
| Webhook events | 90 days |
| Support emails | 2 years after the request is closed |
| Technical request logs | Up to 90 days, longer only if needed to investigate abuse |
| Sign-in links | Expire after 20 minutes; the hashed record is kept only as long as needed to stop abuse |
| Sessions | Up to 30 days, or until you log out |
| Cookie and preferences on your device | See section 17 |
When a retention period ends, we delete the information or make it anonymous. Payment ids already created may be kept so a refund can still be matched to the original payment.
14How we protect it
- There are no passwords to leak. Sign-in links, sessions, and API keys are stored only as one-way hashes.
- A sign-in link works once and expires after 20 minutes. Requests for links are limited per email and per IP address.
- A live key cannot be created until the account is verified, and test keys can never move a live balance.
- Webhook endpoints must use https and cannot point at private network addresses.
- A hidden form field stops simple scripts from opening accounts.
- Access to payment records is limited to the people who need it to run the Service.
No system is perfectly secure. If a breach affects your personal information, we will tell you and the relevant authority without undue delay where the law requires. More detail is on the Security page.
15Your rights
Depending on where you live, you may have the right to:
- Access — get a copy of the personal information we hold about you.
- Correction — fix information that is wrong or incomplete.
- Deletion — ask us to delete information we no longer need, subject to records we must keep by law.
- Restriction — ask us to limit how we use your information while a question is resolved.
- Objection — object to use based on our legitimate interests.
- Portability — receive your account and payment records in a common, machine-readable format.
- Withdraw consent — where we rely on consent, withdraw it at any time.
- Complain — lodge a complaint with the data-protection authority where you live or work.
We will not treat you differently for using these rights.
16How to make a request
Email norashillings@benuru.com from the address on your account and say which right you want to use. Include a payment id if the request is about a payment. We may ask you to confirm your identity before we act. We will reply within 30 days; if a request is complex, we may extend that by up to 60 days and will tell you why.
We will never ask you to send a sign-in link or a secret key to make a request.
17Cookies and browser storage
This website does not set advertising or analytics cookies. Your balance, activity, and keys live on our servers, not in your browser. The browser holds only these items:
| Name | Type | Purpose | Lasts |
|---|---|---|---|
nsh_session | Cookie (HttpOnly, Secure) | Keeps you signed in. Page scripts cannot read it. | 30 days, or until you log out |
nsh-mode | Local storage | Remembers whether you last chose Sandbox or Live | Until you clear it |
nsh-next | Local storage | Remembers the page to return to after you open a sign-in link, such as a checkout | Removed once you are signed in |
These items are strictly necessary for the Service. You can remove them at any time in your browser settings; you will then be signed out.
18Emails we send
We send service emails about your account, verification, payments, security, and changes to the Terms. You cannot opt out of these while the account is open because they are part of the Service. We do not send marketing email unless you have asked for it, and every marketing email will include a way to stop.
19Automated checks
We use automated checks, such as a hidden form field at sign-up and limits on repeated requests, to stop abuse. We do not make decisions that have legal or similarly significant effects on you based solely on automated processing. If a check blocks you, you can write to us and a person will review it.
20Children
Nuru is not for children. You must be at least 18, or the age of legal majority where you live, to open an account. If we learn that a child has opened an account, we will close it and delete the information we are not required to keep.
21Other websites
A company that accepts Nuru, and payment methods such as PayPal or M-Pesa, run their own services under their own privacy notices. This notice does not cover them. Read their notices before you give them information.
22Changes to this notice
If we change this notice, the “Last updated” date at the top changes. If a change materially affects how we use your information, we will email you before it takes effect. The version published on this page is the one that applies.
23Contact
Privacy questions and requests: norashillings@benuru.com
Account and payment help: supportnorashillings@benuru.com
Nuru Shillings · Privacy Notice · Version 10 October 2026