Privacy Policy

Effective Date: 10th October 2025

RefHub (“we”, “us”, “our”) is committed to protecting your privacy. This Privacy Policy describes how we collect, use, disclose, and safeguard your personal data when you visit our website refhub.co.ke (the “Site”) and use our services (e.g. browsing, purchasing, contacting us, subscribing).

1. Interpretation & Definitions

Data Subject
A natural person who can be identified, directly or indirectly, by reference to data such as name, email address, phone number, etc.

Personal Data
Any information that relates to an identified or identifiable individual. Examples include name, email address, telephone number, IP address, etc.

Processing
Any operation performed on personal data — collection, recording, storing, use, disclosure, deletion, etc.

Controller / Data Controller
RefHub, as the entity determining how and why personal data is processed.

Processor / Data Processor
Any third party that processes personal data on our behalf (e.g. email service provider, hosting provider).

Website / Site
The online platform at https://refhub.co.ke/ and its associated subpages.

2. Legal Basis for Processing

Under Kenya’s Data Protection Act, 2019 (DPA) and other applicable laws, we rely on one or more of the following legal bases to process personal data:

  • Consent: You give us permission (e.g. when you fill a contact form or subscribe).

  • Contractual necessity: Processing is required to fulfill a contract (e.g. ordering, delivery).

  • Legal obligation: Complying with a law or regulation.

  • Legitimate interests: We have legitimate business interests (e.g. security, improving our Site), provided these do not override your rights.

3. What Data We Collect

We may collect the following categories of personal data:

a) Information You Provide Directly

  • Name

  • Email address

  • Phone number

  • Postal address

  • Payment or billing information

  • Other optional fields you supply (e.g. company name, message)

b) Automatically Collected Data

  • IP address

  • Device information (browser type, operating system)

  • Usage data (pages visited, time spent)

  • Cookies, tracking technologies, analytics data

c) Third-Party Data

  • Data from payment processors (e.g. via WooCommerce)

  • Data from analytics/advertising providers (if used)

4. How We Use Your Data

We use your data for the following purposes:

  • To provide, operate, and maintain the Site

  • To process and fulfill orders, payments, and invoices

  • To respond to your inquiries, requests, or support issues

  • To send transactional emails (order confirmations, shipping notices)

  • To send promotional or marketing communications (if you opt in)

  • To improve our Site, products, and services

  • To detect, prevent, and address technical or security issues

  • To comply with legal or regulatory obligations

5. Cookies & Tracking Technologies

We use cookies and similar technologies to enhance user experience, analyze usage, and deliver targeted content. By using our Site, you consent to the use of cookies unless disabled in your browser.

You may refuse or disable cookies via your browser settings. However, some features of the Site may not function properly if cookies are disabled.

We also comply with Kenya’s Data Protection Act guidelines that using cookies or similar technologies requires explicit, informed, and freely given consent.

6. Disclosure of Your Data

We may share your data with:

  • Service providers / processors (e.g. hosting, email, payment gateways)

  • Business partners (for joint offerings, only with consent)

  • Legal & regulatory authorities (if required by law)

  • Successors or assignees (if the business is sold or merged)

We require that third parties protect data securely and only use it for our agreed purposes.

7. Data Retention

We keep your personal data only as long as necessary for the purposes for which it was collected (e.g. to fulfill orders, maintain accounts, comply with legal obligations). When no longer needed, data will be securely deleted or anonymized.

8. Security Measures

We adopt appropriate technical and organizational measures to protect personal data against unauthorized access, loss, alteration, or destruction. These may include encryption, secure servers, access controls, regular audits, and staff training.

While we strive to protect your data, no transmission over the internet or storage is 100% secure. We cannot guarantee absolute security.

9. Your Rights as a Data Subject

Under the DPA (and relevant principles), you have rights including:

  • Right to be informed — about how we collect and use data

  • Right of access — to see what personal data we hold

  • Right to rectification — to correct inaccurate or incomplete data

  • Right to erasure — to request deletion under certain conditions

  • Right to restrict processing — in certain cases

  • Right to object — to processing based on legitimate interests or direct marketing

  • Right to data portability — to obtain your data in a machine-readable format

  • Right to withdraw consent — where processing is based on consent

To exercise these rights, please contact us via the contact information below.

10. Children’s Data

Our Site is not intended for children under 18. If you believe we have collected data from a minor without parental consent, please contact us and we will delete it.

11. International Transfers

If your data is transferred outside Kenya (e.g. to servers in other countries), we ensure that such transfers are done in compliance with applicable law (using standard contractual clauses or adequate safeguards) or with your consent.

12. Changes to This Privacy Policy

We may update this Privacy Policy periodically. The “Effective Date” at the top will reflect the last revision. We encourage you to review this page to stay informed about how we process your data.

13. How to Contact Us

If you have questions, requests, or complaints regarding this Privacy Policy or how we process personal data, you may contact:

RefHub
Email: info@refhub.co.ke

You also have the right to lodge a complaint with Kenya’s Office of the Data Protection Commissioner (ODPC).

Subscribe to our newsletter