Last Updated: 2025-08-29
1. What We Collect
We may collect the following categories of information, depending on your interactions with us:
- Personal Information: name, email address, phone number, business name, role/title, shipping/billing addresses.
- Account and Business Profile Data: account credentials you provide, preferences, consent records, opt-in/opt-out choices, communications settings.
- Communications and Content: messages you send to us (including via email, website forms, Facebook/Instagram pages, and WhatsApp), attachments you upload, and related metadata (timestamps, delivery/read status, message IDs). If you use the WhatsApp Business Platform to message us, we process message content solely to deliver and respond to your requests.
- Transaction and Order Information: purchase history, invoices, order details, delivery information, payment method type (we do not store full payment card numbers on our systems).
- Technical and Usage Data: IP address, device identifiers, browser type, operating system, referring URLs, pages viewed, interactions, session duration, error logs.
- Cookies and Similar Technologies: identifiers stored using cookies, pixels (including Meta Pixel), SDKs, and local storage. See Section 6 for details.
- Data From Meta Products and APIs: if you interact with our Facebook/Instagram pages, use Facebook Login with our app, or message us via WhatsApp, we may receive basic profile data (e.g., name, profile ID), page messaging events, WhatsApp phone numbers and message metadata, template approvals, and delivery reports as provided by Meta.
- Data From Service Providers and Partners: logistics/courier status, fraud signals, payment verification responses, and analytics.
2. How We Use Information
We use information to:
- Provide, operate, and improve our products and services.
- Process orders, payments, deliveries, and returns.
- Communicate with you, including via WhatsApp and Facebook/Instagram messaging, email, and phone.
- Verify identity and manage accounts and permissions.
- Provide customer support and handle inquiries, complaints, and disputes.
- Maintain security, prevent fraud and abuse, and enforce terms and policies.
- Comply with legal obligations and regulatory requirements.
- Analyze performance and usage to improve our offerings and user experience.
- With your consent, send marketing communications and measure campaign effectiveness.
3. Our Use of Meta (Facebook) Products and WhatsApp
3.1 Facebook Login and Permissions
If you choose to log into our app or integrations using Facebook Login, we will request only the permissions needed to provide the feature (for example, email and public_profile). For page-related features, we may request pages_messaging, pages_manage_metadata, or related scopes, and we will use them solely to manage conversations and provide support. We do not sell Facebook data, and we do not use Facebook data for credit, insurance, or employment decisions. We cache tokens and data only as permitted by Meta’s Platform Terms and store them securely. If you remove our app from your Facebook account, we will delete your associated Facebook data within 30 days (see Section 7).
3.2 Facebook/Instagram Pages and Messaging
If you message us via our Facebook/Instagram pages, we receive message content and metadata to allow us to respond. We do not disclose message content to third parties except to our processors who provide messaging infrastructure and solely on our instructions.
3.3 WhatsApp Business Platform (including Cloud API)
When you message us on WhatsApp, Meta delivers messages to our business using end-to-end encryption between your device and WhatsApp. If we use the WhatsApp Business Platform/Cloud API, WhatsApp delivers your messages to our chosen hosting environment, where we process them to respond and provide support and order updates. We require your opt‑in before sending you business-initiated messages, and you can opt out at any time by replying “STOP”. We may use WhatsApp-approved message templates for notifications (e.g., order status). We do not sell or rent WhatsApp contact data.
3.4 Webhooks and Events
Our systems may receive webhook events from Meta (e.g., message delivery/read receipts). We store only what is required to provide the service and for the periods set out in Section 5.
4. Data Sharing and Disclosure
We do not sell personal information. We share information only as follows:
- Service Providers/Processors: hosting, cloud infrastructure, analytics, customer support tools, payment processors, logistics/couriers, and communications providers (including Meta for WhatsApp delivery). They process data only on our instructions and under confidentiality obligations.
- Business Transfers: as part of a merger, acquisition, or asset sale, subject to this Privacy Policy.
- Legal and Safety: to comply with laws, enforce our terms, or protect the rights, safety, or property of users, the public, or us.
- With Your Direction: when you ask us to share information or integrate with third-party services.
- Aggregated or De-identified Data: may be shared for analytics and research.
5. Data Retention
We retain personal data for as long as necessary to fulfill the purposes described in this policy, including to comply with legal, accounting, or reporting requirements. Typical retention periods include:
- Account and Transaction Records: for the life of the account and up to 7 years after the last transaction (to satisfy tax and audit requirements).
- WhatsApp/Facebook Messages and Metadata: typically up to 12 months for customer support history, unless a longer period is required by law or to resolve disputes.
- Webhooks, Access Logs, and Security Logs: up to 12 months, unless required longer for security or legal reasons.
We will delete or anonymize data when retention is no longer necessary.
6. Cookies and Similar Technologies
We use cookies, SDKs, and pixels (including the Meta Pixel) to enable basic site functionality, remember preferences, perform analytics, measure the effectiveness of our communications, and, where permitted, tailor content. You can control cookies through your browser settings. Where required, we will obtain your consent before setting non-essential cookies. If we use the Meta Pixel, Meta may collect or receive information from our website and use it to provide measurement services and targeted ads in accordance with their policies. You can learn about ad choices in your Facebook settings.
7. Facebook Data Deletion Instructions (Required for Facebook Apps)
If you have used Facebook Login to access a Kanini Haraka app or integration and wish to delete your associated data:
- Remove the app via your Facebook account: go to Settings & privacy > Settings > Apps and Websites, select "Kanini Haraka", and choose Remove. This triggers deletion of your app-linked data on our systems.
- Or send an email to [email protected] with the subject line "Facebook Data Deletion Request" and include your name, the email/phone tied to your Facebook account, and (if known) your Facebook User ID. We will delete your Facebook-sourced data within 30 days, and we will revoke/clear cached tokens within 24 hours, except where retention is required by law or to resolve disputes.
8. WhatsApp Opt-Out and Data Deletion
- Opt-Out: You can stop receiving business-initiated WhatsApp messages from us at any time by replying "STOP". You may also email [email protected] and ask to be removed from WhatsApp communications.
- Deletion: You can request deletion of your WhatsApp-related data by emailing us. We will delete message history and related metadata (subject to legal retention obligations) within 30 days. We may retain your phone number on a suppression list to honor your opt-out.
9. Data Sharing Specific to Meta
To deliver messages and related functionality, we share limited necessary data with Meta Platforms (Facebook/Instagram/WhatsApp) in accordance with their terms and our agreements. We do not sell personal data. We prohibit our processors from using data for their own purposes and require them to protect it.
10. Contact Us
If you have questions about this Data Policy or our data practices, or if you wish to exercise your rights, contact us at:
Kanini Haraka
Email: [email protected]
Phone: +254 716 901443
Address: P.O. Box 5292 0100