Legal

Privacy Policy

Effective date: 1 June 2026

This Privacy Policy explains how Credit-Nest collects, uses, stores, and protects information about you when you use our loan management platform. We are committed to protecting your privacy and handling your data with care and transparency.

1. Who We Are

Credit-Nest is a Software-as-a-Service loan management platform operated from Kampala, Uganda. References to “Credit-Nest”, “we”, “us”, or “our” in this policy refer to the Credit-Nest platform and its operators.

For questions about this policy, contact us at privacy@credit-nest.stock-nest.com.

2. Information We Collect

We collect different types of information depending on how you use the Service:

Account and registration data: Your name, email address, and password when you create an account. If you create an Organisation, we also collect the organisation name and any details you provide.

Customer Data (loan and borrower data): Information you enter into the Service about your borrowers (names, contacts, identification), loans (amounts, dates, terms, interest), repayments, payments, and collateral. This data belongs to you — we process it only to operate the Service on your behalf.

Usage data: Information about how you interact with the Service, including pages visited, features used, actions taken, and timestamps. This helps us improve the platform.

Device and technical data: IP address, browser type, operating system, and device identifiers, collected automatically when you access the Service.

Communications: If you contact us via email or the contact form, we retain the content of those communications to respond to you and improve our support.

Payment data: When you subscribe, payment processing is handled by our payment processor. We do not store your full payment card details — only a transaction reference and subscription status.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Process your subscription and manage billing
  • Authenticate you and manage your account and Organisation
  • Enable team collaboration features (invitations, role-based access)
  • Respond to your support requests and communications
  • Send account-related notifications (billing, security, service changes)
  • Improve the Service through usage analytics
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with our legal obligations

We do not use your Customer Data (borrower and loan records) for any purpose other than providing the Service to you.

Marketing: We may send you service-related updates and, with your consent, product news. You can opt out of marketing communications at any time.

4. Legal Basis for Processing

We process your personal data on the following legal bases:

  • Contract performance: To provide the Service you have subscribed to
  • Legitimate interests: To operate and improve the Service, and to protect against fraud and abuse
  • Legal obligation: To comply with applicable laws
  • Consent: For marketing communications (you can withdraw consent at any time)

5. Data Sharing and Disclosure

We do not sell your personal data to any third party.

We may share data with the following categories of third parties:

  • Infrastructure providers: Cloudflare (hosting and CDN) and Render (backend hosting) — both process data under their own privacy commitments and our service agreements
  • Payment processors: To handle subscription billing (no full card data is stored by us)
  • Email service providers: To send transactional and account emails
  • Analytics tools: Aggregated, anonymised usage data only

We may also disclose data if required by law, legal process, or to protect the safety and rights of Credit-Nest, our users, or the public.

All third-party service providers are contractually required to handle data securely and only for the purposes we specify.

6. Data Retention

We retain your account and Customer Data for as long as your account is active. If you cancel your subscription, your data is retained for 30 days after account closure to allow you to export it.

After the 30-day retention window, Customer Data is permanently deleted. Billing records and account metadata may be retained for longer periods as required by financial record-keeping laws.

You can request deletion of your data at any time by contacting us at privacy@credit-nest.stock-nest.com.

7. Data Security

We implement industry-standard security measures to protect your data, including:

  • HTTPS encryption for all data in transit
  • Encryption of data at rest
  • Logical tenant data isolation — each Organisation's data is isolated from others
  • Secure session management and authentication via industry-standard libraries
  • Deployment on Cloudflare's global edge network and Render's secure infrastructure
  • Regular security reviews and dependency updates

No system is completely secure. In the event of a data breach that affects your rights or freedoms, we will notify you as required by applicable law.

8. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Request correction of inaccurate or incomplete data
  • Erasure: Request deletion of your personal data (subject to legal retention requirements)
  • Restriction: Request that we limit processing of your data in certain circumstances
  • Portability: Request your data in a structured, machine-readable format
  • Objection: Object to processing based on legitimate interests
  • Withdraw consent: Withdraw consent for marketing at any time

To exercise any of these rights, contact us at privacy@credit-nest.stock-nest.com. We will respond within 30 days. These rights are subject to applicable legal exemptions.

9. Cookies and Tracking

Credit-Nest uses essential cookies and similar technologies to operate the Service, including session cookies for authentication and CSRF protection. These are strictly necessary and cannot be disabled.

We may also use analytics cookies to understand how the Service is used. Where required by law, we will seek your consent before placing non-essential cookies.

You can control cookies through your browser settings, though disabling certain cookies may affect Service functionality.

10. Cross-Border Data Transfers

Your data may be processed in countries other than Uganda, including countries where our infrastructure providers (Cloudflare, Render) operate. Where we transfer data internationally, we ensure appropriate safeguards are in place in accordance with applicable data protection laws.

11. Children's Privacy

Credit-Nest is designed for use by businesses and professionals. We do not knowingly collect personal data from individuals under 18 years of age. If you believe a minor has provided us with personal data, please contact us so we can delete it.

12. Your Borrowers' Data

When you use Credit-Nest to manage your borrowers' data, you are the data controller for that data and Credit-Nest is the data processor. You are responsible for ensuring you have the legal basis to collect and process your borrowers' personal and financial information and that you comply with applicable data protection laws in your jurisdiction, including the Uganda Data Protection and Privacy Act 2019.

We process your borrowers' data only on your instructions and as necessary to provide the Service, as set out in our Terms of Service.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through a prominent notice in the Service at least 14 days before the change takes effect. The effective date at the top of this policy will always reflect when it was last updated.

The current version is always available at https://credit-nest.stock-nest.com/privacy.

14. Contact Us

For any questions, concerns, or requests related to this Privacy Policy or your personal data, please contact our privacy team:

Email: privacy@credit-nest.stock-nest.com
Address: Credit-Nest, Kampala, Uganda
Contact form: credit-nest.stock-nest.com/contact

We take all privacy enquiries seriously and will respond within 30 days.