NeoMali Privacy Policy

Last updated: January 2026

1. Introduction

NeoMali is an online shop creation platform operated by Birowaks Media and Technology, a company incorporated in the Republic of Kenya (“Company”, “we”, “our”, or “us”).

This Privacy Policy explains how we collect, use, disclose, store, and protect personal data when you access or use:

  • https://neomali.com
  • Any NeoMali subdomains (including shop subdomains)
  • NeoMali web or mobile applications

(collectively, the “Service”).

This Policy is issued in accordance with the Data Protection Act, 2019 (Kenya).

By using the Service, you acknowledge that you have read and understood this Privacy Policy.

2. Who We Are (Data Controller)

For purposes of the Data Protection Act, 2019:

  • Data Controller: Birowaks Media and Technology
  • Platform: NeoMali

We determine the purpose and means of processing personal data on the NeoMali platform.

3. Personal Data We Collect

We collect personal data directly from you and automatically through your use of the Service.

a) Information You Provide

This may include:

  • First and last name
  • Email address
  • Phone number
  • Physical delivery address (customers)
  • Business or shop details (vendors)
  • Product listings and descriptions
  • Communication with support

b) Account and Authentication Data

  • Login credentials (stored securely)
  • Google OAuth profile information (name and email only)

We do not store plaintext passwords.

c) Payment Information

Payments on NeoMali are processed through third-party payment providers (e.g. M-Pesa).

We do not store:

  • M-Pesa PINs
  • Full card numbers
  • Payment authorization credentials

4. How We Use Personal Data

We process personal data for the following lawful purposes:

  • Creating and managing user accounts
  • Enabling vendors to operate online shops
  • Processing orders and facilitating deliveries
  • Communicating order confirmations and notifications
  • Providing customer support
  • Improving platform functionality and security
  • Preventing fraud and misuse of the platform
  • Complying with legal and regulatory obligations

We only process data that is necessary and relevant to these purposes.

5. Legal Basis for Processing (Kenya)

We process personal data based on:

  • Your consent
  • Performance of a contract (providing the Service)
  • Compliance with legal obligations
  • Our legitimate interests (platform security, fraud prevention)

6. Cookies and Similar Technologies

NeoMali uses cookies and similar technologies to:

  • Maintain user sessions
  • Remember preferences
  • Improve performance and usability
  • Analyze aggregated platform usage

You can control cookies through your browser settings. Disabling cookies may limit some features of the Service.

7. Sharing of Personal Data

We do not sell personal data.

We may share personal data with:

  • Payment service providers
  • Hosting and infrastructure providers
  • Authentication providers (e.g. Google)
  • Delivery or notification service providers
  • Law enforcement or regulators where required by law

All third parties are required to handle data securely and lawfully.

8. Vendors and Customer Data

If you are a vendor, you acknowledge that:

  • You act as an independent data controller for your customers’ data
  • You are responsible for lawful use of customer information obtained through NeoMali

NeoMali provides infrastructure but does not control vendor fulfillment activities.

9. Data Security

We implement appropriate technical and organizational measures to protect personal data, including:

  • Encrypted connections (HTTPS)
  • Secure authentication
  • Access controls
  • Restricted administrative access

While we take reasonable measures to protect data, no system is completely secure.

10. Data Retention

We retain personal data only for as long as necessary to:

  • Provide the Service
  • Meet legal and regulatory requirements
  • Resolve disputes
  • Enforce our agreements

When data is no longer required, it is securely deleted or anonymized.

11. Your Rights Under Kenyan Law

Under the Data Protection Act, 2019, you have the right to:

  • Be informed about data processing
  • Access your personal data
  • Correct inaccurate or incomplete data
  • Object to processing
  • Request deletion of personal data
  • Withdraw consent (where applicable)

Requests can be made using the contact details below.

12. Children’s Data

NeoMali is not intended for use by persons under the age of 18.

We do not knowingly collect personal data from children. If such data is identified, it will be deleted promptly.

13. International Data Transfers

Where personal data is processed or stored outside Kenya, we ensure appropriate safeguards are in place in accordance with Kenyan law.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date.

Continued use of the Service constitutes acceptance of the revised Policy.

15. Contact Information

For privacy-related inquiries or requests, contact:

  • Birowaks Media and Technology
  • privacy@neomali.com