Skip to content

SmartDuka — Privacy Policy

Project-specific privacy policy. For the site-wide policy, see /privacy.

NashIntelli • SmartDuka

Privacy Policy

For SmartDuka — EAC Duka & POS • Effective: 21 September 2026 • Last updated: 21 September 2026 • Package com.nashintelli.smartduka

This Privacy Policy explains how NashIntelli (“we”, “us”, “our”) collects, uses, discloses and safeguards information when you use SmartDuka (the “App”) — Android, iOS and web (expo-router static) — including offline SQLite cache and Firebase/Firestore sync. By using SmartDuka you agree to this Policy.

Contact: support@smartduka.firebase.app • Data controller: NashIntelli, East African Community. Kenya DPA 2019, Tanzania/Uganda/Rwanda DPAs, and where applicable GDPR — rights in §10.

1. Scope & summary

SmartDuka helps sellers across the EAC (Kenya, Tanzania, Uganda, Rwanda, Burundi, South Sudan, DRC, Somalia) create a store, list products & services, manage inventory, accept mobile-money and get discovered via town/country and AI search. The App works offline-first (local SQLite) and syncs to Google Firebase / Firestore when online.

In short: we collect only what is needed to run your duka: account data, store & listing content you create, location you optionally share, and mobile-money SMS you explicitly allow us to read to automate accounting. We do not sell your personal data.

2. Information we collect

Category Examples Source
Account & contactPhone number, email (email/Google Sign-In), display name, auth UID, photo if providedYou provide; Firebase Auth
Store & listingsStore name, number/till, description, colour, logo/banner, categories, products/services (title, price, currency KES/TZS/UGX/RWF/BIF/SSP/CDF, units, rateType fixed/hourly/per_unit, stock, town, country, images ≤3, featured flags)You provide
Mobile-money SMSSMS body, sender ID, amount, transaction code, timestamp — only with SMS permission, for payment verificationDevice SMS inbox (consent) — §3
Images & mediaPhotos via image picker (expo-image-picker)You provide; Firebase Storage
LocationGPS, reverse-geocoded town/country, “Near Me” radiusDevice (expo-location) with permission
Feedback & activityRatings, reviews, matched payment → verified badge, searches, product views, accounting/wallet eventsYou & customers; App-generated
Agents & KnowledgeBaseAgent instructions, skills, working hours, notesYou provide
Device & diagnosticsModel, OS, app version, crash logs, IP, language (EN/SW/FR), notification tokensAutomatic — Firebase/Expo

We do not collect government IDs or infer sensitive categories (health, political, biometric).

3. SMS & mobile-money disclosure

Google Play prominent disclosure

SmartDuka requests READ_SMS RECEIVE_SMS and where needed SEND_SMS solely to automate mobile-money accounting (M-Pesa, Tigo Pesa, Airtel Money, MTN MoMo) — reading payment confirmation SMS to extract amount/transaction code, match it to your products, and mark feedback as verified. You can deny or revoke SMS permission anytime in system settings; the App falls back to manual entry. Without SMS, verification/accounting accuracy is reduced. We never read non-mobile-money SMS and never use SMS for advertising.

  • Opt-in: off by default. First use shows a consent sheet; Allow grants access.
  • Processing: matching on-device where possible; matched records and raw SMS you keep for audit are stored encrypted in Firestore under your store.
  • Scope limitation: filtered to known mobile-money sender IDs/short codes; other SMS is ignored and not uploaded.
  • Withdrawal: Settings → Apps → SmartDuka → Permissions → SMS → Deny. Existing matched data remains until you delete it.

4. How we use information

  • Provide/operate SmartDuka: stores, listings, town/country & AI (Gemini) discovery, Featured/Trending/Top.
  • Automate accounting & wallet: parse mobile-money SMS, reconcile sales, show payments/matched product/raw SMS for audit.
  • Enable trust: verify reviews against real payments → “Verified” badges.
  • Personalise: remember store colour, language/currency selection, offline cache, near-me ordering; debug/improve.
  • Communicate: transactional notifications (orders, payments, subscriptions), support replies, and — with consent — marketing/AI-agent messages per your working hours.
  • Comply with law, prevent fraud/abuse, enforce Terms.

Firebase AI Logic (Gemini) runs only on content you submit for search/inference; we do not train foundation models on your private store data.

6. How we share information

We do not sell personal data.

  • Processors: Google Firebase (Auth, Firestore, Storage, Cloud Functions, Crashlytics, Remote Config), Google Sign-In/OAuth, Expo, and where enabled — Google Gemini via Firebase AI Logic.
  • Other users: public store profile and active listings (name, logo, town/country, prices, images, ratings) visible to anyone browsing. Do not put personal phone/email in descriptions.
  • Legal/safety: if required by EAC law or court order, or to protect rights/safety.
  • Business transfer: merger/acquisition with notice.

Mobile operators (Safaricom M-Pesa, Tigo, Airtel, MTN) are not given your SmartDuka data by us.

7. Storage, security & retention

  • Where stored: local SQLite cache (expo-sqlite, expo-secure-store for tokens) + Google Cloud Firestore nam5 and backups.
  • Security: TLS in transit, encrypted at rest (Google), Firestore Security Rules, least-privilege access. No system is 100% secure — keep device/PIN safe.
  • Retention: account/store data while active + up to 24 months after deletion for audit/fraud (unless law requires longer). SMS bodies kept until you delete the payment record. Crash logs ~90 days.
  • Backups: encrypted; purged per Firebase retention.

8. Device permissions

Permission Purpose Optional?
READ_SMS / RECEIVE_SMSParse mobile-money confirmation SMS to auto-create payments and verify feedbackYes — deny → manual entry
SEND_SMSInitiate customer payment request where supportedYes
Location (GPS)Near Me discovery, reverse-geocode to townYes — type town manually
Photos / CameraStore logo, banner, product imagesYes
NotificationsOrder/payment/subscription/agent alertsYes
Secure StoreAuth tokens (expo-secure-store)Required for login

9. Children

Not directed to children under 18 (or 13 where applicable). We do not knowingly collect children’s data. If you believe a child provided data, contact us to delete it.

10. Your rights & choices

  • Access / correct / delete / port your data; object/restrict; withdraw consent; complain to your DPA (e.g., ODPC Kenya — odpc.go.ke).
  • Permissions: grant/deny SMS, location, photos, notifications in OS settings.
  • Delete account: Profile → Settings → Delete Account, or email support@smartduka.firebase.app from registered email/phone. Firestore store data deleted within 30 days, subject to legal retention.
  • Opt out of marketing: unsubscribe link or Profile → Notifications toggle.

We respond within 30 days. We may verify identity via auth UID + OTP.

11. International transfers

Data may be processed in the EAC, US (nam5), and other processor regions. We rely on SCCs / processor DPAs and Firebase safeguards.

12. Cookies & SDKs (web)

On web we use essential cookies/localStorage for auth, preferences (theme, language, currency), and Firebase analytics/crash strictly necessary to operate the service. Blocking cookies may break sign-in.

13. Changes to this Policy

We update as SmartDuka evolves. Material changes notified in-app and via the “Last updated” date. For changes requiring consent (e.g., new SMS use) we re-prompt.

14. Contact & DPO

NashIntelli — SmartDuka

Email: support@smartduka.firebase.app (also support@smartduka-55f2a.firebaseapp.com)

Project: smartduka-55f2a • Package: com.nashintelli.smartduka

Postal: contact via email for registered address. EU/UK representative via same email.


This Policy was drafted for SmartDuka v1.0.0 across EAC markets and does not constitute legal advice. For Kenya-specific requests, see ODPC at odpc.go.ke.

© 2026 NashIntelli. SmartDuka® is a trademark of NashIntelli. • Terms of Service