← Back to Kantini

Privacy Policy

Last updated: 30 September 2026

Kantini is a cashless wallet for school payments. Parents fund a wallet, and a student pays at the school canteen by holding a palm over a reader or tapping a Kantini wristband or card. This policy explains what we collect, why, who we share it with, and how you get it deleted.

It covers the Kantini parent app, the Kantini web portal, the point-of-sale terminals used inside schools, and the Kantini backend service.

Who is responsible for your data

Kantini is operated by Kantini LTD, in Kampala, Uganda. Kantini LTD is the data controller for the information described here. For any question about this policy or about your data, contact ugkantini@gmail.com.

What we collect

From parents

Data Why we need it
Phone number It is how you sign in. We send a one-time code to verify it.
Name, email address, occupation, profile photo To identify your account and show it back to you. All optional except your name.
Deposit and spending history To show you where the money went, and to keep an auditable record.

About your children

You provide this when you register a child, or your school does:

  • Name, school, class, and student number
  • Wallet balance, spending, and daily spending limit
  • A photograph, taken at the school when they are registered
  • A palm template, if the school enrols one
  • The serial number of a card or wristband, if they are given one

Palms, stated plainly

We never capture or store a photograph of a palm. The reader in the school terminal looks at the pattern of veins beneath the skin using infrared light, and converts it to a mathematical template. That template cannot be turned back into an image of a hand, and it cannot be used to unlock anything outside Kantini.

The template is stored on our servers, and copies are sent to the terminals at that child's school so a payment can be checked. The comparison itself happens on the terminal, not on our servers. A terminal is only ever given the templates of children at its own school, and a terminal with no school recorded against it is given none at all. We would rather say this directly than imply that nothing biometric ever leaves the device.

The infrared images the reader captures while looking for a palm are never stored and never sent anywhere. Only the template is kept.

Palms are only ever enrolled at school, on a terminal or an administrator's device. The parent app does not collect biometrics at all.

A palm is not required. A child can be given a card or a wristband instead, and we keep only that item's serial number, which is not biometric and identifies nothing outside Kantini. A school that would rather not enrol any palms can run entirely on cards.

Photographs

A child's photograph is taken when they are registered, so that whoever is serving them can see they are handing food to the right pupil. School terminals have no camera, so the photograph is taken on a phone: the terminal shows a one-time code, the phone that scans it opens a single page, and the photograph goes straight to that one child's record. That link works once and expires after ten minutes.

The photograph is shown in the parent app, the school's own screens, and at the till. It is not used for face recognition, and we do not run any face matching anywhere in Kantini.

What we do not collect

  • Card numbers, mobile money PINs, or any payment credential. Payments are handled by Pesapal; we receive only the result.
  • Location data.
  • Contacts, photos, or files, beyond a profile picture you deliberately choose.
  • Anything for advertising. We do not sell data and we do not run ads.

Who we share it with

Who What they receive Why
Google Firebase and Google Cloud All account and wallet data They host our database, our sign-in, and our servers.
Pesapal Your phone number and the amount, when you deposit They process the payment. They receive no student data.
Your child's school That child's wallet, spending, and enrolment status Administrators manage students and canteen terminals.

We share your data with nobody else, except where the law requires it.

Where it is stored

On Google Cloud servers in Johannesburg, South Africa, which means your data leaves Uganda. Google infrastructure carries its own data protection commitments.

How long we keep it

  • While your account is open: for as long as you use Kantini.
  • Palm templates: deleted when a student leaves the school, or whenever you ask us to remove them.
  • Photographs: deleted with the student record, or whenever you ask us to remove them.
  • Card and wristband serial numbers: deleted when the item is unassigned or the student leaves.
  • Transaction records: kept for seven years after your account closes. Financial records must be retained, so we cannot delete these on request. They are held separately from your contact details.

Your rights

Under the Data Protection and Privacy Act, 2019, you may ask us to:

  • Show you the data we hold about you and your children
  • Correct anything that is wrong
  • Delete your account and its data — see Delete your account
  • Remove a palm template, a card, or a photograph while keeping the wallet
  • Stop processing your data, accepting that the wallet then stops working

Write to ugkantini@gmail.com and we will reply within 30 days. If our answer does not satisfy you, you may complain to the Personal Data Protection Office of Uganda.

Children

Kantini holds data about schoolchildren, but children do not use Kantini. There is no student app and students hold no account. A student's only interaction with the system is holding a palm over the reader, or tapping a wristband or card, at the till.

Only a parent, a guardian, or an authorised school administrator can create or manage a student record. By registering a child you confirm you have the authority to do so.

How we protect it

  • All traffic between the apps and our servers is encrypted with HTTPS.
  • Our database refuses direct access from apps. Everything passes through our server, which checks who is asking on every request.
  • Parents can only ever see their own children. This is enforced on the server using your verified phone number, never by anything the app claims.
  • Each canteen terminal holds its own key. A lost terminal is switched off centrally and immediately, without anyone touching the device.
  • Terminal keys are stored only as cryptographic hashes, so not even we can read them.

No system is perfect. If you believe your account has been misused, contact us immediately and we will freeze the wallet.

Changes to this policy

If we change this policy in a way that affects you, we will tell you in the app before the change takes effect.