UP TO 40% OFF
SHOP NOW

Legal

Privacy Policy

Last updated: 9 June 2026

Maschon Home is committed to protecting your personal data in accordance with Kenya's Data Protection Act No. 24 of 2019 and its subsidiary regulations. This Policy explains what data we collect, why we collect it, and your rights as a data subject.

1. Data Controller

Maschon Home(hereinafter “we,” “us,” or “our”) is the data controller responsible for your personal data. We are registered with the Office of the Data Protection Commissioner (ODPC) of Kenya.

Maschon Home — Nairobi, Kenya

Email: privacy@maschon.co.ke

Tel / WhatsApp: +254 700 000 000

2. Data We Collect

We may collect the following categories of personal data:

Identity Data
First name, last name, username or similar identifier
Contact Data
Email address, phone number (including M-Pesa-registered number), delivery address
Transaction Data
Details of products purchased, order history, payment method used (M-Pesa transaction IDs, masked card numbers)
Technical Data
IP address, browser type, device information, pages visited, referral source
Usage Data
Information about how you use our website and services
Communications
Records of emails, WhatsApp messages, or calls with our support team

3. How We Collect Your Data

  • Directly from you — when you register, place an order, or contact us.
  • Automatically — via cookies and similar tracking technologies when you browse our site.
  • Third parties — payment processors (e.g., M-Pesa/Safaricom), delivery partners, and analytics providers.

4. Purpose & Legal Basis for Processing

Process and fulfil your orders
Performance of a contract (Section 30, Data Protection Act)
Create and manage your account
Performance of a contract / Your consent
Send order confirmations and updates
Performance of a contract
Process payments (M-Pesa, card)
Performance of a contract / Legal obligation
Provide customer support
Legitimate interest
Send promotional communications
Your explicit consent (opt-in only)
Prevent fraud and ensure security
Legitimate interest / Legal obligation
Comply with Kenyan laws (KRA, CAK)
Legal obligation
Improve our platform (analytics)
Legitimate interest

You may withdraw consent for marketing communications at any time by emailingprivacy@maschon.co.ke or using the unsubscribe link in any email we send.

5. Data Sharing & Third Parties

We do not sell your personal data. We may share it with the following categories of recipients:

  • Payment processors: Safaricom (M-Pesa), card acquirers — for transaction processing only.
  • Delivery partners: DHL, Aramex, Fargo, EasyCoach, Little — to fulfil your orders.
  • IT service providers: Hosting, analytics, and email providers bound by confidentiality obligations.
  • Regulators & law enforcement: Where required by Kenyan law (KRA, CAK, police).

All third parties are contractually required to protect your data and use it only for the specified purpose.

6. International Data Transfers

Some of our service providers may process data outside Kenya. Where this occurs, we ensure adequate safeguards are in place (such as standard contractual clauses) in line with Section 48 of the Data Protection Act 2019.

7. Data Retention

We retain your personal data only as long as necessary for the purposes outlined in this Policy or as required by Kenyan law (e.g., tax records must be retained for 5 years under the Tax Procedures Act). When data is no longer needed, it is securely deleted or anonymised.

8. Your Rights as a Data Subject (Data Protection Act 2019)

Under the Data Protection Act 2019, you have the following rights:

Right of Access (s.26(a))
Request a copy of the personal data we hold about you
Right to Rectification (s.26(b))
Ask us to correct inaccurate or incomplete data
Right to Erasure (s.26(c))
Request deletion of your data where there is no lawful basis for continued processing
Right to Restriction (s.26(d))
Request that we restrict processing of your data in certain circumstances
Right to Portability (s.26(e))
Receive your data in a structured, machine-readable format
Right to Object (s.26(f))
Object to processing based on legitimate interests or for direct marketing
Right to withdraw consent
Withdraw consent for any processing based on consent at any time

To exercise any of these rights, please contact our Data Protection Officer at privacy@maschon.co.ke. We will respond within 21 days as required by law.

If you are unsatisfied with our response, you may lodge a complaint with the Office of the Data Protection Commissioner (ODPC) at www.odpc.go.ke.

9. Cookies

We use cookies and similar technologies to enhance your browsing experience. Cookies we use include:

  • Strictly necessary cookies: Required for the platform to function (session management, security). These cannot be disabled.
  • Analytics cookies: Help us understand how visitors use our site (e.g., Google Analytics). You can opt out via your browser settings.
  • Preference cookies: Remember your choices (language, region).

You may control cookies via your browser settings. Disabling cookies may affect the functionality of our platform.

10. Security Measures

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction, including:

  • SSL/TLS encryption for all data transmitted over our platform.
  • Secure password hashing (bcrypt).
  • Access controls limiting staff access to personal data on a need-to-know basis.
  • Regular security assessments.

In the event of a data breach that poses a risk to your rights, we will notify the ODPC within 72 hours and affected users without undue delay, in accordance with Section 43 of the Data Protection Act 2019.

11. Children's Privacy

Our platform is not directed at children under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected such data, please contact us immediately and we will delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. The updated version will be posted on this page with a revised “Last updated” date. We encourage you to review this Policy periodically. Material changes will be communicated via email or a prominent notice on our site.

13. Contact Us

Data Protection Officer — Maschon Home

Email: privacy@maschon.co.ke

WhatsApp: +254 700 000 000

Physical address: Nairobi, Kenya