// Legal

Terms & Conditions

Please read these terms carefully before using HashBack or HashPay services. By accessing or using our Services, you agree to be bound by these Terms.

Effective: 20 March 2026 Governed by Kenyan Law 25 Sections
Republic of Kenya
Hashback Solutions
Language: English
Welcome to HashBack. These Terms and Conditions ("Terms") govern your access to and use of the HashBack platform, services, APIs, and related systems ("Services"). By accessing or using our Services, you agree to be bound by these Terms.
01

Definitions

  • —"HashBack" refers to Hashback Solutions and its platform.
  • —"User" / "You" means any individual or entity using the Services.
  • —"Services" include STK Push, B2C, APIs, dashboards, and integrations.
  • —"Third-Party Providers" include mobile network operators, banks, and payment processors.
02

Eligibility

You must:

  • Be at least 18 years old
  • Have the legal capacity to enter into a binding contract
  • If acting on behalf of a business, have authority to bind that entity
HashBack reserves the right to request proof of eligibility at any time.
03

Account Registration & Security

You agree to:

  • Provide accurate and complete information
  • Maintain confidentiality of your credentials
  • Be fully responsible for all activity under your account
HashBack is not liable for losses arising from unauthorized account access due to your failure to secure credentials.
04

Services Description

HashBack Solutions operates a technology platform for Kenyan businesses, made up of the products described below. One account gives access to all of them and they share a single balance; you pay only for what you use.

HashBack is not a bank, does not hold customer deposits, and is not a party to transactions between you and your customers. Money moves over Safaricom M-Pesa and our banking partners; we provide the software that initiates, records and reconciles it.

4.1 — HashPay (payment collection)

Collection of customer payments over M-Pesa: STK Push prompts, C2B Till and Paybill confirmations, payment links, hosted checkout, QR payments, webhooks and automated reconciliation. Payment channels are provisioned, reviewed and activated by HashBack, and may be operated on a subscription or, after a first completed subscription month, on Pay-As-You-Go. A sandbox mode is available for testing before go-live, restricted to numbers you have nominated and verified.

4.2 — Wallet as a Service (payouts and payroll)

Merchant wallets, B2C disbursements, bulk payment and payroll runs, withdrawals to M-Pesa or bank, float management, transaction ledgers and receipts. Payout fees are charged per payout on a published scale that varies with the amount. Funds held in a wallet are held for settlement purposes only and are not a deposit, do not earn interest, and confer no banking relationship.

4.3 — HashPay SMS (bulk messaging)

Bulk and transactional SMS delivered through our licensed messaging partner, with contact groups, templates, scheduling, per-recipient delivery reports and a REST API. Messages may be sent under a shared sender ID or, once approved and mapped to your account, your own registered sender ID; registration of a sender ID attracts a separate fee. SMS is billed per 168-character unit at a single flat rate regardless of which sender ID is used. Promotional traffic carries an opt-out line as required by Kenyan regulation, and the characters it adds are billed.

4.4 — WhatsApp messaging

One-time passwords, transaction alerts, receipts and customer notifications delivered over the WhatsApp Business platform. Use is additionally subject to WhatsApp's and Meta's own policies on what may be sent, to whom, and when; we cannot override those rules on your behalf.

4.5 — HashBack (MSISDN hash decoding)

Decoding of the hashed mobile numbers that appear in Safaricom M-Pesa C2B callbacks, so a payment can be matched to a payer. Sold as pay-as-you-go credits at a per-request rate set by your plan, with a minimum top-up per plan. Credits do not expire and no credit is charged for a failed decode. Decoding is available for Kenyan mobile numbers only, and may only be used against callbacks for payments genuinely made to you.

4.6 — Supporting tools

  • —Short links for receipts and payment pages.
  • —Service tokens which pay for notifications and certain per-request features; each notification sent on your behalf consumes a token.
  • —Developer tooling — API documentation, sandbox, and C2B/B2C callback simulators.
  • —A stablecoin wallet, where enabled on your account, subject to the separate risks and charges disclosed in the wallet itself.

4.7 — Custom systems

We also build bespoke systems — retail and point-of-sale, transport and fleet, property and rentals, ERP, web and mobile applications — on separately agreed terms. Nothing on our website constitutes a quotation, a delivery date or a commitment to build.

4.8 — Abuse controls applied to payer numbers

Repeatedly prompting a mobile number that does not complete the payment is abusive to that subscriber and puts our access to Safaricom's platform at risk. HashBack therefore operates automated controls on the numbers your channels prompt:

  • Repeated cancellations. A mobile number that repeatedly cancels payment prompts from the same account — more than five cancellations within an hour, or more than three across a day — is placed on a temporary watchlist for that account. Prompts the customer simply ignores or leaves to time out count the same way.
  • While watchlisted, further prompts from that account to that number are silently not delivered. Your request is accepted and answered normally, but no prompt is sent. This is deliberate: an alert would simply tell an abusive sender how to work around the control.
  • The same applies to numbers that repeatedly come back as unreachable or non-existent.
  • Watchlisting is temporary and lifts automatically. Thresholds and durations are set by us, are not published, and may change at any time without notice.
  • Separately, an account whose confirmed-success rate falls below the required floor across its recent prompts may be moved to Pay-As-You-Go, restricted, or suspended.
You remain charged for prompts that are genuinely delivered, whatever the customer does next. Prompts suppressed by these controls are not delivered and are not charged.

4.9 — Removal of accounts, channels and linked records

To keep the platform and our partner integrations clean, HashBack may deactivate, purge or permanently delete accounts, payment channels and linked records — including any data held in them — in the following cases:

  • Dormant accounts or channels with no genuine activity over an extended period.
  • Channels pending renewal or left expired after a subscription has lapsed.
  • Channels registered but never activated, and registrations abandoned before completion.
  • Accounts involved in fraud, attempted fraud, impersonation or money laundering, or used to collect payments under false pretences.
  • Accounts showing other suspicious activity, including prompt spamming, testing of stolen card or M-Pesa credentials, evasion of a suspension, or abuse of another person's identity or shortcode.
Purging is permanent and data removed in this way cannot be recovered. Export anything you need to keep before an account or channel lapses. Where fraud or a legal obligation is involved, we may instead retain records for as long as the law requires, and we may report the matter to Safaricom, our banking partners, or the authorities.

Settled funds belonging to you that are held at the time of closure remain payable to you, subject to our verification, any applicable investigation, and any deduction we are lawfully entitled to make.

05

KYC, AML & Compliance

You agree to:

  • Provide all required KYC documentation
  • Comply with all applicable anti-money laundering (AML) and counter-terrorism financing (CTF) laws
  • Cooperate with verification requests

HashBack reserves the right to:

  • Monitor transactions
  • Report suspicious activity to authorities
  • Suspend accounts pending compliance review
06

Transaction Control & Limitations

HashBack may, at its sole discretion:

  • Delay, reject, cancel, or reverse transactions
  • Set transaction limits
  • Suspend services due to risk, fraud, or regulatory requirements
HashBack does not guarantee successful transaction completion, real-time processing, or accuracy of third-party systems.
07

Fees & Charges

All applicable fees will be communicated through the platform or official channels. You agree that:

  • Fees may change with notice
  • Transaction fees are non-refundable, except where required by law

See our Pricing Page for current rates.

08

Refunds, Reversals & Errors

  • Users are responsible for verifying transaction details before submission
  • HashBack does not guarantee reversals of completed transactions
  • Duplicate or erroneous payments may be addressed at HashBack's discretion
09

User Responsibilities

You agree:

  • Not to use the platform for illegal or fraudulent purposes
  • To verify the legitimacy of your customers
  • To comply with all applicable laws and regulations

You are solely responsible for:

  • Fraudulent transactions initiated through your account
  • Disputes with your customers
10

Fraud & Risk Liability

HashBack shall not be liable for fraud committed by customers or third parties, unauthorized payments from your system vulnerabilities, or social engineering / phishing attacks affecting your account.
  • Fraud committed by your customers or third parties
  • Unauthorized payments resulting from your system vulnerabilities
  • Social engineering or phishing attacks affecting your account
11

Third-Party Services

HashBack relies on third-party providers including mobile networks and financial institutions. We are not responsible for:

  • Downtime or failures from mobile networks or banks
  • Delays in transaction processing
  • Errors caused by external systems
12

Service Availability

Services are provided on an "as is" and "as available" basis. HashBack does not guarantee continuous uptime, error-free operation, or uninterrupted access.
13

User Content

You grant HashBack a non-exclusive, worldwide license to use, store, and process data you submit, and to analyze transaction data for service improvement and compliance.

You retain ownership of your data at all times.
14

Data Protection & Privacy

HashBack processes personal data in accordance with applicable data protection laws. We may collect and process:

  • Identity information
  • Transaction data
  • Device and usage data

You have the right to:

  • Access your data
  • Request correction or deletion where applicable
Kenya Data Protection Act compliance is required for all data processed through our APIs.
15

Intellectual Property

All platform content, APIs, and systems are owned by HashBack. You may not:

  • Copy, modify, or reverse engineer the platform
  • Use the platform beyond the permitted scope of these Terms
16

Indemnification

You agree to indemnify and hold harmless HashBack from any claims, damages, or losses arising from:

  • Your misuse of the Services
  • Your violation of these Terms
  • Disputes between you and your customers
17

Limitation of Liability

To the maximum extent permitted by law, HashBack shall not be liable for indirect or consequential damages, loss of profits, revenue, or data, or transaction failures due to third-party systems.
18

Termination & Suspension

HashBack may suspend or terminate your account for:

  • Violation of these Terms
  • Suspected fraud or illegal activity
  • Regulatory or compliance reasons
You may terminate your account at any time by contacting our support team.
19

Dispute Resolution

Any disputes shall be resolved through:

  • 1.Negotiation in good faith between the parties
  • 2.If unresolved, arbitration in Nairobi, Kenya in accordance with applicable arbitration laws
All proceedings shall be conducted in English.
20

Governing Law

These Terms are governed by and construed under the laws of the Republic of Kenya.

21

Entire Agreement

These Terms constitute the entire agreement between you and HashBack and supersede all prior agreements, representations, and understandings.

22

Severability

If any provision of these Terms is found invalid or unenforceable by a court of competent jurisdiction, the remaining provisions shall continue in full force and effect.

23

Changes to Terms

HashBack may update these Terms at any time. Significant changes will be communicated via email or dashboard alerts.

Continued use of the Services after updates constitutes your acceptance of the revised Terms.
24

Contact Information

For legal inquiries or questions about these Terms, contact us at:

25

HashPay P2P — Privacy & Data Use

This section applies specifically to users of the HashPay Peer-to-Peer (P2P) payment services, including P2P gateways, payment automations, and related integrations.

Your P2P data is private. HashPay does not share P2P transaction data, gateway configurations, or automation settings with any third parties.

25.1 — Data Ownership & Exclusivity

  • All data generated through your use of HashPay P2P services — including transaction records, recipient details, gateway configurations, and automation rules — belongs exclusively to you, the user.
  • This data is used solely to power your own gateway and your own automations. It is not pooled, sold, or made accessible to other users or external parties.

25.2 — No Third-Party Data Sharing

  • HashPay will not sell, rent, or otherwise disclose your P2P data to any third party.
  • Your P2P data will not be shared with advertisers, data brokers, or any commercial third parties.
  • Disclosure may occur only where required by law (e.g., court order, regulatory directive) or as strictly necessary to process your transactions through mobile network operators and financial institutions under Section 11.

25.3 — Service Improvement & Analytics

HashBack may use aggregated, anonymised analytics derived from P2P activity across the platform to:

  • Improve the reliability, performance, and security of the HashPay P2P infrastructure
  • Develop new features and optimise existing P2P gateway capabilities
  • Monitor platform health and detect fraud patterns at a systemic level
Any analytics used for service improvement are aggregated and anonymised — they cannot be traced back to your individual account, transactions, or customers.

25.4 — Data Retention

  • P2P transaction data is retained for as long as your account is active and as required by applicable Kenyan law and regulatory obligations.
  • Upon account termination, your personal P2P data will be deleted or anonymised within a reasonable period, except where retention is legally required.

25.5 — Your Rights

  • You may request access to your P2P data at any time by contacting HashBack support.
  • You may request correction of inaccurate data or deletion of data where legally permissible.
By using HashPay P2P services you confirm that you have read and agree to the data practices described in this section, which supplement and are governed by the broader privacy obligations in Section 14 of these Terms.
⚖️ Your Agreement

By using HashBack, you acknowledge that you understand the risks involved in digital payments and accept full responsibility for your use of the platform. You confirm that you have read, understood, and agreed to all 25 sections of these Terms.

Effective: 20 March 2026 hashbacksolutions@gmail.com