Privacy Policy

Tawana Commerce Ltd (“Tawana”, “we”, “us”, or “our”) is committed to protecting and respecting your privacy.

This Privacy Policy explains how we collect, use, disclose, store, transfer, and otherwise process personal data when you use our websites, merchant dashboards, storefronts, mobile applications, APIs, and related services available at https://www.tawana.shop and related Tawana domains and subdomains (collectively, the “Platform” or “Services”), or when you contact us.

By using the Platform, you acknowledge that you have read and understood this Privacy Policy.

1. Who this Policy applies to

Tawana is an eCommerce platform. This Policy applies to:

  • Merchants: individuals or businesses that create and manage shops, publish products, accept orders, and serve customers
  • Customers: individuals who browse storefronts, place orders, make payments, and interact with merchants
  • Visitors: individuals who browse Tawana websites, landing pages, or storefronts without creating an account

In this Policy, we refer to merchants, customers, and visitors collectively as “users”, “you”, or “your”.

2. Who we are and our role

2.1 Data controller

Unless stated otherwise, Tawana Commerce Ltd is the data controller for personal data processed in connection with the operation of the Tawana Platform. This means we decide why and how personal data is processed for our own platform purposes, such as account management, security, fraud prevention, billing, support, analytics, and platform improvement.

2.2 When Tawana acts as a processor or service provider

Where Tawana hosts a merchant storefront, stores order information on behalf of a merchant, or provides tools that a merchant uses to manage customer data, Tawana may act as a processor or similar service provider on behalf of that merchant. In those cases, the relevant merchant may also be a separate controller of customer personal data and may provide its own privacy notice, policies, or terms.

2.3 Contact details

Privacy contact: admin@tawana.shop

Please use the subject line “Privacy Request” for data protection requests.

3. Scope

This Privacy Policy applies when you use:

  • the Tawana marketing website and informational pages
  • Tawana-hosted storefronts and shop domains
  • the Tawana merchant dashboard and admin tools
  • Tawana mobile applications (where available)
  • Tawana APIs and connected platform services
  • Tawana support channels, including email and other enabled communication channels

This Policy does not cover the processing of personal data relating to job applicants, employees, contractors, or corporate suppliers except where required by law or where a separate notice applies.

4. The personal data we collect

We may collect personal data directly from you, automatically from your device or browser, from merchants, from payment providers, from connected services, and from other lawful third-party sources.

4.1 Information you provide to us

A) Account and profile information

  • Name
  • Email address
  • Phone number
  • Country, city, or region
  • Profile photo (optional)
  • Login credentials or authentication identifiers
  • Account preferences and settings

B) Merchant and business information

  • Shop name, shop URI, branding, logos, banners, and business profile details
  • Business registration details where required
  • Tax, VAT, invoicing, or billing details where required
  • Business address, fulfilment address, or collection details
  • Delivery rules, return rules, and operating preferences
  • Payment setup, settlement, payout, or subscription-related information

C) Catalogue and content information

  • Product names, descriptions, categories, pricing, stock status, variants, attributes, and images
  • Promotions, discounts, campaigns, catalogue structure, and merchandising content
  • Feed configuration, sharing metadata, preview content, and storefront content

D) Order and checkout information

  • Items ordered
  • Order references
  • Customer name and contact details
  • Shipping, delivery, collection, or billing details
  • Order status history
  • Order notes, invoice details, and support interactions relating to an order

E) Payment and billing information

  • Transaction references
  • Payment status and method metadata
  • Refund and chargeback information
  • Subscription, plan, billing, commission, and fee records

Important: Tawana generally does not store any payment card details. Payment card data is usually collected and processed by third-party payment providers under their own privacy notices and security controls.

F) Communications

  • Emails, support requests, and attachments
  • Messages sent through enabled support or communication channels
  • Records of complaints, disputes, reports, and resolutions

G) User-generated content

  • Reviews, ratings, and comments
  • Uploaded files, images, documents, and media
  • Responses to surveys, promotions, or feedback requests

4.2 Information we collect automatically

A) Device and technical information

  • IP address
  • Browser type and version
  • Operating system and device type
  • App version, build number, and device identifiers where permitted
  • Language, time zone, and regional settings

B) Usage information

  • Pages viewed, features used, clicks, searches, and navigation patterns
  • Cart activity and checkout activity
  • Merchant dashboard actions
  • Session timestamps and login events
  • Error logs, diagnostics, crashes, and performance metrics

C) Approximate location information

  • Approximate location inferred from IP address or device settings
  • Delivery or collection locations you enter manually
  • Shop location or branch location details provided by merchants

D) Cookies and similar technologies

We use cookies and similar technologies for functions such as authentication, session management, cart persistence, security, fraud prevention, analytics, and user preferences. Some cookies are strictly necessary for the Platform to work. Others are optional and will be used only where the law allows and, where required, where you have given consent.

4.3 Information we receive from other sources

  • Payment processors and payment gateways
  • Authentication providers and social sign-in providers
  • Fraud prevention and risk services
  • Analytics and advertising partners, where permitted
  • Merchants, customers, or other users involved in transactions or disputes
  • Public authorities, regulators, law enforcement, or courts where lawfully required

5. Special category data and children

We do not intentionally request or require special category personal data unless it is strictly necessary and legally permitted. Please do not provide sensitive personal data unless we specifically request it for a lawful reason.

The Platform is not directed at children where local law requires parental authorisation or prohibits collection. If we learn that we have collected personal data from a child unlawfully, we will take steps to delete it.

6. How and why we use personal data

Purpose Examples Lawful basis
Provide and operate the Platform Account creation, shop hosting, product publishing, cart, checkout, order processing, receipts, storefront delivery, merchant tools Performance of a contract; legitimate interests
Billing, subscriptions, commissions, and financial records Charging plan fees, maintaining billing history, reconciling transactions, issuing invoices Performance of a contract; legal obligation; legitimate interests
Security and fraud prevention Detecting account abuse, suspicious transactions, bot activity, chargeback risk, and unauthorised access Legitimate interests; legal obligation
Customer support and dispute handling Resolving support tickets, complaints, refund questions, and merchant-customer disputes Performance of a contract; legitimate interests; legal obligation
Platform improvement and analytics Diagnostics, feature testing, performance analysis, product improvement Legitimate interests; consent where required
Marketing and communications Sending product updates, newsletters, offers, and campaign messages Consent where required; legitimate interests where permitted by law
Legal and compliance matters Record-keeping, tax compliance, responding to lawful requests, enforcing terms Legal obligation; legitimate interests

Where we rely on legitimate interests, we consider and balance our interests against your rights and freedoms.

7. Marketing communications

We may send service messages that are necessary for your use of the Platform, such as order confirmations, billing notices, security alerts, or important account updates.

We may also send marketing communications where permitted by law. Where consent is required, we will ask for it. You can opt out of marketing at any time using the unsubscribe link or by contacting us.

8. Automated decision-making and profiling

We may use automated tools to help detect fraud, score transaction risk, flag suspicious behaviour, improve search and merchandising, personalise content, and prioritise support or moderation workflows.

Where required by law, if we make a decision based solely on automated processing that produces legal or similarly significant effects, we will apply appropriate safeguards, which may include human review and a way to contest the decision.

9. How we share personal data

We share personal data only where necessary for the purposes described in this Policy.

9.1 With merchants and customers

To enable orders, fulfilment, and customer service, relevant customer data may be shared with the merchant operating the relevant shop, and relevant merchant business information may be shown to customers.

9.2 With processors and service providers

We may share personal data with vendors that provide services such as cloud hosting, infrastructure, authentication, payment processing, fraud prevention, analytics, email delivery, support tooling, search, monitoring, accounting, legal, and audit services. These providers are required to process personal data only on appropriate instructions and with suitable protections.

9.3 With platform integrations

Where a merchant enables integrations, we may share relevant data with connected services such as payment gateways, analytics services, marketing channels, shipping providers, feed destinations, or social commerce platforms.

9.4 For legal reasons

We may disclose personal data where necessary to comply with a legal obligation, protect our rights, investigate fraud, enforce our terms, or respond to valid requests from courts, regulators, law enforcement, or public authorities.

9.5 Corporate transactions

If Tawana is involved in a merger, acquisition, financing, restructuring, or sale of assets, personal data may be disclosed as part of that transaction subject to appropriate safeguards.

9.6 Aggregated or anonymised information

We may use and share aggregated or anonymised information that does not identify you personally.

10. International transfers

Your personal data may be processed in countries outside your country of residence, including where our service providers, infrastructure, support teams, or partners operate. Where UK GDPR or GDPR applies, and personal data is transferred internationally, we will use an appropriate transfer mechanism where required, such as an adequacy decision or contractual safeguards.

11. Retention

We keep personal data only for as long as reasonably necessary for the purposes set out in this Policy, including to comply with legal, tax, accounting, dispute, security, and operational requirements.

  • Account data: while your account is active and for a reasonable period afterwards
  • Order and transaction records: for as long as needed for accounting, tax, chargeback, refund, fraud-prevention, and dispute purposes
  • Merchant billing and subscription records: for as long as required by applicable accounting and tax rules
  • Support and complaint records: for as long as needed to resolve issues and demonstrate compliance
  • Security logs: for as long as needed to protect the Platform and investigate incidents

12. Your rights

Depending on the law that applies, you may have rights to:

  • request access to your personal data
  • request correction of inaccurate or incomplete data
  • request erasure in certain circumstances
  • request restriction of processing in certain circumstances
  • object to processing based on legitimate interests
  • request portability of certain data
  • withdraw consent where processing is based on consent
  • lodge a complaint with a supervisory authority

To exercise your rights, contact support@tawana.shop with the subject line “Privacy Request”. We may ask you to verify your identity before acting on a request.

If you are in the UK, you may also have the right to complain to the Information Commissioner’s Office.

13. Cookies and similar technologies

We use cookies and similar technologies to operate and secure the Platform, remember settings, keep shopping carts working, measure performance, and, where permitted, understand usage and improve marketing.

We classify cookies broadly as:

  • Strictly necessary cookies — needed for core site functions such as login, security, session continuity, and cart functionality
  • Preferences cookies — remember settings such as language or display choices
  • Analytics cookies — help us understand traffic and performance
  • Advertising or targeting cookies — used for marketing or campaign measurement where enabled

Where consent is required, we will request it before setting non-essential cookies or similar technologies. We will also provide a way to manage or withdraw cookie preferences.

You can also manage cookies through your browser settings, although disabling certain cookies may affect the operation of the Platform.

14. Security

We implement appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage. These measures may include access controls, encryption in transit where appropriate, logging, monitoring, least-privilege access, and vendor due diligence.

However, no method of transmission over the internet or method of electronic storage is completely secure, so we cannot guarantee absolute security.

15. Third-party sites and services

The Platform may link to, embed, or integrate with third-party sites and services. Merchants may also connect their own third-party tools. We are not responsible for the privacy practices of third parties, and you should review their policies separately.

16. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated version on the Platform. Where required by law, we will take additional steps to notify you.

17. Contact us

Email: support@tawana.shop