Privacy

What we do with your information

This page explains exactly what Merik Network Co. collects when you use this site, why we collect it, who else gets to see it, how long we keep it, and what you can tell us to do about it. We have written it to be read, not to be survived.

Last updated 28 August 2026 Eldoret, Kenya support@merikagency.com

The short version

  • We collect what we need to run an account, take a payment, deliver a course or a guide, and let you message other members. Nothing beyond that.
  • We do not sell your information. Not to anyone, not ever, and not in a rephrased form that technically is not selling.
  • We do not run Google Analytics, the Meta pixel, or any advertising tracker on this site today. If that changes, this page changes first.
  • We never see your card number or your M-Pesa PIN. Those go straight to the payment provider.
  • You can hide when you were last online, stop every marketing email with one click, download what we hold, and ask us to delete your account.
  • If something here worries you, email support@merikagency.com and a person will read it.

1. Who we are

Merik Network Co. is a technology company based in Eldoret, Kenya. We build websites and software for businesses, we run an online learning platform called Merik Academy, we publish paid written guides for business owners, and we operate a small community and code playground for members. This site, merikagency.com, is where all of that lives.

In the language of the Kenyan Data Protection Act, 2019, we are the data controller for the information described on this page. That means we are the ones who decide what is collected and why, and we are the ones you hold responsible for it. Our contact address for anything on this page is support@merikagency.com.

If you are reading this from the European Union or the United Kingdom, the General Data Protection Regulation may also apply to you. Where it does, the rights in section 12 are yours as well, and we handle them the same way for everybody rather than running two different standards.

2. What we collect

It is easier to be honest about this if we split it into three: what you type in yourself, what the site records as a side effect of you using it, and what we are told by somebody else.

2.1 What you give us directly

  • Your account. A name, a username, an email address, and a password. We never store the password itself. What is saved is a one way hash, which means that even we cannot read it, and if our database were ever stolen the passwords would not come with it in a usable form. If you sign in with Google instead, we do not have a password for you at all.
  • Your profile. Anything you choose to add: a short bio, a photograph, a timezone, links to your work. All of this is optional and all of it can be edited or emptied at any time from your profile page.
  • Messages you send. Direct messages to other members, and any files or images you attach to them. These are stored so that the conversation still exists when you come back to it.
  • Things you post publicly. Community posts, comments, reactions, code you save in the playground, and projects you publish. You choose whether these exist.
  • Enquiries. If you use the contact form or the client questionnaire, we keep your name, your email, and what you wrote, because we need it to answer you.
  • Job applications. If you apply through the careers page, we keep your CV and whatever you wrote alongside it.
  • Identity documents. Only if you are appealing a suspended account and you choose to send them. This is the most sensitive thing on the site and section 9 deals with it separately.

2.2 What the site records as you use it

  • Sign in attempts. The time, whether it worked, and the IP address it came from. We keep this because it is the only way to notice somebody trying to break into your account, and because it is what lets us show you the recent activity list on your own security page.
  • When you were last around. A single timestamp, refreshed while you have the inbox, the community, or the playground open in a visible tab. It is not recorded while you read a guide, pay an invoice, or sit on your profile, because being logged in somewhere is not the same as being available to talk. You can switch this off entirely, and if you do we stop recording it and erase what was there.
  • Whether you are typing. While you are typing a message to somebody, that fact is stored briefly so their screen can show it. It is only ever visible to the person you are typing to, it says nothing about what you are writing, and it clears itself within seconds of you stopping.
  • Your learning. Which courses you enrolled in, which lessons you completed, your quiz attempts and scores, and any certificates issued to you.
  • Your purchases. What you bought, when, how much was charged, in which currency, and the reference number from the payment provider.
  • Ordinary server logs. Our host records the usual technical information about requests, including IP addresses. This is standard for every website on the internet and is used for security and for fixing faults.

2.3 What other people tell us about you

  • Google, if you choose to sign in with your Google account. We receive your name, your email address, and your profile picture. We do not receive your Google password and we cannot read anything else in your Google account.
  • Payment providers, when a payment succeeds or fails. We are told the amount, the currency, a reference number, and in the case of M-Pesa the phone number that paid. We are never told your card number, your CVV, or your M-Pesa PIN.
What we deliberately do not collect. We do not ask for your date of birth, your national ID number, your physical address, or your gender, because none of those are needed to run this site. We do not track you across other websites. We do not build an advertising profile of you. There is no analytics script and no advertising pixel on this site at the time of writing, and section 15 explains what we will do if that ever changes.

3. Why we use it, and what allows us to

Under the Data Protection Act we have to have a lawful reason for every use, not just a good intention. Ours are these.

What we doWhyWhat allows it
Create and run your account You cannot have an account without one Performance of our agreement with you
Take payment and give you what you bought To deliver the course, plan, or guide Performance of our agreement with you
Send receipts, verification codes, password resets You need them, and some are legally required records Agreement, and legal obligation
Show your messages, posts, and presence to the people you chose It is the feature you are using Performance of our agreement with you
Keep sign in records and block abuse To protect your account and the site Our legitimate interest in a secure service
Answer your enquiry You asked us something Your request, and our legitimate interest in replying
Send you news about new guides You asked to be told Your consent, which you can withdraw at any time
Keep financial records Tax and accounting law Legal obligation

Where the basis is consent, you can take it back whenever you like and it costs you nothing else. Unsubscribing from guide announcements does not affect your receipts, your password resets, or anything you have paid for.

4. Cookies and local storage

We use very few. There is no advertising cookie on this site and no cookie that follows you to somebody else's website. Here is the complete list.

NameWhat it doesHow long
PHPSESSID Keeps you signed in as you move between pages. Without it every click would log you out. Until you close the browser
mr_rm Set only if you tick "remember me" when signing in, so you are not asked again on your next visit. Until it expires or you sign out
pg_theme Stored in your browser, not sent to us. Remembers whether you chose the light or dark editor theme. Until you clear your browser data
mk_app_ver, mk_install_dismissed Stored in your browser, not sent to us. Remembers that you dismissed the "get the app" bar so we stop showing it. Until you clear your browser data

Your currency choice and your timezone are held in the same session as your sign in, so the prices and the times you see match where you actually are. Google reCAPTCHA, which protects the contact form from automated abuse, sets its own cookies when that form is on screen. That is Google's, and their privacy policy governs it.

5. Payments

We accept M-Pesa through Safaricom's Daraja service, cards through Paystack, and cryptocurrency through NOWPayments. In every case the actual payment happens on the provider's system, not ours.

This matters more than it sounds. It means that your card number never touches our server. Neither does your CVV, your M-Pesa PIN, or your wallet's private key. We could not leak them if we tried, because we never have them. What we receive back is a confirmation: an amount, a currency, a reference number, and for M-Pesa the paying phone number, which we keep so that we can find your payment again if you ask us about it.

We keep a record of what you bought and what you were charged. We have to: it is your receipt, it is how your access is granted, and it is a financial record we are required to hold. You can see all of it yourself under Payment History on your profile.

6. Who else sees your information

We do not sell personal information and we do not share it for anyone else's marketing. We share it only with the companies we need in order to run the service, and only the part each of them needs.

WhoWhat they getWhy
IONOSEverything, as our hosting and email providerThe site and the database physically live there, and our email is sent through them
Safaricom (M-Pesa Daraja)The amount and the paying phone numberTo take an M-Pesa payment
PaystackYour email and the amountTo take a card payment
NOWPaymentsThe amount and an order referenceTo take a cryptocurrency payment
GoogleYour name, email and picture, if you use Google Sign In. Separately, reCAPTCHA sees your interaction with the contact form.Sign in, and blocking automated abuse
Your browser's push serviceAn anonymous subscription token, only if you enable notificationsApple, Google or Mozilla deliver the notification to your device

We will also disclose information if the law genuinely requires it, for example a valid court order. If that ever happens we will tell you unless we are legally prevented from doing so.

If the business is ever sold or merged, your information would move with it. You would be told before that happened, and the new owner would be bound by this notice until they published their own.

7. Email and notifications

There are two kinds of email from us, and they are governed by different rules.

Emails you cannot switch off are the ones the service cannot work without: your verification code, a password reset, a payment receipt, a notice that your account has been suspended or reinstated. These are not marketing. Turning them off would mean sending you a code you never receive.

Emails you can switch off are everything else: announcements about new guides, and general news. You only get these if you asked for them, every one carries an unsubscribe link, and the link works in one click without asking you to sign in first. Leaving the new guides list does not stop your receipts, and leaving everything does not stop your password resets.

Our marketing emails contain a small invisible image that tells us the message was opened. It records that an open happened and when, tied to the address we sent to. It does not read your inbox and it cannot see anything else. If you would rather not be counted, most email apps have a setting to stop loading remote images, and blocking them does not affect the content of the message. Delivery counts and open counts are used for one purpose only, which is to see whether an announcement was any good.

If you allow browser notifications, we store an anonymous token from your browser so we can push a notification to your device. You can revoke it from your browser settings at any time and we will not know who you are from the token alone.

8. What other members can see

Some information on this site is meant to be seen by other people. It is worth being clear about exactly which.

  • Your username, your picture and your bio appear next to anything you post, and on your public profile.
  • Community posts, comments and published projects are visible to anyone who can reach the page. Treat them as public.
  • The leaderboard lists members by activity score. You can take yourself off it from your profile settings.
  • Whether you are online, or when you were last online, is shown to people you have a conversation with. You can switch this off, and if you do we stop recording it at all rather than merely hiding it.
  • Whether you are typing is shown only to the person you are typing to.
  • Direct messages are private between you and the person you sent them to. We do not read them as a matter of course. We may look at a specific conversation if it is reported to us for abuse, or if the law requires it.
Please remember. Anything you send to another member is in their hands too. They can screenshot it, quote it, or keep it after you delete your copy. That is true of every messaging system ever built, and no privacy setting on our side can change it.

9. Identity documents and CVs

Two parts of this site accept documents that deserve more care than the rest.

Appeal documents. If your account has been restricted and you choose to appeal, you may send us identification. We ask for this only when you are appealing, we use it only to decide the appeal, and it is seen only by the people who make that decision. We do not use it for anything else, we do not share it, and once the appeal is closed and any period we are required to keep records has passed, it is deleted. If you would rather not send identification at all, say so and we will do what we can with the rest of what you tell us.

CVs sent through the careers page. We keep these to consider you for the role you applied for. If we do not hire you, we keep the application for up to twelve months in case something suitable comes up, and then delete it. Tell us at any point and we will delete it sooner.

10. How long we keep things

We do not keep things forever out of habit. Roughly:

WhatHow longWhy that long
Your account and profileUntil you delete itIt is your account
Payment recordsSeven yearsKenyan tax and accounting rules require it, so these survive account deletion
Certificates you earnedIndefinitely, unless you askSo the verification link on your CV keeps working
Direct messagesUntil you or the other person deletes themA conversation belongs to two people
Sign in recordsRolling recent historyLong enough to spot an intrusion, not long enough to be a log of your life
Presence and typingA single current value, overwritten constantlyThere is no history to keep and we do not build one
Contact enquiriesUntil resolved, then periodically clearedWe only need them to answer you
Appeal documentsDeleted after the appeal closesSensitive, and the reason for holding it has gone
Job applicationsUp to twelve monthsIn case a suitable role opens

11. How we protect it

No website can honestly promise perfect security, and you should be suspicious of any that does. What we can tell you is what we actually do.

  • The whole site is served over HTTPS, so what travels between your device and us is encrypted.
  • Passwords are stored as one way hashes. Nobody at Merik can read your password, including us.
  • Card details and M-Pesa PINs never reach our servers at all.
  • Every database query that includes something you typed uses prepared statements, which is the standard defence against a large family of attacks.
  • Administrative pages are behind a separate login and are blocked from search engines.
  • Repeated failed sign ins lock an account temporarily, so a password cannot be guessed by brute force.
  • Private files you send us are not listed or linked publicly.

If we ever discover a breach that puts you at real risk, we will tell you and we will notify the Office of the Data Protection Commissioner, as the Act requires. We would rather tell you awkwardly than quietly.

12. Your rights, and how to use them

Under the Data Protection Act, 2019, and under the GDPR where it applies to you, you have rights that we are obliged to honour. In plain terms:

  • To know. To be told what we hold about you and what we do with it. That is what this page is for, and you can always ask for more detail.
  • To see it. To get a copy of your information. Much of it is already on your profile page, and we will send the rest.
  • To correct it. If something is wrong, tell us and we will fix it. Most of it you can edit yourself.
  • To delete it. To ask us to erase your account and what is in it. There is a delete option on your profile. Some records, payments in particular, we are legally required to keep even then, and we will tell you which.
  • To object. To tell us to stop a particular use, especially anything based on our legitimate interest rather than on a contract.
  • To restrict. To have us pause using your information while a dispute about it is sorted out.
  • To take it elsewhere. To receive what you gave us in a form you can hand to somebody else.
  • To withdraw consent. Wherever we relied on your consent, you can take it back, and it will not affect anything that happened before you did.

To use any of these, email support@merikagency.com from the address on your account, or write from another address and we will verify it is you first. We do not charge for this. We aim to reply within seven days and to finish within thirty, and if something is genuinely going to take longer we will tell you why rather than go quiet.

We will ask you to prove who you are before we hand over or delete anything. That is not an obstacle we are putting in your way, it is the thing that stops somebody else emptying your account by pretending to be you.

13. Children

This site is not intended for children under the age of eighteen, and we do not knowingly collect information from them. If you are a parent or guardian and you believe your child has created an account, email us and we will delete it and everything attached to it. We will not ask you to jump through hoops for that.

14. When information leaves Kenya

Some of the companies we rely on operate outside Kenya. Our hosting and email are with IONOS in Europe, Google operates globally, and our payment providers each have their own arrangements. This means your information may be processed outside the country.

Where that happens we rely on providers who commit to recognised data protection standards, and we only send them what they need for their part of the job. We do not move your information anywhere simply because it is cheaper to store it there.

15. Advertising

At the time of writing there is no advertising on this site and no advertising tracker in its code. We would rather be paid by the people we serve than by somebody paying for their attention.

If we do introduce advertising, we will update this page before the first advert appears, not afterwards, and we will say plainly which network it is and what it can see. We will not place advertising inside anything you have paid for, and we will not hand an advertiser your name, your email address, or your message history in order to target you.

16. Changes to this notice

We will update this page when what we do changes. The date at the top always tells you when it was last revised. If a change is significant, for example a new category of information, a new company seeing your data, or advertising arriving, we will tell you directly by email or by a notice on the site rather than hoping you check.

We will not make a material change quietly and rely on the fact that you agreed to an earlier version.

17. If you are unhappy

Please tell us first. Most problems are a misunderstanding or a mistake, and we would like the chance to fix ours. Email support@merikagency.com and say what happened.

If we cannot put it right, you have the right to complain to the Office of the Data Protection Commissioner in Kenya, which regulates how organisations handle personal information. You do not need our permission to do that and you do not have to come to us first, although we would appreciate the opportunity. If you are in the European Union or the United Kingdom, you may also complain to your own national supervisory authority.


Still want to ask a person?

If anything here is unclear, or you want to know something this page does not answer, write to us. We would rather explain it than have you guess.

Chat with us