Privacy Policy
GadgetDeals KE Limited · Last updated 1 July 2026
GadgetDeals KE Limited ("we", "us") is the data controller for personal data collected through this website. We are registered with the Office of the Data Protection Commissioner and we process personal data in line with the Data Protection Act, 2019.
This policy is written to be read, not to be survived. If anything in it is unclear, write to us and we will explain it in plain language.
1. The data we collect
We collect only what we need to sell you a phone, deliver it, honour the warranty and keep the business lawful.
- Identity and contact data — your name, email address, mobile number and any alternative number you give us.
- Delivery data — county, town, estate or area, street, building, house number, landmark and, only if you choose to share it, a GPS pin.
- Order data — the devices you bought, storage, colour, cosmetic grade, price paid, delivery method and order history.
- Payment data — the payment method, the transaction reference and the last four digits of a card. We never see or store full card numbers; those are handled entirely by our payment processor.
- Device data — the IMEI and serial number of the specific handset sold to you, which is what lets us tie a warranty certificate to your device.
- Trade-in and repair data — the device details, photographs you upload, battery health and the technician's notes.
- Partner data — for Partner Hub members, national ID number, county, payout details (M-Pesa number or bank account) and KYC documents.
- Technical data — IP address, browser type, device type, pages viewed, and the referral code that brought you to the site.
- Communications — messages you send us by email, WhatsApp, the contact form or in a warranty claim.
2. Why we process it, and our lawful basis
- To perform our contract with you: processing orders, taking payment, delivering, invoicing, honouring warranty, trade-in and repair obligations.
- To comply with a legal obligation: tax records, KRA reporting, anti-fraud and stolen-goods obligations, and responding to lawful requests from authorities.
- For our legitimate interests: preventing fraud, securing our systems, calculating partner commissions, understanding which models to stock, and improving the site — always balanced against your rights.
- With your consent: marketing emails and SMS, non-essential cookies, and any optional feature you switch on. You can withdraw consent at any time without affecting anything done before you withdrew it.
3. Cookies and analytics
Essential cookies keep your cart, your session and your partner referral working; the site cannot function without them. Analytics and marketing cookies are off until you turn them on, and rejecting them is exactly as easy as accepting them.
You can change your choice at any time from the cookie preferences link in the footer. See the Cookie Policy for the full breakdown.
4. Marketing communications
We only send marketing where you have opted in. Every message carries a working unsubscribe link or a STOP instruction, and we act on it within 48 hours.
Transactional messages — order confirmations, delivery updates, warranty certificates, repair status — are not marketing and are sent as part of performing our contract with you.
5. Who we share data with
We do not sell personal data. We share it only with processors who need it to do a job for us, under contract, and only for that job.
- Payment providers — Safaricom (M-Pesa), our card acquirer and banks, to take and reconcile payment.
- Courier and pick-up partners — name, phone number and delivery address only.
- Cloud hosting and storage providers, who host the site and store uploaded photographs.
- SMS, email and WhatsApp providers, to send the messages you have asked for.
- Professional advisers, auditors and insurers, where there is a genuine need.
- Law enforcement or regulators, where we are legally required to disclose.
6. Partner Hub referrals
If you arrive through a partner's referral link, we store that partner's code against your session for 30 days so commission can be calculated correctly.
Partners see the value and status of orders attributed to them. Partners never see your name, address, phone number, email or payment details.
7. International transfers
Some of our processors host data outside Kenya. Where that happens, we only use providers who offer protection at least equivalent to the Data Protection Act, 2019, backed by contractual safeguards.
8. How long we keep data
- Order, invoice and tax records: seven years, as required by Kenyan tax law.
- Warranty and device records: the warranty period plus two years, so we can honour and evidence claims.
- Trade-in photographs and inspection records: 24 months.
- Repair records and technician notes: 36 months.
- Partner KYC records: the life of the partnership plus seven years.
- Marketing consent records: until you withdraw consent, plus two years to evidence that the consent existed.
- Analytics data: 26 months, then aggregated beyond recognition.
- Abandoned carts and inactive accounts: deleted after 24 months of inactivity.
9. Your rights
Under the Data Protection Act, 2019, you have the right to:
- Be informed of how your data is used — that is what this document is for.
- Access a copy of the personal data we hold about you.
- Correct data that is inaccurate or incomplete.
- Request deletion of data where we no longer have a lawful reason to keep it.
- Object to processing based on legitimate interests, and to direct marketing at any time.
- Request that processing be restricted while a dispute is resolved.
- Receive your data in a portable, machine-readable format.
- Not be subject to a decision based solely on automated processing that significantly affects you.
10. Exercising your rights
Write to privacy@gadgetdealske.co.ke or to our Data Protection Officer at Luthuli Avenue, Nairobi CBD, P.O. Box 00100, Nairobi, Kenya. We respond within 30 days and we do not charge a fee for a reasonable request.
If you are not satisfied with how we handle your request, you have the right to complain to the Office of the Data Protection Commissioner, Kenya.
11. Security
- All traffic is encrypted with TLS.
- Passwords are hashed with bcrypt and are never stored or recoverable in plain text.
- Administrative access is role-based, individually accountable and logged in an audit trail.
- Payment card data never touches our servers.
- Databases are backed up daily and the backups are encrypted at rest.
- Trade-in and warranty devices are wiped to a certified data-destruction standard before resale.
12. Data breaches
If a breach is likely to result in a risk to your rights and freedoms, we will notify the Office of the Data Protection Commissioner within 72 hours of becoming aware of it, and we will tell you directly and promptly where the risk to you is high.
13. Children
This site is not directed at children under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.
14. Changes to this policy
We may update this policy. The version date at the top always reflects the current version, and material changes will be notified by email to account holders at least 14 days before they take effect. This version is dated 1 July 2026.
15. Contact
GadgetDeals KE Limited, Luthuli Avenue, Nairobi CBD, P.O. Box 00100, Nairobi, Kenya. Privacy enquiries: privacy@gadgetdealske.co.ke. General enquiries: support@gadgetdealske.co.ke or +254 700 000 000.
Questions about this policy?
Write to privacy@gadgetdealske.co.ke or call +254 700 000 000. We will explain any part of it in plain language — that is not a courtesy, it is the point of publishing it.