Privacy Policy
Last updated: 27 March 2026
Your privacy matters to us. This policy explains what data we collect, why we collect it, and how we use and protect it when you shop or sell on Merchant.
Overview
Merchant (Pvt) Ltd (“Merchant”, “we”, “us”, or “our”) operates the marketplace at merchant.co.zw. This Privacy Policy describes how we collect, use, and protect your personal data.
By using our platform, you consent to the practices described here. If you do not agree, please stop using the platform and contact us to request deletion of your data.
Data We Collect
2.1 Information You Provide
- Full name or business name
- Email address and phone number
- National ID, passport, or business registration documents (sellers)
- Business address and pickup locations (sellers)
- Bank or mobile money account details for payouts (sellers)
- Delivery addresses (buyers)
- Product listings — names, descriptions, pricing, images (sellers)
- Messages sent to our support team
2.2 Information Collected Automatically
- IP address and approximate geographic location
- Browser type, device type, and operating system
- Pages visited, features used, and session duration
- Login timestamps
- Error logs and diagnostic data
2.3 Information from Third Parties
- Authentication data from Firebase (Google Sign-In, email/password)
- Payment confirmation data from EcoCash and banking partners
- Identity verification results from document review
How We Use Your Data
We use the data we collect for the following purposes:
To register accounts, verify identities, process seller approvals, and deliver platform features.
To facilitate sales, manage orders, process customer payments, and credit seller earnings.
To verify payout details and transfer seller balances to linked EcoCash or bank accounts.
To send account notifications, order updates, policy changes, and support responses.
To detect and prevent fraud, abuse, and Terms violations.
To comply with Zimbabwean law, including ZIMRA obligations and AML regulations.
To analyse usage patterns and improve platform features and performance.
Sharing Your Data
We do not sell your personal data. We may share it with:
- Payment processors (EcoCash, banking partners) — to process transactions and payouts.
- Identity verification providers — to confirm seller identities during onboarding.
- Cloud infrastructure (DigitalOcean) — to host the platform and store data securely.
- Analytics tools — aggregate, anonymised usage data only.
- Law enforcement or regulators — where required by Zimbabwean law or court order.
- Acquiring businesses — in the event of a merger or acquisition, with prior notice to you.
Buyers see seller store names, logos, and product details. Personal contact details and payout account information are never visible to customers.
Payment & Financial Data
Payout account details (EcoCash number, bank account) are stored encrypted and used solely for withdrawals you initiate. We never store mobile money PINs or full card numbers.
All financial transaction logs are retained for a minimum of seven (7) years as required by Zimbabwean financial regulations.
Never share your EcoCash PIN, bank password, or Merchant password with anyone — including Merchant staff. We will never ask for these.
Data Retention
We retain personal data as long as your account is active, or as required:
- Account data: retained for the lifetime of your account plus 3 years after closure.
- Transaction and financial records: retained for 7 years as required by law.
- Product listings: deleted 30 days after account closure.
- Support communications: retained for 2 years.
- Identity verification documents: retained for 5 years after account closure.
Security
We implement industry-standard security measures including:
- TLS/HTTPS encryption for all data in transit.
- Encryption at rest for sensitive fields (payout details, identity documents).
- Firebase Authentication for secure, token-based login.
- Role-based access controls limiting staff access to personal data.
- Regular security audits and vulnerability assessments.
In the event of a data breach affecting your personal information, we will notify you within 72 hours of becoming aware, as required by applicable law.
Your Rights
Subject to Zimbabwean data protection law, you have the right to:
Request a copy of the personal data we hold about you.
Ask us to correct inaccurate or incomplete data.
Request deletion of your data, subject to legal retention obligations.
Receive your data in a structured, machine-readable format.
Object to processing of your data for marketing purposes.
Withdraw consent at any time where processing is consent-based.
To exercise any right, email privacy@merchant.co.zw. We will respond within 30 days.
Third-Party Services
Our platform integrates with third-party services, each with its own privacy policy:
Children's Privacy
Merchant is not intended for users under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with data, contact us immediately and we will delete it.
Changes to This Policy
We may update this policy periodically. Material changes will be communicated by email and via a platform notice at least 14 days before they take effect. Continued use of the platform after that date constitutes acceptance.
Contact Us
For questions, concerns, or data requests, contact our Data Protection Officer:
Merchant (Pvt) Ltd — Data Protection
Harare, Zimbabwe
Privacy: privacy@merchant.co.zw
Support: support@merchant.co.zw
Website: merchant.co.zw
© 2026 Merchant (Pvt) Ltd. All rights reserved.