LEGAL AGREEMENT

Terms of Service

Effective Date: August 2026 | Last Updated: August 26, 2026

1 Acceptance of Terms

Welcome to PayWay Kenya ("PayWay", "we", "us", or "our"), accessible via payway.co.ke. By creating an account, accessing our REST APIs, or using our payment prompt automation services, you ("Merchant", "User", or "Customer") agree to be bound by these Terms of Service.

If you are entering into this agreement on behalf of a company or legal entity, you represent that you have the authority to bind such entity to these terms.

2 Daraja STK Push & Direct Settlement Architecture

PayWay Kenya utilizes Safaricom Daraja STK Push technology to initiate payment prompts to end customers.

Direct Settlement Guarantee: All customer payments prompted via PayWay land directly in the merchant's own Safaricom M-Pesa Till Number, Paybill Shortcode, or registered Commercial Bank Account. PayWay does not hold customer funds in transit.
  • Service Wallet Model: PayWay monetizes by deducting prompt fees (KES 5.00 per successful payment prompt) directly from the merchant's Service Wallet.
  • Positive Service Balance: Merchants must maintain a positive balance in their Service Wallet to send STK Push prompts to customers.
  • Non-Refundable Top-Ups: Top-ups deposited into the Service Wallet are non-refundable and used strictly for prompt fees.

3 Account Registration & Security

To access the PayWay portal, merchants must register using a valid email address and password.

  • Passwords must be a minimum of 6 characters containing at least one letter and one number.
  • Account activation requires entering a 5-digit verification code sent to your registered email address.
  • Merchants are responsible for maintaining the confidentiality of their login credentials and API secret keys.

4 Merchant Credentials & Zero Exposure Policy

PayWay strictly enforces a zero-exposure security architecture:

Security Commitment: PayWay System Administrators and Super Admin accounts NEVER store, expose, or view merchant passwords, secret passkeys, or private API secret tokens in cleartext. Passwords remain 100% encrypted via one-way bcrypt hashing.

5 B2C Disbursements & Outbound Payouts

PayWay provides Swift B2C Disbursement services allowing merchants to dispatch payouts to customer M-Pesa phone numbers.

  • Disbursements require sufficient funds in your Payments Wallet ledger.
  • Payouts dispatched to M-Pesa numbers are processed instantly upon confirmation.

6 Prohibited Activities & AML Compliance

Merchants agree not to use PayWay Kenya for illegal activities, including but not limited to fraudulent money schemes, unauthorized gambling, money laundering, or processing illegal transactions under the Laws of Kenya.

7 Governing Law & Dispute Resolution

These Terms of Service are governed by and construed in accordance with the Laws of the Republic of Kenya. Any disputes shall be subject to the exclusive jurisdiction of the Courts in Nairobi, Kenya.

8 Contact Channels

For inquiries regarding these Terms of Service, please reach out to our team: