1. Introduction & Scope
Welcome to CraftCrest Marketplace, an e-commerce platform connecting talented artisans with craft enthusiasts in kenya. This Privacy Policy governs your use of our mobile application, website, and all related services (collectively, the "Service").
This policy applies to all users of CraftCrest Marketplace, including buyers, sellers and any other individuals who interact with our platform. By using CraftCrest Marketplace, you agree to the collection and use of information in accordance with this policy.
CraftCrest Marketplace is operated by CraftCrest Team., a team dedicated to supporting independent artisans and crafters. We provide a platform for:
- Selling handmade and custom craft items
- Connecting buyers with unique, artisanal products
- Facilitating secure transactions and communications
- Building a community around craft and creativity
This privacy policy covers:
- Data collection through our mobile apps ( Android)
- Information gathered through our website
- Data collected during transactions and communications
- Third-party integrations and services
Our legal basis for processing personal information includes:
- Contractual Necessity: To provide our services and fulfill transactions
- Legal Obligation: To comply with applicable laws and regulations
- Legitimate Interest: For fraud prevention, security, and service improvement
- Consent: For marketing communications and non-essential data processing
Important Note: This privacy policy is part of our broader commitment to transparency and user privacy. It should be read alongside our Terms of Service, Cookie Policy, and Community Guidelines.
2. Information We Collect
Personal Information
When you create an account or use our services, we may collect:
- Identity Information: Full name, username, profile photo, date of birth
- Contact Information: Email address, phone number, mailing address
- Financial Information: Payment methods (processed securely)
- Verification Documents: Government-issued ID (for seller verification)
- Biometric Data: Facial recognition data (for account security features)
Marketplace-Specific Information
As a marketplace platform, we also collect:
- Seller Data: Shop details, product listings, inventory management, sales history
- Buyer Data: Purchase history, wishlist items, browsing behavior, saved searches
- Transaction Data: Order details, payment information, returns
- Reviews & Ratings: Both given and received, with timestamps
- Communications: Messages between buyers and sellers, support tickets
- Preferences: Language preferences, currency choices
Technical & Usage Data
We automatically collect information about how you interact with our app:
- Device Information: Device type, model, operating system, unique device identifiers
- App Usage: Features used, time spent, session duration, crash reports
- Location Data: GPS location (with permission), IP address, general location
- Network Information: Carrier, connection type, signal strength
- Performance Data: Load times, response rates, error logs
Sessions & Tracking Technologies
We use various tracking technologies:
Sessions
Essential for functionality, authentication, and preferences
Analytics Pixels
To measure user engagement and app performance
Social Media & Third-Party Integrations
When you connect social media accounts or use third-party services:
- Social media profile information (when you choose to connect)
- Third-party authentication data (Google, Facebook, Apple Sign-In)
- Integration data from shipping carriers, payment processors
- Marketing platform data (email services, analytics tools)
3. How We Use Your Information
Primary Service Purposes
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Account Management | Name, email, password, preferences | Contractual |
| Transaction Processing | Payment info, shipping details, order data | Contractual |
| Product Recommendations | Browsing history, purchases, wishlist | Legitimate Interest |
| Communication | Contact info, message history | Contractual |
| Fraud Prevention | Device info, location, transaction patterns | Legitimate Interest |
Secondary Purposes
- Service Improvement: Analyzing usage patterns to enhance features
- Research & Development: Developing new features and services
- Analytics: Understanding user behavior and preferences
- Compliance: Meeting legal and regulatory requirements
- Dispute Resolution: Resolving conflicts between users
Automated Decision Making
We use automated systems for:
- Fraud detection and prevention
- Product recommendations and personalization
- Search result ranking
- Risk assessment for sellers
Note: You have the right to request human review of significant automated decisions that affect you.
4. Information Sharing & Disclosure
We Do Not Share Your Personal Information
At CraftCrest Marketplace, we are committed to protecting your privacy. We do not share, sell, or rent your personal information with third parties for their marketing purposes.
Limited Exceptions
We may only share your information in the following limited circumstances:
- Service Providers: With trusted third parties who help us operate our service, such as payment processors and shipping carriers, but only the minimum information necessary to complete the transaction
- Legal Requirements: When required by law, court order, or to protect our rights and safety
- Business Transfers: In case of merger, acquisition, or sale, user data may be transferred as part of the transaction
Our Commitment: We do not sell your personal information to third parties for their marketing purposes without your explicit consent.
5. Data Security & Protection
Security Measures
We implement multiple layers of security:
- Encryption: AES-256 encryption for data at rest and TLS 1.3 for data in transit
- Access Controls: Role-based access, multi-factor authentication for staff
- Monitoring: 24/7 security monitoring and intrusion detection
- Regular Audits: Quarterly security assessments and penetration testing
- Compliance: PCI DSS, GDPR, CCPA compliance measures
Data Breach Response
In the event of a data breach:
- We will notify affected users within 72 hours (as required by law)
- We will provide information about the breach and its impact
- We will outline steps taken to mitigate the breach
- We will provide recommendations for protecting your account
International Data Transfers
Your information may be stored and processed in:
- United States (primary location)
- European Union (for EU users)
- Other countries with adequate data protection laws
We ensure appropriate safeguards including Standard Contractual Clauses (SCCs) and adherence to Privacy Shield principles where applicable.
6. Data Retention
90-Day Retention Policy
At CraftCrest Marketplace, we follow a strict 90-day data retention policy:
- All user information is automatically deleted after 90 days of collection
- This includes personal data, transaction records, and usage information
- The deletion process is permanent and irreversible
- No backup copies are retained beyond the 90-day period
Exceptions to 90-Day Policy
The only exceptions to our 90-day retention policy are:
- Information required to be retained longer by law (e.g., tax records)
- Data involved in ongoing legal disputes or investigations
- Information that has been anonymized and no longer identifies you
Important: If you wish to delete your information before the 90-day period, you can request immediate deletion through your account settings or by contacting our support team.
7. Your Rights & Choices
Data Subject Rights GDPR/CCPA
You have the following rights:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your personal data
- Portability: Receive your data in a machine-readable format
- Restriction: Limit how we process your data
- Objection: Object to certain processing activities
- Withdraw Consent: Revoke consent for marketing
How to Exercise Your Rights
You can exercise your rights by:
- Using the privacy settings in your account
- Emailing us at craftcrmarket@gmail.com
- Submitting a request through our privacy portal
- Calling our privacy hotline
We will respond to your request within 30 days (or as required by law).
Privacy Controls
Visibility Settings
Control who can see your profile and activity
Ad Personalization
Opt out of personalized advertising
Data Download
Request a copy of all your data
Data Deletion
Delete your data before the 90-day period
8. Children's Privacy
CraftCrest Marketplace is not intended for children under 13 years of age (or under 16 in the EU). We do not knowingly collect personal information from children under these ages.
Parental Controls
If you are a parent or guardian:
- You can request deletion of your child's information
- You can restrict data collection for your child's account
- You can review and approve your child's public profile
Important: If you believe your child has provided us with personal information, please contact us immediately at craftcrmarket@gmail.com.
9. User-Generated Content & Public Information
Public Information
The following information is publicly visible:
- Your username and profile picture
- Your shop name and description
- Product listings and descriptions
- Reviews you give and receive
- Public collections and favorites
Content Rights
By posting content on CraftCrest:
- You grant us a license to display and distribute your content
- You retain ownership of your original content
- You represent you have the right to post such content
- You agree to our content guidelines and policies
10. Legal & Regulatory Compliance
Applicable Regulations
We comply with:
- GDPR: General Data Protection Regulation (EU)
- CCPA: California Consumer Privacy Act
- CPRA: California Privacy Rights Act
- PIPEDA: Personal Information Protection Act (Canada)
- LGPD: Lei Geral de Proteção de Dados (Brazil)
International Transfers
For international data transfers, we use:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions where available
- Binding Corporate Rules (BCRs)
11. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or applicable law.
Notification Process
Minor Changes
Posted on this page with updated date
Significant Changes
Email notification 30 days before implementation
Material Changes
In-app notification and explicit consent required
Your Continued Use: Continuing to use our services after changes indicates acceptance of the updated policy.
12. Contact Information
If you have any questions about this Privacy Policy or our data practices, please contact us:
Privacy Support Team
Email: craftcrmarket@gmail.com
Phone: 0768175519
Address: 616 Craft Korongo Road, karen Nairobi
Specific Contacts
Data Protection Officer
craftcrmarket@gmail.com
Privacy Rights Requests
craftcrmarket@gmail.com
Data Breach Reports
craftcrmarket@gmail.com
Legal Inquiries
craftcrmarket@gmail.com
Response Times
- General inquiries: 3-5 business days
- Data subject requests: 30 days (extendable to 60 if complex)
- Urgent security matters: Immediate response