The short version
- We collect what a marketplace needs: account details, delivery details, order history, the content you post and basic technical logs. Card numbers never reach us; Stripe handles payment.
- We use it to run the marketplace, deliver your orders, send order emails and texts, keep the site safe and meet legal duties. We do not sell or rent personal data and we run no advertising or tracking networks.
- The seller fulfilling a shipment sees the delivery details for that shipment. Our service providers (Stripe, Microsoft Azure, SendGrid/Resend, Sendblue, Anthropic, Google Fonts) process data under contract.
- Data is hosted in Microsoft Azure data centres and may be transferred internationally with safeguards such as Standard Contractual Clauses.
- You can access, correct, export, delete or object to our use of your data, and complain to a regulator. Write to privacy@africandiscountfoods.com.
Contents
- Who is responsible for your data
- Scope and definitions
- Personal data we collect
- Why we use it and our legal bases
- Who we share it with
- Sellers as independent controllers
- AI features and automated decisions
- SMS and email
- Cookies and browser storage
- International transfers
- How long we keep data
- Security
- Your rights
- Children
- Regional privacy notices
- Do Not Track and Global Privacy Control
- Changes to this policy
- How to contact us or complain
1. Who is responsible for your data
The data controller (or “business”, “responsible party” or “data fiduciary” under some laws) for personal data processed through the AfricanDiscountFoods marketplace is [Operator legal entity name], [Registered office address]. Contact our privacy team at privacy@africandiscountfoods.com. Where the law requires a Data Protection Officer or a local representative (for example under Article 27 GDPR or the UK GDPR), their details will be published here once appointed; in the meantime the privacy team handles all requests.
2. Scope and definitions
This policy covers the website at africandiscountfoods.com, the installable web app, our emails and SMS messages, and our support channels. It does not cover websites we link to, or the independent practices of sellers once they receive your order details (see section 6), or of Stripe on its hosted checkout pages. “Personal data” means any information relating to an identified or identifiable person. Terms such as “process”, “controller” and “processor” have the meanings given in the GDPR and equivalent laws.
3. Personal data we collect
3.1 Data you give us
| Category | Examples | When |
|---|---|---|
| Account data | Name, email address, a one-way hash of your password (we cannot read the password), email-verification status, admin status if you are on the operator's admin list | Creating or updating an account |
| Order and delivery data | Recipient name, email, phone number, street address, city, country, delivery option, items and quantities, prices, payment status, payment provider reference (e.g. Stripe session id, never a card number), order events and timestamps | Checkout, signed in or as a guest |
| Seller and store data | Store name, type, city and country, tagline, listings, prices, product photos, restaurant menus, Stripe Connect account id, payout requests and amounts, compliance status and notes | Opening or managing a store |
| Identity and banking data for sellers | Government ID, date of birth, address, bank account or debit-card details, tax identifiers | Collected by Stripe during Connect onboarding; we receive only status flags (e.g. “payouts enabled”) and the account id |
| Content | Reviews, star ratings, recipe titles, stories, steps, chosen ingredients, author name, likes, the display name shown with your content | Posting on the marketplace |
| Communications | Emails you send to our support addresses, complaint and appeal submissions, reports about content, security reports | Contacting us |
| AI inputs | Search queries, store and product details you enter into AI-assisted forms | Using AI features |
3.2 Data collected automatically
| Category | Examples | Notes |
|---|---|---|
| Technical and log data | IP address, request URL and method, response status, timing, user agent, referrer, error traces, security events (failed sign-ins, lockouts, rate-limit hits) | Generated by our hosting platform (Microsoft Azure) and application logs for security, debugging and performance; kept for a limited period (section 11) |
| Session data | An encrypted sign-in token in your browser, an anti-forgery token, the real-time connection between your browser and our server | See the Cookie Policy |
| Preferences | Language, currency and light/dark theme | Stored in your own browser only; never sent to our servers as a profile |
| Inferred data | Whether a review is a “verified purchase”, aggregate ratings, compliance screening results for stores, indicative fraud or abuse signals | Derived from the data above |
3.3 Data from third parties
- Stripe sends us payment status events (paid, failed, refunded, disputed), the last four digits and brand of a card where shown on a receipt, and Connect account status for sellers.
- Carriers and sellers may provide tracking status that we display on your order timeline.
- Public sources and reports from other users may be used when we investigate suspected fraud, prohibited goods or policy breaches.
3.4 Sensitive data
We do not ask for, and ask you not to submit, special categories of data such as health, religious or ethnic information. Be aware that dietary choices (for example halal, kosher, or an allergen note you type into a recipe or review) can reveal such information; we process it only because you chose to include it, for the purpose you submitted it, and you may delete it at any time. Government ID for seller verification is collected and stored by Stripe, not by us.
4. Why we use it and our legal bases
Where the GDPR, UK GDPR or a similar law applies, we rely on the legal bases shown.
| Purpose | Data | Legal basis |
|---|---|---|
| Create and manage your account; authenticate you; verify your email; reset passwords | Account, session | Performance of a contract (the Terms) |
| Take, process, deliver and track orders; split baskets by seller; pass delivery details to sellers; issue receipts and refunds | Order and delivery, payment status | Performance of a contract |
| Send transactional email and SMS about your account and orders | Email, phone, order | Performance of a contract; where required, your consent for SMS |
| Operate seller stores, compute earnings, commission and payouts; onboard sellers with Stripe Connect | Seller and store, Stripe account status | Performance of a contract; legal obligation (tax, anti-money-laundering, INFORM Consumers Act, DSA trader traceability) |
| Publish reviews and recipes you choose to share | Content, display name | Performance of a contract; legitimate interest in an authentic community |
| Screen stores and content for prohibited goods, scams and policy breaches; moderate reports and appeals | Store, content, communications, technical | Legitimate interests (safety, legal compliance, protecting users); legal obligation (DSA, consumer law) |
| Prevent fraud and abuse; rate-limit and lock accounts; investigate chargebacks | Technical, account, order | Legitimate interests (security); legal obligation |
| Provide AI-assisted search, suggestions, listing copy and compliance screening | AI inputs, store and product details | Performance of a contract for features you invoke; legitimate interests for screening |
| Analyse how the marketplace performs (order volumes, revenue, category sales, new sign-ups) in aggregate for the admin console | Order and account (aggregated) | Legitimate interests (running the business) |
| Respond to support, privacy and legal requests; handle disputes | Communications, relevant records | Legitimate interests; legal obligation; establishment and defence of legal claims |
| Comply with law: tax and accounting records, sanctions screening, responding to lawful requests from authorities, food-safety recalls | Order, seller, payment | Legal obligation |
| Send marketing (only if we introduce it) | Email, phone | Consent, withdrawable at any time |
Where we rely on legitimate interests we have balanced them against your rights; you can object (section 13). Where we rely on consent you can withdraw it at any time without affecting earlier processing. Providing account and delivery data is necessary to buy or sell; without it we cannot provide the Service.
5. Who we share it with
We share personal data only as described here. We do not sell it, rent it, or share it for cross-context behavioural advertising.
| Recipient | What and why | Location |
|---|---|---|
| Sellers fulfilling your shipment | Recipient name, address, phone, email, items, delivery option, and your review text and display name for products they sell | Wherever the seller is (see section 6) |
| Stripe (payments, Connect payouts, fraud prevention) | Order amount, currency, email, order reference; sellers' identity and bank details (collected directly by Stripe) | United States, Ireland and other Stripe regions |
| Microsoft Azure (hosting, database, storage, logs) | All data we hold, encrypted at rest and in transit | Primary region Canada Central; Azure global network for backups and edge services |
| SendGrid or Resend (transactional email) | Email address, name, order and account-action content | United States |
| Sendblue (transactional SMS) | Mobile number and the text of order notifications | United States |
| Anthropic (AI model API) | Store names, taglines, locations, product names, categories and origins submitted to AI features; search queries when AI search is enabled. No account or delivery data is sent. Anthropic does not use API inputs to train its models. | United States |
| Google Fonts | Your browser requests typeface files from Google's servers, which receive your IP address and user agent | Google global network |
| GitHub (source control and CI/CD) | No personal data of users; listed for transparency about our build pipeline | United States |
| Professional advisers (lawyers, accountants, auditors, insurers) | Records needed for advice, audits or claims | Varies |
| Authorities, courts and regulators | When required by law, a valid legal request, or to protect safety, prevent fraud or enforce our Terms; we review every request and disclose the minimum necessary | Varies |
| A buyer or successor of our business | In a merger, acquisition, financing, reorganisation or insolvency, subject to this policy and notice to you | Varies |
| Other users | Reviews and recipes you post are public with your display name; seller store details are public | Worldwide |
6. Sellers as independent controllers
When a seller receives your delivery details to fulfil a shipment, the seller becomes an independent controller of that data under their own local law. The Seller Agreement obliges every seller to use buyer data only to fulfil and support that order, to protect it, not to add you to marketing lists without your consent, and to delete it when no longer needed. Sellers may be located in any country. If you believe a seller has misused your data, tell us at privacy@africandiscountfoods.com and we will investigate and, where appropriate, suspend the store.
7. AI features and automated decisions
- Automated compliance screening reviews every new store's content (name, tagline, location, listings) for prohibited goods and scam signals using rule-based checks and, where enabled, a large language model. A clean result grants the “verified” badge automatically. A flagged result places the store in a queue for human review; the automated system never rejects or removes a store on its own, and does not evaluate any personal characteristic of the seller.
- Search, suggestions and recommendations rank products using the query, product text and marketplace-wide sales data. They do not build a persistent profile of you, and they have no legal or similarly significant effect.
- Fraud and security controls (rate limiting, sign-in lockouts, chargeback review) are largely automated; an account restriction with significant effect is reviewed by a person on request.
- You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, to obtain human intervention, to express your point of view and to contest the decision. Use legal@africandiscountfoods.com.
- Inputs sent to the model provider are limited to what the feature needs (section 5) and are sent under API terms that prohibit training on them. Please do not type personal or sensitive data into AI-assisted fields.
8. SMS and email
We send transactional email and, to the mobile number you give at checkout, SMS messages at the following milestones: order received, payment confirmed, shipment dispatched and shipment delivered. Email is also used for email verification, password resets and replies to your requests. Reply STOP to any text to opt out of SMS, or email support@africandiscountfoods.com. We do not send marketing messages without separate opt-in consent, and we never share your number with third parties for their marketing. Phone numbers without a country code are not texted. Mobile information will not be shared with third parties or affiliates for marketing or promotional purposes.
9. Cookies and browser storage
We use only strictly necessary cookies and browser storage: an anti-forgery cookie, an encrypted sign-in session in your browser's local storage, your language/currency/theme preferences, and a service worker that makes the site installable. We use no analytics, advertising or social-media trackers, and our Content-Security-Policy blocks third-party scripts. Stripe sets its own cookies on its checkout pages. Full details, lifetimes and controls are in the Cookie Policy.
10. International transfers
We are a global marketplace, so your data will be transferred to and processed in countries other than your own, including the United States, Canada and the countries where sellers are located. Where we transfer personal data out of the European Economic Area, the United Kingdom, Switzerland, Brazil, South Africa, Nigeria, Kenya or another jurisdiction that restricts transfers, we rely on one or more of: an adequacy decision or equivalent recognition; the EU Standard Contractual Clauses and the UK International Data Transfer Addendum (used with Microsoft, Stripe, Twilio SendGrid, Resend, Sendblue and Anthropic as applicable); the EU-US, UK-US and Swiss-US Data Privacy Framework where a recipient is certified; your explicit consent; or the necessity of the transfer to perform your contract (for example sending your address to a seller abroad). You can request a copy of the relevant safeguards at privacy@africandiscountfoods.com.
11. How long we keep data
| Data | Retention |
|---|---|
| Account data | For the life of the account, then deleted or anonymised within 30 days of closure, except as needed below |
| Orders, payments, refunds, payouts and related communications | Up to 7 years after the transaction for tax, accounting, consumer-law and dispute purposes (or the longer period required in your country) |
| Sign-in tokens | Expire after 30 days, or immediately on sign-out or password reset |
| Email verification and password-reset tokens | 24 hours and 1 hour respectively; single use |
| Reviews and recipes | Until you delete them or close your account; we may keep an anonymised copy of reviews to preserve aggregate ratings |
| Compliance and moderation records, reports, appeals | Up to 5 years, to demonstrate compliance and detect repeat abuse |
| Server and security logs | Typically 30 to 90 days, longer where a log forms part of a security investigation |
| Email and SMS delivery logs held by providers | Per the provider's retention (typically 30 days or less) |
| Backups | Encrypted backups roll over on a fixed schedule; deleted data leaves backups within 35 days |
12. Security
We protect data with technical and organisational measures appropriate to the risk, including: TLS encryption for all traffic and HTTP Strict Transport Security; encryption at rest for the database, storage and backups; PBKDF2 password hashing; sign-in and account-action tokens stored only as SHA-256 hashes with automatic expiry; rate limiting and lockouts on authentication; a strict Content-Security-Policy and other security headers; signed and verified payment webhooks; secrets held in a managed key vault; least-privilege access for staff; and continuous dependency vulnerability monitoring. No system is perfectly secure; if we discover a breach that is likely to harm you we will notify you and the relevant authority as the law requires (for example within 72 hours under the GDPR). Please report vulnerabilities responsibly to privacy@africandiscountfoods.com.
13. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you and receive a copy, including the categories, sources, purposes and recipients;
- Correct inaccurate or incomplete data (you can edit your name, email and store details in the app);
- Delete your data (“right to be forgotten”), subject to records we must keep by law;
- Port the data you gave us to you or another provider in a machine-readable format;
- Restrict or object to processing based on legitimate interests, and object to any direct marketing at any time;
- Withdraw consent where processing is based on consent;
- Opt out of any “sale”, “sharing” or targeted advertising (we do none) and of profiling with significant effects;
- Limit use of sensitive personal information (we do not use it beyond what you submit);
- Not be discriminated against for exercising your rights;
- Appeal our decision on a request, and complain to a supervisory authority (section 18);
- Nominate a person to exercise your rights after your death (France, Italy, India and others), or authorise an agent to act for you.
To exercise a right, email privacy@africandiscountfoods.com from the address on your account, or include enough detail for us to verify you. We respond within one month (or 45 days where US state law provides, extendable once with notice), free of charge unless requests are manifestly unfounded or excessive. We may need to keep certain data despite a deletion request, for example order records required for tax law, records of a dispute, or anonymised review statistics. We honour requests from authorised agents on proof of authority.
14. Children
The Service is for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18, and we do not knowingly collect data from children under 13 (or 16 in the EU, or the applicable age in your country) in any circumstances. If you believe a child has given us data, contact privacy@africandiscountfoods.com and we will delete it promptly. We do not sell the personal information of anyone under 16.
15. Regional privacy notices
- European Economic Area, United Kingdom and Switzerland
- The GDPR, UK GDPR and Swiss FADP apply. Sections 4, 10, 11 and 13 set out our legal bases, transfer safeguards, retention and your rights. You may lodge a complaint with your national data-protection authority (for example the CNIL in France, the ICO in the United Kingdom, the Irish Data Protection Commission, or the FDPIC in Switzerland). We will appoint an EU or UK representative under Article 27 if and when required and publish their details here.
- United States (California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island and other states with comprehensive privacy laws)
- In the preceding 12 months we collected the categories of personal information listed in section 3 (identifiers, customer records, commercial information, internet activity, inferences, and for sellers, professional information) from the sources in section 3, for the purposes in section 4, and disclosed them for business purposes to the service providers and contractors in section 5. We do not sell personal information, do not share it for cross-context behavioural advertising, and do not use or disclose sensitive personal information for purposes requiring a right to limit. We do not knowingly sell or share the personal information of consumers under 16. You have the rights to know, delete, correct, port, opt out, limit, and not be discriminated against, and you may designate an authorised agent. We honour opt-out preference signals (section 16). Under the CCPA we are not a “financial incentive” programme. Verification uses the email on your account. If we deny a request you may appeal by replying to our response; if the appeal is denied you may contact your state attorney general. California residents may also request the “Shine the Light” disclosure; we share no personal information with third parties for their direct marketing.
- Canada
- PIPEDA and provincial laws (including Quebec's Law 25, Alberta's and British Columbia's PIPA) apply. Our privacy officer can be reached at privacy@africandiscountfoods.com. Data is primarily stored in Canada (Azure Canada Central) but may be accessed from or transferred to other countries as described in section 10, where it may be subject to foreign law. Quebec residents have the additional rights to be informed of automated decisions and of technology that identifies, locates or profiles them (we use none), and to request de-indexing. You may complain to the Office of the Privacy Commissioner of Canada or the Commission d'accès à l'information du Québec.
- Nigeria
- The Nigeria Data Protection Act 2023 and NDPR apply; you may complain to the Nigeria Data Protection Commission. We process data on the lawful bases in section 4 and transfer it abroad only with adequate protection under section 10.
- Kenya, Ghana, South Africa and other African jurisdictions
- The Data Protection Act 2019 (Kenya; complaints to the Office of the Data Protection Commissioner), the Data Protection Act 2012 (Ghana; Data Protection Commission), the Protection of Personal Information Act 2013 (South Africa; Information Regulator; our Information Officer is reachable at privacy@africandiscountfoods.com and a PAIA manual is available on request), and equivalent laws in Uganda, Rwanda, Tanzania, Egypt, Morocco, Senegal, Côte d'Ivoire, Ethiopia and other countries apply to residents there. Direct marketing by electronic means requires your consent under POPIA section 69; we send none without it.
- Brazil
- The Lei Geral de Proteção de Dados (LGPD) applies. Our encarregado (DPO) contact is privacy@africandiscountfoods.com. You have the rights in Article 18 LGPD, including confirmation, access, correction, anonymisation, portability, deletion, information about sharing, and revocation of consent, and may petition the ANPD.
- India
- The Digital Personal Data Protection Act 2023 applies; we act as a Data Fiduciary and you as a Data Principal. Our grievance officer is reachable at privacy@africandiscountfoods.com; unresolved grievances may be escalated to the Data Protection Board of India. Verifiable parental consent is required for anyone under 18, which is why the Service is limited to adults.
- Australia and New Zealand
- The Privacy Act 1988 (Cth) and Australian Privacy Principles, and the New Zealand Privacy Act 2020, apply. Data is disclosed to overseas recipients in the countries listed in section 5. You may complain to the Office of the Australian Information Commissioner or the New Zealand Privacy Commissioner. We do not use government identifiers.
- Japan, South Korea, Singapore, Hong Kong, Philippines, Indonesia, Thailand, Malaysia
- The APPI, PIPA, PDPA (Singapore, Malaysia, Thailand), PDPO, Data Privacy Act 2012 and PDP Law respectively apply. Cross-border transfers are made with the safeguards in section 10 and, where required, your consent at the point of transfer. Contact points for each jurisdiction are the privacy team.
- China
- We do not currently target the Service at mainland China. If you use it from there, the Personal Information Protection Law may apply, and your data will be transferred outside China with your separate consent as required.
- Middle East and North Africa
- The UAE PDPL (and DIFC/ADGM regimes where applicable), Saudi PDPL, Qatar, Bahrain, Egypt and Morocco data-protection laws apply to residents. Transfers rely on the safeguards in section 10 or your consent.
16. Do Not Track and Global Privacy Control
Because we do not track you across sites or sell or share data, there is nothing for a Do Not Track or Global Privacy Control signal to switch off; we nonetheless treat a GPC signal as a valid opt-out of sale and sharing for any future feature that would otherwise require one.
17. Changes to this policy
We will post any changes here with a new effective date and version. For material changes, or where the law requires, we will notify you by email or an in-app notice before the change takes effect and, where required, ask for renewed consent. Earlier versions are available on request.
18. How to contact us or complain
Privacy team: privacy@africandiscountfoods.com
Post: [Operator legal entity name], [Registered office address]
Legal requests and DSA point of contact: legal@africandiscountfoods.com
If you are unhappy with our response you may complain to the data-protection or consumer authority of your country. We would appreciate the chance to resolve your concern first.