Draft. This document is being finalised and is not yet in force.
Vazi — Privacy Policy
Version: 0.1 (baseline draft) · Effective date: [PLACEHOLDER: effective date]
This policy explains what personal data Vazi collects, why, and your rights under the Kenya Data Protection Act, 2019 ("KDPA"). We have written it to be readable; if anything is unclear, ask us at the contact in section 12.
1. Who is responsible for your data
The data controller is [PLACEHOLDER: registered legal name of the operating company], registered office [PLACEHOLDER: registered office address], trading as "Vazi" ("Vazi", "we"). We are registered with the Office of the Data Protection Commissioner ("ODPC") as [PLACEHOLDER: ODPC registration number and category — controller and/or processor; see lawyer briefing].
Privacy contact / data protection contact: the Vazi founder, reachable at officialvazike@gmail.com (marked "Privacy").
2. What we collect
We collect only what the service needs:
| Category | Examples | Who it applies to |
|---|---|---|
| Identity & contact | Name, phone number, optional email | Everyone with an account |
| Delivery details | Descriptive address, landmark, optional GPS pin, town/area, recipient phone | Buyers |
| Body measurements | The measurements you save in a body profile (e.g. chest, waist, inseam, foot length), used only to show fit information | Buyers who choose to create a body profile |
| Transactions | Orders, items bought or sold, amounts, M-Pesa transaction references, refunds, receipts | Buyers and vendors |
| Vendor KYC | National ID number, ID photos, selfie photo, base location, M-Pesa payout number | Vendors and Official Store operators only |
| Claims & reviews | Claim descriptions and photos, ratings and review text | Buyers who claim or review |
| Usage data | Screens viewed, searches, filters, wishlists, app events — linked to a pseudonymous account identifier, not to your phone number (see section 8) | Everyone |
| Technical data | Device model, OS version, app version, crash reports, IP address in server logs | Everyone |
| Support | Messages you send our support channels (including WhatsApp and email) | Anyone contacting support |
We do not collect M-Pesa PINs, and we never see your full M-Pesa account details — payments are processed by our licensed payment provider.
Body measurements are treated as sensitive. They are stored encrypted, are never shown to vendors or other users, and are used solely to compute fit information for you.
3. Why we use it, and our lawful basis
Under the KDPA, every use of personal data needs a lawful basis. Ours are:
| Purpose | Data used | Lawful basis (KDPA s.30) |
|---|---|---|
| Creating your account and signing you in by OTP | Phone, email | Performance of a contract |
| Showing fit information against your body profile | Body measurements | Consent (creating a body profile is optional; delete it any time) |
| Taking payment, holding it securely until you confirm, refunds | Transaction data, phone | Performance of a contract; legal obligation (financial records) |
| Delivering orders and pickup collection | Delivery details, phone | Performance of a contract |
| Vendor onboarding and payouts | Vendor KYC data | Performance of a contract; legal obligation (identity and payment integrity); legitimate interests (fraud prevention) |
| Handling claims and disputes | Claims data, hub quality-check records | Performance of a contract; legitimate interests (evidence of what was verified) |
| Order and account notifications (SMS/push) | Phone, device token | Performance of a contract |
| Marketing messages and marketing analytics | Contact details, usage data | Consent — off by default; opt in or out any time in the app |
| Product analytics and service improvement | Pseudonymous usage data | Legitimate interests (understanding and improving the service) — see section 8 |
| Security, fraud prevention, enforcing our terms | Technical data, transaction patterns | Legitimate interests; legal obligation |
| Tax and regulatory compliance | Transaction records, receipts | Legal obligation |
4. Who we share it with (processors and recipients)
We use a small set of service providers ("processors") who handle data on our instructions:
| Provider | Role | Data involved | Hosting region |
|---|---|---|---|
| IntaSend (IntaSend Limited) | Licensed payment aggregator — M-Pesa collections, refunds, and payouts | Phone number, transaction amounts and references; vendor payout numbers | Kenya |
| Safaricom (M-Pesa) | Mobile money network executing payments | Phone number, amounts | Kenya |
| Africa's Talking | SMS delivery (OTPs, order notifications) | Phone number, message content | Kenya/regional |
| Railway | Cloud hosting of our servers and database | All service data (encrypted in transit; sensitive fields encrypted at rest) | EU (West) |
| Cloudflare (R2 storage, CDN, Pages) | Image and file storage and delivery; website hosting | Listing photos; claim photos; KYC images (private, access-controlled); site traffic | Global edge; storage [PLACEHOLDER: confirm R2 bucket jurisdiction setting] |
| Sentry | Error and crash reporting | Technical data, pseudonymous identifiers | US |
| PostHog | Product analytics | Pseudonymous usage events (see section 8) | US |
| [PLACEHOLDER: transactional email provider — not yet selected] | Email delivery (OTP fallback, receipts) | Email address, message content | [PLACEHOLDER: provider region] |
| Expo / Google Firebase Cloud Messaging | Push notification delivery | Device push tokens | Global |
| Courier partners | Delivering your order | Recipient name, phone, delivery address, COD amount due | Kenya |
| Pickup point agents | Handing over your parcel | Name, partial phone number, collection code only — agents never see order contents or other account data | Kenya |
Some providers host data outside Kenya (regions noted above). Where data leaves Kenya we rely on the transfer safeguards required by the KDPA and its regulations, including contractual protections with each provider. We do not sell personal data, and we do not share it with anyone for their own marketing.
We may disclose data where the law requires it — for example to the ODPC, the Kenya Revenue Authority, law enforcement with lawful authority, or to defend legal claims.
Vendors never see buyer identities or measurements; buyers never see second-hand vendor identities. Support mediates all contact.
5. How long we keep it
| Data | Retention |
|---|---|
| Account identity and contact | While your account is active, then deleted or anonymised within [PLACEHOLDER: e.g. 90 days] of account closure, except as below |
| Transaction and payment records (including the financial ledger and receipts) | [PLACEHOLDER: statutory financial/tax retention period — counsel to confirm, e.g. 5–7 years] after the transaction, as required for tax and financial compliance; on account deletion these records are retained anonymised (unlinked from your identity) wherever the law allows |
| Body measurements | Until you delete the profile or your account — deletion is immediate |
| Vendor KYC (ID number, ID photos, selfie) | Duration of the vendor relationship plus [PLACEHOLDER: retention period — counsel to confirm against fraud/AML and limitation periods]; stored encrypted throughout |
| Claims evidence and hub quality-check records | [PLACEHOLDER: e.g. 2 years] after the claim or order closes (evidence for disputes) |
| Support messages | [PLACEHOLDER: e.g. 2 years] |
| OTP and authentication logs | [PLACEHOLDER: e.g. 12 months] |
| Analytics events | Pseudonymous; retained [PLACEHOLDER: e.g. 24 months] then aggregated or deleted |
| Server and audit logs | [PLACEHOLDER: e.g. 12 months]; access logs for KYC data are kept for the KYC retention period |
6. How we protect it
- Encryption in transit (TLS) everywhere.
- Field-level encryption at rest (AES-256-GCM) for national ID numbers and KYC document references; KYC, claim, and quality-check images live in private storage accessible only through role-checked, expiring links.
- Body measurements are stored in a dedicated, access-controlled table and are excluded from logs.
- Staff access to KYC data requires two-factor authentication, and every view of a vendor's ID is audit-logged.
- Role-based access for all staff surfaces; append-only audit trail of administrative actions.
- Daily backups, held encrypted, with the same retention discipline.
No system is perfectly secure. If a breach occurs that risks your rights, we will notify the ODPC and affected users as the KDPA requires (within 72 hours of becoming aware, for ODPC notification).
7. Your rights under the KDPA
The KDPA (in particular sections 26, 38, and 40 — statutory references for counsel to verify) gives you the right to:
- Be informed about how your data is used (this policy).
- Access a copy of the personal data we hold about you. The app can export your data in-app [PLACEHOLDER: confirm final menu path at launch], or contact us and we will provide it.
- Correction of inaccurate, false, or misleading data — most details you can edit directly in the app; for the rest, contact us.
- Deletion of data we no longer have a lawful reason to keep, requested in-app [PLACEHOLDER: confirm final menu path at launch] or through support. Note: financial records we must keep by law are retained but anonymised — unlinked from your identity (section 5).
- Object to processing, including withdrawing consent for marketing (Profile → Notifications / Privacy) or for your body profile (delete it) at any time. Withdrawing consent does not affect processing that already happened.
- Data portability — your export (above) is provided in a structured, machine-readable format.
- Not to be subject to solely automated decisions with legal or similar significant effect. Fit indicators, search ranking, and COD eligibility checks are automated but do not produce such effects without human review; you may ask support for a human review of any COD or account restriction.
To exercise any right, use the in-app tools above or contact officialvazike@gmail.com. We respond within the timelines the KDPA sets [PLACEHOLDER: counsel to confirm response window to state, e.g. within 30 days]. Exercising your rights is free of charge except where the KDPA permits a reasonable fee for repetitive requests.
Complaints. You may complain at any time to the Office of the Data Protection Commissioner (ODPC) — https://www.odpc.go.ke — including through its online complaint portal. We would appreciate the chance to resolve your concern first, but you do not have to contact us before going to the ODPC.
8. Cookies and analytics
- The apps use a pseudonymous analytics identifier (your internal account ID) to record screens viewed and actions taken. Analytics events never contain your phone number, email, or name. This helps us understand what works (for example, which filters people use) and improve the product.
- Marketing analytics and marketing messages happen only with your consent, which you can give or withdraw in the app at any time. Without consent, analytics is limited to service operation and improvement.
- The website uses only strictly necessary cookies [PLACEHOLDER: confirm final site cookie inventory before launch; add a cookie banner only if non-essential cookies are added].
- Crash reports (Sentry) are used solely to fix defects.
9. Children
Vazi is for adults. You must be 18 or older to use the Platform, and we do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, contact us and we will delete it.
10. Where your data lives
Our servers are hosted in the European Union (Railway, EU-West region); images are stored with Cloudflare and delivered from its global network; the processors in section 4 host data in the regions noted there. Payment and SMS processing happen in Kenya. We apply the KDPA's cross-border transfer safeguards to data leaving Kenya.
11. Changes to this policy
We will notify you in the app of material changes before they take effect. The version and effective date appear at the top.
12. Contact
- Privacy/data protection: the Vazi founder, reachable at officialvazike@gmail.com (marked "Privacy")
- General support: officialvazike@gmail.com · WhatsApp +254 111 269 826
- Postal: [PLACEHOLDER: registered office address]