Privacy policy

Kava Kenya (“we,” “us,” “our”) operates this store and website, including all related information, content, features, tools, products, and services (the “Services”). We use Shopify to power our store. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit, use, or make a purchase via the Services or otherwise communicate with us. If anything here conflicts with our Terms of Service, this Privacy Policy controls for the collection, use, and disclosure of personal information.

By using the Services, you acknowledge this Privacy Policy.

1) Personal Information We Collect

Personal information” means information that identifies or can reasonably be linked to you. It does not include anonymized or de-identified data.

Categories we may collect:

  • Contact details (name, billing/shipping address, phone, email).
  • Payment & transaction data (order details, payment method, payment confirmations). We do not store full card details—payments are processed by secure providers (e.g., Shopify Payments and/or M-Pesa/Safaricom).
  • Account info (username, password, preferences).
  • Device & usage info (IP address, browser, device, pages viewed, cookies/GPC signals). 
  • Communications (emails, support messages, reviews).
  • Inferences (preferences drawn from browsing/purchase activity).

2) Sources of Personal Information

  • Directly from you (creating an account, placing orders, contacting support).
  • Automatically via cookies, pixels, or similar tech when you browse our store.
  • Service providers (hosting, payments, fulfillment, analytics, customer support).
  • Partners/third parties (e.g., advertising or analytics, as applicable).

3) How We Use Personal Information

  • Provide & improve the Services (process orders, payments, shipping/returns, account management, customer support, personalize content, recommendations).
  • Marketing & advertising (emails/SMS/postal mail; showing ads on our site or others based on your activity—see “Your Rights” for opt-out). Shopify may support personalized advertising across merchants; see Shopify’s consumer privacy notice and privacy portal for choices. 
  • Security & fraud prevention (authenticate accounts, detect/prevent fraud or abuse).
  • Legal & compliance (comply with laws, respond to lawful requests, enforce our terms).

4) How We Disclose Personal Information

We may disclose personal information to:

  • Shopify (store hosting, checkout, analytics, advertising features), and other service providers (payments, M-Pesa/Safaricom, fulfillment/couriers, cloud storage, support tools, analytics) who process data for us under instructions. 
  • Business/marketing partners (to show ads or measure campaigns, where allowed). You may have the right to direct us not to share for targeted advertising—see “Your Rights.” Shopify also offers consumer opt-out choices. 
  • Parties you direct us to share with (e.g., couriers), our affiliates, and in a business transaction (merger, acquisition, insolvency), or where required by law.

5) Relationship with Shopify

We use Shopify to power our store. Shopify collects and processes certain data about your interactions with our store (and across other merchants) to operate and improve its services, including advertising features. For details or to exercise rights available with Shopify as controller for those features, visit: Shopify Consumer Privacy Policy and Shopify Privacy Portal

6) Cookies, Analytics & Global Privacy Control (GPC)

We use cookies and similar technologies for functionality, analytics, and (where applicable) advertising. If your browser sends a GPC signal, Shopify honors it in regions where a data-sharing opt-out page is used; we also provide manual opt-out methods described below. 

7) Children’s Data

Our Services are not intended for children under the age of majority in your jurisdiction. We do not knowingly collect personal information from children. If you believe a child has provided data, contact us to delete it.

8) Security & Retention

We use reasonable technical and organizational measures to protect personal information; however, no method is 100% secure. We retain data only as long as necessary for the purposes described (e.g., to provide Services, comply with law, resolve disputes, enforce policies). See Kenya DPA storage/retention expectations. 

9) Your Rights & Choices (Kenya & Other Regions)

Under the Kenya Data Protection Act, 2019 and applicable regulations/guidance, you may have the right to:

  • Be informed of how your data is used.
  • Access your personal data we hold.
  • Object to processing (including direct marketing).
  • Correction of inaccurate data.
  • Deletion/erasure of inaccurate or unlawfully held data.
  • Data portability (receive/transfer a copy, where applicable).
  • Not be subject to decisions based solely on automated processing that significantly affect you. 

How to exercise your rights

  • Email us at dicksonomondi11@gmail.com with your request and enough information to verify your identity.
  • For data Shopify controls in connection with cross-merchant features, use the Shopify Privacy Portal or see their Consumer Privacy Policy
  • Marketing emails: use the unsubscribe link in our messages.
  • Targeted ads/data sharing: contact us to opt out; where available, we also honor GPC signals as described above. 

We will not discriminate against you for exercising your rights. You may appoint an authorized agent, subject to verification.

10) Complaints (Kenya)

If you have concerns about our handling of personal information, please contact us first (see “Contact” below). If unresolved, you may lodge a complaint with the Office of the Data Protection Commissioner (ODPC). See ODPC’s official site and complaint portal for instructions and contact details. 

11) International Transfers

We may transfer, store, and process your personal information outside Kenya (e.g., in the EU, UK, or US) where our providers (including Shopify) operate. When we do, we rely on appropriate safeguards (such as Standard Contractual Clauses) or other lawful bases recognized by applicable law. 

12) Third-Party Links

Our Services may link to third-party sites. Their privacy and security practices apply when you visit them; we are not responsible for their content or policies.

13) Changes to this Privacy Policy

We may update this Privacy Policy to reflect operational, legal, or regulatory changes. We will post updates here and revise the “Last updated” date; where required by law, we will provide additional notice.

14) Contact Us

Kava Kenya
Ruhan Plaza, Kahawa Sukari
Postal Code: 00100, Ruiru, Kenya
Phone/WhatsApp: +254 702 251255
Email: dicksonomondi11@gmail.com

If you have questions about this Privacy Policy or wish to exercise your rights, contact us at the details above.