Draft under review — this document is being finalised and may change before the programme launch. Version v0.1 draft, 14 Sept 2026. Text shown [like this] is still to be confirmed.

Privacy Policy

How Denri Africa handles personal data in the Veniate affiliate programme

v0.1 draft · Last updated 14 Sept 2026

Dates

Last updated: [date of publication]. Effective from: [date].

1. Who we are

Veniate is the affiliate programme of [Denri Africa Limited] (“Denri Africa”, “we”, “us”), a company registered in Kenya with its principal office at [registered address]. Denri Africa operates the online store at denriafricastores.com and Denri Africa retail stores, and is the data controller for the personal data described in this policy.

Questions about this policy or your data: partners@denriafrica.co.ke, or write to [postal address]. [Data Protection Officer / privacy contact name, if designated.]

This policy covers people who apply to or take part in the Veniate programme (“partners”), visitors to the partner portal, and — in a limited way described in Section 4 — customers whose purchases are attributed to a partner. It does not replace the denriafricastores.com store privacy policy, which continues to govern shopping on the store.

2. Personal data we collect

2.1 Data you give us

WhenWhat
ApplicationFull name, email address, M-Pesa phone number, social media platform(s) and handle(s), stated audience size, your promotion plan, and the version of the programme terms you accepted.
Identity verification (before first payout)Kenyan national ID number and KRA PIN. We do not collect or store ID photographs or document scans.
ProfileChanges to the above, email-notification and leaderboard preferences.
SupportThe content of tickets and messages you send us, and any files you attach.
Campaign participationWhich campaigns you join and any campaign-specific codes issued to you.

2.2 Data we generate or observe

CategoryDetails
Account and programme dataYour promo code, partner status, tier, join date, and the identifiers our systems assign to you in our store and point-of-sale platforms.
Share-link clicksTimestamp, campaign and channel, the referring page, browser user-agent string, and a one-way hash of the visitor’s IP address. We do not store the IP address itself and cannot reverse the hash.
Sales and commissionsAttributed orders (with order numbers partly masked), order dates and values, eligible subtotals, commission amounts and status, adjustments, and refund or cancellation events.
PayoutsWithdrawal requests, payout amounts, M-Pesa transaction receipts, transaction charges, and failure reasons.
Integrity signalsAutomated flags for suspected self-referral, coupon-site leakage or unusual redemption velocity, and the outcome of any review.
Sign-in and securitySign-in timestamps, one-time-code delivery records, and session cookies.
Audit logA record of actions taken on your account by you or by Denri Africa staff, for accountability.
Portal analyticsIf enabled, Google Analytics 4 collects aggregated usage of the portal (pages viewed, device type, approximate location). No analytics cookie is set unless the tag is active.

2.3 Data about customers

When an order is attributed to a partner, we receive the order from our store or point-of-sale system. To detect self-referral we compare the customer’s email address and phone number on the order against the partner’s own registered details. The comparison result is stored as a flag; the customer’s contact details are not shown to partners and are not used for any other purpose within Veniate.

4. Who we share data with

We share personal data only where needed to run the programme, with parties who are bound to protect it:

  • Denri Africa staff who administer the programme, on a need-to-know basis.
  • Payment processing[Sasapay] and Safaricom (M-Pesa) receive your M-Pesa number, name and payout amount to complete disbursements.
  • Store and point-of-sale platforms — Shopify and our Odoo point-of-sale system hold your promo code and the discount rule linked to it so that codes work at checkout and in store.
  • Infrastructure and tooling — Supabase (database, sign-in and secure file storage), Vercel (hosting), Resend (transactional email), Google (Analytics, if enabled, and fonts), and a self-hosted error-monitoring service operated by Denri Africa.
  • Professional advisers, auditors, regulators or law enforcement where we are legally required or where necessary to protect our rights.
  • Other partners see your first name and ranking only if you opt in to the leaderboard.

If Denri Africa is reorganised or the programme is transferred to another entity, your data may be transferred as part of that change; we would tell you in advance.

5. Cookies and similar technologies

The partner portal uses strictly necessary cookies to keep you signed in after you enter your one-time code. If Google Analytics is enabled, it sets analytics cookies; [we will show a consent notice before doing so / these are treated as non-essential and you may opt out via ...].

Share links redirect to denriafricastores.com, where Shopify applies the discount code to the shopper’s session using Shopify’s own cookie. That cookie is governed by the store’s privacy policy and Shopify’s policies, not by Veniate. Veniate itself does not set tracking cookies on shoppers, and sale attribution is based on the promo code used at checkout rather than on cookies.

6. How long we keep data

DataRetention
Declined applications[12] months from decision, then deleted
Account, sales, commission and payout recordsLife of your account plus [7] years, to satisfy tax and accounting law
National ID number and KRA PINLife of your account plus the period required for tax records, then deleted
Share-link click logs (hashed IP, user agent)[12] months, then aggregated or deleted
Support tickets and attachments[24] months after closure, then deleted
Audit log[7] years
Sign-in and security logs[90] days

When you close your account, we first settle any payable balance, then delete or anonymise data that we are not required to keep.

7. How we protect data

We use encryption in transit and at rest, role-based access so staff only see what their job requires, short-lived signed links for any support attachments, hashing of IP addresses at the point of collection, masking of order numbers shown to partners, and an audit log of administrative actions. We deliberately do not collect ID document images, which limits the impact of any incident. If a breach is likely to cause real risk to you, we will notify the ODPC within 72 hours and inform you without undue delay, as the Act requires.

8. Your rights

Under the Data Protection Act you have the right to:

  • be told how your data is used (this policy);
  • access a copy of the personal data we hold about you;
  • have inaccurate or incomplete data corrected — most details can be edited in your profile;
  • object to processing, or ask us to restrict it, in certain circumstances;
  • ask for deletion of data we are not legally required to keep;
  • withdraw consent for optional processing (leaderboard, optional notifications) at any time;
  • receive your data in a portable, machine-readable format;
  • not be subject to purely automated decisions with significant effects.

To exercise any right, email partners@denriafrica.co.ke from your registered address. We respond within the time limits set by the Act (generally within [7 / 30] days) and may ask you to confirm your identity first. If you are not satisfied, you may complain to the Office of the Data Protection Commissioner (odpc.go.ke).

9. International transfers

Some of our service providers store or process data outside Kenya, including in the United States and the European Union. Where this happens we rely on the transfer being necessary to perform our contract with you and/or on contractual safeguards with the provider that meet the requirements of sections 48–49 of the Act. [List each provider’s hosting region once confirmed.]

10. Children

The programme is open to adults only. We do not knowingly collect data from anyone under 18, and we will close any account we discover belongs to a minor.

11. Changes to this policy

We may update this policy as the programme develops — for example if we introduce tax withholding, expand beyond Kenya, or add a new identity-verification provider. Material changes will be emailed to partners at least [14] days before they take effect, and the “last updated” date above will change.

12. Contact

[Denri Africa Limited] · [registered address] · partners@denriafrica.co.ke · denriafricastores.com

Questions about this document? Email partners@denriafrica.co.ke or open a ticket from Support in your dashboard.