Privacy Policy

Your privacy matters to us. Learn how we collect, use, and protect your personal information on the Blyss digital marketplace.

Last updated: January 2024

1. Information We Collect

We collect information to provide you with the best possible marketplace experience and ensure platform security. Personal Information: • Name and contact details (email, phone number) • M-Pesa phone number for secure payments • Identity verification documents for seller accounts • Profile information and account preferences • Communication history with our support team Digital Product Information: • Product files, descriptions, and pricing information • Sales history and transaction records • Customer reviews and feedback Usage Information: • How you navigate and use our platform • Pages visited and features accessed • Search queries to improve our services • Device and browser information for compatibility • IP address for security and fraud prevention

2. How We Use Your Information

We use your information to provide, improve, and protect our marketplace services. Platform Operations: • Process transactions and facilitate M-Pesa payments • Verify seller identities to maintain marketplace trust • Deliver digital products to buyers securely • Provide customer support and resolve issues • Maintain platform security and prevent fraud Communication: • Send transaction confirmations and receipts • Notify you about important account updates • Respond to your support requests and inquiries • Share platform news and feature updates (with your consent) Service Improvement: • Analyze usage patterns to enhance user experience • Develop new features based on user needs • Monitor platform performance and reliability • Generate insights to improve our services • Ensure compliance with applicable laws and regulations

3. Information Sharing

We respect your privacy and only share information when necessary for platform operations or required by law. Service Providers: • M-Pesa and Safaricom for payment processing • Cloud hosting providers for secure file storage • Email services for platform communications • Analytics services to improve user experience (anonymized data only) • Customer support tools to assist you better Legal Requirements: • Government authorities when required by Kenyan law • Law enforcement for valid legal requests • Courts in response to legal proceedings • Regulatory bodies for compliance purposes • Tax authorities as required by law Business Transfers: • In case of merger, acquisition, or sale of assets • We will notify you of any ownership changes • Your rights under this policy will be maintained • You can delete your account if you disagree with transfers

4. Data Security

We take your data security seriously and implement multiple layers of protection. Technical Safeguards: • Encryption of data both in transit and at rest • Secure servers with regular security updates • Multi-factor authentication for sensitive operations • Regular security audits and vulnerability assessments • Secure backup and recovery systems Operational Safeguards: • Employee training on data protection best practices • Limited access to personal information on a need-to-know basis • Regular monitoring for suspicious activities • Incident response procedures for security events • Compliance with industry security standards Your Role in Security: • Use strong, unique passwords for your account • Keep your login credentials confidential • Report suspicious activities immediately • Log out from shared or public devices • Keep your contact information updated for security alerts

5. Your Rights and Choices

You have several rights regarding your personal information, and we're committed to helping you exercise them. Access and Correction: • View and update your account information anytime • Request copies of your personal data we hold • Correct any inaccurate or incomplete information • Download your transaction history and data Data Control: • Delete your account and associated data • Opt out of marketing communications • Control your privacy settings and preferences • Request data portability where technically feasible Communication Preferences: • Unsubscribe from promotional emails anytime • Manage notification settings in your account • Choose your preferred communication channels • Update contact preferences as needed Important Notes: • Some information may be retained for legal compliance • We'll respond to requests within 30 days • Identity verification may be required for security

6. Data Retention

We retain your information only as long as necessary to provide our services and comply with legal obligations. Active Accounts: • Account information maintained while your account is active • Transaction records kept for tax and legal compliance (7 years) • Support communications retained for 3 years • Usage analytics anonymized after 2 years Deleted Accounts: • Most personal information deleted within 30 days • Transaction records retained for legal compliance periods • Anonymized data may be retained for platform improvements • Backup systems may retain data for up to 90 days Legal Requirements: • Some data retained longer when required by Kenyan law • Court orders may affect normal retention schedules • Tax and financial records follow regulatory requirements • We'll inform you if legal holds affect your data deletion requests

7. Cookies and Tracking

We use cookies and similar technologies to improve your experience and ensure platform functionality. Essential Cookies: • Maintain your login session securely • Remember your preferences and settings • Enable core platform functionality • Process transactions and payments safely Analytics Cookies: • Understand how you use our platform • Identify popular features and content • Improve user experience and performance • Test new features and improvements Your Cookie Choices: • Control non-essential cookies through your browser settings • Opt out of analytics tracking in your account preferences • Essential cookies are required for platform functionality • We respect "Do Not Track" signals where technically feasible Cookie Management: • Clear explanations provided for all cookie types • Regular review and cleanup of unnecessary tracking • Transparent cookie policy available in your account settings

8. Third-Party Services

Our platform works with trusted third-party services to provide you with secure and reliable marketplace features. Payment Processing: • M-Pesa integration handled by Safaricom PLC • Transaction data shared only as necessary for payment processing • Subject to Safaricom's privacy policy and security standards • We don't store sensitive payment information on our servers Cloud Storage and Hosting: • Digital products hosted on secure cloud infrastructure • Data encrypted and access-controlled • Regular backups and redundancy for reliability • Compliance with international security standards Analytics and Support: • Anonymized usage data shared with analytics providers • Customer support tools to help us assist you better • Email services for platform communications • Security services for fraud prevention and platform protection Your Protection: • We carefully vet all third-party partners • Contractual agreements require appropriate data protection • Regular audits of third-party security practices • You can contact us with concerns about third-party data handling

9. Global Data Transfers and Jurisdictional Rights

User data may be transferred globally without restriction, and users consent to processing under various international legal frameworks that may provide different or lesser protections. Unrestricted Transfer Authority: • Data may be transferred to any country or jurisdiction as operationally required • No guarantee of equivalent data protection laws in destination countries • Processing may occur under legal frameworks with reduced user rights • Transfers may occur without notice or additional consent requirements Jurisdictional Compliance: • Data processing subject to laws of countries where processing occurs • Users may have different or no rights under foreign jurisdictions • Legal recourse limited to jurisdiction where Blyss operates • International law enforcement cooperation may affect data access User Acceptance of Risks: • Continued platform use constitutes consent to all international transfers • Users assume risks of processing under foreign legal systems • No withdrawal of consent possible while maintaining platform access • Blyss not liable for foreign jurisdiction data protection failures

10. Age Restrictions and Verification Limitations

While Blyss maintains age restrictions, verification processes are limited and users bear responsibility for compliance and any consequences of misrepresentation. Age Verification Limitations: • Blyss relies on user-provided information without independent verification • No guarantee that age verification prevents underage access • Users responsible for ensuring compliance with age requirements • False age representation may result in account termination without recourse Parental and Guardian Responsibilities: • Parents and guardians responsible for monitoring minor's internet usage • Blyss not liable for unauthorized access by minors • No obligation to implement additional safeguards beyond basic age gates • Parental controls and supervision remain external responsibilities Liability Limitations: • Users assume full responsibility for age-related compliance • Blyss not liable for damages resulting from underage platform access • No compensation for issues arising from age verification failures • Legal guardians bear sole responsibility for minor's platform activities

11. Policy Modification Rights and User Acceptance

Blyss reserves unlimited rights to modify this privacy policy at any time without user consent, with changes taking immediate effect upon publication. Modification Authority: • Privacy policy may be changed at any time at Blyss's sole discretion • No user consent required for policy modifications • Changes effective immediately upon posting regardless of notification • Retroactive application of new terms to existing data and relationships Limited Notification Obligations: • Notification provided at Blyss's discretion and convenience • No guarantee of advance notice for policy changes • Users responsible for regularly reviewing policy updates • Continued platform use constitutes acceptance of all modifications User Acceptance Requirements: • Any platform use after policy changes constitutes full acceptance • No opt-out mechanism available while maintaining platform access • Disagreement with changes requires immediate account termination • Historical data remains subject to new policy terms regardless of user preference

12. Contact Information

We're here to help with any privacy questions or concerns you may have. Privacy Officer: • Email: privacy@blyss.co.ke • Phone: 0740 455 200 or 0773 739 080 • WhatsApp: 0740 455 200 or +254 746 403 888 • Response time: Within 48 hours during business days Data Protection Requests: • Submit requests through your account settings • Email privacy@blyss.co.ke for specific data requests • Include verification information for security purposes • Processing time: Up to 30 days as required by law General Support: • Email: hello@blyss.co.ke for general inquiries • Visit our Help Center for common questions • Contact form available on our website • We're committed to addressing your privacy concerns promptly and fairly

Your Privacy Matters

We're committed to protecting your privacy and being transparent about our data practices. If you have any questions or concerns about how we handle your information, please don't hesitate to contact us.

Trust and Transparency

Your privacy is protected every step of the way. Join Blyss with confidence, knowing your data is secure and your rights are respected.

Privacy Policy | Blyss Digital Marketplace