Launch offer · your first month for KES 500 only

Legal · Vol. 02 Last updated June 7, 2026 · v3.1 · GDPR & Kenya DPA compliant

Privacy Policy —
what we keep, what we don't.

We collect only what we need to run your duka, we keep it safe, and we never sell it. This page walks you through exactly what that means in practice.

Effective

June 2, 2026

UTC · all regions

Version

v3.1

Changelog below

Region

Kenya · GDPR-aligned

ODPC registration #OPC-2024-…

Read time

~ 8 minutes

Plain-English version: 2 min

00 · In plain English

The short version.

If you only read one section, read this one.

  • 01

    We collect what we need to run your duka — products, orders, customers, and your account info.

  • 02

    For storefront shoppers, the store owner is responsible for the customer relationship, order, delivery, refund, and lawful use of buyer data.

  • 03

    We use Google Sign-In to make signing in easier. We only see your name, email, and photo. We never see your Google password.

  • 04

    We never sell your data. We never use it to advertise to your customers.

  • 05

    You can export or delete your data at any time from Settings.

  • 06

    If we change this policy in a meaningful way, we will email you first.

01 · Who we are

The data controller.

TopDuka is operated by ScaleNodes Ltd, a company registered in Kenya. For merchant accounts, billing, platform security, support, and product analytics, ScaleNodes Ltd is the "data controller" — the party that decides why and how that personal data is processed.

For customer data entered into a merchant storefront, the store owner is usually the data controller and TopDuka acts as the platform processor. That means the merchant is responsible for having a lawful reason to collect customer information, using it fairly, handling order support, and honouring customer privacy requests connected to that store.

— Registered office

ScaleNodes Ltd · Westlands, 4th Floor · P.O. Box 12345 · Nairobi, Kenya

Data Protection Officer · dpo@topduka.com

02 · Collection

What we collect.

Six categories, and a reason for each. If we ever need something new, we will ask first.

01

Account info

Name, email, profile photo, password (hashed), phone number (optional), and which sign-in method you chose.

e.g. wanjiru@honeylane.co.ke

02

Storefront content

Product names, descriptions, photos, prices, stock levels, categories, and any digital assets you upload.

Stored on our EU-backed object store.

03

Customer & order data

Order details, delivery addresses, transaction records, and messages between a store owner and their customers. We process this to run the merchant storefront; the store owner remains responsible for the buyer relationship.

Used for fulfilment, returns, support, and tax.

04

Usage & device data

Pages viewed, button clicks, device type, browser, country, and IP-derived location (not precise GPS).

Helps us fix bugs and improve UX.

05

Support & feedback

Anything you send to our support team, including email, in-app chat, and recorded screen-share sessions (only with your consent).

Kept for 24 months for training purposes.

06

Integrations you connect

If you connect M-Pesa, a delivery partner, an accounting tool, or a custom API, we receive the data those tools send us to do their job.

You can disconnect any of them at any time.

03 · Purpose

Why we collect it.

Each purpose is tied to a legal basis under GDPR and the Kenya Data Protection Act.

Purpose
01

Run the service you signed up for

Host your storefront, process orders, send receipts.

02

Keep your account and customers safe

Detect fraud, block bots, verify suspicious sign-ins.

03

Meet legal and tax obligations

Issue VAT-compliant receipts, keep audit logs.

04

Help you when you ask

Reply to support tickets, follow up on bugs.

05

Make TopDuka better (aggregated)

See which features are used most, A/B test UI changes.

06

Tell you about TopDuka (optional)

Product updates and launch offers. You can unsubscribe in one click.

04 · Featured

Google Sign-In: what we see, what we don't.

We let you sign in with Google so you don't have to remember another password. This section is the full breakdown of what that does to your data, written so you can make an informed choice before you click the button.

Google Sign-In — limited-use compliant

When you choose Continue with Google, Google confirms your identity and shares a small set of profile facts with us. That is the only data we ever receive from Google — and we use it only to create and sign you into your TopDuka account.

— What we receive from Google

5 fields
  • sub

    A unique Google user ID (not your email, not reversible to your password).

  • name

    Your full name as saved in your Google profile.

  • email

    Your primary email address.

  • email_verified

    A boolean telling us Google has verified the email.

  • picture

    A URL to your profile photo, used in the dashboard.

— What we NEVER receive

0 fields
  • Your Google password (we could not see it if we wanted to).

  • Your Gmail messages, contacts, or calendar.

  • Any file in your Google Drive, Docs, Sheets, or Photos.

  • Your search history, location history, or YouTube history.

  • Data from any other Google service you have not shared.

— The flow, step by step

~ 2 seconds
  1. 01

    You TopDuka

    You click "Continue with Google" on our sign-in page.

  2. 02

    TopDuka Google

    We send you to a Google-hosted window that asks for your consent.

  3. 03

    Google You

    Google asks you to confirm which profile and email you want to share.

  4. 04

    You Google

    You tap Allow. (You can also cancel — we never see your password.)

  5. 05

    Google TopDuka

    Google sends us a short-lived code. We exchange it for your basic profile.

  6. 06

    TopDuka You

    We create or open your account and sign you in. We do not see anything else in your Google account.

— How we store it

Encrypted at rest in our EU-hosted database. Tied to your TopDuka account row, not stored separately.

— How long we keep it

For as long as your TopDuka account is open. If you disconnect Google, we keep the email so you can still sign in by password.

— How we use it

To create your account, sign you in, send receipts to the right address, and show your name and photo inside the dashboard.

— How we do NOT use it

We do not enrich your profile, build an advertising ID, sell it to anyone, or share it with other tenants.

05 · Cookies & analytics

Cookies, pixels, and trackers.

We try to keep this list short. The cookies and similar tech we use fall into four buckets:

Type What it does

Strictly necessary

Keeps you signed in and prevents fraud.

Preferences

Remembers your dashboard layout, theme, and language.

Product analytics

Aggregated usage data on our own infrastructure. No Google Analytics, no Meta Pixel.

Marketing

We do not run third-party advertising trackers on your storefronts.

06 · Sharing

Who we share data with.

We do not sell your data. We share the minimum required to run TopDuka, with companies that have signed strict data processing agreements.

  • 01

    Cloud infrastructure

    enterprise-grade · DPA signed

    We host on AWS (Frankfurt, Ireland) and Cloudflare. They store data on our behalf under strict contracts.

  • 02

    Payments

    PCI-DSS where applicable

    M-Pesa, Paystack, card processors, and banks. They only see the data needed to authorise, settle, refund, or investigate payments. TopDuka does not store full card numbers.

  • 03

    Email & SMS delivery

    delivery-only · no marketing

    We use transactional email providers to send order confirmations and receipts.

  • 04

    Analytics

    no third-party trackers

    Privacy-friendly, aggregated analytics. We do not use Google Analytics or Meta Pixel on the storefront.

  • 05

    Customer support tools

    staff-only access

    Helpdesk software that holds your support emails and in-app chats.

  • 06

    Law enforcement

    last resort · logged

    We will only share data with authorities when compelled by a valid legal order. We will tell you first if we are allowed to.

07 · Retention

How long we keep your data.

We delete data when we no longer need it. Some data we have to keep for tax and legal reasons.

Type of data How long

Account profile

Until you delete the account

Storefront & products

Until you delete or close the duka

Orders, invoices, tax records

7 years (required by Kenyan tax law)

Order email logs

90 days, then aggregated

Support tickets

24 months, then pseudonymised

Backups

30 days rolling, then overwritten

Backups after account deletion

30 days, then permanently wiped

08 · Your rights

Your rights over your data.

You have seven rights under the Kenya Data Protection Act and the GDPR. We respect all of them, and we will not make it hard to use them.

Access

01

Get a copy of every piece of data we hold about you and your duka.

Correct

02

Fix anything that is wrong. Most things you can change in the dashboard yourself.

Delete

03

Delete your account and all your data, subject to the tax retention we have to keep.

Export

04

Download your products, orders, and customers as CSV or JSON whenever you want.

Object

05

Object to specific processing — for example, marketing emails — and we will stop.

Withdraw consent

06

If we ever rely on consent (today, only for marketing), you can take it back at any time.

Complain

07

Complain to a data protection authority. In Kenya that is the Office of the Data Protection Commissioner.

To exercise any of these, email dpo@topduka.com. We respond within 14 days, often faster.

09 · International transfers

Where your data lives.

TopDuka is hosted on AWS in the EU (Frankfurt and Ireland) by default. If you explicitly choose the South-Africa region for your storefront, your customer-facing data is hosted in Cape Town. Some metadata (sign-in, audit logs) may be processed in the US by our sub-processors under Standard Contractual Clauses.

10 · Security

How we keep it safe.

Security is layered. The most important things we do:

Encryption in transit

HTTPS only, TLS 1.2+ everywhere.

Encryption at rest

Customer data and backups are encrypted with AES-256.

Access control

Staff access is least-privilege, audited, and protected by hardware MFA.

Penetration testing

Independent pen-test every 12 months. Findings published in our trust report.

Bug bounty

We run a paid bug bounty for security researchers.

Incident response

We will notify affected account owners within 72 hours of any confirmed breach.

11 · Children

Children's privacy.

TopDuka is built for adult business owners. We do not knowingly collect data from anyone under 18. If you believe a child has signed up, email dpo@topduka.com and we will close the account within 48 hours.

12 · Changes

Changes to this policy.

We may update this Privacy Policy. For material changes — for example, a new data category or a new sub-processor — we will email account owners and show an in-app notice at least 14 days before the change takes effect. The version number and "Last updated" date at the top will always tell you which version you are reading.

v

Changelog

  • v3.1 · 2026-06-07Clarified merchant storefront customer data roles, payment provider sharing, and store owner responsibility for buyer relationships.
  • v3.0 · 2026-06-02Added a dedicated Google Sign-In section with the field-by-field data flow and revoke instructions.
  • v2.4 · 2025-11-14Aligned to the TopDuka rebrand. Replaced ScaleNodes brand references.
  • v2.3 · 2025-04-02Added a clear retention table and brought cookies into a single table.
  • v2.2 · 2024-10-18Added sub-processor list and made the data controller identity explicit.
13 · Contact

Contact the DPO.

Questions, requests, complaints — start with our Data Protection Officer. We will reply within 14 days, usually much faster.

That's it. No dark patterns, no fine print.

If anything on this page is unclear, send a screenshot and a quick note to dpo@topduka.com and we will rewrite the part that confused you.

Comfortable with this?

Then come open your duka.

7 days free. Your first paid month is KES 500 only. You can delete everything the day after if you change your mind.