top_banner top_banner top_banner

Privacy Policy

SAARIDAA COMMERCE – PRIVACY POLICY (B2B PLATFORM EDITION)

Effective Date: August 6, 2026



1. INTRODUCTION AND SCOPE

Saaridaa Commerce ("Company," "We," "Our," or "Us") respects your privacy and is committed to protecting the personal data you share with us. This Privacy Policy ("Policy") explains how we collect, use, disclose, and safeguard your information when you visit our platform, including all websites, mobile applications, and related services (collectively, the "Platform") . This Policy applies to all Users of the Platform, including Buyers, Sellers, and visitors, and is designed to comply with the Data Protection Act, 2012 (Act 843) of the Republic of Ghana, the Electronic Transactions Act, 2008 (Act 772), and all other applicable laws . By using the Platform, you consent to the data practices described in this Policy. If you do not agree with this Policy, please do not use the Platform .



2. DEFINITIONS

In this Policy, unless the context otherwise requires:

"Data Controller" means a person who either alone, jointly with other persons or in common with other persons or as a statutory duty determines the purposes for and the manner in which personal data is processed or is to be processed .

"Data Processor" means any person other than an employee of the data controller who processes the data on behalf of the data controller .

"Data Subject" means an individual who is the subject of personal data .

"Personal Data" means data about an individual who can be identified from that data or from that data and other information to which the data controller has or is likely to have access .

"Processing" means any operation or set of operations performed on personal data, whether or not by automatic means, including collection, recording, organisation, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction .

"Platform" means the Saaridaa Commerce website, mobile application, and all related services.

"User" means any person or entity who accesses or uses the Platform, including Buyers, Sellers, and visitors.



3. DATA CONTROLLER AND DATA PROTECTION OFFICER

Saaridaa Commerce acts as a Data Controller for the personal data we collect and process on the Platform . We are registered with the Data Protection Commission as a Data Controller, and our registration is renewed every two years as required by law . We have appointed a Data Protection Supervisor responsible for overseeing our data protection strategy and implementation . The Data Protection Supervisor ensures that we comply with the Data Protection Act, 2012 (Act 843), manage data subject requests, conduct internal reviews and risk assessments, and maintain data governance structures . For questions about this Policy or to exercise your data protection rights, you may contact our Data Protection Supervisor at the contact details provided in Section 14 of this Policy .



4. WHAT PERSONAL DATA WE COLLECT


4.1 Information You Provide to Us

We collect personal data that you voluntarily provide to us when you:

- Register for an account on the Platform .

- Create or update your profile and store information.

- Place an order or make a purchase.

- List products or services for sale.

- Communicate with us through email, phone, or other channels.

- Participate in promotions, surveys, or contests.

- Submit reviews, comments, or other content to the Platform .


The types of personal data we may collect include:

- Identity Data: Full name, business name, registration number, Tax Identification Number (TIN), and other business identification details.

- Contact Data: Email address, phone number, physical address, and delivery addresses.

- Financial Data: Bank account details, payment card information, and transaction history.

- Account Data: Username, password, and account preferences.

- Profile Data: Profile picture, store description, product catalogue, and business credentials.

- Verification Data: Copies of identification documents (e.g., Ghana Card, Passport), certificates of incorporation, and other verification documents .

- Content Data: Product descriptions, images, reviews, comments, and other content you submit to the Platform .

- Communication Data: Records of your communications with us, including emails, chat messages, and call recordings.


4.2 Information Collected Automatically

When you use the Platform, we automatically collect certain information about your device and usage:

- Device Information: IP address, browser type and version, operating system, device type, unique device identifiers, and mobile network information.

- Usage Information: Pages you visit, products you view, search queries, clickstream data, time spent on pages, and navigation patterns.

- Location Information: Approximate location derived from your IP address or GPS data (with your consent).

- Cookies and Tracking Technologies: Information collected through cookies, web beacons, and similar technologies to enhance your experience and analyse usage patterns .

- Log Data: Server logs that record requests to our servers, including date and time of access, pages accessed, and error messages.


4.3 Information from Third Parties

We may receive personal data about you from third parties, including:

- Payment Service Providers: Information about payment transactions, including confirmation of payment and refunds.

- Delivery and Logistics Partners: Delivery status and confirmation of receipt.

- Verification Services: Information from identity verification and background check services.

- Business Partners: Information from affiliates, advertising partners, and other third parties with whom we collaborate.

- Public Sources: Information available in public records and databases.



5. HOW WE USE YOUR PERSONAL DATA


5.1 Lawful Basis for Processing

Under the Data Protection Act, 2012 (Act 843), we process personal data only on the following lawful bases:

- Consent: Where you have given clear consent for us to process your personal data for a specific purpose.

- Contract: Where processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract.

- Legal Obligation: Where processing is necessary for compliance with a legal obligation to which we are subject.

- Legitimate Interests: Where processing is necessary for our legitimate interests or those of a third party, provided your interests and fundamental rights do not override those interests.

- Vital Interests: Where processing is necessary to protect your vital interests or those of another person.


5.2 Purposes of Processing

We use your personal data for the following purposes:

- Account Management: To create, maintain, and manage your account, including identity verification and authentication.

- Order Processing: To process and fulfil orders, including payment processing, delivery coordination, and order tracking.

- Product Listing: To enable Sellers to list products, manage inventory, and process sales .

- Customer Support: To provide customer support, respond to inquiries, resolve disputes, and handle complaints.

- Communication: To send order confirmations, delivery updates, and other transactional communications, as well as marketing communications where you have consented.

- Platform Improvement: To analyse usage patterns, improve the Platform, develop new features, and personalise your experience.

- Security and Fraud Prevention: To detect, prevent, and investigate fraud, security incidents, and violations of our Terms and Conditions .

- Legal Compliance: To comply with legal obligations, regulatory requirements, and requests from law enforcement or government authorities.

- Research and Analytics: To conduct research and data analysis to understand user behaviour and improve our services.

- Business Operations: To manage our business operations, including accounting, auditing, and reporting.



6. SHARING AND DISCLOSURE OF PERSONAL DATA


6.1 Sharing with Service Providers

We may share your personal data with third-party service providers who assist us in operating the Platform and providing our services, including:

- Payment Processing Partners: To process payments, handle refunds, and manage financial transactions.

- Delivery and Logistics Partners: To coordinate product delivery, track shipments, and confirm receipt.

- Cloud Service Providers: To host the Platform, store data, and provide IT infrastructure.

- Analytics Providers: To analyse usage patterns and improve the Platform.

- Customer Support Providers: To assist in handling support tickets and complaints.

- Marketing Partners: To conduct marketing campaigns and send promotional communications where you have consented.

- Verification Service Providers: To verify identity and business credentials .


6.2 Sharing with Sellers and Buyers

In the context of transactions on the Platform, we share certain personal data between Buyers and Sellers to facilitate the transaction:

- When you make a purchase, we share your delivery information with the Seller to enable order fulfilment.

- When you sell a product, we share your store information and contact details with the Buyer to facilitate communication and delivery coordination.

- We may share transaction details, including order history and ratings, with both parties for the purpose of dispute resolution and performance evaluation.


6.3 Sharing for Legal and Regulatory Compliance

We may disclose your personal data to third parties when required by law or in response to legal process, including:

- Regulatory Authorities: To comply with requests from the Data Protection Commission, Ghana Revenue Authority, Food and Drugs Authority, Cyber Security Authority, and other regulatory bodies .

- Law Enforcement: To respond to court orders, subpoenas, or requests from law enforcement agencies.

- Fraud Prevention: To investigate and prevent fraud, security incidents, and violations of our Terms and Conditions.

- Dispute Resolution: To resolve disputes between Users, including mediation and arbitration processes.


6.4 Sharing for Business Transfers

In the event of a merger, acquisition, reorganisation, or sale of assets, we may transfer your personal data to the relevant third party, provided that the third party agrees to comply with the Data Protection Act, 2012 (Act 843) and this Policy.


6.5 Sharing with Your Consent

We may share your personal data with third parties for purposes not covered in this Policy only with your explicit consent.



7. CROSS-BORDER DATA TRANSFERS


7.1 International Data Transfers

Saaridaa Commerce may transfer personal data to countries outside Ghana, including to our service providers and business partners. Under Section 45 of the Data Protection Act, 2012 (Act 843), the Act applies to a data controller in respect of data where the data controller is established in Ghana and the data is processed in Ghana, or the data controller is not established in Ghana but uses equipment or a data processor carrying on business in Ghana to process the data . Sending information to a foreign cloud provider does not remove the Ghanaian company's responsibility to assess the destination, safeguards, contract terms, and lawful basis for the transfer . Where we transfer personal data to countries that do not have an adequate level of data protection, we implement appropriate safeguards, including:

- Standard Contractual Clauses approved by the Data Protection Commission.

- Binding Corporate Rules for intra-group transfers.

- Consent from the data subject for the specific transfer.

- Transfers necessary for the performance of a contract with the data subject.


7.2 Data Originating from Ghana

The Data Protection Act, 2012 (Act 843) applies to data which originates partly or wholly from Ghana . We ensure that personal data originating from Ghana is protected in accordance with the Act, regardless of where it is processed or stored.



8. DATA SECURITY


8.1 Security Measures

We implement appropriate technical and organisational measures to protect your personal data from unauthorised access, loss, destruction, or alteration, including:

- Encryption: We use encryption technologies to protect data during transmission and storage .

- Access Controls: We restrict access to personal data to authorised personnel only, based on the principle of least privilege.

- Firewalls and Intrusion Detection: We deploy firewalls and intrusion detection systems to prevent unauthorised access to our systems.

- Regular Security Assessments: We conduct regular security assessments and vulnerability scans.

- Staff Training: We provide training to our staff on data protection and security practices.

- Incident Response: We maintain an incident response plan to address data breaches and security incidents.


8.2 Business Continuity

We maintain business continuity and disaster recovery plans to ensure that personal data is protected and available in the event of a disruption.


8.3 Third-Party Security

We require our third-party service providers to implement adequate security measures to protect the personal data they process on our behalf.


8.4 Your Responsibilities

You are responsible for maintaining the security of your account credentials and for notifying us immediately of any unauthorised use of your account.



9. DATA RETENTION


9.1 Retention Periods

We retain your personal data only for as long as is necessary for the purposes set out in this Policy, unless a longer retention period is required or permitted by law . The retention period depends on the following factors:

- The type of data and its purpose.

- The nature of the processing activity.

- Legal and regulatory requirements.

- Business needs and operational requirements.

- The existence of any ongoing disputes or investigations.


9.2 Retention of Transaction Data

We retain transaction data for at least six years to comply with legal and regulatory record-keeping requirements . After the retention period expires, we securely delete or anonymise the data.


9.3 Retention of Account Data

We retain your account data for as long as your account is active and for a reasonable period thereafter in case of reactivation or to address any disputes or legal claims.


9.4 Data Minimisation

We apply the principle of data minimisation by collecting only the personal data that is necessary for the purposes of processing .



10. YOUR RIGHTS AS A DATA SUBJECT


Under the Data Protection Act, 2012 (Act 843), you have the following rights regarding your personal data:


10.1 Right to be Informed

You have the right to be informed about the processing of your personal data, including the purposes of processing, the categories of data processed, the recipients of the data, and the retention period . This Policy serves to inform you of these details.


10.2 Right of Access

You have the right to request access to your personal data held by us and to obtain a copy of that data . You may request information about the personal data we hold about you, the purposes of processing, and the recipients of the data.


10.3 Right to Rectification

You have the right to request the correction of inaccurate or incomplete personal data . If your personal data is incorrect or incomplete, you may request that we update it.


10.4 Right to Erasure (Right to be Forgotten)

You have the right to request the deletion of your personal data where:

- The data is no longer necessary for the purposes for which it was collected.

- You withdraw consent and there is no other legal basis for processing.

- You object to processing and there are no overriding legitimate grounds.

- The processing is unlawful.

- The data must be erased for compliance with a legal obligation.


10.5 Right to Restrict Processing

You have the right to request the restriction of processing of your personal data where:

- You contest the accuracy of the data.

- The processing is unlawful, and you oppose erasure and request restriction instead.

- We no longer need the data for processing, but you require it for the establishment, exercise, or defence of legal claims.

- You have objected to processing and are awaiting verification of whether our legitimate grounds override your interests.


10.6 Right to Object

You have the right to object to the processing of your personal data for direct marketing purposes, including profiling, and to object to processing based on our legitimate interests . You may object at any time to the processing of your personal data for direct marketing by giving written notice to us without stating a reason .


10.7 Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another data controller where technically feasible.


10.8 Right to Withdraw Consent

Where processing is based on consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.


10.9 Right to Lodge a Complaint

You have the right to lodge a complaint with the Data Protection Commission if you believe that our processing of your personal data infringes the Data Protection Act, 2012 (Act 843) .


10.10 Right to Compensation

You have the right to seek compensation in the courts if your rights under the Data Protection Act have been infringed .



11. HOW TO EXERCISE YOUR RIGHTS


11.1 Submitting a Request

To exercise any of your rights as a data subject, please contact us using the contact details provided in Section 14 of this Policy. You may submit your request in writing by email or by post.


11.2 Verification of Identity

To protect your privacy, we may request proof of your identity before processing your request. This helps ensure that your personal data is not disclosed to unauthorised persons.


11.3 Response Time

We will respond to your request within a reasonable time, and in any event within the timeframes prescribed by the Data Protection Act, 2012 (Act 843). If your request is complex or we receive a large number of requests, we may extend the response time and will inform you of the extension.


11.4 Fees

In most cases, we will respond to your request free of charge. However, we may charge a reasonable fee if your request is manifestly unfounded, excessive, or repetitive, or if you request additional copies of your data.


11.5 Refusal of Request

We may refuse to comply with your request if it is manifestly unfounded or excessive, or if we are permitted by law to refuse. If we refuse, we will provide you with a reason and inform you of your right to lodge a complaint with the Data Protection Commission.



12. DIRECT MARKETING AND UNSOLICITED COMMUNICATIONS


12.1 Consent for Marketing

Under Section 40 of the Data Protection Act, 2012 (Act 843), we require prior written consent from data subjects before using their personal data for direct marketing purposes . We will obtain your consent before sending you marketing communications, including newsletters, promotional offers, and product recommendations.


12.2 Right to Object to Marketing

You have the right to object at any time to the processing of your personal data for direct marketing by giving written notice to us without stating a reason . You may exercise this right by using the unsubscribe link in marketing emails, adjusting your account settings, or contacting us directly.


12.3 Prohibition on Spam

Under Section 50 of the Electronic Transactions Act, 2008 (Act 772), we do not send unsolicited electronic communications to consumers without obtaining prior consent . Where we send electronic commercial communication, we provide you with the option to cancel your subscription and identify the source from which we obtained your personal information, upon your request .


12.4 Penalties for Violation

A person who sends unsolicited electronic

All categories
Flash Sale
Todays Deal