Privacy Policy
Who we are
Swam Technologies is an e-commerce business registered in Kenya, operating at swamtechnologies.co.ke. We sell products and services to both individual consumers (B2C) and business clients (B2B) across Kenya and beyond.
As the data controller, Swam Technologies is responsible for the personal information you share with us when browsing, placing orders, or creating an account on our platform.
Information we collect
Identity and contact information
When you place an order or create an account, we collect:
- Full name (and business name, for B2B orders)
- Email address and phone number
- Billing and shipping address
- KRA PIN or business registration number (where required for invoicing)
Payment information
We collect details necessary to process your payment, including card type and last four digits, M-Pesa transaction references, or bank transfer confirmation numbers. Full card numbers are never stored on our servers — see the Payment Processing section below.
Order and account data
- Purchase history, cart contents, and wishlists
- Account login credentials (password stored in hashed form)
- Communications with our support team
- Returns, refund requests, and dispute records
Device and usage data
When you visit our site, we automatically collect:
- IP address and approximate location
- Browser type and version, operating system
- Pages visited, time on site, and referring URLs
- Device identifiers and screen resolution
- Clickstream data (how you navigate the store)
B2B-specific information
For business clients, we may additionally collect your company registration details, VAT/tax numbers, procurement contact information, and details about your business requirements to tailor bulk pricing or service agreements.
How we use your information
To fulfil your orders
- Process and confirm purchases
- Arrange delivery and provide tracking updates
- Handle returns, exchanges, and refunds
- Issue invoices and tax receipts
To manage your account
- Maintain your order history and saved addresses
- Provide customer support and respond to enquiries
- Send transactional emails (order confirmation, shipping alerts)
To improve our store
- Analyse browsing and purchasing patterns
- Fix bugs and improve site performance
- Personalise product recommendations
Marketing (with your consent)
- Send promotional emails and offers if you opt in
- Run retargeting ads based on browsing activity
- Notify you of restocks or new arrivals for items you have shown interest in
You can unsubscribe from marketing at any time via the link in any email or by contacting us directly.
Legal and fraud prevention
- Detect and prevent fraudulent transactions
- Comply with Kenyan law, including the Data Protection Act 2019
- Respond to lawful requests from regulators or courts
Payment processing
All payment transactions on our store are handled by PCI-DSS compliant third-party payment processors. We accept M-Pesa, credit/debit cards, and bank transfers.
We do not store your full card number, CVV, or M-Pesa PIN on our servers. Payment credentials are tokenised by our payment processor and never transmitted to or stored by Swam Technologies in raw form.
For B2B clients on credit terms or invoice-based payment, we retain invoice and payment records for the period required by Kenyan tax law (currently 7 years).
Cookies and tracking
Our store uses cookies and similar technologies to give you a smooth shopping experience.
Essential cookies
Required for the store to function — your cart, session login, and security tokens. These cannot be disabled.
Analytics cookies
We use tools such as Google Analytics to understand how visitors use our store. Data is aggregated and anonymised where possible.
Marketing cookies
With your consent, we use cookies to show you relevant ads on other platforms (e.g. Facebook, Google Shopping). You can manage these preferences via our cookie banner or your browser settings.
Who we share your data with
We do not sell your personal data. We share it only where necessary:
- Delivery partners — your name, address, and contact number to fulfil shipping
- Payment processors — to authorise and complete transactions
- Cloud hosting providers — our website and order data are hosted on secure servers
- Email/SMS service providers — to send order confirmations and marketing (where consented)
- Analytics platforms — aggregated, anonymised usage data
- Legal authorities — when required by Kenyan law or a valid court order
All third-party processors are contractually required to protect your data and use it only for the purpose we specify.
Data retention
- Active accounts: Data retained for the life of the account plus 2 years after last activity
- Order records: Retained for 7 years to comply with Kenyan tax regulations
- Marketing consents: Retained until you withdraw consent or unsubscribe
- Analytics/usage data: Aggregated data retained for up to 26 months
- Fraud/security logs: Retained for up to 3 years
You may request deletion of your personal data at any time (subject to legal retention obligations).
Your rights
Under the Kenya Data Protection Act 2019, you have the following rights:
- Access — Request a copy of the personal data we hold about you
- Correction — Ask us to update inaccurate or incomplete data
- Deletion — Request erasure of your data (subject to legal obligations)
- Portability — Receive your data in a structured, machine-readable format
- Objection — Object to processing for marketing or profiling purposes
- Withdraw consent — Opt out of any processing based on your consent at any time
To exercise any of these rights, contact us using the details below. We will respond within 21 days as required by the Act.
Security
We implement appropriate technical and organisational measures to protect your data, including:
- SSL/TLS encryption for all data transmitted on our site (HTTPS)
- Encrypted storage for sensitive account data
- Restricted internal access to personal data on a need-to-know basis
- Regular security reviews of our platform and third-party integrations
If we become aware of a data breach that affects your rights or freedoms, we will notify you and the Office of the Data Protection Commissioner (ODPC) within 72 hours as required by law.
Contact us
For any questions about this policy, to exercise your data rights, or to report a concern:
Swam Technologies
Website: swamtechnologies.co.ke
Email: privacy@swamtechnologies.co.ke
Location: Nairobi, Kenya
If you are not satisfied with our response, you may lodge a complaint with the Office of the Data Protection Commissioner (ODPC) at odpc.go.ke.
Effective date: March 21, 2026. This policy is reviewed annually and updated when our practices change.