1. Information We Collect
When you use the SixStores platform, we may collect the following categories of personal data:
1.1 Information You Provide
- Account Data -- full name, email address, phone number (including MTN and Airtel numbers), date of birth, gender, and profile photograph
- Transaction Data -- delivery addresses, order history, payment method details (Mobile Money numbers, transaction IDs), billing information
- Vendor Data -- business name, TIN number, National ID, bank/mobile money details, business registration documents, store location
- Communications -- messages, reviews, ratings, support tickets, feedback, and any correspondence with SixStores or vendors
- Referral Data -- referral codes, names and contact details of persons you refer
1.2 Information Collected Automatically
- Device Data -- IP address, browser type and version, operating system, device identifiers, screen resolution
- Usage Data -- pages visited, products viewed, search queries, click patterns, time spent on pages, referring URLs
- Location Data -- approximate location derived from IP address; precise GPS location only with your explicit consent for delivery services
- Performance Data -- error logs, loading times, feature interactions
1.3 Information from Third Parties
- Payment confirmation from Mobile Money providers (MTN MoMo, Airtel Money)
- Delivery status from logistics partners
- Fraud prevention data from security service providers
2. How We Use Your Information
We process your personal data for the following purposes:
2.1 Service Delivery
- Creating, managing, and securing your account
- Processing orders, payments, refunds, and returns
- Coordinating delivery and logistics
- Operating the loyalty points programme and applying earned rewards
- Facilitating communication between buyers and sellers
2.2 Platform Improvement
- Analysing usage patterns to improve user experience and interface design
- Personalising product recommendations and search results
- Developing new features, products, and services
- Conducting analytics, research, and benchmarking
2.3 Marketing & Communication
- Sending order confirmations, shipping updates, and receipts (transactional)
- Sending promotional offers, flash sale alerts, and personalised recommendations (with your consent)
- Displaying targeted advertisements on our platform
2.4 Safety & Compliance
- Preventing, detecting, and investigating fraud, abuse, or security incidents
- Verifying vendor identities and ensuring product compliance
- Complying with applicable laws, regulations, court orders, and government requests
- Enforcing our Terms of Service and protecting the rights and safety of SixStores, our users, and the public
3. Legal Basis for Processing
Under the Data Protection and Privacy Act, 2019, we process your data on the following lawful bases:
| Basis | Applies To |
|---|---|
| Contractual necessity | Order processing, account management, delivery coordination |
| Consent | Marketing emails/SMS, location tracking, non-essential cookies |
| Legitimate interest | Fraud prevention, analytics, platform security, product recommendations |
| Legal obligation | Tax records, regulatory reporting, law enforcement cooperation |
5. Data Security
We implement industry-standard technical and organisational measures to safeguard your data:
- TLS/SSL encryption for all data in transit
- AES-256 encryption for sensitive data at rest
- Password hashing using bcrypt with salting
- Row Level Security (RLS) on database tables to ensure data isolation
- Regular security audits, penetration testing, and vulnerability assessments
- Restricted employee access on a need-to-know basis with audit logging
- Automatic session expiry and suspicious activity detection
Disclaimer: While we employ commercially reasonable measures, no method of electronic storage or transmission is 100% secure. SixStores shall not be held liable for any unauthorised access resulting from factors beyond our reasonable control, including but not limited to user negligence in safeguarding account credentials.
7. Data Retention
- Account data -- retained for the duration of your account plus 3 years after deletion
- Transaction records -- retained for 7 years as required by Uganda Revenue Authority regulations
- Communications -- retained for 2 years for dispute resolution and quality assurance
- Analytics data -- retained in anonymised form indefinitely
- Marketing preferences -- retained until you withdraw consent
After the applicable retention period, data is securely deleted or irreversibly anonymised.
8. Your Rights
Under the Data Protection and Privacy Act, 2019, you have the following rights:
- Access -- request a copy of the personal data we hold about you
- Rectification -- request correction of inaccurate or incomplete data
- Erasure -- request deletion of your data, subject to legal retention obligations
- Restriction -- request we limit processing in certain circumstances
- Objection -- object to processing based on legitimate interest
- Portability -- receive your data in a structured, machine-readable format
- Withdraw consent -- withdraw previously given consent at any time
To exercise any right, email privacy@sixstores.ug. We will respond within 30 days. We may request identity verification before processing your request. Requests that are manifestly unfounded, excessive, or repetitive may be subject to a reasonable administrative fee.
If you are unsatisfied with our response, you may lodge a complaint with the Personal Data Protection Office (PDPO) of Uganda.
9. Children's Privacy
SixStores is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that a child under 18 has provided us with personal data, we will take steps to delete such information promptly. Parents or guardians who believe their child has provided data may contact us at privacy@sixstores.ug.
10. International Data Transfers
Your data is primarily stored on servers located outside Uganda (cloud infrastructure). Where data is transferred internationally, we ensure adequate safeguards including contractual clauses, encryption, and compliance with the Data Protection and Privacy Act, 2019. By using SixStores, you acknowledge and consent to the transfer of your data outside Uganda for processing and storage.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email, in-app notification, or a prominent banner on the platform. Your continued use of SixStores after any changes constitutes acceptance of the revised policy. We encourage you to review this page periodically.
12. Contact Us
For any questions, concerns, or requests regarding this Privacy Policy or your personal data:
SixStores Limited
Data Protection Officer
privacy@sixstores.ugGeneral Support
support@sixstores.comPhone
+256 789 700 060Address
Kampala Road, Kampala, Uganda