Tawana Commerce Ltd (“Tawana”, “we”, “us”, or “our”) is committed to protecting and respecting your privacy.
This Privacy Policy explains how we collect, use, disclose, store, transfer, and otherwise process personal data when you use our websites, merchant dashboards, storefronts, mobile applications, APIs, and related services available at https://www.tawana.shop and related Tawana domains and subdomains (collectively, the “Platform” or “Services”), or when you contact us.
By using the Platform, you acknowledge that you have read and understood this Privacy Policy.
1. Who this Policy applies to
Tawana is an eCommerce platform. This Policy applies to:
Merchants: individuals or businesses that create and manage shops, publish products, accept orders, and serve customers
Customers: individuals who browse storefronts, place orders, make payments, and interact with merchants
Visitors: individuals who browse Tawana websites, landing pages, or storefronts without creating an account
In this Policy, we refer to merchants, customers, and visitors collectively as “users”, “you”, or “your”.
2. Who we are and our role
2.1 Data controller
Unless stated otherwise, Tawana Commerce Ltd is the data controller for personal data processed in connection with the operation of the Tawana Platform. This means we decide why and how personal data is processed for our own platform purposes, such as account management, security, fraud prevention, billing, support, analytics, and platform improvement.
2.2 When Tawana acts as a processor or service provider
Where Tawana hosts a merchant storefront, stores order information on behalf of a merchant, or provides tools that a merchant uses to manage customer data, Tawana may act as a processor or similar service provider on behalf of that merchant. In those cases, the relevant merchant may also be a separate controller of customer personal data and may provide its own privacy notice, policies, or terms.
2.3 Contact details
Privacy contact: admin@tawana.shop
Please use the subject line “Privacy Request” for data protection requests.
3. Scope
This Privacy Policy applies when you use:
the Tawana marketing website and informational pages
Tawana-hosted storefronts and shop domains
the Tawana merchant dashboard and admin tools
Tawana mobile applications (where available)
Tawana APIs and connected platform services
Tawana support channels, including email and other enabled communication channels
This Policy does not cover the processing of personal data relating to job applicants, employees, contractors, or corporate suppliers except where required by law or where a separate notice applies.
4. The personal data we collect
We may collect personal data directly from you, automatically from your device or browser, from merchants, from payment providers, from connected services, and from other lawful third-party sources.
4.1 Information you provide to us
A) Account and profile information
Name
Email address
Phone number
Country, city, or region
Profile photo (optional)
Login credentials or authentication identifiers
Account preferences and settings
B) Merchant and business information
Shop name, shop URI, branding, logos, banners, and business profile details
Business registration details where required
Tax, VAT, invoicing, or billing details where required
Business address, fulfilment address, or collection details
Delivery rules, return rules, and operating preferences
Payment setup, settlement, payout, or subscription-related information
C) Catalogue and content information
Product names, descriptions, categories, pricing, stock status, variants, attributes, and images
Promotions, discounts, campaigns, catalogue structure, and merchandising content
Feed configuration, sharing metadata, preview content, and storefront content
D) Order and checkout information
Items ordered
Order references
Customer name and contact details
Shipping, delivery, collection, or billing details
Order status history
Order notes, invoice details, and support interactions relating to an order
E) Payment and billing information
Transaction references
Payment status and method metadata
Refund and chargeback information
Subscription, plan, billing, commission, and fee records
Important: Tawana generally does not store any payment card details. Payment card data is usually collected and processed by third-party payment providers under their own privacy notices and security controls.
F) Communications
Emails, support requests, and attachments
Messages sent through enabled support or communication channels
Records of complaints, disputes, reports, and resolutions
G) User-generated content
Reviews, ratings, and comments
Uploaded files, images, documents, and media
Responses to surveys, promotions, or feedback requests
4.2 Information we collect automatically
A) Device and technical information
IP address
Browser type and version
Operating system and device type
App version, build number, and device identifiers where permitted
Language, time zone, and regional settings
B) Usage information
Pages viewed, features used, clicks, searches, and navigation patterns
Cart activity and checkout activity
Merchant dashboard actions
Session timestamps and login events
Error logs, diagnostics, crashes, and performance metrics
C) Approximate location information
Approximate location inferred from IP address or device settings
Delivery or collection locations you enter manually
Shop location or branch location details provided by merchants
D) Cookies and similar technologies
We use cookies and similar technologies for functions such as authentication, session management, cart persistence, security, fraud prevention, analytics, and user preferences. Some cookies are strictly necessary for the Platform to work. Others are optional and will be used only where the law allows and, where required, where you have given consent.
4.3 Information we receive from other sources
Payment processors and payment gateways
Authentication providers and social sign-in providers
Fraud prevention and risk services
Analytics and advertising partners, where permitted
Merchants, customers, or other users involved in transactions or disputes
Public authorities, regulators, law enforcement, or courts where lawfully required
5. Special category data and children
We do not intentionally request or require special category personal data unless it is strictly necessary and legally permitted. Please do not provide sensitive personal data unless we specifically request it for a lawful reason.
The Platform is not directed at children where local law requires parental authorisation or prohibits collection. If we learn that we have collected personal data from a child unlawfully, we will take steps to delete it.
6. How and why we use personal data
Purpose
Examples
Lawful basis
Provide and operate the Platform
Account creation, shop hosting, product publishing, cart, checkout, order processing, receipts, storefront delivery, merchant tools
Performance of a contract; legitimate interests
Billing, subscriptions, commissions, and financial records
Charging plan fees, maintaining billing history, reconciling transactions, issuing invoices
Performance of a contract; legal obligation; legitimate interests
Security and fraud prevention
Detecting account abuse, suspicious transactions, bot activity, chargeback risk, and unauthorised access
Legitimate interests; legal obligation
Customer support and dispute handling
Resolving support tickets, complaints, refund questions, and merchant-customer disputes
Performance of a contract; legitimate interests; legal obligation
Platform improvement and analytics
Diagnostics, feature testing, performance analysis, product improvement
Legitimate interests; consent where required
Marketing and communications
Sending product updates, newsletters, offers, and campaign messages
Consent where required; legitimate interests where permitted by law
Legal and compliance matters
Record-keeping, tax compliance, responding to lawful requests, enforcing terms
Legal obligation; legitimate interests
Where we rely on legitimate interests, we consider and balance our interests against your rights and freedoms.
7. Marketing communications
We may send service messages that are necessary for your use of the Platform, such as order confirmations, billing notices, security alerts, or important account updates.
We may also send marketing communications where permitted by law. Where consent is required, we will ask for it. You can opt out of marketing at any time using the unsubscribe link or by contacting us.
8. Automated decision-making and profiling
We may use automated tools to help detect fraud, score transaction risk, flag suspicious behaviour, improve search and merchandising, personalise content, and prioritise support or moderation workflows.
Where required by law, if we make a decision based solely on automated processing that produces legal or similarly significant effects, we will apply appropriate safeguards, which may include human review and a way to contest the decision.
9. How we share personal data
We share personal data only where necessary for the purposes described in this Policy.
9.1 With merchants and customers
To enable orders, fulfilment, and customer service, relevant customer data may be shared with the merchant operating the relevant shop, and relevant merchant business information may be shown to customers.
9.2 With processors and service providers
We may share personal data with vendors that provide services such as cloud hosting, infrastructure, authentication, payment processing, fraud prevention, analytics, email delivery, support tooling, search, monitoring, accounting, legal, and audit services. These providers are required to process personal data only on appropriate instructions and with suitable protections.
9.3 With platform integrations
Where a merchant enables integrations, we may share relevant data with connected services such as payment gateways, analytics services, marketing channels, shipping providers, feed destinations, or social commerce platforms.
9.4 For legal reasons
We may disclose personal data where necessary to comply with a legal obligation, protect our rights, investigate fraud, enforce our terms, or respond to valid requests from courts, regulators, law enforcement, or public authorities.
9.5 Corporate transactions
If Tawana is involved in a merger, acquisition, financing, restructuring, or sale of assets, personal data may be disclosed as part of that transaction subject to appropriate safeguards.
9.6 Aggregated or anonymised information
We may use and share aggregated or anonymised information that does not identify you personally.
10. International transfers
Your personal data may be processed in countries outside your country of residence, including where our service providers, infrastructure, support teams, or partners operate. Where UK GDPR or GDPR applies, and personal data is transferred internationally, we will use an appropriate transfer mechanism where required, such as an adequacy decision or contractual safeguards.
11. Retention
We keep personal data only for as long as reasonably necessary for the purposes set out in this Policy, including to comply with legal, tax, accounting, dispute, security, and operational requirements.
Account data: while your account is active and for a reasonable period afterwards
Order and transaction records: for as long as needed for accounting, tax, chargeback, refund, fraud-prevention, and dispute purposes
Merchant billing and subscription records: for as long as required by applicable accounting and tax rules
Support and complaint records: for as long as needed to resolve issues and demonstrate compliance
Security logs: for as long as needed to protect the Platform and investigate incidents
12. Your rights
Depending on the law that applies, you may have rights to:
request access to your personal data
request correction of inaccurate or incomplete data
request erasure in certain circumstances
request restriction of processing in certain circumstances
object to processing based on legitimate interests
request portability of certain data
withdraw consent where processing is based on consent
lodge a complaint with a supervisory authority
To exercise your rights, contact support@tawana.shop with the subject line “Privacy Request”. We may ask you to verify your identity before acting on a request.
If you are in the UK, you may also have the right to complain to the Information Commissioner’s Office.
13. Cookies and similar technologies
We use cookies and similar technologies to operate and secure the Platform, remember settings, keep shopping carts working, measure performance, and, where permitted, understand usage and improve marketing.
We classify cookies broadly as:
Strictly necessary cookies — needed for core site functions such as login, security, session continuity, and cart functionality
Preferences cookies — remember settings such as language or display choices
Analytics cookies — help us understand traffic and performance
Advertising or targeting cookies — used for marketing or campaign measurement where enabled
Where consent is required, we will request it before setting non-essential cookies or similar technologies. We will also provide a way to manage or withdraw cookie preferences.
You can also manage cookies through your browser settings, although disabling certain cookies may affect the operation of the Platform.
14. Security
We implement appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage. These measures may include access controls, encryption in transit where appropriate, logging, monitoring, least-privilege access, and vendor due diligence.
However, no method of transmission over the internet or method of electronic storage is completely secure, so we cannot guarantee absolute security.
15. Third-party sites and services
The Platform may link to, embed, or integrate with third-party sites and services. Merchants may also connect their own third-party tools. We are not responsible for the privacy practices of third parties, and you should review their policies separately.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated version on the Platform. Where required by law, we will take additional steps to notify you.
17. Contact us
Email: support@tawana.shop