1. Who this applies to
P8 ISP is used by internet service providers to run their operations. That means two groups of people appear in the platform: the operator staff who sign in, and the operator’s own end customers, whose records the operator enters and manages.
For operator staff, we decide how their information is used. For end customer records, the operator decides, and we process that information on the operator’s behalf in order to run the service.
2. Account information
When an account is created we collect the business name, the owner’s first and last name, email address, country and timezone. Passwords are stored only as a cryptographic hash and are never readable by us.
Email verification codes and password reset tokens are stored as digests, are single use, and expire.
3. End customer information
Operators enter records about the people they serve. Depending on how an operator uses the platform this can include names, phone numbers, email addresses, service addresses, account numbers, subscription plans and payment history.
4. Service and usage information
Running the service produces operational records: sign-in activity, actions taken in the application, and logs used to diagnose faults and investigate abuse.
5. Payment information
Payments are collected through third-party providers such as M-Pesa, using credentials the operator supplies. We record the details needed to reconcile a payment — amounts, references, timestamps, and the payer identifier the provider returns.
We do not collect or store card numbers. Funds are settled to the operator by the payment provider, not by us.
6. Communications
The platform sends messages on an operator’s behalf, such as payment reminders and service notices, through third-party messaging providers. It also sends a small number of platform emails of its own, including signup verification and password reset.
7. Device and network information
Because the platform manages network equipment, it handles technical identifiers such as device addresses, IP addresses, session records and usage counters. These are used to provision service, enforce plans, and show operators what their network is doing.
8. How information is used
- to provide, operate and support the service;
- to authenticate people and protect accounts;
- to provision and manage network service on an operator’s behalf;
- to process and reconcile payments;
- to send messages an operator has configured;
- to detect, investigate and prevent abuse, fraud and technical faults;
- to meet obligations that apply to us.
We do not sell personal information.
9. Service providers
We rely on third parties to deliver parts of the service, including hosting and infrastructure, payment providers, messaging providers, email delivery and file storage. They receive only what they need for their part of the service.
Where an operator connects a provider using its own credentials, that provider’s handling of the data is governed by the operator’s agreement with them.
10. Retention
Account and operational records are kept for as long as an account is active, and afterwards where we need them for legitimate business or legal reasons.
Short-lived security records are removed sooner: unverified signups and spent or expired password reset requests are deleted on a retention schedule.
11. Security
Access to the platform requires authentication, and each operator’s data is scoped to that operator. Passwords are hashed, verification codes and reset tokens are stored as digests, and traffic to the service is encrypted in transit.
No system is perfectly secure, but we treat credential handling and tenant isolation as the parts that matter most.
12. Your choices
Operator staff can view and update their own account details in the application, and an account owner can manage who has access.
If you are an end customer of an operator using P8 ISP, your records are controlled by that operator, and requests about them should be made to them directly. We will support an operator in responding.
13. Processing locations
The service and the providers it depends on may process information in more than one country. Where information moves between countries, we rely on the protections offered by those providers.
14. Changes to this policy
This policy carries the same version identifier as the Terms of Service, shown at the top of this page as version 2026-09. We will give notice of material changes through the platform or by email to the account owner.
15. Contact
A contact address for privacy enquiries has not been configured for this deployment.