Primary Logo

Privacy Policy

Effective Date: 30 July 2026 · Version 2.1

Vyete Solutions ("Vyete", "we", "us") is committed to protecting your personal data. This Privacy Policy explains what data we collect, how we use it, who we share it with, your rights, and how to exercise them. It applies to all users of the Vyete platform: shoppers, shop operators, brand partners, carriers, and experience providers.

Vyete is registered in Kenya and processes personal data primarily under Kenya's Data Protection Act, 2019. Where UK or EU/EEA data protection law also applies to you, this Policy is written to meet that standard too: see Section 8 for the rights available to you and Section 13 for how to lodge a complaint with the relevant authority.


1. Who We Are

Vyete Solutions is the data controller for personal data processed via the Vyete platform. Our Data Protection Officer can be reached at [email protected]. General privacy questions can go to [email protected].

Registered address: [Vyete Solutions's registered office address, to be confirmed and inserted here]

2. Data We Collect

2.1 Data You Provide

  • Account data: Name, email address, phone number, and password hash when you register.
  • Date of birth: Not collected at registration. Vyete may ask for it later (for example, before a purchase) to support the minimum age requirement in the Terms of Service. Providing it is not currently required to use the Platform: see Section 10.
  • Profile data: Delivery addresses, saved payment method tokens, and preferences.
  • Order data: Items ordered, delivery instructions, and communication with shops or carriers.
  • Reviews and content: Text, ratings, and images you submit on the Platform.
  • Support communications: Messages sent to Vyete customer support.

2.2 Data Collected Automatically

  • Usage data: Pages visited, search queries, clicks, and time spent on the Platform.
  • Device data: IP address, browser type and version, operating system, and device identifiers.
  • Location data: Approximate location derived from IP address; precise location only if you grant permission.
  • Cookies and similar technologies: As described in our Cookie Policy.

2.3 Data From Third Parties

  • Payment processors: Where you interact with a Vyete-billed service (for example, if you operate a Shop, Brand, or Carrier account with a platform subscription), our payment processor shares transaction status and fraud signals with us: we do not receive full card numbers. Vyete does not process payment for a product purchase itself; see Terms of Service §3.3.
  • Social login providers: If you register or sign in using Google, we receive your basic Google profile information (name, email address) as permitted by your Google account settings.
  • Carriers: Delivery status updates and GPS scan data linked to your order.

3. How We Use Your Data

| Purpose | Legal Basis | |---|---| | Processing and fulfilling orders | Contract performance | | Account management and authentication | Contract performance | | Verifying you meet the minimum age requirement to use the Platform | Legal obligation | | Sending order confirmations and delivery updates | Contract performance | | Preventing fraud and ensuring platform security | Legitimate interest | | Improving Platform features and performance | Legitimate interest | | Personalising recommendations and offers | Legitimate interest (or consent where required) | | Ranking and assigning the carrier for your delivery | Contract performance | | Sending marketing communications | Consent | | Complying with legal obligations | Legal obligation | | Resolving disputes and enforcing terms | Legitimate interest / Legal obligation |

4. Automated Decision-Making

Some of the purposes in Section 3 are carried out by automated systems rather than a person reviewing your data by hand. None of these are AI or machine-learning systems. Each is a fixed, rule-based scoring formula over concrete signals, described below for transparency:

  • Personalised recommendations ("Recommended for You" and similar sections): scored from your own purchase, click, view, and share activity on the Platform. See the Search & Ranking Policy for the full signal list.
  • Carrier assignment: when a delivery is created, the carrier offered the job first is chosen by a weighted formula combining proximity to pickup, cost, past delivery reliability, and any existing relationship between the Shop and that carrier. This is the one automated decision in this list with a direct real-world effect: it decides who delivers your order.
  • Search ranking: results are ordered using a combination of relevance, availability, a quality score built from ratings/reviews/response time, listing recency, delivery coverage, and price; again, see the Search & Ranking Policy.

None of these systems make a decision about you that has a legal effect (for example, none of them can reject your order, restrict your account, or deny you a refund on their own). You can request human review of any of them under your Automated decisions right in Section 8.

5. How We Share Your Data

Vyete does not sell your personal data. We may share data with:

5.1 Shops and Brands

Order details (name, address, items, and contact number) are shared with the shop fulfilling your order and, where necessary, the brand that supplied the product for warranty or recall purposes.

5.2 Carriers

Your name, delivery address, and contact number are shared with the verified carrier assigned to your delivery.

5.3 Service Providers

We engage third-party processors under data processing agreements. The current list is published in the Data Processing Agreement §5.

5.4 Legal Disclosure

We may disclose your data where required by law, court order, or regulatory authority, or where necessary to protect the rights, property, or safety of Vyete, its users, or the public.

5.5 Business Transfers

If Vyete is involved in a merger, acquisition, or asset sale, your data may be transferred to the acquiring entity, subject to the same protections.

6. International Transfers

Where your data is transferred outside your country of residence, Vyete ensures adequate safeguards are in place (such as Standard Contractual Clauses or equivalent mechanisms) in compliance with applicable data protection law.

7. Data Retention

We retain personal data for as long as necessary for the purpose it was collected, and no longer. Specific periods:

| Category | Retention Period | |---|---| | Account and profile data | For as long as your account is active, plus the erasure process described in Section 8 once you close it | | Order and transaction records | Up to 7 years from the transaction date, in line with Kenyan financial record-keeping practice | | Security logs, login history, and fraud-prevention signals | Up to 24 months from the event, unless a specific investigation or legal claim requires longer, in which case only the data relevant to that matter is retained until it concludes | | Support communications | Up to 3 years after the matter is resolved | | Marketing consent and preferences | Until you withdraw consent | | Reviews (after account erasure) | Retained with the personal-data link removed: see the Data Rights Request Procedure §5 |

Where a specific matter (an open dispute, a legal claim, a regulatory inquiry) requires Vyete to hold a category of data longer than the table above, we retain only what that matter requires and will explain the basis for doing so if you ask.

8. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access a copy of the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data where we no longer have a lawful basis to process it, completed within 21 days of your request (see below).
  • Restrict processing while a dispute is pending.
  • Data portability: receive your data in a machine-readable format.
  • Object to processing based on legitimate interest or for direct marketing.
  • Withdraw consent at any time where processing is consent-based.
  • Automated decisions: request human review of any decision described in Section 4.
  • Lodge a complaint: see Section 13.

Submit a request through the Data Privacy section of your account at id.vyete.com, or by email to [email protected]. See our Data Rights Request Procedure for step-by-step instructions and response timeframes.

Note

Access and Portability requests submitted at id.vyete.com are fulfilled immediately by email. Erasure (account deletion) requires additional identity verification via a one-time code, disables your account immediately, and permanently deletes it 21 days later, with a cancellation link in the confirmation email in case you change your mind. See the Data Rights Request Procedure for the full mechanics, including what's deleted versus anonymised, and how backups are handled.

9. Privacy Controls on vyete.com

In addition to your statutory data rights (Section 8), you can manage social privacy preferences directly from Settings → Privacy at vyete.com. These controls are effective immediately and do not require a formal data request:

| Control | What it does | |---|---| | Follow gating | Choose whether anyone can follow you automatically or whether you must approve each follow request. | | Direct message permissions | Control who can send you direct messages: everyone, people you follow, or no one. | | Activity visibility | Choose whether your recent activity is shown on your public profile. |

These settings affect how other users interact with you on the Platform. They do not affect how Vyete processes your personal data for the purposes described in Section 3.

10. Children's Privacy

The Platform is intended for use by people aged 18 and over (see the eligibility requirement in the Terms of Service). Vyete does not currently verify age at registration or otherwise, and does not knowingly collect personal data from children. If you believe a child has provided data to us, contact [email protected] and we will investigate and delete it promptly.

11. Security

Vyete implements appropriate technical and organisational measures including encryption in transit (TLS), encryption at rest, access controls, and regular security assessments. In the event of a personal data breach, Vyete follows the notification commitments in the Security Incident Response Policy, including notifying affected individuals directly, without undue delay, wherever a breach is likely to result in a high risk to them. No system is completely secure; you should use a strong, unique password and enable two-factor authentication.

12. Changes to This Policy

Material changes will be communicated by email or in-Platform notice at least 14 days before they take effect. The current version will always be accessible at the URL of this page.

13. Complaints

If you are unhappy with how Vyete has handled your personal data or a rights request, you may:

  1. Escalate internally to [email protected].
  2. Contact the Office of the Data Protection Commissioner (ODPC), Kenya's data protection authority, which oversees the Data Protection Act, 2019.
  3. If you are located in the UK or EU/EEA, you may instead or additionally contact your local supervisory authority: for example the ICO in the United Kingdom or the DPC in Ireland.

14. Contact

Data Protection Officer: [email protected]

General privacy enquiries: [email protected]

Registered address: [Vyete Solutions's registered office address, to be confirmed and inserted here]