Shopeak

Legal

Privacy Policy

Last updated: August 12, 2026

1.Introduction

Shopeak Global (“Shopeak”, “we”, “us”, or “our”) is a company incorporated in Kenya and operated by Theta Holdings. Our mission is to make commerce accessible, affordable, and rewarding for every entrepreneur in Africa.

This Privacy Policy explains how we collect, use, share, and protect personal information when you use our platform, mobile applications, websites, APIs, and related services (collectively, the “Services”). It applies to:

  • Merchants (Sellers)— individuals and businesses who use Shopeak to sell products and manage their commerce operations.
  • Buyers (Consumers)— individuals who browse and purchase products through Shopeak storefronts.
  • Partners— developers, logistics providers, and other third parties who integrate with or provide services through our platform.
  • Visitors— anyone who visits our websites.

This Policy is written to comply with the Kenya Data Protection Act, 2019 (the “KDPA”) and related regulations issued by the Office of the Data Protection Commissioner (“ODPC”). By using our Services, you agree to the practices described in this Policy. If you do not agree, please do not use our Services.

2.Our values

Your information belongs to you

We believe that your personal data is yours. We design our systems with privacy in mind from the ground up, collect only what is necessary to deliver our Services, and give you meaningful control over how your information is used.

We protect your information from others

If a third party requests your personal information, we will refuse to share it unless you have given consent or we are legally required to do so. When we are compelled by law to disclose your information, we will provide you with notice wherever reasonably possible.

We help our merchants meet their obligations

We provide tools, documentation, and platform features that help Merchants using Shopeak comply with the KDPA and other applicable data-protection laws, so they can build trust with their own customers.

3.Who is the controller

For the Shopeak Services, the data controller is:

Shopeak Global
A company of Theta Holdings
Nairobi, Kenya
privacy@shopeak.co.ke

For Buyer data flowing through a Merchant’s Storefront, the Merchant is typically the controller of Buyer Personal Data (for example, the Buyer’s name, delivery address, and Order history), and Shopeak acts as a processor on the Merchant’s behalf. Merchants are responsible for their own privacy notice, lawful basis for processing, and (where applicable) registration with the ODPC. We provide the tools to help.

4.Why we process your information

We process your personal information only when we have a lawful basis under the KDPA and other applicable laws. The lawful basis for each activity is:

  • Performance of a contract— to provide, maintain, and improve our Services, process transactions, activate settlement, deliver Orders, provide support, and manage your account.
  • Legitimate interests— to detect and prevent fraud, secure our platform, monitor abuse, improve user experience, conduct analytics, and send product updates (where you have not opted out). We balance these interests against your rights and expectations.
  • Legal obligations— to comply with applicable laws, regulations, court orders, or government requests, including anti-money-laundering, sanctions screening, tax reporting, and record-keeping obligations in Kenya.
  • Your consent— where we rely on your consent to process your data (for example, marketing communications, non-essential cookies, or precise location), you may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.
  • Vital interests / public interest— in rare cases where processing is necessary to protect someone’s life or to comply with a task carried out in the public interest.

5.What information we collect

The personal information we collect depends on how you interact with our Services.

Information you provide directly

  • Account information— name, email address, phone number (including WhatsApp number), password, and business details when you register.
  • Payment and financial information— M-Pesa phone numbers, bank account details, till and paybill numbers, mobile-money transaction references, and billing addresses necessary to process payments and settle funds to Merchants. Payments are processed by our payment processor, Paystack; Shopeak does not store full card numbers.
  • Identity and business verification— National ID number, KRA PIN, business registration certificates, licence numbers, beneficial-owner information, and other documents required for seller verification, KYC, and regulatory compliance.
  • Store and product content— product descriptions, images, pricing, inventory data, and storefront customisation settings.
  • Buyer and Order data— delivery address, order contents, gift-message text, and returns or dispute correspondence.
  • Communications— messages you send through our support channels, feedback forms, or correspondence with us, including recordings or transcripts of support calls where notified.

Information collected automatically

  • Device and usage data— IP address, browser type, device model, operating system, unique device identifiers, pages visited, actions taken, timestamps, and referral URLs.
  • Location data— approximate location derived from your IP address. We do not collect precise GPS location without your explicit consent.
  • Fraud and security signals— device fingerprints, behavioural signals, and risk scores used to detect fraud, abuse, and account takeover.
  • Cookies and similar technologies— see the Cookies section below.

Information from third parties

  • Payment providers— transaction confirmation, settlement, and account-verification details from our payment processor, Paystack, and from M-Pesa and other payment networks.
  • Sanctions and identity screening services — results of screening against publicly available sanctions and law-enforcement lists.
  • Analytics services— aggregated usage and performance data from our analytics providers.
  • Social login providers— basic profile information when you choose to sign in through a third-party service (e.g., Google).

6.How we use your information

We use the information we collect to:

  • Create and administer your account, verify your identity, and provide the Services.
  • Process transactions, activate direct Settlement, disburse Payouts, and reconcile fees.
  • Enable communication between Buyers and Merchants and send transactional notifications (Order confirmations, delivery updates, dispute correspondence, security alerts).
  • Detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms or Acceptable Use Policy.
  • Comply with legal, regulatory, tax, accounting, and reporting obligations, and respond to lawful requests from regulators or law-enforcement agencies.
  • Provide analytics, measure the effectiveness of our Services, and improve them.
  • Send you product updates, tips, and marketing communications you have not opted out of (see Direct marketing).
  • Enforce our agreements and defend legal claims.

7.Sub-processors and third parties

To deliver the Services we rely on a small set of trusted sub-processors. Each is bound by written terms that require them to protect your data at a standard consistent with the KDPA. Our current sub-processors are:

  • Paystack Payments Limited— payment processing and settlement (Kenya, Nigeria, South Africa). Privacy notice at paystack.com/privacy.
  • Microsoft Azure— cloud hosting and database infrastructure, primarily in the South Africa North region.
  • Vercel Inc.— front-end hosting and edge delivery for our public websites.
  • Google LLC— Google Sign-In for optional social login; Google Fonts for typography; Google Maps for address autocomplete where enabled by the Merchant.
  • Meta Platforms, Inc.— WhatsApp Business API for optional order notifications and Merchant ↔ Buyer messaging where the Merchant has enabled it.
  • Transactional email provider— for sending Order confirmations, security emails, and support correspondence.
  • Sanity.io— content management for our marketing website and Merchant help centre.
  • Vercel Analytics and Speed Insights— aggregate, privacy-preserving traffic and performance analytics for our public websites.

We may also disclose information to professional advisers (lawyers, auditors, accountants), potential acquirers in connection with a merger or sale, regulators, courts, or law-enforcement agencies where required or permitted by law.

8.Automated decision-making and profiling

We use limited automated processing to keep the Platform safe and functional, including to score transactions for fraud risk, prioritise dispute investigations, prevent account takeover, and enforce our Acceptable Use Policy. These systems can, in some cases, block a transaction, hold a Settlement, or suspend an account without human intervention.

Under KDPA §35, you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, unless the decision is necessary for a contract with us, authorised by law, or based on your explicit consent. Where an automated decision affects you, you may request human review by contacting privacy@shopeak.co.ke. We will re-review the decision, explain the reason, and correct it if the review finds error.

We do not use automated decision-making for advertising, credit scoring, or employment.

9.Your rights over your information

Under the KDPA and other applicable data-protection laws, you have the following rights:

  • Right of access— request a copy of the personal data we hold about you.
  • Right to rectification— request correction of inaccurate or incomplete personal data.
  • Right to erasure— request deletion of your personal data, subject to legal and contractual retention obligations.
  • Right to restrict processing— request that we limit how we use your data in certain circumstances.
  • Right to data portability— receive your personal data in a structured, commonly used format or request its transfer to another controller.
  • Right to object— object to processing based on our legitimate interests (including profiling) or for direct marketing.
  • Right to withdraw consent— where processing is based on consent, withdraw that consent at any time.
  • Right to human review of solely automated decisions with significant effects (see Automated decision-making).
  • Right to lodge a complaint with the ODPC.

To exercise any of these rights, please contact us at privacy@shopeak.co.ke. We will respond within 30 days as required by the KDPA. We may ask you to verify your identity before processing your request, and we may extend the response period by up to 60 days for complex requests (with notice to you).

10.Where we send your information

Shopeak is headquartered in Nairobi, Kenya. To deliver our Services, your personal data may be transferred to and processed in countries outside Kenya. These transfers occur principally with our cloud infrastructure providers (South Africa, Ireland, or the United States) and our payment processor.

Sharing with our payment processor. To enable payments and direct Settlement, we share certain information with our payment processor, Paystack:

  • For Merchants— business name and registration details, and settlement account details (bank account, M-Pesa number, till, or paybill), used to provision the Merchant’s dedicated settlement subaccount, verify the account holder, and settle funds directly to the Merchant. This sharing also supports Paystack’s own know-your-customer (KYC) and anti-money-laundering obligations.
  • For Buyers— transaction details (amount, payment channel, and contact details needed to process the payment). Card payments are processed by Paystack on PCI-compliant infrastructure; Shopeak never receives or stores full card numbers.

When we transfer personal data outside Kenya, we ensure appropriate safeguards are in place under the KDPA, including:

  • Transfers to countries that have been determined to have adequate data-protection standards by the ODPC;
  • Contractual arrangements with our service providers that require them to protect your data to a standard equivalent to that required in Kenya;
  • Your explicit consent, where appropriate.

11.How long we retain your information

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required to satisfy legal, regulatory, accounting, or reporting obligations. Our default retention periods are:

  • Active accounts— for the duration of your account and your use of the Services.
  • Closed Merchant accounts— Storefront configuration and product catalogues are retained for 2 years after account closure, after which they are securely deleted or anonymised.
  • Financial and transaction records— up to 7 years to comply with the Income Tax Act, VAT Act, and anti-money-laundering record-keeping requirements.
  • KYC and identity verification documents — up to 7 years after the end of the customer relationship, in line with AML retention obligations.
  • Support communications— typically 3 years after resolution.
  • Marketing and waitlist data— until you unsubscribe or request removal, at which point we suppress your email on our marketing list to honour the opt-out.
  • Server logs and security telemetry— typically 90 days, longer for records tied to a specific security incident.

When personal data is no longer needed, we securely delete or anonymise it so that it can no longer be associated with you.

12.How we protect your information

We implement appropriate technical and organisational measures to protect your information against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit (TLS 1.2+) and at rest.
  • Role-based access controls that limit who within our organisation can access personal data, based on role and necessity.
  • Multi-factor authentication for administrative access.
  • Least-privilege infrastructure design, network segmentation, and audit logging.
  • Regular vulnerability scanning, dependency-security monitoring, and periodic penetration testing.
  • Secure handling of payment data through PCI-compliant partners; Shopeak does not store full card numbers.
  • Vendor risk assessment before onboarding a new sub-processor.

While we strive to protect your personal data, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but we are committed to promptly investigating and addressing any breach.

13.Data breach notification

We maintain an incident-response process that identifies, contains, investigates, and remediates security incidents. If a personal-data breach is likely to result in a risk to the rights and freedoms of natural persons, we will:

  • Notify the ODPC without undue delay and, where feasible, within 72 hours of becoming aware of the breach, as required by KDPA §43;
  • Notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms;
  • Include in each notification the nature of the breach, the categories and approximate number of data subjects concerned, the likely consequences, and the measures we have taken or propose to take;
  • Maintain internal records of all incidents, including those that do not require notification.

If you become aware of, or suspect, a security incident affecting your account or data on the Services, please email security@shopeak.co.ke immediately.

14.Direct marketing

We send two kinds of email and messaging:

  • Transactional communications(Order confirmations, delivery updates, security notices, billing) — you cannot opt out of these while your account is active, because they are necessary to provide the Services.
  • Marketing communications(product news, tips, promotional offers) — sent only where you have opted in, or where permitted by law and you have not objected. You may withdraw consent at any time by clicking “unsubscribe” in any marketing email, adjusting your notification preferences in your account, or emailing privacy@shopeak.co.ke.

Merchants are separately responsible for obtaining consent for their own marketing to Buyers on their Storefront.

15.Cookies and tracking technologies

We use cookies and similar tracking technologies to operate, improve, and personalise our Services. Cookies are small text files placed on your device that help us understand how you interact with our platform.

Types of cookies we use

  • Essential cookies— required for the basic operation of our Services, such as maintaining your session and security. These are always active.
  • Analytics cookies— help us understand how visitors interact with our websites, enabling us to improve performance and user experience.
  • Functional cookies— remember your preferences and settings to provide a more personalised experience.
  • Advertising cookies— we do not currently set third-party advertising cookies on our marketing website. If we introduce them, we will update this Policy and (where required) request your consent.

Managing cookies

You can control or disable cookies through your browser settings. Please note that disabling essential cookies may affect the functionality of our Services.

16.Children's privacy

Our Services are not directed at individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal data from a child without appropriate parental consent, we will take steps to delete that information promptly. If you believe a child has provided us with personal data, please contact us at privacy@shopeak.co.ke.

17.Data Protection Officer

Shopeak has designated a Data Protection Officer (“DPO”) responsible for advising on our compliance with the KDPA, monitoring processing activities, and acting as the contact point for the ODPC and data subjects. The DPO can be contacted at dpo@shopeak.co.ke.

18.Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or sub-processors. When we make material changes, we will notify you by posting the updated policy with a revised “Last updated” date and, where appropriate, by email or in-app notification at least 14 days before the change takes effect.

Your continued use of our Services after the posting of changes constitutes your acceptance of the revised Policy.

19.How to reach us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Privacy enquiries

Data Protection Officer

Security incidents

Mailing address

Shopeak Global
A company of Theta Holdings
Nairobi, Kenya

Regulatory authority

Office of the Data Protection Commissioner (ODPC)
P.O. Box 00200, Nairobi, Kenya