Your Data & Choices

Privacy Policy

Effective date: 15 August 2026

This policy explains how Kratom Kenya handles personal data when you browse, create an account, place an order, use WhatsApp checkout, make a payment, or contact us.

1. Who is responsible for your data?

Kratom Kenya, operating from Nairobi, Kenya, is responsible for deciding how personal data collected through this website is used. Privacy questions and requests can be sent to info@kratomkenya.com or WhatsApp +254 722 606 896.

2. Personal data we collect

  • Identity and contact data: name, email address, phone number, age confirmation, and account identifier.
  • Delivery and billing data: address, town, county, saved addresses, and delivery instructions.
  • Order and support data: cart contents, orders, returns, refunds, communications, and support history.
  • Payment metadata: payment method, provider reference, amount, currency, and status. We do not receive or store your full card number, CVV, or M‑Pesa PIN.
  • Account and security data: a securely hashed password, email-verification state, login/session records, security tokens, rate-limit events, and fraud-prevention information.
  • Device and usage data: IP address, browser/device information, pages and actions, cookie choices, and logs needed to operate and secure the service.
  • Information you choose to provide: messages sent through email, phone, WhatsApp, forms, or other support channels.

3. How we collect data

We collect data directly from you, automatically from your browser or device, from your activity on our service, and from service providers such as Paystack, delivery partners, email providers, or fraud-prevention services when they confirm a transaction or service event.

4. Why we use personal data

PurposeData usedReason
Process and deliver ordersContact, address, order, payment statusPerform the purchase contract and take requested pre-contract steps
Provide accounts, carts, and supportAccount, cart, contact, communicationsProvide requested services and our legitimate interest in customer service
Payments and reconciliationOrder and payment metadataPerform the contract, prevent fraud, and meet financial obligations
Security and abuse preventionSession, IP, device, and activity logsLegitimate interests and legal/security obligations
Records and complianceOrders, payments, refunds, communicationsApplicable legal, tax, accounting, and consumer obligations
Optional analytics or marketingCookie and usage data; contact data if subscribedYour consent where required; you can withdraw it

We do not sell personal data. If we need to use data for a materially different purpose, we will provide appropriate notice and seek consent where required.

5. Payments through Paystack

When you choose M‑Pesa or card payment, we send Paystack the order reference, total, currency, email address, and other contact details needed to create and reconcile its hosted checkout. You enter payment credentials on Paystack's service. Paystack returns transaction status and reference information so we can verify, fulfil, refund, or reconcile the order.

Paystack is responsible for its own handling of data on its hosted service. Review the information presented on that service before payment. Never send us a card CVV or M‑Pesa PIN.

6. Who may receive personal data?

We disclose only what is reasonably necessary to:

  • Paystack and relevant payment, banking, card-network, or mobile-money participants for payment processing, verification, refunds, and fraud prevention;
  • couriers and delivery partners for fulfilment;
  • hosting, database, security, backup, email, support, and approved analytics providers that help operate the service;
  • professional advisers, insurers, auditors, regulators, law-enforcement bodies, courts, or other parties where law, safety, or a legal claim requires it;
  • a buyer or successor during a genuine business reorganisation, subject to appropriate confidentiality and privacy safeguards.

We require service providers to handle data only for authorised purposes and with appropriate safeguards.

7. International transfers

Some technology or payment providers may store or process data outside Kenya. Where this occurs, we take reasonable steps to use a lawful transfer basis and safeguards appropriate to the sensitivity of the data. Contact us for information about a specific transfer relevant to you.

8. How long we keep data

We keep personal data only for as long as needed for the purpose collected, including order fulfilment, support, security, legal claims, and applicable tax, accounting, consumer, or regulatory requirements. Retention depends on the record type and legal context. When data is no longer required, it is deleted, anonymised, or securely isolated until deletion is possible.

You may request account deletion, but we may retain limited order, payment, fraud, or legal records where required or reasonably necessary.

9. Security

We use measures designed to protect data, including HTTPS in production, server-side sessions, access controls, password hashing, CSRF protection, rate limiting, restricted secrets, transaction verification, and backups. No system is completely risk-free. Protect your password and contact us promptly if you suspect unauthorised account activity.

10. Cookies, sessions, and carts

Strictly necessary cookies and local browser storage keep your session secure and your cart available. Optional analytics are used only according to your preference. See our Cookie Policy or select “Cookie Settings” in the footer.

11. Your privacy rights

Subject to the Data Protection Act, 2019 and applicable exceptions, you may ask us to:

  • confirm whether we process your personal data and give you access to it;
  • correct inaccurate or incomplete data;
  • erase data that is no longer lawfully required;
  • restrict or object to certain processing;
  • provide portable data where the right applies;
  • withdraw consent for future consent-based processing; and
  • explain or review a significant decision made solely by automated means, if applicable.

Email info@kratomkenya.com with enough detail to identify the request. We may verify your identity before acting and will respond within the period required by law. You may also complain to Kenya's Office of the Data Protection Commissioner if you believe your data has been handled unlawfully.

12. Children

The website and products are intended only for people aged 18 or older. We do not knowingly seek personal data from children. Contact us if you believe a child has provided data so we can investigate and take appropriate action.

13. Marketing choices

We send promotional email or messages only where permitted. You can unsubscribe using the message instructions or contact us. Service messages about orders, security, or accounts are not marketing and may still be sent where necessary.

14. Changes to this policy

We may update this policy when our services, providers, or legal obligations change. We will post the updated version and effective date here and provide additional notice where a change materially affects your rights.

15. Contact

Email: info@kratomkenya.com
WhatsApp: +254 722 606 896
Location: Nairobi, Kenya