1. Who we are
Fika Duka is operated by [registered company name], registered in Rwanda under company number [registration number], with its registered office at [registered address, Kigali, Rwanda]. We are the controller of the personal data described here.
For anything in this policy, write to [privacy@example.rw], or to the address above marked for the attention of [data protection contact].
2. Who this covers
This policy covers everyone who uses Fika Duka: shopkeepers, distributors, sales reps and drivers, and anyone who visits this website. Where you use the platform on behalf of a business, it covers you personally as well as the business.
3. What we collect
What we hold depends on which part of the platform you use. We collect it because the platform cannot do its job without it, not because it might be useful later.
Everyone with an account
- Name, phone number and email address
- A password, stored only as a one-way hash, and one-time codes when two-factor login or a password reset is used
- Which role the account holds, and which business it belongs to
- A device token where push notifications are allowed, so alerts reach the right phone
- Your notification preferences, per event and per channel
Shops
- Shop type, business registration number, TIN and trading hours
- The shop’s address by province, district and sector, and its map coordinates, so deliveries can be planned and found
- Order history: what was ordered, when, from whom, at what price, and how it was paid
- Where a credit line is open: the limit, the balance, the due dates, and whether payments arrived on time
Drivers
- Driving licence number and expiry date
- Photographs of both sides of the national ID, held to confirm identity
- Vehicle type and carrying capacity
- Assigned deliveries, the outcome of each, any note added, and the daily total collected, split by payment method
Sales reps
- Assigned territory and visit schedule
- Shops onboarded, orders placed on their behalf, and payments attributed to the rep
Distributors
- Company registration details and credit policy
- The mobile money number collections are paid out to
- Catalogue, prices, stock levels and order records
Records of what was done
Every action that changes something — a price, an order status, an account — is written to an audit log recording the account, the time, and the values before and after. This is what makes it possible to settle a disagreement about an order months later, and it is kept even where other data is removed.
Technical data
Our servers log IP address, device and browser type, and the pages or screens requested, to keep the service running and to investigate abuse.
4. Why we collect it, and on what basis
- To perform our contract with you — taking orders, reserving stock, routing deliveries, taking payment, issuing invoices, and running credit accounts.
- Because the law requires it — tax, accounting and record-keeping duties, and identity checks where they apply.
- For our legitimate interests — confirming who is trading on the platform, preventing fraud and non-payment, keeping the service secure, and improving how it works. We balance these against your interests, and you can object (see section 10).
- With your consent — push notifications and marketing messages. You can withdraw consent at any time without affecting what came before.
5. Credit decisions made automatically
This section matters, so it is set out on its own.
Whether a shop can buy on credit is decided automatically, by rule, without a person reviewing it. The platform continuously measures three things about a shop: how long it has been trading with us, how consistently it orders each week over a run of consecutive weeks, and its average order value. When all three thresholds are met, a credit line opens. When one is not, it does not.
The thresholds are set by us and can change. Where a shop falls short, the platform shows exactly which rule is unmet and by how much — the decision is not a black box, and there is no hidden score.
A daily job also flags accounts whose credit is overdue, which can suspend further credit ordering.
You can ask for a person to look at it. If you think a credit decision is wrong, or rests on data that is inaccurate, write to [privacy@example.rw]. You can put your case, and a member of staff — not the system — will review it and reply.
6. Who else sees it
We do not sell your data, and we do not share it for advertising. It reaches others only where the service needs it to.
- Your distributor sees the orders you place with them, your shop details and your credit standing with them. Distributors are restricted to their own business at the point data is queried, not only in what the interface shows, so one distributor cannot see another’s shops or orders.
- Your driver sees the delivery address and what is owed on the order they are carrying.
- Your sales rep sees the shops in their territory and the orders they placed on your behalf.
- A mobile money provider processes payments made from a phone and receives what it needs to settle them. It handles that data under its own privacy terms.
- Our service providers — cloud hosting and file storage, push notification delivery, and transactional email — acting on our instructions and no one else’s.
- QuickBooks, but only where a distributor has connected their own account, and only for payments already settled.
- Professional advisers — accountants, lawyers, auditors — where they need it to advise us.
- Authorities, where the law requires it of us.
- A buyer, if the business is sold or merged. We would tell you first.
7. Where it is held
Our infrastructure is hosted in [region]. Where data leaves Rwanda, we rely on [transfer mechanism] to protect it, and we take the same care over it wherever it sits.
8. How it is protected
- Passwords are stored as one-way hashes. We never see or store them in readable form.
- Uploaded documents — ID photographs, proof of payment — are held in private storage and reached only through links that expire.
- Traffic between your device and our servers is encrypted.
- Access is limited by role, and two-factor login by one-time code is available on every account.
- Every change is written to the audit log, so misuse of an account can be traced.
No system is perfectly secure. If a breach happens that puts your rights at risk, we will tell you and the relevant authority without undue delay.
9. How long we keep it
- Account details — while the account is open, and [period] after it closes.
- Orders, invoices and payment records — [period, e.g. 7 years], to meet tax and accounting rules.
- KYC documents — [period] after the account closes.
- Audit logs — [period].
- Server logs — [period, e.g. 90 days].
When a period ends, data is deleted or anonymised so it can no longer be traced back to you.
10. Your rights
You can ask us to:
- Show you the personal data we hold about you, and give you a copy
- Correct anything inaccurate or incomplete — most of it you can edit yourself from your account
- Delete data we no longer have a reason to keep
- Pause what we do with it while a dispute is sorted out
- Stop processing we do for our legitimate interests, where your circumstances outweigh them
- Hand over the data you gave us, in a portable form
- Have a person review an automated credit decision (section 5)
Write to [privacy@example.rw]. We will reply within [period]. Some records we must keep — an invoice, an audit entry — and where that applies we will tell you which and why.
11. Notifications and marketing
Operational messages — an order accepted, a delivery on its way, credit falling due — are part of the service and cannot be turned off entirely, though you can choose which channel they arrive on. Marketing messages only go to people who opted in, and every one carries a way to stop them.
12. This website
This site uses only what it needs to work. We do not use advertising cookies or third-party trackers. Where we store anything in your browser it is to remember a preference, and it is not shared with anyone.
13. Children
Fika Duka is for businesses. Accounts are not available to anyone under 18, and we do not knowingly collect data from children. If you believe a child has an account, tell us and we will remove it.
14. Complaints
If you are unhappy with how we have handled your data, tell us first at [privacy@example.rw] and we will try to put it right. You also have the right to complain to [the relevant Rwandan supervisory authority].
15. Changes to this policy
If we change this policy we will update the date at the top. Where a change materially affects you, we will tell you in the app or by email before it takes effect.