The short version.
If you only read one section, read this one.
-
01
We collect what we need to run your duka — products, orders, customers, and your account info.
-
02
For storefront shoppers, the store owner is responsible for the customer relationship, order, delivery, refund, and lawful use of buyer data.
-
03
We use Google Sign-In to make signing in easier. We only see your name, email, and photo. We never see your Google password.
-
04
We never sell your data. We never use it to advertise to your customers.
-
05
You can export or delete your data at any time from Settings.
-
06
If we change this policy in a meaningful way, we will email you first.
The data controller.
TopDuka is operated by ScaleNodes Ltd, a company registered in Kenya. For merchant accounts, billing, platform security, support, and product analytics, ScaleNodes Ltd is the "data controller" — the party that decides why and how that personal data is processed.
For customer data entered into a merchant storefront, the store owner is usually the data controller and TopDuka acts as the platform processor. That means the merchant is responsible for having a lawful reason to collect customer information, using it fairly, handling order support, and honouring customer privacy requests connected to that store.
— Registered office
ScaleNodes Ltd · Westlands, 4th Floor · P.O. Box 12345 · Nairobi, Kenya
Data Protection Officer · dpo@topduka.com
What we collect.
Six categories, and a reason for each. If we ever need something new, we will ask first.
Account info
Name, email, profile photo, password (hashed), phone number (optional), and which sign-in method you chose.
e.g. wanjiru@honeylane.co.ke
Storefront content
Product names, descriptions, photos, prices, stock levels, categories, and any digital assets you upload.
Stored on our EU-backed object store.
Customer & order data
Order details, delivery addresses, transaction records, and messages between a store owner and their customers. We process this to run the merchant storefront; the store owner remains responsible for the buyer relationship.
Used for fulfilment, returns, support, and tax.
Usage & device data
Pages viewed, button clicks, device type, browser, country, and IP-derived location (not precise GPS).
Helps us fix bugs and improve UX.
Support & feedback
Anything you send to our support team, including email, in-app chat, and recorded screen-share sessions (only with your consent).
Kept for 24 months for training purposes.
Integrations you connect
If you connect M-Pesa, a delivery partner, an accounting tool, or a custom API, we receive the data those tools send us to do their job.
You can disconnect any of them at any time.
Why we collect it.
Each purpose is tied to a legal basis under GDPR and the Kenya Data Protection Act.
| Purpose | |
|---|---|
| 01 | Run the service you signed up for Host your storefront, process orders, send receipts. |
| 02 | Keep your account and customers safe Detect fraud, block bots, verify suspicious sign-ins. |
| 03 | Meet legal and tax obligations Issue VAT-compliant receipts, keep audit logs. |
| 04 | Help you when you ask Reply to support tickets, follow up on bugs. |
| 05 | Make TopDuka better (aggregated) See which features are used most, A/B test UI changes. |
| 06 | Tell you about TopDuka (optional) Product updates and launch offers. You can unsubscribe in one click. |
Google Sign-In: what we see, what we don't.
We let you sign in with Google so you don't have to remember another password. This section is the full breakdown of what that does to your data, written so you can make an informed choice before you click the button.
When you choose Continue with Google, Google confirms your identity and shares a small set of profile facts with us. That is the only data we ever receive from Google — and we use it only to create and sign you into your TopDuka account.
— What we receive from Google
5 fields-
sub
A unique Google user ID (not your email, not reversible to your password).
-
name
Your full name as saved in your Google profile.
-
email
Your primary email address.
-
email_verified
A boolean telling us Google has verified the email.
-
picture
A URL to your profile photo, used in the dashboard.
— What we NEVER receive
0 fields-
Your Google password (we could not see it if we wanted to).
-
Your Gmail messages, contacts, or calendar.
-
Any file in your Google Drive, Docs, Sheets, or Photos.
-
Your search history, location history, or YouTube history.
-
Data from any other Google service you have not shared.
— The flow, step by step
~ 2 seconds-
01
You → TopDuka
You click "Continue with Google" on our sign-in page.
-
02
TopDuka → Google
We send you to a Google-hosted window that asks for your consent.
-
03
Google → You
Google asks you to confirm which profile and email you want to share.
-
04
You → Google
You tap Allow. (You can also cancel — we never see your password.)
-
05
Google → TopDuka
Google sends us a short-lived code. We exchange it for your basic profile.
-
06
TopDuka → You
We create or open your account and sign you in. We do not see anything else in your Google account.
— How we store it
Encrypted at rest in our EU-hosted database. Tied to your TopDuka account row, not stored separately.
— How long we keep it
For as long as your TopDuka account is open. If you disconnect Google, we keep the email so you can still sign in by password.
— How we use it
To create your account, sign you in, send receipts to the right address, and show your name and photo inside the dashboard.
— How we do NOT use it
We do not enrich your profile, build an advertising ID, sell it to anyone, or share it with other tenants.
How long we keep your data.
We delete data when we no longer need it. Some data we have to keep for tax and legal reasons.
| Type of data | How long |
|---|---|
Account profile | Until you delete the account |
Storefront & products | Until you delete or close the duka |
Orders, invoices, tax records | 7 years (required by Kenyan tax law) |
Order email logs | 90 days, then aggregated |
Support tickets | 24 months, then pseudonymised |
Backups | 30 days rolling, then overwritten |
Backups after account deletion | 30 days, then permanently wiped |
Your rights over your data.
You have seven rights under the Kenya Data Protection Act and the GDPR. We respect all of them, and we will not make it hard to use them.
Access
01Get a copy of every piece of data we hold about you and your duka.
Correct
02Fix anything that is wrong. Most things you can change in the dashboard yourself.
Delete
03Delete your account and all your data, subject to the tax retention we have to keep.
Export
04Download your products, orders, and customers as CSV or JSON whenever you want.
Object
05Object to specific processing — for example, marketing emails — and we will stop.
Withdraw consent
06If we ever rely on consent (today, only for marketing), you can take it back at any time.
Complain
07Complain to a data protection authority. In Kenya that is the Office of the Data Protection Commissioner.
To exercise any of these, email dpo@topduka.com. We respond within 14 days, often faster.
Where your data lives.
TopDuka is hosted on AWS in the EU (Frankfurt and Ireland) by default. If you explicitly choose the South-Africa region for your storefront, your customer-facing data is hosted in Cape Town. Some metadata (sign-in, audit logs) may be processed in the US by our sub-processors under Standard Contractual Clauses.
How we keep it safe.
Security is layered. The most important things we do:
Encryption in transit
HTTPS only, TLS 1.2+ everywhere.
Encryption at rest
Customer data and backups are encrypted with AES-256.
Access control
Staff access is least-privilege, audited, and protected by hardware MFA.
Penetration testing
Independent pen-test every 12 months. Findings published in our trust report.
Bug bounty
We run a paid bug bounty for security researchers.
Incident response
We will notify affected account owners within 72 hours of any confirmed breach.
Children's privacy.
TopDuka is built for adult business owners. We do not knowingly collect data from anyone under 18. If you believe a child has signed up, email dpo@topduka.com and we will close the account within 48 hours.
Changes to this policy.
We may update this Privacy Policy. For material changes — for example, a new data category or a new sub-processor — we will email account owners and show an in-app notice at least 14 days before the change takes effect. The version number and "Last updated" date at the top will always tell you which version you are reading.
v Changelog
- v3.1 · 2026-06-07Clarified merchant storefront customer data roles, payment provider sharing, and store owner responsibility for buyer relationships.
- v3.0 · 2026-06-02Added a dedicated Google Sign-In section with the field-by-field data flow and revoke instructions.
- v2.4 · 2025-11-14Aligned to the TopDuka rebrand. Replaced ScaleNodes brand references.
- v2.3 · 2025-04-02Added a clear retention table and brought cookies into a single table.
- v2.2 · 2024-10-18Added sub-processor list and made the data controller identity explicit.
Contact the DPO.
Questions, requests, complaints — start with our Data Protection Officer. We will reply within 14 days, usually much faster.
01 · DPO email
dpo@topduka.com
Reply within 14 days
02 · General privacy
privacy@topduka.com
For sub-processor & cookie questions
03 · Supervisory authority
Office of the DPC, Kenya
odpc.go.ke · +254 20 222 5680
That's it. No dark patterns, no fine print.
If anything on this page is unclear, send a screenshot and a quick note to dpo@topduka.com and we will rewrite the part that confused you.