Privacy Policy
Avenue Fashion ("we," "our," or "us"), a brand powered by Nyota Imara, respects your privacy and is committed to protecting your personal data. This Privacy Policy outlines how we collect, use, process, and disclose your personal information when you access or use our website (avenuefashion.co.ke), our native mobile applications, and our associated services (collectively, the "Platform").
By accessing or using the Platform, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.
1. Information We Collect
We collect information about you directly from you, automatically through your use of the Platform, and from third-party partners.
A. Information You Provide to Us Directly
- Account Registration: When you create an account via Nyota ID, we collect your full name, email address, and profile picture (if provided via Single Sign-On).
- Billing and Shipping Details: When you place an order, we collect your delivery name, phone number, physical address, county, region, and any additional delivery instructions.
- Payment Information: To process M-Pesa payments, we collect your mobile phone number. Note: We do not process or store raw credit card data or M-Pesa PINs. All transactions are securely routed through our payment gateway partner, PayHero, and Safaricom.
- Customer Support: When you submit a ticket via our Support Center, we collect your name, email, subject, and the contents of your message.
B. Information Collected Automatically
- Device and Usage Data: We collect information about how you access the Platform, including your IP address, browser type, operating system (iOS/Android), device identifiers, and browsing actions (e.g., pages viewed, links clicked).
- Push Notification Tokens: If you use our mobile application and opt-in to notifications, we generate and store a secure Expo Push Token to send you real-time order updates and marketing alerts.
- Cookies and Tracking Technologies: We use Google Analytics (GA4) to track user behavior. Tracking only initiates if you explicitly grant permission via our Cookie Consent banner.
2. How We Use Your Information
We use the data we collect for the following business and commercial purposes:
- Fulfillment & Logistics: To process your cart, execute M-Pesa STK Pushes, generate order invoices, and deliver products to your specified county and region.
- Communication: To send transactional emails (via Resend) and push notifications (via Expo) regarding your order status, refunds, or security alerts.
- Customer Support: To assign, track, and resolve your inquiries via our internal ticketing system.
- Platform Improvement: To analyze user behavior, optimize our mobile application performance, and resolve fatal crashes or UI bugs.
- Marketing & Advertising: Subject to your consent, to deliver targeted promotions, editorial lookbooks, and personalized shopping recommendations.
3. How We Share Your Information
We do not sell your personal data. We only share your information with trusted third-party service providers who assist us in operating the Platform:
- Identity Providers: We use Supabase to power "Nyota ID" for secure, cross-platform authentication and session management.
- Payment Processors: We share your phone number and order total with PayHero and Safaricom strictly for the purpose of executing the M-Pesa payment prompt.
- Cloud Infrastructure: Your data is stored securely on our managed databases (PostgreSQL via Supabase), and media assets are served via Cloudflare R2.
- Logistics Partners: We share your name, phone number, and delivery address with our dispatch riders and third-party courier services to fulfill your order.
- Analytics Providers: If you consent to tracking, we share anonymized, aggregated browsing data with Google Analytics.
We may also disclose your information if required to do so by law, or in the good-faith belief that such action is necessary to comply with legal obligations, protect our rights or property, or prevent fraud.
4. Cookies & Tracking Preferences
We use a strict opt-in consent model for tracking. By default, all analytical and advertising storage is denied.
- Essential Cookies: We use strictly necessary cookies (like the Supabase Auth token) to keep you logged in across our web storefront and mobile app. These cannot be disabled.
- Analytics Cookies: If you click "Accept All" on our consent banner, we utilize Google Tag Manager to track page views, cart additions, and purchases to improve our merchandising. You can clear your browser cache or app data at any time to revoke this consent.
5. Data Security & Retention
We implement industry-standard security measures to protect your personal data. Our databases utilize Row Level Security (RLS) to ensure that your private information (such as saved addresses and order history) is only accessible by you and authorized Avenue Fashion staff. Mobile session tokens are stored securely using OS-level keystore mechanisms.
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy, including any legal, accounting, or reporting requirements. Order histories and immutable shipping receipts are retained indefinitely for tax and dispute resolution purposes.
6. Your Data Privacy Rights
Under the Kenyan Data Protection Act (2019), you possess specific rights regarding your personal data:
- Right to Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You can update your name and shipping addresses directly from the "Profile Settings" and "Shipping Addresses" sections of your account dashboard.
- Right to Erasure: You may request that we delete your account and associated personal data, subject to our legal obligations to retain transaction records.
- Right to Object: You may opt-out of marketing communications by clicking "unsubscribe" in our emails, or by disabling push notifications in your device settings.
To exercise any of these rights, please submit a request through our Support Center or email us directly at privacy@nyotaimara.com.
7. Children's Privacy
Avenue Fashion does not knowingly collect or solicit personal information from children under the age of 18 without verifiable parental consent. If we learn that we have collected personal information from a minor, we will delete that information as quickly as possible.
8. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our technology, business practices, or legal requirements. When we make material changes, we will update the "Effective Date" at the top of this page and notify you via email or a prominent banner on the Platform.
9. Contact Us
If you have any questions, concerns, or complaints regarding this Privacy Policy or our data processing practices, please contact our Data Protection Officer:
Nyota Imara / Avenue FashionEmail: support@avenuefashion.co.keSupport Center: avenuefashion.co.ke/support