Privacy Policy
Last updated: June 23, 2026
1. Information We Collect
We collect information you provide directly (name, email, phone, address), information generated when you use our platform (orders, browsing history, device info), and payment confirmation data from our payment processors (M-Pesa, Pesapal). We do not store raw card or M-Pesa PIN data.
2. How We Use Your Information
We use your data to process orders, send transactional notifications, prevent fraud, personalise your shopping experience, and improve our platform. We do not sell your personal data to third parties.
3. Cookies
We use strictly necessary cookies for session management, cart persistence, and CSRF protection. We do not use third-party advertising or tracking cookies.
4. Data Sharing
Your data may be shared with the seller you purchase from (for order fulfilment), Safaricom (M-Pesa payment processing), Pesapal (card payment processing), Africa's Talking (SMS notifications), and Google (if you use Google Sign-In). All processors are bound by their own privacy policies.
5. Data Retention
We retain order and account data for up to 7 years for tax and legal compliance. You may request deletion of your account data by contacting support, subject to our retention obligations.
6. Your Rights
You have the right to access, correct, or delete your personal data. Contact us at support@esoko.com for any data requests.
7. Security
We use industry-standard encryption (TLS), bcrypt password hashing, and access controls to protect your data. However, no system is completely secure and we cannot guarantee absolute security.
8. Contact
Questions about this policy? Email support@esoko.com or write to us at our registered address in Nairobi, Kenya.