Effective date: 14 August 2026 · Last updated: 14 August 2026 · v1.0

Privacy Policy

1. Who is responsible

The service operator is responsible for account, billing, security and support information it determines how to use. Each registered business is responsible for personal data it enters about customers, suppliers and staff and must provide its own notices and instructions where required.

2. Data we collect

We may process names, business names and types, email addresses, telephone numbers, roles, authentication records, subscription records and support communications. The service also processes products, sales, expenses, customer and supplier records entered by authorised users. Technical records may include IP address, browser or device information, login time, session identifiers, audit events and error logs.

3. How data is collected

Data is collected directly during registration, account use and support communications; from administrators who create staff or business records; and automatically through necessary session cookies, security logs and server diagnostics. We do not intentionally collect payment-card or mobile-money PIN information.

4. Purposes and lawful grounds

Data is used to create and secure accounts, provide requested features, maintain inventory and transaction records, administer subscriptions, respond to support, prevent abuse, investigate incidents, improve reliability, comply with legal duties and establish or defend legal claims. Processing relies on performance of the service agreement, consent where required, legitimate operational and security interests, and compliance with law.

5. Cookies and sessions

DukaFlow uses a necessary session cookie to keep a user signed in, protect forms and apply language preferences. It is not intended for behavioural advertising. Blocking this cookie may prevent login and other secure features from working.

6. Sharing and service providers

Data may be shared with vetted hosting, backup, security, communications and professional-service providers only as needed to operate or protect the service. It may also be disclosed where required by lawful authority, to protect rights or safety, or during a legitimate business reorganisation subject to appropriate safeguards. Personal data is not sold.

7. International transfers

If a provider stores or accesses personal data outside Tanzania, transfers will be assessed and handled using the approvals, adequacy findings, contractual safeguards or other lawful mechanisms required under Tanzanian law.

8. Retention

Account and business records are kept while the account is active and for a reasonable period afterward for restoration, legal, audit, fraud-prevention and dispute purposes. Security logs may be retained for a shorter operational period. Records are deleted or anonymised when no longer necessary, subject to legal retention duties and backup rotation. A precise retention schedule should be adopted before commercial launch.

9. Security

Measures include password hashing, encrypted HTTPS transport, role-based access, database query parameterisation, session controls, audit logging, restricted private configuration and backups. No system is completely secure. Users must protect their devices and credentials and promptly report suspected unauthorised access.

10. Data subject rights

Subject to applicable law and valid exceptions, a person may request access to personal data, correction, deletion, restriction or objection; withdraw consent where processing depends on consent; object to direct marketing; and complain about handling of personal data. Identity may be verified before a request is completed. Requests concerning a shop’s customer records may need to be directed first to that shop.

11. Children

DukaFlow is a business service and is not directed to children. A person registering an account must be at least 18. Businesses must not enter children’s personal data unless they have a lawful purpose and all safeguards required by law.

12. Automated decisions

DukaFlow does not currently make solely automated decisions that produce legal or similarly significant effects on account holders. Dashboard calculations and stock alerts are informational outputs based on entered records.

13. Data breaches

Suspected breaches are investigated, contained and documented. Affected businesses, individuals and the Personal Data Protection Commission will be notified where and within the period required by applicable law.

14. Complaints

Contact the privacy address below first so the concern can be investigated. A person may also lodge a complaint with the Tanzania Personal Data Protection Commission where entitled to do so.

15. Policy updates

This Policy may be updated when services, providers or legal requirements change. Material changes will be communicated through the service or registered contact details, and renewed consent will be requested where required.

MyShop

United Republic of Tanzania
myshop@myhotels.co.tz

← Back to registration