Privacy & DataLast updated: October 2026

Privacy Policy

How QC NetCore collects, processes, isolates, and protects personal, operational, network, and billing data across our ISP Operating System.

Key Compliance Highlights
  • Transparently distinguishes between data collected for QC NetCore platform administration (Controller) and subscriber data processed on behalf of ISP Tenants (Processor).
  • Does NOT store customer M-Pesa PINs, full credit card numbers, or raw banking passwords; only transaction references, phone numbers, and payment confirmation metadata are processed.
  • Zero third-party ad-network tracking or sale of subscriber or ISP operational data.

Section 1Overview & Privacy Principles

QC NetCore respects the privacy of ISP Operators, network engineers, and end-user internet subscribers. This Privacy Policy explains what information is collected when you interact with the QC NetCore website, operator console, captive portals, Free Tools, and APIs, how that information is used, and the rights available to data subjects.

Our privacy architecture is built on data minimization, strict multi-tenant Row-Level Security (RLS) isolation, and alignment with the Kenya Data Protection Act, 2019 and internationally recognized privacy principles (including GDPR core safeguards).

Section 2Categories of Information Collected

Depending on whether you are visiting our public website, operating an ISP tenant workspace, or connecting through a hotspot/PPPoE network managed by QC NetCore, the system processes the following categories of data:

  • ISP Operator & Staff Account Data: Full name, business email address, phone/WhatsApp number, organization name, role/permissions, and authentication session identifiers.
  • Subscriber & Customer CRM Data (Tenant-Scoped): Subscriber name, phone number, email address (optional), installation location/notes, assigned service plan, account status, and expiration timestamps.
  • Network & Session Telemetry: Device MAC address, assigned local/public IP address, PPPoE username, NAS/MikroTik router identifier, session start/stop times, bandwidth upload/download counters, and voucher codes.
  • Payment & Billing Metadata: M-Pesa receipt/transaction reference codes (e.g., QK89X...), payer phone number, transaction amount, currency, invoice ID, and timestamp. QC NetCore NEVER collects or stores M-Pesa PINs.
  • Support & Communication Records: Inquiries submitted via WhatsApp (0712052104), email (quantumcode7777@gmail.com), or support ticket logs.

Section 3How We Use Information

We process collected data strictly for legitimate operational, contractual, and security purposes:

  • Authenticating ISP administrators and enforcing organization-level Row-Level Security (RLS).
  • Executing automated RADIUS AAA authentication, bandwidth profile provisioning, and captive portal voucher/package activation.
  • Reconciling M-Pesa STK Push and C2B Paybill/Till callbacks with subscriber invoices and hotspot sessions.
  • Generating real-time operational dashboards, network health alerts, and financial audit trails for ISP Operators.
  • Detecting fraud, unauthorized router API access, brute-force login attempts, and network abuse.

Section 5Data Sharing & Infrastructure Subprocessors

QC NetCore does NOT sell, rent, or trade ISP operator lists, subscriber phone numbers, or network usage logs to advertisers or data brokers.

Information is shared only with essential infrastructure components required to run the platform:

  • Cloud Database & Authentication Infrastructure (Supabase / PostgreSQL): For encrypted data storage and session authentication.
  • Application Hosting & Edge Delivery (Vercel): For secure HTTPS web application delivery.
  • Connected ISP Payment Gateways (e.g., Safaricom Daraja M-Pesa API): When initiating STK Push payment requests or validating payment callbacks for a specific ISP tenant.
  • Connected Tenant Network Hardware: Sending RADIUS attributes and RouterOS API commands to the ISP Operator's own MikroTik routers.

Section 6Data Retention & Data Subject Rights

Operational and subscriber records are retained for the duration of an ISP Operator's active tenancy, plus any statutory retention period required for financial and tax audit records. Demo Mode configurations stored in your browser's local storage remain only on your local device and can be cleared at any time using the 'Reset Demo' button or browser settings.

Subject to applicable law, individuals have the right to request access to, correction of, deletion of, or restriction of processing of their personal data, as well as data portability. Where QC NetCore acts as a Data Processor on behalf of an ISP Tenant, we will coordinate subscriber privacy requests with the relevant ISP Operator.

Section 7Privacy Inquiries & Contact Channel

To exercise your data protection rights or ask questions about our privacy practices, contact our Privacy & Compliance team:

  • Email: quantumcode7777@gmail.com (Subject: Privacy Request — QC NetCore)
  • WhatsApp: 0712052104 (+254 712 052 104)

Questions About This Policy or Compliance Verification?

Reach our legal, privacy, billing, and security engineering desk directly via email or WhatsApp.