How Havey collects, uses and protects your information.
Version 0.1.0·Last updated 2026-06-10
Havey is launching in Meru and Nanyuki. These policies describe how we operate today; we may update them as our service grows. Questions: support@haveyapp.com.
1. Policy details
This Privacy Policy applies to the Havey platform operated by:
Havey Operator:
Legal Name: Havey
Registration Number: Available on request
KRA PIN: Available on request
Address: Registered office details are available on request — contact us by email.
Email: support@haveyapp.com
Phone: support@haveyapp.com
Data Protection Contact: support@haveyapp.com
This Policy applies to:
Platform Name: Havey
Platform Promise: Have it delivered.
Supported Initial Towns: Meru and Nanyuki, Kenya
Effective Date: 10 June 2026
2. Purpose
This Privacy Policy explains how Havey collects, uses, stores, shares, protects, and manages personal data.
It applies to:
Customers
Vendors
Vendor staff
Drivers
Dispatchers
Support users
Admin users
Invited payers
Website visitors
Other people interacting with Havey
3. Important privacy statement
Havey should only collect personal data that is necessary for platform operations.
Havey should use personal data for clear, lawful, and legitimate purposes.
Havey should protect personal data from unauthorized access, misuse, loss, disclosure, alteration, or destruction.
Havey should not sell personal data.
4. Definitions
Term
Meaning
Havey
The platform operator listed in Clause 1
Platform
Havey mobile app, website, dashboards, systems, APIs, and related services
Personal Data
Information relating to an identified or identifiable person
Data Subject
A person whose personal data is collected or processed
Customer
Person using Havey to place or receive orders
Vendor
Business approved to sell products through Havey
Driver
Independent delivery service provider using Havey
Invited Payer
Person invited to pay for an order
Processing
Collection, storage, use, sharing, retrieval, alteration, deletion, or other handling of personal data
Data Controller
Person or entity that determines why and how personal data is processed
Data Processor
Person or entity that processes personal data on behalf of a controller
Sensitive Data
Personal data requiring higher care, such as health-related or identity-related information
Restricted Product
Product requiring extra controls, including pharmacy or alcohol-related products
5. Scope
This Policy applies when a person:
Creates a Havey account
Browses the app or website
Places an order
Pays for an order
Invites someone else to pay
Receives delivery
Applies as a Vendor
Applies as a Driver
Uses the Vendor Dashboard
Uses the Driver App
Contacts support
Participates in promotions
Receives notifications
Visits Havey public pages
Interacts with Havey systems
6. Data controller statement
For most platform operations, Havey is expected to act as a data controller because it determines why and how personal data is processed.
In some cases, Havey may also work with third-party processors, including:
Cloud hosting providers
Database providers
Authentication providers
Payment providers
Notification providers
Analytics providers
Support tools
Communication providers
This section requires legal review before publication.
7. Personal data Havey may collect
7.1 Customer data
Havey may collect:
Full name
Phone number
Email address
Delivery addresses
Order history
Payment references
Support messages
Refund/dispute details
App usage data
Device information
Notification tokens
Location information where needed
Communication preferences
7.2 Vendor data
Havey may collect:
Business name
Business owner/contact name
Phone number
Email address
Business location
Business registration details
KRA PIN where applicable
Settlement details
Vendor documents
Product listings
Product images
Order history
Vendor dashboard activity
POS/catalog sync data
Support records
Compliance review records
7.3 Driver data
Havey may collect:
Full name
Phone number
Email address
National ID or passport details
KRA PIN where applicable
Profile photo
Emergency contact
Transport method
Vehicle or motorbike details
Licence details where applicable
Insurance details where applicable
Driver availability
Delivery history
Active delivery location
Settlement details
Cash reconciliation records
Safety reports
Support records
Driver app usage data
7.4 Invited payer data
Where Havey supports “Pay for me” or invite-payer features, Havey may collect:
Payer phone number
Payment reference
Payment status
Limited order payment summary
Payment link activity
Support records where needed
Havey should minimize the Customer information shown to the invited payer.
7.5 Website and technical data
Havey may collect:
IP address
Device type
Browser type
App version
Operating system
Session logs
Error logs
Security logs
Cookie or similar technology data where used
Page interactions
Referral source
7.6 Sensitive or high-risk data
Havey may process sensitive or high-risk data where needed.
Examples may include:
Identity documents
Driver licence details
Health-related or pharmacy-related order details
Restricted Product order details
Location data during active delivery
Payment references
Dispute evidence
Support evidence
Safety reports
Sensitive or high-risk data should be handled with extra care and limited access.
8. Why Havey collects personal data
Havey may process personal data for the following purposes:
Purpose
Examples
Account creation
Create and manage user accounts
Identity verification
Verify Vendors, Drivers, and restricted access where needed
Order processing
Create, validate, track, and complete orders
Payment processing
Initiate, verify, reconcile, refund, and record payments
Delivery coordination
Assign Drivers, track active deliveries, update Customers
Vendor operations
Manage products, availability, orders, and settlement
Driver operations
Manage availability, assignments, delivery status, and settlement
Send order, payment, delivery, and support updates
Marketing
Send offers or promotions where allowed
Analytics
Improve service quality and business performance
Legal compliance
Keep records and respond to lawful requests
9. Legal basis for processing
Havey may process personal data where:
Processing is necessary to provide the platform service.
Processing is necessary to perform a contract or requested transaction.
Processing is necessary for legitimate platform operations.
Processing is required by law.
Processing is necessary to protect safety, security, or legal interests.
Processing is based on consent where required.
Processing is necessary for payment, delivery, support, fraud prevention, or dispute handling.
This section must be reviewed by a qualified Kenyan data protection professional before publication.
10. How Havey uses customer data
Havey may use Customer data to:
Create and manage Customer accounts
Process orders
Validate delivery location
Coordinate delivery
Send order updates
Verify payments
Process refunds
Handle disputes
Prevent fraud
Improve user experience
Send relevant service messages
Send promotional messages where allowed
Provide support
11. How Havey uses vendor data
Havey may use Vendor data to:
Review and approve Vendor applications
Manage Vendor accounts
Display Vendor profile and products
Process customer orders
Coordinate order pickup
Track Vendor performance
Calculate commission and settlement
Manage refunds and disputes
Sync or import product/catalog data
Review restricted category compliance
Provide support
Offer promotions, advertising, and premium tools
12. How Havey uses driver data
Havey may use Driver data to:
Review and approve Driver applications
Manage Driver accounts
Assign delivery requests
Track active deliveries
Show limited Driver details to Customers and Vendors where needed
Process Driver settlement
Manage cash-on-delivery reconciliation
Handle delivery disputes
Review safety and conduct issues
Improve dispatch operations
Provide support
13. Driver location data
Havey may collect Driver location data when the Driver is online or handling an active delivery.
Location data may be used for:
Driver dispatch
Delivery tracking
Customer delivery updates
Vendor pickup coordination
Support
Safety
Dispute review
Fraud prevention
Operational analytics
Havey should avoid exposing unnecessary full location history to Customers or Vendors.
Driver location should be collected and used only as needed for platform operations and subject to applicable law.
14. Payment data
Havey may collect and process payment-related data, including:
Payment method
M-Pesa phone number
Transaction reference
Transaction status
Payment amount
Payment time
Refund status
Manual transaction code
Cash-on-delivery status
Settlement records
Reconciliation records
Havey should not collect unnecessary payment credentials.
Havey should not store sensitive payment credentials unless legally and technically approved.
Payment providers may process payment data under their own terms and policies.
15. Pharmacy and restricted category data
Where Havey supports pharmacy or other sensitive categories, additional personal data may be processed.
This may include:
Restricted Product order information
Supporting information required for compliance
Customer eligibility information
Vendor compliance records
Support review notes
Delivery instructions
Havey should minimize sensitive data and restrict access to authorized users.
Pharmacy-related data should receive higher privacy controls.
This section requires legal and compliance review before restricted categories go live.
16. Alcohol and age-restricted category data
Where Havey supports alcohol or age-restricted products, Havey may process data needed to support compliance.
This may include:
Age or eligibility checks where applicable
Restricted category order history
Delivery confirmation records
Vendor compliance status
Support review notes
Havey should not collect unnecessary identity data.
This section requires legal review before alcohol categories go live.
17. Data sharing
Havey may share limited data with:
Recipient
Reason
Vendors
To prepare and fulfill orders
Drivers
To pick up and deliver orders
Payment providers
To process and verify payments
Cloud providers
To host and secure the platform
Authentication providers
To manage login and access
Notification providers
To send push notifications
Support tools
To manage customer/vendor/driver issues
Legal/compliance advisers
To obtain advice or comply with obligations
Government or regulatory authorities
Where required by law
Security or fraud prevention providers
To detect abuse and protect the platform
Havey should share only what is necessary for the purpose.
18. Data shared with Vendors
Vendors may receive limited information needed to fulfill orders, such as:
Order ID
Ordered items
Order notes
Customer first name or limited identifier where needed
Pickup/delivery coordination information where required
Vendors should not receive unnecessary Customer data.
Vendors must not misuse Customer data.
19. Data shared with Drivers
Drivers may receive limited information needed for delivery, such as:
Order ID
Vendor pickup location
Customer delivery location
Customer contact method where needed
Delivery instructions
Cash-on-delivery amount where applicable
Restricted category delivery instructions where applicable
Drivers should not receive unnecessary Customer data.
Drivers must not misuse Customer data.
20. Data shared with invited payers
Invited payers should only see information necessary to pay for an order.
This may include:
Payment amount
Limited order summary
Payment deadline
Payment status
Customer-provided context where applicable
Havey should avoid exposing unnecessary delivery address, sensitive items, account details, or full order history to invited payers.
21. Data storage
Havey may store personal data in:
Supabase PostgreSQL
Azure Blob Storage
Azure Key Vault
Azure Monitor / Application Insights
Firebase Cloud Messaging systems
Payment provider systems
Support systems
Secure operational tools
Havey should apply appropriate security controls to storage systems.
22. Cross-border data transfers
Havey may use cloud, authentication, payment, notification, monitoring, or support providers that process data outside Kenya.
Where personal data is transferred outside Kenya, Havey should ensure appropriate safeguards, legal basis, consent where required, contractual controls, or other lawful transfer mechanisms are in place.
This section requires legal review before publication.
23. Data retention
Havey should keep personal data only for as long as needed for lawful and legitimate purposes.
Retention reasons may include:
Account operation
Order history
Payment records
Refunds
Disputes
Settlement records
Tax/accounting records
Security logs
Legal compliance
Fraud prevention
Support history
Audit requirements
Placeholder retention schedule:
Data category
Suggested retention direction
Customer account data
While account is active, plus legal retention period
Order records
As required for business, tax, dispute, and legal purposes
Payment records
As required for payment, tax, accounting, and compliance purposes
Driver documents
While driver is active, plus required legal/safety retention period
Vendor documents
While vendor is active, plus required legal/compliance retention period
Support records
For dispute, audit, and service quality purposes
Location data
Keep detailed location data only as long as reasonably needed
Security logs
Keep for security, audit, and fraud investigation purposes
Actual retention periods must be defined after legal review.
24. Data security
Havey should protect personal data using reasonable technical and organizational safeguards.
Safeguards may include:
Authentication
Authorization
Role-based access control
Strong admin access controls
Encryption in transit
Secure secret storage
Audit logs
Access logging
Least-privilege access
Secure cloud storage
Secure development practices
Monitoring and alerts
Backup and recovery controls
Staff access restrictions
Incident response procedures
No system is completely risk-free, but Havey should take reasonable steps to protect personal data.
25. Access control
Access to personal data should be limited based on role.
Examples:
Role
Access direction
Customer
Own account, orders, payments, support cases
Vendor
Own business, products, relevant order information
Driver
Assigned delivery information only
Dispatcher
Active delivery operations
Support
Information needed to resolve cases
Admin
Controlled access based on duty
Finance
Payment, refund, settlement, reconciliation data
Engineering
Limited production access, preferably through audited tools
Sensitive data should require stricter access controls.
26. Data subject rights
A person may have rights regarding their personal data, subject to applicable law.
These may include the right to:
Be informed about how personal data is used
Access personal data
Correct inaccurate, false, or misleading data
Object to certain processing
Request deletion of false or misleading data
Withdraw consent where processing is based on consent
Raise a complaint with Havey or the relevant authority
Havey should provide a clear process for exercising these rights.
27. How to make a data request
A user may contact Havey using:
Data Protection Contact Email: support@haveyapp.com
Support Email: support@haveyapp.com
Phone: support@haveyapp.com
Postal Address: Registered office details are available on request — contact us by email.
A data request should include:
Full name
Phone number or email linked to the account
User type: Customer / Vendor / Driver / Other
Request type
Clear description of the request
Proof of identity where required
Havey may need to verify identity before acting on a request.
28. Account deletion and data deletion
A user may request account deletion or data deletion where allowed.
However, Havey may retain some data where necessary for:
Payment records
Order records
Refunds
Disputes
Settlement records
Tax/accounting obligations
Fraud prevention
Legal claims
Safety investigations
Compliance obligations
Havey should explain when full deletion is not possible and what data must be retained.
29. Marketing communications
Havey may send marketing communications where allowed.
Marketing may include:
Offers
Promotions
Vendor campaigns
Featured products
Discounts
New feature announcements
Users should be given a way to opt out of non-essential marketing where required.
Operational messages may still be sent, including:
Order updates
Payment updates
Delivery updates
Security alerts
Support messages
Important policy updates
30. Push notifications
Havey may use push notifications to send:
Order status updates
Payment status updates
Delivery updates
Vendor acceptance/rejection updates
Refund updates
Support messages
Driver assignment alerts
Vendor order alerts
Promotional messages where allowed
Push notifications should avoid unnecessary sensitive details.
Sensitive information should be viewed inside authenticated app screens.
31. Cookies and similar technologies
Havey websites or dashboards may use cookies or similar technologies for:
Login sessions
Security
Preferences
Analytics
Performance monitoring
Fraud prevention
Marketing where allowed
Havey should provide cookie controls or disclosures where required.
This section requires review before website publication.
32. Children and minors
Havey is not designed for unsupervised use by children.
Where children’s data may be processed, Havey should follow applicable legal requirements and obtain appropriate consent or authorization where required.
Restricted Products should not be ordered by persons who are not legally allowed to order or receive them.
This section requires legal review.
33. Automated decisions and profiling
Havey may use automated or semi-automated systems for:
Fraud checks
Risk flags
Payment verification support
Dispatch recommendations
Vendor ranking
Product recommendations
Promotion targeting
Cash-on-delivery eligibility
Account safety checks
Where decisions significantly affect a user, Havey should provide review or support escalation where appropriate.
This section requires legal review.
34. Data breach and security incidents
A data breach or security incident may include unauthorized access, loss, disclosure, alteration, or destruction of personal data.
Havey should maintain an incident response process.
Possible incident steps:
Detect incident
-> Contain incident
-> Assess affected data
-> Notify internal responsible team
-> Notify regulator/users where legally required
-> Fix root cause
-> Record incident and lessons learned
Havey should report data breaches where required by law or regulator guidance.
35. Third-party links and services
The Platform may contain links or integrations with third-party services.
Examples:
Payment providers
Maps
Communication services
Cloud services
Vendor websites
Social media
Analytics services
Third parties may have their own privacy policies and practices.
Havey is not responsible for third-party privacy practices except where required by law or contract.
36. Vendor and Driver privacy responsibilities
Vendors and Drivers who receive personal data through Havey must use it only for approved platform purposes.
They must not:
Sell personal data
Share personal data unnecessarily
Contact Customers for unrelated reasons
Store unnecessary Customer data
Use Customer data for unrelated marketing
Misuse delivery addresses or phone numbers
Publish Customer information
Use data outside Havey order operations
Havey may suspend Vendors or Drivers who misuse personal data.
37. Internal staff and admin access
Havey staff, admins, support users, dispatchers, and finance users should only access personal data where needed for their role.
Sensitive actions should be logged.
Examples of sensitive actions:
Viewing identity documents
Viewing payment records
Viewing restricted category order data
Changing settlement information
Approving refunds
Accessing support case details
Exporting data
Changing user permissions
38. Data accuracy
Users should keep their information accurate and up to date.
This includes:
Phone number
Email
Delivery address
Vendor business information
Product information
Driver documents
Settlement details
Havey may request updates or verification where information appears outdated, false, incomplete, or misleading.
39. Changes to this Policy
Havey may update this Privacy Policy from time to time.
Where changes are material, Havey should provide reasonable notice where practical.
Continued use of the Platform after notice may be treated as acceptance of the updated Policy, subject to legal review.
40. Contact and complaints
Privacy questions, data requests, or complaints may be sent to:
Data Protection Contact: Data protection — Havey support
Email: support@haveyapp.com
Phone: support@haveyapp.com
Postal Address: Registered office details are available on request — contact us by email.
Users may also have the right to complain to the relevant data protection authority.
This section should be completed after legal review.
41. Operational privacy requirements
PRIVACY-001 — Privacy policy must be accessible
id: PRIVACY-001
priority: P0
statement: The Privacy Policy SHALL be accessible from the app and website.
acceptance:
Customer app links to Privacy Policy.
Website footer links to Privacy Policy.
Signup flow links to Privacy Policy.
PRIVACY-002 — Data access must be role-based
id: PRIVACY-002
priority: P0
statement: Personal data access SHALL be limited by user role and business need.
acceptance:
Vendor cannot view unrelated customer data.
Driver can only view delivery data needed for assigned orders.
Support/admin access is permission-controlled.
PRIVACY-003 — Sensitive data must be minimized
id: PRIVACY-003
priority: P0
statement: Sensitive data SHALL be collected only where necessary.
acceptance:
Restricted category flows collect only required information.
Push notifications avoid sensitive details.
PRIVACY-004 — Data subject requests must be supported
id: PRIVACY-004
priority: P1
statement: Havey SHALL provide a process for users to request access, correction, objection, or deletion where allowed.
acceptance:
Support/admin can log and track privacy requests.
PRIVACY-005 — Driver location must be controlled
id: PRIVACY-005
priority: P0
statement: Driver location SHALL be collected mainly for availability, dispatch, active delivery, support, safety, and dispute purposes.
acceptance:
Driver location is not exposed unnecessarily to Customers or Vendors.
PRIVACY-006 — Breach response must be documented
id: PRIVACY-006
priority: P1
statement: Havey SHALL maintain a breach and security incident response process.
acceptance:
Incident process exists and defines escalation steps.
42. Review notes
Before publishing this Privacy Policy, legal and data protection review is required for: