Privacy Policy — Shop Plus Platform
Last updated: 2026
This Privacy Policy explains how VEKTAEDGE TECHNOLOGIES trading as Shop Plus ("Company", "we", "us", "our") collects, uses, stores, protects and shares personal data when you use our digital receipt, loyalty and related services (the "Platform"). We are committed to protecting personal data in accordance with applicable law including the Kenyan Data Protection Act, 2019 (DPA) and other relevant regulations.
1. Scope
This Policy applies to:
- Customers (individuals who receive receipts, participate in loyalty programs, or otherwise interact with merchants via the Platform);
- Merchants and merchant administrators who subscribe to or use the Platform; and
- Visitors to our websites and mobile applications.
2. Data Controller / Data Processor
Unless otherwise agreed in writing, Merchants determine the purposes and means of processing customer personal data and therefore act as Data Controllers in relation to their customers.
3. Personal Data We Collect
We collect only data necessary to provide the Platform and as specified in merchant agreements. Categories include:
A. Customer / End-User Data
- Identity: full name, date of birth (if provided), national ID or other identifier (if required by merchant).
- Contact: email, phone number, postal address.
- Account: username, hashed password, profile preferences.
- Transactional: purchase amounts, items purchased, transaction timestamps, store/terminal ID, loyalty points awarded/redemptions, receipts.
- Engagement: program participation, referrals, opt-in/opt-out status, communication preferences.
B. Merchant Data
- Business name, business registration number, trading addresses, contact persons.
- POS integration credentials (securely stored), billing and invoicing details.
C. Device & Technical Data
- IP address, device identifiers, browser type/version, OS, app version, SDK identifiers, crash logs.
D. Usage & Analytical Data
- Feature usage, pages/screens visited, timestamps, referral sources, aggregated behavioural analytics.
E. Sensitive Data
We do not knowingly collect special categories of personal data (sensitive data) except where expressly required and permitted (e.g., identity verification where legally required). If sensitive data is required, we will obtain explicit consent and apply additional protections.
4. Sources of Data
- Directly from users (registration forms, profile updates, communications).
- From Merchants (transaction feeds).
- Automatically via the Platform (cookies, analytics).
- From third-party service providers where permitted by you or your merchant.
5. Purposes and Legal Bases for Processing
We process personal data only for specified, legitimate purposes:
- To perform the contract with Merchants and Customers (provision of digital receipts, loyalty program administration, fulfilment of redemptions).
- To comply with legal obligations (tax, accounting, anti-fraud, regulatory reporting).
- For legitimate business interests (service improvement, fraud prevention, analytics, security), balanced with data subject rights.
- On consent, where required (marketing communications, promotions, profiling for marketing).
- For other lawful bases specified in merchant agreements or user consents.
6. Specific Uses
- Provide and maintain the Platform, issue receipts, award and redeem loyalty points.
- Authenticate users and secure accounts.
- Customer support and dispute resolution.
- Send transactional communications (receipts, security alerts), and marketing where consented.
- Detect, prevent and investigate fraud, abuse and security incidents.
- Generate anonymized or aggregated analytics for Merchants and internal use.
7. Cookies and Tracking
We use cookies, local storage and similar technologies to:
- Enable essential platform functionality and session management.
- Analyse usage and performance (analytics cookies).
- Support marketing and personalization (with consent where required).
You can manage or block cookies through your browser or device settings. Blocking cookies may affect Platform functionality.
8. Disclosure and Sharing of Personal Data
We may share personal data with:
- Merchants (transactional and loyalty information relevant to their customers).
- Service providers and sub-processors: cloud hosting, payment processors, communication providers (email/SMS), analytics vendors, support tools. Processors act under contract and only on our instructions.
- Legal or regulatory authorities where required by law, court order or to protect rights and safety.
- Acquirers or other parties in connection with a reorganisation, sale, merger or asset transfer (with notice to affected parties where required).
We do not sell personal data.
9. International Transfers
Data may be transferred or stored outside Kenya. When transfers occur, we implement safeguards such as:
- Standard contractual clauses, adequate security measures, or other lawful transfer mechanisms.
- Ensuring sub-processors meet equivalent data protection standards.
10. Data Retention
We retain personal data only for as long as necessary for the purposes set out, considering:
- Contractual obligations and the duration of the merchant relationship.
- Legal, tax and accounting retention requirements (receipt and transaction records may be retained for statutory periods — typically up to 7 years or as required).
- Fraud prevention and dispute resolution needs.
- After account termination we will securely delete or anonymize data per our retention schedule, except where legal obligations require longer retention.
11. Security
We implement appropriate technical and organisational measures, including:
- Encryption in transit (TLS) and at rest where appropriate;
- Access controls and role-based permissions;
- Secure key management;
- Regular security testing and vulnerability management;
- Logging, monitoring and incident response procedures;
- Employee training and confidentiality obligations.
No system is perfectly secure; however we maintain commercially reasonable measures to protect personal data.
12. Data Breach Notification
In the event of a personal data breach, we will:
- Promptly assess the incident and take remedial action;
- Notify the Data Protection Commissioner and other authorities as required by the DPA "as soon as practicable" where notification obligations arise; and
- Notify affected data subjects when the breach is likely to result in a high risk to their rights and freedoms, providing information about mitigation and available support.
13. Data Subject Rights (Kenya)
Subject to legal limitations and verification, data subjects may exercise the following rights:
- Access: obtain confirmation of processing and a copy of personal data.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion where lawful (right to be forgotten), subject to retention obligations.
- Restriction: request restriction of processing in specific circumstances.
- Objection: object to processing based on legitimate interests or direct marketing.
- Portability: receive personal data in a machine-readable format (where technically feasible).
- Withdraw consent: withdraw consent to processing where consent is the legal basis.
To exercise any right, contact admin@vektaedge.tech. We will verify identity and respond within the timeframes required by law.
14. Marketing Communications and Opt-Out
We will only send marketing communications where you have given consent (or where lawful). You can opt out at any time via:
- Unsubscribe links in messages; or
- Updating preferences in your account; or
- Contacting admin@vektaedge.tech.
15. Automated Decision-Making and Profiling
We may use automated processing for analytics, fraud detection and personalization. Decisions that have legal or similarly significant effects on individuals will not be based solely on automated processing unless necessary and with appropriate safeguards; affected users will be informed and permitted to request human review where required by law.
16. Children's Data
Our Platform is not directed to children under 18 (the age of majority in Kenya). We do not knowingly collect personal data of children under 18. If we become aware we have collected such data without appropriate consent, we will delete it as required.
17. Merchant Obligations and Controller Responsibilities
Merchants are responsible for:
- Complying with applicable data protection laws as Controllers (obtaining consents, providing privacy notices, responding to data subject requests relating to their customers).
- Providing lawful instructions to VEKTAEDGE TECHNOLOGIES for processing.
- Ensuring they have rights to share customer data with us.
18. Complaints and Supervisory Authority
If you are dissatisfied with our handling of your personal data, contact us at admin@vektaedge.tech. You may also lodge a complaint with the Office of the Data Protection Commissioner — Kenya.
19. Transfers in Event of Sale or Reorganisation
If the Company is involved in a merger, acquisition or sale of assets, personal data may be transferred to prospective purchasers and successor entities. We will notify users and provide choices where required.
20. Links to Third-Party Sites
Our Platform may link to third-party websites or services. We are not responsible for their privacy practices. Review their privacy policies before sharing personal data.
21. Changes to this Policy
We may update this Privacy Policy to reflect changes in law, practice or Platform functionality. Material changes will be communicated by posting the updated policy and, where required, notifying users. Continued use after notification constitutes acceptance of the updated Policy.
22. Effective Date
This Policy is effective as of the "Last Updated" date above.