Data Protection Policy
Last updated: 1 January 2025
This policy sets out how DashDrop Ventures collects, processes, stores, and protects personal data in compliance with applicable data protection laws, including the Kenya Data Protection Act.
Account & Data Deletion
How to delete your account in the app
You can delete your account directly inside the Dashdrop app at any time:
- Open the Dashdrop app and log in.
- Tap your profile icon at the top of the screen.
- Scroll down to Account Settings and tap Delete Account.
- Confirm your choice when prompted. You will receive an email acknowledging your request.
Alternative: request via email
If you are unable to access the in-app option, email privacy@dashdrop.ke with the subject line "Account Deletion Request" and include your registered email address or phone number. We will process your request within the same timelines below.
What is deleted
When your account is deleted, the following data is permanently removed:
- ✓Account profile — name, email address, phone number, and profile photo
- ✓Saved delivery addresses
- ✓Saved payment methods and wallet balance (any remaining balance is refunded)
- ✓Active and pending orders (cancelled automatically)
- ✓Push notification tokens and device identifiers
- ✓Marketing preferences and consent records
- ✓In-app messages and chat history with riders
What is retained and why
Certain records must be kept after deletion to meet legal obligations:
Processing timeline
1. Data controller
DashDrop Ventures is the data controller for all personal data processed through our platform. Our Data Protection Officer can be reached at privacy@dashdrop.ke.
2. Lawful basis for processing
We process personal data on the following lawful bases:
- ·Contract performance — to fulfil your orders and operate your account
- ·Legitimate interests — to improve our service and prevent fraud
- ·Legal obligation — to comply with financial, tax, and regulatory requirements
- ·Consent — for optional communications such as marketing emails
3. Data security measures
We implement appropriate technical and organisational measures to protect personal data, including:
- ·Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
- ·Access controls — only staff with a business need can access personal data
- ·Regular security audits and penetration testing
- ·Incident response procedures — we will notify affected users and regulators within 72 hours of a confirmed breach
- ·Staff training on data protection obligations
4. Data processors
We use third-party processors (cloud hosting, payment gateways, SMS providers) under data processing agreements that require them to protect data to the same standard we apply. A current list of processors is available on request from privacy@dashdrop.ke.
5. International transfers
Some of our processors operate outside Kenya. Where data is transferred internationally, we ensure appropriate safeguards are in place, including contractual clauses that meet applicable data protection standards.
6. Retention schedule
7. Your rights
For details of your data subject rights and how to exercise them, see our Privacy Policy — Section 7.
8. Policy review
This policy is reviewed annually or whenever there is a material change to our processing activities. Contact privacy@dashdrop.ke for any data protection queries.