This Privacy Policy ("Policy") explains how myDuka ("myDuka", "we", "us", "our") collects, uses, shares and protects personal data when you visit our website at www.myduka.co.tz, register an account, manage a Storefront, place an order on a vendor Storefront or otherwise interact with our services (collectively, the "Platform").
We process your personal data in accordance with the Personal Data Protection Act, 2022 (Act No. 11 of 2022) of the United Republic of Tanzania (the "PDPA"), the Personal Data Protection (Personal Data Collection and Processing) Regulations, 2023, the Electronic Transactions Act, 2015, the Electronic and Postal Communications Act, 2010 and any other applicable Tanzanian law. The Personal Data Protection Commission ("PDPC") is the supervisory authority in Tanzania.
1. Who we are (Data Controller)
For the purposes of the PDPA, myDuka acts as the data controller in respect of:
- data of Vendors, their staff and admins of the platform;
- data we collect directly from visitors of
myduka.co.tz(e.g. through the contact form, registration, login or analytics); - operational logs, cookies and security data.
With respect to data that Vendors collect from their own customers (Buyers) on their Storefronts (e.g. order name, phone, email, delivery address), the Vendor is the data controller and myDuka acts as a data processor on their behalf, subject to a data-processing arrangement reflected in the Terms and Conditions and this Policy.
Contact for data-protection matters:
Email: support@myduka.co.tz
Web: https://www.myduka.co.tz/contact
Country: United Republic of Tanzania.
2. Personal data we collect
2.1 Account data (Vendors and platform users)
- Full name, mobile number, email address, password (stored hashed), profile photo (avatar), preferred language and role (tenant, staff, admin, super-admin).
- Shop information: shop name, business phone, business category, sub-domain slug, custom domain (if any) and DNS verification status.
- Subscription data: chosen plan, billing interval, plan limits, subscription status, trial information, promo codes redeemed and affiliate code.
2.2 Buyer data (collected on Vendor Storefronts)
- Customer name, customer phone number, customer email (optional), delivery address, order history (items, quantities, prices in TZS, order status).
- Cart contents (held in your browser session) and the WhatsApp message generated for WhatsApp checkout.
2.3 Payment data
- For SaaS subscription payments and Vendor storefront orders processed through integrated payment gateways (e.g. Pesapal, Selcom, AzamPay): merchant reference, payment status, gateway tracking ID, amount in TZS, billing interval and gateway metadata.
- For manual subscription payments: the proof of payment and admin confirmation.
- We do not see or store full card numbers, CVV codes or mobile-money PINs. These are entered directly on the payment provider's secure environment.
2.4 Communications data
- Contact-form submissions (name, email, phone, message) sent to support@myduka.co.tz.
- SMS one-time passwords sent through licensed Tanzanian aggregators (e.g. Beem Africa) for mobile verification or password reset.
- Transactional and marketing emails (only where you have a relationship with us or where you have opted in).
2.5 Technical and usage data
- IP address, device and browser information, time-zone, referring URLs, pages viewed, language and locale.
- Server logs and security events used to detect fraud, abuse and to comply with legal obligations.
- Session and CSRF cookies, locale preference cookie, and similar technologies (see Section 7 below).
2.6 Affiliate / referral data
- Your unique affiliate code, the user who referred you (if any), and the credit ledger entries (in TZS) used only against future myDuka subscriptions.
2.7 Mobile application data (myDuka Vendor and myDuka Shop)
We publish two mobile applications: myDuka Vendor (for shop owners and staff, package tz.co.myduka) and myDuka Shop (for shoppers, package tz.co.mydukashop). When you use these apps we may additionally process:
- Device and diagnostic data — device model, operating-system version, app version, language, crash logs and performance/diagnostic data used to keep the apps stable and secure.
- Push notification tokens — a Firebase Cloud Messaging (FCM) registration token used to deliver order, delivery and account notifications. You can disable notifications in your device settings.
- Delivery address data — in myDuka Shop, the labels, region, ward, street and contact phone you type for delivery. Address details are entered by you; the apps do not track your precise GPS location in the background.
- Photos and camera — in myDuka Vendor, the images you choose to upload for products or your shop. The app accesses the camera or photo library only when you initiate an upload.
- Usage and identifiers — analytics events and identifiers described in Section 2.8.
2.8 Advertising and analytics identifiers
- Our apps use Google Analytics for Firebase to understand feature usage and improve the apps. This service may collect an advertising identifier (Advertising ID / IDFA) and app-instance identifiers. We use these only for analytics and core app functionality; we do not operate a third-party advertising network and we do not sell this data.
- "Sponsored" or "boosted" product placements you may see in myDuka Shop are first-party promotions of products listed by Vendors on our own Platform; they are not served by an external advertising network.
- Where applicable, we will request your consent (for example, App Tracking Transparency on iOS) before any processing that constitutes tracking.
We do not knowingly collect personal data of children under the age of 18. If you believe a child has provided us with personal data, please contact us so we can delete it.
3. Sources of personal data
We collect data:
- directly from you when you fill in a form (registration, login, contact, checkout, store settings);
- automatically through cookies, server logs and similar technologies as you use the Platform;
- from third parties such as payment processors (Pesapal, Selcom, AzamPay), SMS aggregators (Beem Africa), and DNS or domain-verification services;
- from Vendors, when they upload customer or staff information into their Storefront.
4. Purposes and lawful bases for processing
Under section 6 of the PDPA, we process personal data only when one or more of the following lawful bases apply:
- Performance of a contract with you (e.g. providing the Platform, fulfilling your subscription, processing your payments and orders).
- Compliance with a legal obligation (e.g. tax, anti-money-laundering, response to lawful requests from competent authorities).
- Your consent, freely given for specific purposes (e.g. marketing communications, optional cookies). You may withdraw consent at any time.
- Our legitimate interests, where these are not overridden by your rights — for example, platform security, fraud prevention, product improvement and limited service-related communications.
- Vital interests or public interest, in the rare cases provided by the PDPA.
5. How we use personal data
- To create and operate your account, authenticate you and protect your password.
- To provide and maintain Storefronts, accept orders, charge subscriptions and add-ons in TZS, apply promo codes and affiliate credits.
- To process payments through BoT-licensed providers and reconcile receipts (Pesapal IPNs and similar callbacks).
- To send service notifications, OTPs, password-reset messages, order confirmations and important updates.
- To detect, investigate and prevent fraud, abuse, security incidents and breaches of the Terms.
- To respond to your support requests and complaints submitted via the contact form or email.
- To comply with legal, regulatory and tax obligations under Tanzanian law.
- For internal analytics, troubleshooting and product improvement, using aggregated or pseudonymised data where possible.
6. Sharing of personal data
We share personal data only as described below and only as necessary:
- With Vendors — Buyer data submitted at checkout (name, phone, email, address and order details) is shared with the Vendor whose Storefront the Buyer used, so they can fulfil and support the order.
- With payment service providers (e.g. Pesapal, Selcom, AzamPay) — to initiate, process and reconcile payments. Their own privacy notices and applicable BoT/financial regulations apply to those processings.
- With messaging providers (e.g. Beem Africa) — to deliver SMS OTPs and notifications under EPOCA and TCRA rules.
- With Google (Firebase) — in our mobile apps we use Firebase Cloud Messaging for push notifications and Google Analytics for Firebase for app analytics and stability diagnostics. Google processes this data as described in the Firebase and Google privacy notices.
- With infrastructure and email providers — including hosting providers, transactional email mailers and CDN/SSL providers, bound by appropriate confidentiality and security obligations.
- With professional advisers — lawyers, accountants and auditors, on a need-to-know basis.
- With competent authorities — including the PDPC, TRA, Police, the courts of Tanzania and other regulators, where disclosure is required by law or by a valid legal process.
- In the context of a corporate transaction — if myDuka is involved in a merger, acquisition, restructuring or sale of assets, personal data may be transferred to the successor entity, subject to confidentiality and continued protection under this Policy.
We do not sell personal data, and we do not use Buyer data for our own marketing without an additional lawful basis.
7. Cookies and similar technologies
The Platform uses a small number of cookies:
- Strictly necessary cookies — the session cookie (name
myduka-session-v2) and CSRF token cookie required to keep you logged in and to protect form submissions. - Functional cookies — for example to remember your language preference (Swahili or English).
- Analytics or marketing cookies — only deployed if and when an admin enables them through the public custom-head/body HTML setting; if so, a cookie banner consistent with PDPC guidance will be shown.
You can configure your browser to refuse non-essential cookies. Disabling strictly necessary cookies will affect basic functionality such as login and checkout.
8. Data retention
We keep personal data only as long as necessary for the purposes described in this Policy or as required by law. Indicative retention periods:
- Account data: for as long as your account is active and up to 24 months after closure for security and dispute-resolution purposes.
- Subscription, payment and tax records: at least 10 years, in line with Tanzanian tax and record-keeping rules.
- Buyer order data on a Vendor Storefront: as long as the Vendor's tenant database exists and as required for their tax and consumer-protection obligations.
- Server logs and security data: typically 12 months, longer if needed to investigate an incident.
- Marketing data: until you opt out or until the data is no longer accurate.
When data is no longer needed, it is deleted or anonymised in a way that prevents re-identification.
9. International transfers
Personal data is primarily processed and stored in Tanzania. Where we use service providers located outside Tanzania (for example, certain email or content-delivery providers), we will only transfer personal data in accordance with section 30 of the PDPA, ensuring that the recipient country offers an adequate level of protection or that appropriate safeguards (such as contractual clauses) are in place. Where required, we will obtain prior authorisation from the PDPC.
10. Security of personal data
We apply reasonable technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction, including:
- HTTPS / TLS encryption for traffic between your browser and our servers and for connections to payment providers;
- password hashing using industry-standard algorithms (bcrypt) and never storing passwords in clear text;
- role-based access control (super_admin, admin, staff, tenant) and per-tenant database isolation;
- OTP-based mobile-number verification for tenant accounts, throttling and CSRF protection;
- logical and physical access restrictions, security logging and periodic review.
Despite these measures, no system is completely secure. In the event of a personal-data breach likely to result in a risk to your rights, we will notify the PDPC and, where required, affected data subjects, in accordance with the PDPA and its Regulations.
11. Your rights as a data subject
Subject to the conditions and exceptions of the PDPA, you have the right to:
- be informed about how we process your personal data;
- access the personal data we hold about you;
- request rectification of inaccurate or incomplete data;
- request erasure ("right to be forgotten") where the data is no longer necessary or processing was based on consent that you have withdrawn;
- restrict or object to certain processing;
- data portability, where technically feasible, for data you provided based on consent or contract;
- withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal;
- lodge a complaint with the PDPC if you believe your rights have been infringed.
To exercise any of these rights, write to support@myduka.co.tz. We will respond within the timelines required by the PDPA (generally not more than 30 days, with possible extension as permitted by law). We may need to verify your identity before acting on a request.
If your request relates to data held by a Vendor on its Storefront (e.g. an order you placed with that Vendor), we may forward the request to the Vendor as the data controller and assist them in responding.
12. Automated decision-making
We do not use automated decision-making that produces legal effects or similarly significant effects on you without human review. Limited automated processing is used for spam protection, throttling, fraud detection, invoice generation and the calculation of affiliate credits.
13. Marketing communications
We may send you service-related messages (e.g. OTPs, billing notices, security alerts) that are necessary for the operation of your account; these are not "marketing" and you cannot opt out so long as you maintain an account. For optional marketing emails or SMS, we will obtain your consent in advance and you may withdraw it at any time using the unsubscribe link or by contacting us.
14. Third-party links and services
The Platform may link to or integrate with third-party services (payment providers, WhatsApp, custom-domain DNS providers, etc.). Their privacy notices apply to data they collect directly from you. We are not responsible for those third parties' practices.
15. Changes to this Policy
We may update this Policy from time to time to reflect changes in our services, the law or PDPC guidance. Material changes will be notified by email or in-app notice and the "Last updated" date at the top of this page will change. Please review this Policy periodically.
16. Account and data deletion
You can request deletion of your account and associated personal data at any time:
- by email to support@myduka.co.tz from your registered email address (or through the in-app support / profile option), stating that you wish to delete your account;
- from your account settings on the web, where that option is available.
Once we have verified your identity, we will delete or irreversibly anonymise your personal data, normally within thirty (30) days, except data we are required to keep under Tanzanian tax, anti-money-laundering, accounting and other legal obligations (see Section 8) or that we need to resolve disputes and enforce our agreements. If you are a Buyer who placed an order with a Vendor, certain order records are controlled by that Vendor; we will forward your request to them.
17. Complaints and contact
If you have any questions, requests or complaints about how we handle personal data, please contact us first:
myDuka
Email: support@myduka.co.tz
Web: https://www.myduka.co.tz/contact
If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commission of Tanzania, the supervisory authority established under the Personal Data Protection Act, 2022.