Stahili Privacy Policy

1. Introduction

At Stahili Commerce Limited (Stahili or We or Us), we're all about keeping your information safe. By accessing or using our services, you consent to the practices described in this policy. We are committed to protecting your personal data in compliance with Data Protection Act (2019) and global best practices, including the General Data Protection Regulation (GDPR). This privacy policy (the Privacy Policy) outlines how Stahili collects, uses, stores and safeguards your personal information when you interact with us on the App, any affiliated digital platforms, websites, software interfaces, or electronic mediums (the Mediums) including any in-person engagements and tells you about your privacy rights and how the law protects you.

This Privacy Policy applies to all information Stahili processes regardless of the Medium on which that data is stored or whether it relates to past or present employees, workers, customers, clients or suppliers contacts, shareholders, website users, or any other person or entity.

This Privacy Policy should be read and applied together with (INSERT LNK TO STAHILI TERMS OF USE AND THE ACCEPTABLE USE POLICY) and you also have the right to withdraw your consent at any time, subject to applicable laws and the terms outlined in this policy.

2. What Information Do We Collect?

We keep it straightforward. Here's the information we may collect directly from you:

Where information is not collected directly from you then:

Where the information is received from another source then Stahili will process the information if: -

We don’t believe in asking for your personal information unless there is a really good reason, and one that you’ll end up benefitting from.

3. How We Use It

We use your information to enhance your Stahili experience, connect you with great opportunities, and ensure you receive your well-earned rewards.

We may use your information for the following purposes to:

We shall only use your information where: -

4. How we minimize and restrict processing your information

We shall only collect and process your information for explicit and legitimate purposes;

Where We intend to process your information beyond the original scope, We shall require your consent unless otherwise permitted in law;

we shall only process your information where proper authorization and a justified need;

We shall only retain your information only as long as required for its intended purpose. Once obsolete, the information shall be anonymized, securely deleted, or destroyed without undue delay;

the information we keep shall be accurate and up-to-date. Inaccurate or outdated information must be corrected or erased promptly upon notification.

We shall on own motion or through your request restrict the processing of personal information where: -

Where the processing of your information is restricted: -

we shall implement mechanisms to ensure that time limits are established for the rectification, erasure or restriction of processing of personal information or for a periodic review of the need for the storage of the information is observed.

5. How long do we retain your information?

We shall only retain your information for as long as reasonably necessary to fulfil the purposes we collected it for, unless our retention is:

We may retain your information for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect of our relationship with you.

To determine the appropriate retention period for personal data, we shall consider:

We shall delete, erase, anonymize or pseudonymize your information that is not necessary to be retained at the expiry of the retention period.

6. What are your rights and how can you exercise these rights?

Your rights and exercise of your rights on the information provided is taken into consideration and we shall ensure that: -

To exercise any of your rights, including accessing, correcting, or deleting your information, you can take the following steps to contact us:

You may also Contact us at dataprotection@stahili.com, and we’ll respond within 24 hours.

If you have any concerns about how we handle your data, you also have the right to file a complaint with the Office of the Data Protection Commissioner.

7. How do we protect your information in respect of third party processors and external contractors?

Stahili engages third party processors to handle your information, we therefore retain all responsibility for the security and proper usage of your information, in such cases, We will: -

We ensure that all third party processers and external contractors comply with data protection laws and acknowledge that unauthorized disclosure or violations may cause irreparable harm, subject to contractual penalties and legal consequences under any data protection regulations.

8. Cookies: The Sweet Stuff That Makes Stahili Better

We use cookies (tiny files on your device) to make your Stahili experience smoother and more personalized. They help us remember who you are and what you like.

These are sent to your browser from our mediums that you visit and are stored on your phone/computer. Subject to your consent, we shall use cookies for the following purposes:

You have the option to either accept or refuse these cookies, as you shall be informed of when you access the Mediums through your phone/computer. Please note that if you choose to refuse our cookies, you may not be able to access some of the features on the respective Mediums. Click here (INSERT COOKIES POLICY LINK) to learn more.

9. Disclosure of Information

Any disclosure of your information shall be done in accordance of the applicable laws and regulations.

We may disclose your information to: -

11. Marketing and Advertising

We will only use your Information for marketing and advertising purposes with your explicit consent, unless permitted by applicable law. If legally authorized to use your data for such purposes without consent, we will inform you at the time of collection;

Whenever possible, we will anonymize your information for marketing purposes to ensure you cannot be identified;

We will not share your information with third parties for direct marketing without your express permission;

You may opt out of any marketing communication by writing to Us at hello@stahili.com (ii) using the unsubscribe instructions in any email/SMS communications sent to you or at the device level through settings.

12. Our roles and responsivities

We will establish and implement comprehensive policies and procedures to ensure full compliance with all applicable data protection laws and regulations;

We have in place a Data Protection Officer (the DPO) who is responsible for ensuring compliance with the Data Protection Act and who is accessible via the email dataprotection@stahili.com;

It is our requirement that Our staff who handle your information must adhere to the provisions of this Privacy Policy;

When we engage third-party processors to handle your information, we will ensure they have in place organizational compliance with all applicable data protection laws and regulations.

13. Keeping Things Secure

Stahili has in place robust data protection measures in accordance with our internal policies and procedures. All access and use of information by staff and authorized personnel shall strictly adhere to these established protocols to ensure the security and confidentiality of the information. These measures are designed to safeguard the information in compliance with applicable laws and best practices. However, while we do our best, no online system is 100% secure, and absolute protection cannot be guaranteed.

To maintain the highest standards of data protection, Stahili shall continuously review and enhance its security frameworks. The Data Protection Office is designated person who shall oversee the governance, implementation, and compliance of these measures, ensuring ethical standards are upheld in the collection, storage, and use of data. This ongoing oversight guarantees that your information safety remains a priority in line with evolving regulations and industry practices.

14. Personal and Sensitive Data

Personal Data means any information relating to an identified or identifiable natural person and Sensitive Data means data revealing the natural person's race, health status, ethnic social origin, conscience, belief, genetic data, biometric data, property details, marital status, family details including names of the person's children, parents, spouse or spouses, sex or the sexual orientation of the data subject.

We don’t collect your Personal Data and Sensitive Data without any reason. If we ask for any information in respect of both, it’s for a reason that ultimately benefits you.

The Personal Data and Sensitive Data we collect will uniquely identify you, either on its own (e.g. your ID number) or in combination with other details (e.g. name and date of birth) and could also be used for discrimination.

To keep our promise, we only collect the absolute minimum Personal Data and Sensitive Data.

Our policy is to avoid collecting Sensitive Data unless strictly necessary for legitimate business or legal purposes and We want to assure you that:

Below is our approach of Personal Data and Sensitive Data and how we stay true to our commitment;

Personal Data Usual Approach Stahili Approach
Age Date of Birth – Easily combined with other data to personally identify the user Year of Birth – Much harder to use to identify someone but still provides the basic age information
Address Full Address - Easily identifies and exposes the user County & Constituency - Allows us to show our partners where demand is based,without exposing personal information
Personal Sensitive Data What we use it for
Year of birth
  • Allows Stahili to ensure appropriate surveys and offers are sent
  • Provides evidence that under 10s are not being invited to the platform
County & Constituency
  • Allows Stahili to ensure surveys and offers are targeted at relevant audiences
  • Allows Stahili to show consumer coverage
Gender
  • Allows Stahili to ensure that surveys and offers are targeted appropriately - Not Mandatory
Phone Number
  • Used to deliver data bundle rewards - Not mandatory

Stahili is a registered data controller and processor under the Office of the Data Protection Commissioner (ODPC) in compliance with applicable data protection laws. As the sole data controller, Stahili is committed to upholding the highest standards of privacy and security in the processing of your personal data. These measures reflect our dedication to protecting your information at every stage of its handling.

To support our operations, Stahili engages trusted third-party data processors, including:

15. Changes and Updates

Stahili shall review this Privacy Policy at least once every two (2) years to ensure its continued relevance, effectiveness, and compliance with evolving best practices. Additionally, the Policy shall be promptly amended in the event of any changes to applicable data protection laws, regulations, or significant operational requirements

Any updates to the Privacy Policy will be communicated to all relevant stakeholders, and staff shall be trained on revised provisions as necessary. Amendments may also be made as deemed appropriate by the Data Protection Officer to address emerging risks or organizational needs.

16. Need Help?

For any questions on this Privacy Policy, reach out to us at dataprotection@stahili.com. We're happy to assist!

17. Non-Compliance with this Privacy Policy

Stahili reserves the right to terminate any agreement with you for failure to comply with the provisions of this Privacy Policy and the Terms of Use and reject any application for information contrary to this Privacy Policy.

18. Applicable Data Privacy Laws

We're a Kenyan company, but we know that people from all over the world may use the Mediums operated by Stahili. We adhere to the Data Protection Act 2019, its regulations while also complying with GDCR global standards, to ensure your privacy is safeguarded.