Privacy Policy — Buddy’s Liquorstore (Kenya)
Last updated: 15 January 2026
This Privacy Policy explains how Buddy’s Liquorstore (“Buddy’s”, “we”, “us”) collects, uses, discloses, and protects personal data when you visit our website, place an order, create an account, or interact with our services.
We aim to comply with Kenya’s Data Protection Act, 2019 and related regulations, and we restrict our alcohol services to adults (18+), consistent with Kenyan alcohol control rules.
Important: This policy is a template you can adapt to your actual operations (payments, couriers, vendors, analytics, etc.). Replace the bracketed placeholders before publishing.
1) Who we are (Data Controller)
Business name: Buddy’s Liquorstore
Legal/registered name: [Insert legal entity name]
Registration number (if any): [Insert]
Physical address: [Insert]
Email: [privacy@buddysliquorstore.co.ke]
Phone: [Insert]
In most cases, Buddy’s is the data controller for personal data processed through our website and ordering channels.
2) Scope
This policy applies to:
- Our website and online store
- Customer accounts and orders (including order on delivery)
- Customer support interactions (WhatsApp/SMS/calls/email, if used)
- Marketing communications (only where permitted/consented)
It does not cover third-party sites we link to. Their privacy policies apply.
3) Age restriction (18+)
Our products and services are intended for persons 18 years and above.
If you are under 18, do not use our services or share personal data with us.
We may take steps to verify age at checkout and/or at delivery (e.g., requesting an ID). If we learn we have collected personal data from a person under 18, we will delete it where legally permissible and may cancel the transaction.
4) Personal data we collect
Depending on how you use our services, we may collect:
A) Data you provide
- Identity & contact: name, phone number, email, delivery address
- Account data: login credentials (hashed), preferences
- Order details: items purchased, special instructions, delivery notes
- Customer support: messages, call records/notes (if recorded, we will inform you)
- Age verification: confirmation that you are 18+ and, if required, ID-check outcome (we try to avoid storing ID numbers unless necessary)
B) Data collected automatically
- Device & usage data: IP address, browser type, pages visited, timestamps
- Cookies/identifiers: for login sessions, preferences, security, analytics (see Cookies section)
C) Data from third parties (if applicable)
- Delivery partners/couriers (delivery status, proof of delivery)
- Payment providers (if you later enable online payments; typically we receive confirmation, not full card/mobile-money details)
- Advertising/analytics providers (only if enabled)
5) Why we use your data (purposes)
We process personal data to:
- Create and manage customer accounts
- Process and deliver orders (including confirming delivery details)
- Provide customer support and handle complaints/returns
- Improve website performance, security, and user experience
- Send service messages (order confirmations, delivery updates)
- Send marketing messages only where you have consented or where lawful (and you can opt out)
- Prevent fraud, abuse, and unauthorized access
- Meet legal and regulatory obligations (records, tax, licensing)
6) Lawful basis for processing (Kenya)
We process personal data only where lawful and necessary, including:
- Performance of a contract (to fulfill your order and deliver products)
- Consent (e.g., marketing messages; certain cookies)
- Legitimate interests (fraud prevention, service improvement, security) balanced against your rights
- Legal obligation (compliance with applicable laws and lawful requests)
7) Marketing preferences
If you subscribe to marketing (SMS/WhatsApp/email), you can opt out anytime by:
- Using an “unsubscribe” link (where available), or
- Replying STOP, or
- Contacting us using the details above.
We do not sell your personal data for third-party marketing.
8) Who we share data with
We may share personal data with:
- Delivery partners/couriers to deliver orders and confirm delivery
- IT & hosting providers (site hosting, email/SMS/WhatsApp tools, security services)
- Analytics providers (only if enabled, typically aggregated/limited)
- Professional advisers (lawyers, auditors) where necessary
- Regulators and law enforcement where legally required
We require our service providers to protect your personal data and only use it for the services they provide to us.
9) International transfers
We may use vendors whose servers are outside Kenya (e.g., cloud hosting). Where we transfer data outside Kenya, we will take reasonable steps to ensure appropriate safeguards and/or rely on a lawful basis for transfer, as required by Kenyan data protection law.
10) Data security
We use reasonable technical and organizational measures designed to protect personal data, such as:
- HTTPS encryption
- Access controls and least-privilege permissions
- Password hashing for accounts
- Monitoring and security updates
- Backups and secure storage
No system is 100% secure. If a breach occurs that poses a real risk of harm, we will take steps consistent with Kenyan law and ODPC guidance.
11) Data retention
We keep personal data only for as long as necessary for the purposes described above, including:
- While your account is active
- As needed to fulfill orders and provide support
- As required for legal, tax, accounting, and audit obligations
- For fraud prevention and security
When data is no longer needed, we securely delete, anonymize, or de-identify it.
12) Your rights under Kenya’s Data Protection Act
You may have the right to:
- Be informed about how your data is used
- Access your personal data
- Object to processing in certain circumstances
- Correct inaccurate or misleading data
- Request deletion of false or misleading data (and in some cases other data, subject to legal requirements)
To exercise your rights, contact us using the details in section 1. We may request verification of identity before fulfilling a request.
If you are unhappy with our response, you may lodge a complaint with Kenya’s Office of the Data Protection Commissioner (ODPC).
13) Cookies and similar technologies
We use cookies and similar technologies to:
- Keep you signed in (session cookies)
- Remember your preferences
- Improve security and prevent fraud
- Measure performance and usage (analytics), if enabled
You can control cookies through your browser settings. Some cookies are required for the site to function properly.
14) Third-party links
Our site may include links to third-party services (e.g., social media platforms). We are not responsible for their privacy practices.
15) Updates to this policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and update the “Last updated” date above. Significant changes may also be communicated via email or a notice on the website.
16) Contact us
For privacy questions or requests, contact:
Buddy’s Liquorstore
Email: [privacy@buddysliquorstore.co.ke]
Phone: [Insert]
Address: [Insert]
References (Kenya)
- Data Protection Act, 2019 (Kenya Law)
- Data Protection (General) Regulations, 2021 (Kenya Law)
- ODPC: Rights of a Data Subject
- Alcoholic Drinks Control Act, 2010 (Kenya Law)