Privacy Policy
Effective Date: [Insert Date]
At Dukasasa (“we”, “our”, or “us”), your privacy is important to us. This Privacy Policy outlines how we collect, use, store, and protect personal information when you use our services.
This policy complies with the Data Protection Act, 2019 of Kenya and applies to all users of our website and eCommerce platform.
1. Information We Collect
We may collect the following types of personal and business information:
a) When You Register:
-
Full name
-
Email address
-
Phone number
-
Business name and registration details
-
Billing address and payment information
b) When You Use Our Platform:
-
IP address and browser type
-
Usage data (pages visited, time spent, etc.)
-
Storefront content (product listings, customer orders, etc.)
c) From Your Storefront Visitors:
If your customers interact with your Storefront (hosted by us), we may process:
-
Customer names and contact details
-
Shipping and billing addresses
-
Order and payment history
Note: You are the data controller for your customer data, and we act as a data processor on your behalf.
2. How We Use Your Information
We use the data we collect to:
-
Provide and maintain our services
-
Set up and host your eCommerce site
-
Communicate with you about updates, billing, or support
-
Analyze usage for performance improvement
-
Comply with legal obligations
We do not sell your data or your customers' data to third parties.
3. Legal Basis for Processing
We process your personal data based on:
-
Your consent
-
The performance of a contract (e.g. delivering your eCommerce service)
-
Compliance with legal obligations
-
Our legitimate interest in operating and improving our platform
4. Data Retention
We retain your data for as long as your account is active, and for a reasonable period thereafter in accordance with regulatory requirements or for backup, audit, or dispute resolution purposes.
5. Data Security
We implement reasonable technical and organizational measures to protect your data, including:
-
Secure cloud hosting
-
Encrypted communications (HTTPS/SSL)
-
Role-based access controls
-
Regular backups
However, no system is 100% secure. You are responsible for safeguarding your login credentials.
6. Your Rights
Under Kenya’s Data Protection Act, you have the right to:
-
Access the personal data we hold about you
-
Correct or update your personal data
-
Request deletion of your personal data
-
Object to certain types of data processing
-
Withdraw consent where applicable
To exercise these rights, contact us at [[email protected]].
7. Sharing Your Data
We may share your data with:
-
Service providers who help us deliver the platform (e.g., payment processors, hosting partners)
-
Regulators or authorities where legally required
-
Third parties only with your explicit consent
All third-party service providers are required to handle your data in accordance with this Privacy Policy.
8. International Transfers
If your data is transferred outside Kenya (e.g., for cloud hosting), we ensure adequate safeguards are in place, such as data processing agreements with the receiving party.
9. Cookies
We use cookies to enhance user experience and gather usage analytics. You can control or disable cookies through your browser settings.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make significant changes, we’ll notify you via email or through the platform.
11. Contact Us
For questions, concerns, or data access requests, please contact:
📧 [email protected]
📞 +254 747 074 707
🌐 [get.dukasasa.co.ke]