Legal · Jalba Elegance
Privacy
Policy
At Jalba Elegance, your privacy matters. This policy explains what personal data we collect, why we collect it, how we use it, and the rights you hold over it. By using our website or placing an order, you agree to the practices described here. If you do not agree, please do not use our services.
Section 01
Who We Are
Jalba Elegance We specialize in delivering high-quality, fashionable shoes that blend comfort, class, and confidence jalbaelegance.com.
For the purposes of the Kenya Data Protection Act 2019, Jalba Elegance is the Data Controller — meaning we determine how and why your personal data is processed.
Section 02
Data We Collect
We collect only the information necessary to provide you with our products and services. This includes:
| Category | Examples | Purpose |
|---|---|---|
| Identity & Contact | Full name, email address, phone number | Account creation, order confirmation, customer support |
| Delivery Address | Street, city, county, country | Processing and delivering your orders |
| Payment Information | M-Pesa transaction reference, card details (tokenised) | Processing payments securely via our payment processors |
| Account Data | Username, password (encrypted), order history, wishlist | Managing your account and purchase history |
| Communication Data | Enquiry content, social media messages, newsletter preferences | Responding to enquiries, sending newsletters you subscribed to |
| Technical / Device Data | IP address, browser type, device type, pages visited, session duration | Website performance, security, analytics, improving user experience |
We do not collect sensitive personal data such as health information, biometric data, or national ID numbers. We never store full card numbers — payment details are handled and tokenised directly by our payment processors.
Section 03
How We Collect It
We collect your personal data through the following channels:
Direct Collection
Online Checkout When you place an order on our website.
Contact Forms When you submit an enquiry or support request.
Newsletter Signup When you subscribe to our email updates.
Account Creation When you register for a customer account.
Indirect Collection
Social Media When you interact with us on Instagram, Facebook, TikTok or other platforms, subject to those platforms' own privacy policies.
Cookies & Tracking Automatically collected as you browse our website (see Section 6).
Section 04
How We Use It
We use your personal data only for the purposes listed below, and only where we have a lawful basis to do so under the Kenya Data Protection Act 2019:
| Purpose | Lawful Basis |
|---|---|
| Processing and fulfilling your orders | Performance of a contract |
| Managing your customer account | Performance of a contract |
| Sending order confirmations and delivery updates | Performance of a contract |
| Responding to your enquiries and support requests | Legitimate interest / contract |
| Sending marketing emails and newsletters | Consent (you may unsubscribe at any time) |
| Improving our website and shopping experience | Legitimate interest |
| Fraud prevention and security | Legitimate interest / legal obligation |
| Complying with legal and regulatory requirements | Legal obligation |
We will never use your data for automated decision-making that produces legal or similarly significant effects without your explicit consent.
Section 05
Who We Share It With
We do not sell, rent, or trade your personal data. We share it only with trusted third parties who help us operate our business, and only to the extent necessary:
Delivery & Logistics Partners
We share your name, phone number, and delivery address with courier and logistics companies in order to fulfil and deliver your orders across Kenya and internationally.
Payment Processors
We use secure payment processors (including M-Pesa and card payment providers) to handle transactions. These processors receive only what is necessary to complete your payment and operate under their own strict security and privacy standards.
Marketing Platforms
With your consent, we may share your email address with email marketing platforms to send you newsletters and promotional updates. You can withdraw this consent at any time by clicking "Unsubscribe" in any email.
Technology & Hosting
Our website is hosted on the Odoo platform. Odoo processes certain technical and transactional data on our behalf as a data processor, bound by contractual obligations to protect your data.
We require all third parties to maintain appropriate security measures and to use your personal data only for the specified purposes. We do not permit them to use your data for their own independent marketing.
Section 06
Cookies & Tracking
Our website uses cookies — small text files placed on your device — to enhance your browsing experience and help us understand how visitors use our site.
| Cookie Type | Purpose | Can You Opt Out? |
|---|---|---|
| Essential | Keep your shopping cart active, enable login sessions, maintain site security | No — required for the site to function |
| Functional | Remember your preferences (language, currency, saved items) | Yes — via browser settings |
| Analytics | Understand how visitors navigate the site (pages visited, time spent, clicks) | Yes — via cookie consent banner |
| Marketing | Track visits from social media ads and measure campaign effectiveness | Yes — via cookie consent banner |
You can manage cookie preferences through our cookie consent tool or your browser settings. Disabling essential cookies may affect your ability to shop on our site. For more on managing cookies, visit allaboutcookies.org.
Section 07
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes it was collected for, including satisfying legal, accounting, or reporting requirements.
Retention Periods
Order Records 7 years (Kenya tax and financial record requirements)
Customer Accounts For the duration of your account; deleted within 30 days of an account deletion request
Marketing Consent Until you withdraw consent or unsubscribe
Support Enquiries 2 years from date of last contact
Technical / Device Data 13 months (analytics standard)
When data is no longer required, we securely delete or anonymise it so it can no longer be associated with you.
Section 08
International Users
Jalba Elegances serves customers internationally. Our website is operated from Kenya and your data is stored and processed primarily within Kenya.
When we share data with third-party service providers (such as payment processors or marketing platforms) who operate outside Kenya, we ensure appropriate safeguards are in place — including contractual data protection clauses — to protect your information in line with the Kenya Data Protection Act 2019.
If you are located in the European Union or United Kingdom, you may have additional rights under the GDPR or UK GDPR. We honour those rights and will respond to any such requests accordingly.
Section 09
Your Rights
Under the Kenya Data Protection Act 2019, you have the following rights over your personal data. We will respond to all valid requests within 30 days.
Right to Access
Request a copy of the personal data we hold about you.
Right to Rectification
Ask us to correct inaccurate or incomplete data.
Right to Erasure
Request deletion of your data where there is no lawful reason to retain it.
Right to Object
Object to processing based on legitimate interests, including direct marketing.
Right to Portability
Receive your data in a structured, machine-readable format.
Right to Restrict
Ask us to pause processing while a complaint is being resolved.
To exercise any of these rights, please use the Contact Us form on our website. We may ask you to verify your identity before processing your request. There is no charge for making a request.
If you believe your data rights have been violated, you have the right to lodge a complaint with the Office of the Data Protection Commissioner of Kenya at odpc.go.ke.
Section 10
Data Security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or disclosure. These measures include:
SSL Encryption All data transmitted through our website is encrypted via HTTPS.
Password Hashing Account passwords are stored using industry-standard encryption — never in plain text.
Payment Security Card and M-Pesa transactions are handled by PCI-DSS compliant processors.
Access Controls Only authorised personnel can access personal data, on a need-to-know basis.
Despite these measures, no method of internet transmission is 100% secure. If you suspect your account has been compromised, please contact us immediately via our website contact form.
Section 11
Children's Privacy
Our website and services are not directed at children under the age of 18. We do not knowingly collect personal data from minors. If you believe a child has provided us with personal information, please contact us through our website and we will promptly delete it.
Section 12
Policy Changes
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make significant changes, we will notify you by posting a clear notice on our website and updating the effective date at the top of this page.
We encourage you to review this policy periodically. Your continued use of our website after any changes constitutes your acceptance of the updated policy.
Section 13
Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or how we handle your personal data, please reach out to us. We are committed to addressing all enquiries promptly and transparently.
Questions about your privacy?
Our team is ready to help. Submit your request through our website and we will respond within 24 hour.
Contact UsLegal · Jalba Elegance
Privacy
Policy
At Jalba Elegance, your privacy matters. This policy explains what personal data we collect, why we collect it, how we use it, and the rights you hold over it. By using our website or placing an order, you agree to the practices described here. If you do not agree, please do not use our services.
Section 01
Who We Are
Jalba Elegance We specialize in delivering high-quality, fashionable shoes that blend comfort, class, and confidence jalbaelegance.com.
For the purposes of the Kenya Data Protection Act 2019, Jalba Elegance is the Data Controller — meaning we determine how and why your personal data is processed.
Section 02
Data We Collect
We collect only the information necessary to provide you with our products and services. This includes:
| Category | Examples | Purpose |
|---|---|---|
| Identity & Contact | Full name, email address, phone number | Account creation, order confirmation, customer support |
| Delivery Address | Street, city, county, country | Processing and delivering your orders |
| Payment Information | M-Pesa transaction reference, card details (tokenised) | Processing payments securely via our payment processors |
| Account Data | Username, password (encrypted), order history, wishlist | Managing your account and purchase history |
| Communication Data | Enquiry content, social media messages, newsletter preferences | Responding to enquiries, sending newsletters you subscribed to |
| Technical / Device Data | IP address, browser type, device type, pages visited, session duration | Website performance, security, analytics, improving user experience |
We do not collect sensitive personal data such as health information, biometric data, or national ID numbers. We never store full card numbers — payment details are handled and tokenised directly by our payment processors.
Section 03
How We Collect It
We collect your personal data through the following channels:
Direct Collection
Online Checkout When you place an order on our website.
Contact Forms When you submit an enquiry or support request.
Newsletter Signup When you subscribe to our email updates.
Account Creation When you register for a customer account.
Indirect Collection
Social Media When you interact with us on Instagram, Facebook, TikTok or other platforms, subject to those platforms' own privacy policies.
Cookies & Tracking Automatically collected as you browse our website (see Section 6).
Section 04
How We Use It
We use your personal data only for the purposes listed below, and only where we have a lawful basis to do so under the Kenya Data Protection Act 2019:
| Purpose | Lawful Basis |
|---|---|
| Processing and fulfilling your orders | Performance of a contract |
| Managing your customer account | Performance of a contract |
| Sending order confirmations and delivery updates | Performance of a contract |
| Responding to your enquiries and support requests | Legitimate interest / contract |
| Sending marketing emails and newsletters | Consent (you may unsubscribe at any time) |
| Improving our website and shopping experience | Legitimate interest |
| Fraud prevention and security | Legitimate interest / legal obligation |
| Complying with legal and regulatory requirements | Legal obligation |
We will never use your data for automated decision-making that produces legal or similarly significant effects without your explicit consent.
Section 05
Who We Share It With
We do not sell, rent, or trade your personal data. We share it only with trusted third parties who help us operate our business, and only to the extent necessary:
Delivery & Logistics Partners
We share your name, phone number, and delivery address with courier and logistics companies in order to fulfil and deliver your orders across Kenya and internationally.
Payment Processors
We use secure payment processors (including M-Pesa and card payment providers) to handle transactions. These processors receive only what is necessary to complete your payment and operate under their own strict security and privacy standards.
Marketing Platforms
With your consent, we may share your email address with email marketing platforms to send you newsletters and promotional updates. You can withdraw this consent at any time by clicking "Unsubscribe" in any email.
Technology & Hosting
Our website is hosted on the Odoo platform. Odoo processes certain technical and transactional data on our behalf as a data processor, bound by contractual obligations to protect your data.
We require all third parties to maintain appropriate security measures and to use your personal data only for the specified purposes. We do not permit them to use your data for their own independent marketing.
Section 06
Cookies & Tracking
Our website uses cookies — small text files placed on your device — to enhance your browsing experience and help us understand how visitors use our site.
| Cookie Type | Purpose | Can You Opt Out? |
|---|---|---|
| Essential | Keep your shopping cart active, enable login sessions, maintain site security | No — required for the site to function |
| Functional | Remember your preferences (language, currency, saved items) | Yes — via browser settings |
| Analytics | Understand how visitors navigate the site (pages visited, time spent, clicks) | Yes — via cookie consent banner |
| Marketing | Track visits from social media ads and measure campaign effectiveness | Yes — via cookie consent banner |
You can manage cookie preferences through our cookie consent tool or your browser settings. Disabling essential cookies may affect your ability to shop on our site. For more on managing cookies, visit allaboutcookies.org.
Section 07
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes it was collected for, including satisfying legal, accounting, or reporting requirements.
Retention Periods
Order Records 7 years (Kenya tax and financial record requirements)
Customer Accounts For the duration of your account; deleted within 30 days of an account deletion request
Marketing Consent Until you withdraw consent or unsubscribe
Support Enquiries 2 years from date of last contact
Technical / Device Data 13 months (analytics standard)
When data is no longer required, we securely delete or anonymise it so it can no longer be associated with you.
Section 08
International Users
Jalba Elegances serves customers internationally. Our website is operated from Kenya and your data is stored and processed primarily within Kenya.
When we share data with third-party service providers (such as payment processors or marketing platforms) who operate outside Kenya, we ensure appropriate safeguards are in place — including contractual data protection clauses — to protect your information in line with the Kenya Data Protection Act 2019.
If you are located in the European Union or United Kingdom, you may have additional rights under the GDPR or UK GDPR. We honour those rights and will respond to any such requests accordingly.
Section 09
Your Rights
Under the Kenya Data Protection Act 2019, you have the following rights over your personal data. We will respond to all valid requests within 30 days.
Right to Access
Request a copy of the personal data we hold about you.
Right to Rectification
Ask us to correct inaccurate or incomplete data.
Right to Erasure
Request deletion of your data where there is no lawful reason to retain it.
Right to Object
Object to processing based on legitimate interests, including direct marketing.
Right to Portability
Receive your data in a structured, machine-readable format.
Right to Restrict
Ask us to pause processing while a complaint is being resolved.
To exercise any of these rights, please use the Contact Us form on our website. We may ask you to verify your identity before processing your request. There is no charge for making a request.
If you believe your data rights have been violated, you have the right to lodge a complaint with the Office of the Data Protection Commissioner of Kenya at odpc.go.ke.
Section 10
Data Security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or disclosure. These measures include:
SSL Encryption All data transmitted through our website is encrypted via HTTPS.
Password Hashing Account passwords are stored using industry-standard encryption — never in plain text.
Payment Security Card and M-Pesa transactions are handled by PCI-DSS compliant processors.
Access Controls Only authorised personnel can access personal data, on a need-to-know basis.
Despite these measures, no method of internet transmission is 100% secure. If you suspect your account has been compromised, please contact us immediately via our website contact form.
Section 11
Children's Privacy
Our website and services are not directed at children under the age of 18. We do not knowingly collect personal data from minors. If you believe a child has provided us with personal information, please contact us through our website and we will promptly delete it.
Section 12
Policy Changes
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make significant changes, we will notify you by posting a clear notice on our website and updating the effective date at the top of this page.
We encourage you to review this policy periodically. Your continued use of our website after any changes constitutes your acceptance of the updated policy.
Section 13
Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or how we handle your personal data, please reach out to us. We are committed to addressing all enquiries promptly and transparently.
Questions about your privacy?
Our team is ready to help. Submit your request through our website and we will respond within 24 hour.
Contact Us