Privacy Policy
Last updated: 5/29/2026
1. Introduction
This Privacy Policy explains how we collect, use, disclose, and safeguard your information in compliance with the Data Protection Act, 2019. We are committed to protecting your personal data and your right to privacy.
2. Information We Collect
2.1 Personal Information
- Full name, contact details, and identification documents
- Business registration information and KRA PIN
- Bank account details and payment information
- Tax compliance certificates and business licenses
2.2 Transaction Information
- Sales data and transaction history
- Customer interactions and feedback
- Payment processing records
- Shipping and delivery information
3. How We Use Your Information
- To verify your identity and business legitimacy
- To process payments and facilitate transactions
- To provide customer support and platform services
- To comply with legal and regulatory requirements
- To improve our platform and services
- To send important updates and marketing communications (with consent)
4. Legal Basis for Processing
Under the Data Protection Act, 2019, we process your data based on:
- Consent: When you explicitly agree to data processing
- Contract: To fulfill our obligations under seller agreements
- Legal Obligation: To comply with Kenyan laws and regulations
- Legitimate Interests: To improve our services and prevent fraud
5. Data Sharing and Disclosure
5.1 Third-Party Service Providers
- Payment processors (M-Pesa, banks, PayPal, Wise)
- Shipping and delivery partners
- Cloud storage and hosting providers
- Customer support platforms
5.2 Legal Requirements
We may disclose your information to:
- Kenya Revenue Authority (KRA) for tax compliance
- Regulatory bodies as required by law
- Law enforcement agencies with valid legal requests
6. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption of sensitive data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication mechanisms
- Secure data storage with Firebase security rules
- Regular backups and disaster recovery procedures
7. Data Retention
We retain your personal data only as long as necessary:
- Active seller accounts: Until account closure + 7 years
- Financial records: 7 years for tax compliance
- Identification documents: 5 years after account closure
- Marketing data: Until consent is withdrawn
8. Your Rights Under Data Protection Act
You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your data (right to be forgotten)
- Restrict or object to data processing
- Data portability
- Withdraw consent at any time
9. International Data Transfers
Your data may be transferred to and processed in countries outside Kenya. We ensure appropriate safeguards are in place and that international data transfers comply with the Data Protection Act, 2019 requirements.
10. Cookies and Tracking
We use cookies and similar technologies to:
- Authenticate users and maintain sessions
- Remember your preferences and settings
- Analyze platform usage and performance
- Provide personalized content and recommendations
11. Children's Privacy
Our platform is not intended for individuals under 18 years. We do not knowingly collect data from children. If we learn we have collected personal data from a child, we will delete that information promptly.
12. Changes to This Policy
We may update this policy periodically. We will notify you of significant changes through email or platform notifications. Continued use of our services after changes constitutes acceptance of the updated policy.
13. Contact Us
For privacy-related questions or to exercise your rights, contact our Data Protection Officer:
Email: dpo@marketplace.co.ke
Phone: +254 700 000 001
Address: Data Protection Office, Nairobi, Kenya
You also have the right to lodge a complaint with the Office of the Data Protection Commissioner Kenya.