1.Who is responsible for your data
Umoja is the data controller for the personal data described here. We handle it under the Kenyan Data Protection Act 2019.
For anything in this policy — a copy of your data, a correction, a deletion, or a complaint — email privacy@umoja.co.ke.
2.What we collect
Everyone with an account. Your email address, and your phone number and display name if you give them. We do not store a password — you sign in with a one-time code.
When you buy. The email address and phone number you enter at checkout, what you bought, what you paid, and a reference from the payment provider. We never see or store your card number or your M-Pesa PIN — those go straight to the payment provider.
When you sell. Your storefront name, handle, bio and avatar, which are public by design. To verify you and pay you we also collect your full legal name and national ID number, and your M-Pesa number or bank account details.
Automatically. Server logs recording requests to the platform — IP address, browser, timestamps, and an identifier that lets us trace a single request end to end when something goes wrong.
We run no advertising trackers, no analytics products and no third-party marketing pixels. The cookie policy lists every cookie we set — there are four, and all of them exist to make the site work.
3.Why we are allowed to use it
Each thing we do with your data rests on one of these grounds.
- To perform our contract with you — creating your account, taking payment, delivering files, paying creators, handling disputes.
- To comply with a legal obligation — verifying creator identity, keeping tax and financial records, responding to lawful demands.
- For our legitimate interests — keeping the platform secure, preventing fraud, debugging failures, and understanding which parts of the product work. We balance these against your interests and use the least data that achieves the purpose.
- With your consent — marketing messages, and nothing else. Consent is opt-in, and withdrawing it is one click in settings or in any message we send.
4.Who else sees it
We do not sell your personal data, and we never have. We share it only with the companies that make the service function, each processing it on our instructions and for no purpose of their own.
- Payment and payout providers — to take payment from buyers and send money to creators. They receive the details necessary for the transaction and are regulated in their own right.
- Email and SMS providers — to send login codes, receipts, download links and payout notices.
- Hosting and file storage providers — to run the platform and store the products creators upload.
Beyond that, we disclose data only where the law requires it, or where it is necessary to establish or defend a legal claim.
Between users.A creator sees the email address on an order placed with them, because they may need to support that buyer. A buyer sees the creator’s public storefront. Neither sees the other’s payout details, ID documents or account history.
5.Where it is processed
Some of our providers process data outside Kenya. Where that happens we rely on the transfer conditions in Part VI of the Data Protection Act: the transfer is necessary to perform our contract with you, and we use providers who commit contractually to appropriate safeguards.
6.How long we keep it
Different data has different clocks, because different laws apply to it.
- Account details — while your account is open, then anonymised when you close it.
- Financial records — orders, payments, ledger entries and payouts are kept for five years, which is the retention period the Tax Procedures Act requires. These survive account closure. They are records of money moving, and we are not permitted to delete them on request.
- Identity verification records — your national ID number is deleted outright when your account closes. It has no retention basis beyond the account, and it is the most sensitive field we hold.
- Payout details — cleared when your account closes.
- Server logs — kept short-term for security and debugging, then discarded.
7.Your rights
Under sections 26 and 40 of the Data Protection Act you can ask us to:
- tell you what we hold about you, and give you a copy;
- correct anything inaccurate or incomplete;
- delete your data, subject to what section 8 below explains;
- restrict what we do with it, rather than delete it;
- stop processing it where we rely on legitimate interests;
- stop sending you marketing, at any time and without a reason.
Most of these are immediate in your account settings. For the rest, email privacy@umoja.co.ke. We respond within 14 days, free of charge. Exercising a right never costs you access to the service.
8.What deleting your account actually does
We would rather tell you precisely than say “we delete your data” and leave you to discover the exceptions.
Removed or replaced:your email address and phone number are replaced with a value derived from your account’s internal identifier — not a scrambled version of the original, which could be worked backwards. Your display name, storefront name, bio and avatar go. Your national ID record is deleted entirely. Your bank and M-Pesa details are cleared. Your listings are taken off sale, every active session ends, and any live download link is revoked. Reviews you wrote keep their text and lose your name, because other buyers rely on them.
Kept: the financial record of transactions that actually happened — order totals, payments, ledger entries and payouts. Section 39 of the Act permits retention that another law requires, and section 40(3) says that where personal data is needed as evidence, we restrict its processing instead of erasing it. The tax record survives; the person attached to it does not.
Requests are actioned within 14 days. We cannot action one while you still have money in your wallet, a payout in flight, or an open dispute — we tell you which of these is in the way so you can clear it.
9.How we protect it
Session cookies are HTTP-only, so no script on the page can read them. Download links are stored only as hashes, expire after 48 hours, and can be revoked. Everything travels over TLS. Access to production data is limited to the people who need it, and administrative actions on accounts are recorded with the identity of whoever took them.
No system is perfect. If a breach occurs that presents a real risk to you, we notify the Office of the Data Protection Commissioner within 72 hours and tell you directly.
10.Children
Umoja is for adults. We do not knowingly collect data from anyone under 18, and we delete such an account and its data when we find one.
11.Complaints
Tell us first — email privacy@umoja.co.ke and we will look into it properly. If you are not satisfied, you have the right to complain to the Office of the Data Protection Commissioner, the supervisory authority for data protection in Kenya.
12.Changes to this policy
The date at the top shows the current version. Where a change materially affects how we use your data, we tell you by email before it takes effect rather than quietly editing this page.