NeoMali Privacy Policy
Last updated: January 2026
1. Introduction
NeoMali is an online shop creation platform operated by Birowaks Media and Technology, a company incorporated in the Republic of Kenya (“Company”, “we”, “our”, or “us”).
This Privacy Policy explains how we collect, use, disclose, store, and protect personal data when you access or use:
- https://neomali.com
- Any NeoMali subdomains (including shop subdomains)
- NeoMali web or mobile applications
(collectively, the “Service”).
This Policy is issued in accordance with the Data Protection Act, 2019 (Kenya).
By using the Service, you acknowledge that you have read and understood this Privacy Policy.
2. Who We Are (Data Controller)
For purposes of the Data Protection Act, 2019:
- Data Controller: Birowaks Media and Technology
- Platform: NeoMali
We determine the purpose and means of processing personal data on the NeoMali platform.
3. Personal Data We Collect
We collect personal data directly from you and automatically through your use of the Service.
a) Information You Provide
This may include:
- First and last name
- Email address
- Phone number
- Physical delivery address (customers)
- Business or shop details (vendors)
- Product listings and descriptions
- Communication with support
b) Account and Authentication Data
- Login credentials (stored securely)
- Google OAuth profile information (name and email only)
We do not store plaintext passwords.
c) Payment Information
Payments on NeoMali are processed through third-party payment providers (e.g. M-Pesa).
We do not store:
- M-Pesa PINs
- Full card numbers
- Payment authorization credentials
4. How We Use Personal Data
We process personal data for the following lawful purposes:
- Creating and managing user accounts
- Enabling vendors to operate online shops
- Processing orders and facilitating deliveries
- Communicating order confirmations and notifications
- Providing customer support
- Improving platform functionality and security
- Preventing fraud and misuse of the platform
- Complying with legal and regulatory obligations
We only process data that is necessary and relevant to these purposes.
5. Legal Basis for Processing (Kenya)
We process personal data based on:
- Your consent
- Performance of a contract (providing the Service)
- Compliance with legal obligations
- Our legitimate interests (platform security, fraud prevention)
6. Cookies and Similar Technologies
NeoMali uses cookies and similar technologies to:
- Maintain user sessions
- Remember preferences
- Improve performance and usability
- Analyze aggregated platform usage
You can control cookies through your browser settings. Disabling cookies may limit some features of the Service.
7. Sharing of Personal Data
We do not sell personal data.
We may share personal data with:
- Payment service providers
- Hosting and infrastructure providers
- Authentication providers (e.g. Google)
- Delivery or notification service providers
- Law enforcement or regulators where required by law
All third parties are required to handle data securely and lawfully.
8. Vendors and Customer Data
If you are a vendor, you acknowledge that:
- You act as an independent data controller for your customers’ data
- You are responsible for lawful use of customer information obtained through NeoMali
NeoMali provides infrastructure but does not control vendor fulfillment activities.
9. Data Security
We implement appropriate technical and organizational measures to protect personal data, including:
- Encrypted connections (HTTPS)
- Secure authentication
- Access controls
- Restricted administrative access
While we take reasonable measures to protect data, no system is completely secure.
10. Data Retention
We retain personal data only for as long as necessary to:
- Provide the Service
- Meet legal and regulatory requirements
- Resolve disputes
- Enforce our agreements
When data is no longer required, it is securely deleted or anonymized.
11. Your Rights Under Kenyan Law
Under the Data Protection Act, 2019, you have the right to:
- Be informed about data processing
- Access your personal data
- Correct inaccurate or incomplete data
- Object to processing
- Request deletion of personal data
- Withdraw consent (where applicable)
Requests can be made using the contact details below.
12. Children’s Data
NeoMali is not intended for use by persons under the age of 18.
We do not knowingly collect personal data from children. If such data is identified, it will be deleted promptly.
13. International Data Transfers
Where personal data is processed or stored outside Kenya, we ensure appropriate safeguards are in place in accordance with Kenyan law.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date.
Continued use of the Service constitutes acceptance of the revised Policy.
15. Contact Information
For privacy-related inquiries or requests, contact:
- Birowaks Media and Technology
- [email protected]