TAG Market
TAG MARKET.

Legal

Privacy Policy

Transparency about what data Tag Market West Africa Limited collects, why, and how long it is kept. Nothing hidden, no marketing surprises.

1. Introduction

Tag Market West Africa Limited ('we', 'us', or 'our') respects your privacy. This Privacy Policy explains what personal information we collect, why we collect it, how we use it, who we share it with, how long we keep it, and the choices and rights you have regarding your data.

This policy applies whenever you visit our website, create or view a cart, authenticate, place an order, use your customer dashboard, or otherwise interact with our services (collectively, the 'Services'). By using our Services, you acknowledge that you have read and understood this policy.

Tag Market West Africa Limited is a company registered in Cote d'Ivoire (Ivory Coast), West Africa, and is the data controller responsible for your personal information in connection with the Services.

2. Who We Are and How the Service Operates

We operate TAG Market, an e-commerce platform for premium Kenyan tea sourced from Kericho and the Great Rift Valley highlands. Our company registration and principal jurisdiction for data protection purposes is Cote d'Ivoire.

Our technical architecture consists of three layers. First, the customer-facing web frontend is a Next.js (App Router) application deployed to Cloudflare Pages via the OpenNext adapter, served from Cloudflare's US-based edge and content delivery network. Second, our backend API is a Go application (Fiber framework, code in the 'e-backend' repository) hosted on Railway in the United States (US region). Third, our primary relational database, Redis caches, and Cloudflare R2 object storage bucket are all hosted and operated from infrastructure located in the United States. As a result, any personal information you submit will be transferred to and processed on servers located in the United States.

Client-side state such as cart items, locale preferences, and session data is managed in the browser using TanStack React Query and Zustand, with persistence only in your browser's local storage for the specific keys described later in this policy.

3. Categories of Personal Information We Collect

We collect only the information reasonably necessary to operate our tea shop and deliver your orders. This includes the following categories, depending on how you interact with us:

3.1 Information Collected When You Browse (No Account Required)

Cart token: When you first visit TAG Market, we generate a cryptographically random UUID and store it in your browser's localStorage under the key 'cart_token'. This token is sent as the HTTP header 'X-Cart-Token' with every cart-related API request so our backend can associate your cart items with your browsing session. The token contains no personal data; it is simply a random identifier. The backend correlates this token with a row in our cart_sessions table (which links to your authenticated user record if and when you sign in). You can delete the token at any time by clearing your browser's local storage or using the 'clear cart' function in the app.

Locale preferences: Our locale popup prompts you to confirm your country and preferred language. Your selection (country code, country name, flag, language code, and a 'confirmed' flag) is stored in localStorage under the key 'user_locale' using Zustand's persist middleware. Your country and language choice are also sent with every API request via the HTTP headers 'X-Country' and 'X-Language'. We use this data to: (a) look up product prices in the local currency associated with your country (KES, NGN, GHS, ZAR, XOF, or USD fallback) using live rates from Open Exchange Rates; (b) serve the UI in your preferred language if a translation is available (English, French, Portuguese, Arabic, Spanish) via our translation service and database table; and (c) pre-set the default country in address autocomplete and phone number inputs during checkout.

Search queries: When you type into our product search bar (desktop or mobile), your search query is debounced (typically 300 milliseconds) and sent to our /api/v1/products/search endpoint, along with any active category filter and an optional limit parameter (up to 8 results for the dropdown or 50 for the products listing page). Search queries are processed in real time against our product search index to return matching teas from our catalog; they are not used to build advertising profiles.

React Query cache: Product data, categories, tags, and cart state are cached in browser memory via the TanStack React Query library ('@tanstack/react-query'). The auth session is cached under the query key 'auth, user' with a stale time of 5 minutes. This cache improves page load speed and minimizes redundant network calls. It does not persist across browser restarts beyond what localStorage explicitly stores (described above).

3.2 Information Collected When You Authenticate

We offer passwordless authentication through two optional methods, both tied to your email address. Authentication is not required to browse, build a cart, or reach the checkout page. It is required only to view your saved orders in the customer dashboard ('/dashboard/orders') and individual order details at '/orders/[id]'.

Email address: The primary identifier for your user record in our 'users' table. Our users table stores, per row: a UUID primary key, your email address (unique and non-null), optional full_name, optional phone, boolean is_active flag (default true), last_login_at timestamp, and created_at and updated_at timestamps. You provide your email when you request a one-time passcode or a magic link.

One-time passcodes (OTP): If you choose the OTP method at '/auth/otp', our backend generates a short numeric code, emails it to you via Resend using our MAIL_FROM_AUTH sender address, and stores a record in our 'otps' database table with columns for email, the code itself, a boolean 'used' flag (default false), an integer 'attempts' counter (default 0), an expiry timestamp, and creation time. Codes are short-lived and single-use; on successful verification the OTP row is marked used and its attempts counter stops incrementing.

Magic links: If you choose the magic link method at '/auth/magic-link', our backend generates a single-use signed token, stores the token (unique), email, 'used' flag, and expiry timestamp in our 'magic_links' database table, and emails you a link of the form '/auth/verify?token=...'. Clicking the link (or copying it into your browser) verifies your identity, marks the token row as used, and signs you in. Tokens expire after one successful use or after a short time window.

Authenticated user data and JWTs: On successful verification of OTP or magic link, our backend issues two signed JWT tokens: (a) an access token signed with HS256, with 15-minute expiry, carrying claims for user_id, email, session_id, a unique jti, issued-at timestamp, and issuer 'e-backend'; and (b) a refresh token with 7-day expiry. Refresh tokens are stored in our Redis instance keyed by session, not written to JavaScript-accessible browser storage. We store the user object (email address, user ID, and any profile metadata we hold) in React Query's cache under the query key 'auth, user' with a 5-minute stale time.

Initials derived from email: In the desktop navigation bar and mobile sheet, we display an avatar with a single-letter initial derived from the portion of your email address before the '@' symbol. This is computed locally in your browser using a simple string slice; the initial is not stored as a separate field on our servers.

3.3 Authentication Security Logs

Every authentication event is written to our 'auth_logs' database table for security auditing, abuse detection, and customer support. Each auth_logs row contains the following columns: a UUID primary key; email; event name (examples: otp.request, otp.verify, magic-link.request, magic-link.verify, refresh, logout); method string; ip_address text; user_agent text; a boolean success flag (default false); a JSONB 'metadata' field for extra structured context; and a created_at timestamp. We maintain database indexes on email, event, and created_at to support security searches and time-windowed queries.

Rows in auth_logs are written regardless of whether the authentication event succeeded, so that we can detect and block brute-force or credential-stuffing attempts against specific email addresses or IP ranges.

3.4 Information Collected at Checkout

When you place an order via '/checkout', our form (validated using the Zod schema library and re-validated server-side) collects and submits the following fields over HTTPS to our /api/v1/checkout endpoint:

Email address, used for payment confirmations, delivery updates, and to associate the order with your account if you later authenticate using the same email.

Recipient name (full name of the person who will receive the delivery). Printed on shipping labels and shared with the courier.

Phone number, required for delivery coordination (courier calls, SMS handoff notices, or address clarification). We validate the format using the 'react-phone-number-input' library and mark the field invalid for impossible numbers in the selected country's numbering plan.

Delivery address (full physical address) plus optional city field. As you type, partial address strings (debounced at 400 ms) are sent to our /api/v1/checkout/address-autocomplete endpoint, which forwards the query plus country='KE' by default to LocationIQ (our geocoding provider). Autocomplete results are LocationIQ display_name strings; the full address you ultimately submit is saved on your order row.

Delivery method, constrained by our database CHECK constraint to either 'pickup' or 'delivery'. If delivery is chosen, the database further enforces that address and phone are non-null.

Order notes (optional), free-form text for delivery instructions, gift messages, gate codes, or other special requests. Do not include sensitive personal, medical, or financial information in this field. Order notes are stored as plain TEXT on your 'orders' row and displayed to our operations and support staff in the admin order details view.

3.5 Payment Information and Transaction Records

Payments are processed exclusively by Paystack, our PCI-DSS Level 1 certified payment processor. We never see, collect, or store your full card number, CVV, card expiry, or PIN. The entire payment entry form is hosted on Paystack's servers and displayed in a redirect flow: after submitting our checkout form, your browser is redirected to a 'payment_url' returned by Paystack, and Paystack sends the outcome back to us via a signed webhook to /api/v1/checkout/webhook.

What we do receive from Paystack and store in our 'payment_transactions' table: a Paystack transaction 'reference' (unique per attempt), the email address the payer entered, the amount charged in both USD (amount_usd) and Kenyan shillings (amount_kes), the settlement 'currency' code, a payment_status enum value (initiated, success, failed, or abandoned), an optional order_id foreign key linking to the order (set to NULL on orphaned or abandoned attempts), and a raw_payload JSONB column containing the full signed webhook event body for audit and reconciliation. The raw_payload field may include, per Paystack's webhook format, values such as the last 4 digits of the card, card brand mask, gateway response messages, and Paystack customer code. We do not store full PANs or CVV values; those fields never reach our servers.

The footer of our checkout page displays the notice 'Payments secured by Paystack. We never store card details.' to surface this practice directly to you during the checkout flow.

3.6 Orders Table and Order Items

Each successfully paid order creates a row in our 'orders' table with the following data: a UUID primary key; user_id foreign key to the users table (always set, because checkout first looks up or creates a user by email); order_status enum (pending, confirmed, shipped, delivered, cancelled); total_amount as numeric; optional notes TEXT; delivery columns added by our delivery migration (recipient_name, phone, delivery_method, address, city); and created_at and updated_at timestamps.

Individual line items are stored in our 'order_items' table, one row per product variant, with columns: UUID primary key; order_id foreign key; product_variant_id foreign key; denormalized product_name and variant_name TEXT; sku TEXT; quantity integer with CHECK (quantity > 0); unit_price and total_price numerics; and created_at timestamp. Product names and variant names are snapshotted at the time of order so they remain accurate even if catalog metadata changes later.

3.7 Order History and Authenticated Dashboard

If you authenticate (per Section 3.2) using the same email address you used at checkout, you can view all orders associated with that user_id by visiting '/dashboard/orders' and individual order details at '/orders/[id]'. Our admin dashboard endpoints (protected by both Protected and AdminOnly middleware) expose aggregated data for internal staff only, including revenue KPIs, revenue over time, order status breakdowns, delivery method breakdowns, orders requiring attention, payment funnel status, payment success rate, currency volume, abandoned payments, top products, and top variants by SKU. All dashboard values are computed by analytics SQL queries from the orders, payment_transactions, and order_items tables; they are stored only in query response and not written to a separate analytics table of personal data.

You can sign out at any time using the dropdown in the desktop header or the mobile sheet. Signing out calls our backend /api/v1/auth/logout endpoint, which invalidates the refresh token in Redis, clears React Query's 'auth, user' cache entry, clears all cached queries locally, and redirects you to '/auth'.

3.8 Server-Side Request Logging (Axiom)

Every HTTP request to our backend API passes through a request-logging middleware. The middleware records a structured JSON event for each request and forwards it in batches to Axiom, our observability and log analytics provider (configured via Axiom token and dataset environment variables). Each log line contains: a randomly generated request UUID (returned to you in the 'X-Request-ID' response header for correlation), HTTP method, path, response status code, elapsed duration in milliseconds, the client IP address as extracted by Fiber's c.IP() helper, and the request User-Agent header string.

These logs are used for debugging, performance monitoring, rate-limit tuning, DDoS detection, abuse investigation, and general site reliability engineering. They are not used for advertising or third-party marketing. Axiom retains logs according to our configured retention window, after which they are purged.

3.9 Object Storage and Product Assets

Product images uploaded by our admin team are stored in Cloudflare R2 object storage (R2_ACCOUNT_ID, R2_ACCESS_KEY_ID, R2_SECRET_KEY, R2_BUCKET, and R2PublicURL are configured in the backend). R2 objects are served through the configured R2PublicURL domain, which goes through Cloudflare's CDN for caching and delivery. Product image uploads go through the protected /api/v1/admin/upload endpoint (AdminOnly middleware) and do not accept end-user uploads.

The website also ships with static public assets (favicon, homepage hero, category hero images: home-page-tea.jpg, tea-farm.jpg, tea-fruit.jpg, tea-herbs.jpg, tea-steam.jpg, logo.jpeg) served locally from our frontend deployment's public folder on Cloudflare Pages. No personal data is embedded in these static assets.

4. Why We Use Your Information (Legal Bases)

We process your personal information only where we have a valid legal basis under applicable Ivorian (Cote d'Ivoire) and African data protection laws, including but not limited to the Ivorian Law No. 2013-456 of March 19, 2013 on the Protection of Personal Data, the African Union Convention on Cyber Security and Personal Data Protection, and national laws of the countries to which we ship. The primary bases are:

Contract performance: Processing your checkout data (name, address, phone, email, payment status) is necessary to execute the sales contract between you and Tag Market West Africa Limited, i.e., to accept your order, charge payment, dispatch tea, and deliver it to the correct address. This also covers sharing delivery data with couriers and passing the minimum required fields to Paystack for payment execution.

Legitimate interests: We rely on legitimate interests to: (a) remember your cart across page loads via the cart token; (b) show local currency and correct UI language based on your locale selection; (c) display relevant product search results; (d) write auth_logs and Axiom request logs to prevent fraud, abuse, and security incidents; (e) cache product, currency, and search results in Redis to keep the site responsive; and (f) send essential transactional messages (order confirmations via MAIL_FROM_ORDERS, dispatch notices, delivery updates, and passwordless authentication emails via MAIL_FROM_AUTH). Where we rely on legitimate interests, we conduct a balancing test and will only process where our interests do not override your rights and freedoms.

Consent: Where required by law (for example, if you subscribe to a marketing newsletter in the future, or where a cookie banner is triggered for optional analytics), we obtain your explicit, freely-given opt-in consent. You can withdraw consent at any time by contacting us or using the mechanism provided (for example, clearing your browser storage).

Legal obligation: We may retain or disclose information as required by court order, Ivorian tax law, Direction Generale des Impots requirements, customs declaration rules applicable to your destination country, or other binding legal process served on Tag Market West Africa Limited.

5. Who We Share Your Information With

We do not sell, rent, or trade your personal information to third parties for their own commercial or marketing purposes. We share data only with the following categories of recipients, strictly on a need-to-know basis and subject to appropriate data protection safeguards (contractual clauses, data processing addenda, industry certifications, or binding intra-group agreements):

Payment processor (Paystack): We share your email, order total, order reference, currency, and callback URL so Paystack can display and process your payment. Paystack returns a signed webhook with transaction status. Paystack's handling of your payment data is governed by Paystack's own Privacy Policy and its PCI-DSS obligations.

Courier and logistics partners: To deliver your tea, we share the recipient name, phone number, delivery address, city, and package weight or value with the courier or last-mile delivery provider responsible for your region. Each courier is contractually required to use this information only to complete and confirm the delivery, and to delete or return it after retention windows defined in our agreements.

Geocoding provider (LocationIQ): Partial address queries typed during checkout are forwarded by our backend to LocationIQ along with country='KE' (by default) to return address display_name suggestions for the autocomplete popover. LocationIQ's handling of those queries is governed by LocationIQ's Privacy Policy.

Transactional email provider (Resend): OTP emails, magic links, order confirmations, dispatch alerts, and support replies are sent via the Resend API using our configured sender addresses (MAIL_FROM_AUTH, MAIL_FROM_ORDERS, MAIL_FROM_SUPPORT, all set via environment). Resend sees your email address and the rendered email body. Resend is contractually prohibited from using your email address for its own marketing, and Resend's published privacy policy governs its processing.

Observability and logging provider (Axiom): Per Section 3.8, every request log (with request UUID, HTTP method, path, status, duration, IP, and User-Agent) is streamed to Axiom for retention and query. Axiom is a US-based observability platform; we configure dataset retention through the Axiom dashboard. Axiom's processing is covered by our data processing agreement with them.

Currency data provider (Open Exchange Rates): To convert product prices and checkout totals between USD and local African currencies, our currency service pulls live rates from the Open Exchange Rates API at the interval configured by the OpenExchangeRatesAppID credential. No personal data is included in those rate requests; they contain only the app ID credential and base currency parameters.

Infrastructure providers: Our backend Go API runs on Railway (US region), our relational database is the managed Postgres instance exposed to our backend through BLUEPRINT_DB_HOST, BLUEPRINT_DB_PORT, BLUEPRINT_DB_DATABASE credentials, our session and cache Redis instance is configured via REDIS_URL, and product images and Next.js incremental cache are stored on Cloudflare R2 and Cloudflare Pages. All of these providers process data only on our instructions and as necessary to host the Services. They do not access personal data for their own independent commercial purposes.

Internal authorized personnel: Access to customer data within Tag Market West Africa Limited is restricted on a strict need-to-know basis: customer support staff for order assistance and refund processing, operations staff for dispatch and courier coordination, and finance or admin staff for reconciliation, tax reporting, and admin dashboard use. Access to admin routes is enforced by the AdminOnly middleware check against user roles stored in the database.

Regulators and law enforcement: We will disclose information where required by a valid court order, warrant, or binding request from a competent Ivorian or regional authority (examples: the Ivorian data protection authority, tax authority, customs administration, or national law enforcement), or where we in good faith believe disclosure is necessary to protect the safety, rights, or property of Tag Market West Africa Limited, our staff, customers, or the public.

Business transfers: In the event of a merger, acquisition, reorganization, insolvency, or sale of all or part of our business or assets, customer information (including order history, email, delivery details, and payment references) may be among the assets transferred. We will notify you by prominent website notice or email of any such change in ownership or control.

6. Cross-Border Data Transfers

Because Tag Market West Africa Limited is registered in Cote d'Ivoire and ships to 50+ African countries, and because our infrastructure providers (Railway, Cloudflare, Axiom, LocationIQ, Paystack, Open Exchange Rates, Resend) maintain data centers around the world, your personal information may be transferred to, stored in, and processed in jurisdictions outside your country of residence, including without limitation Cote d'Ivoire, Nigeria, South Africa, Kenya, the United States of America, Singapore, the United Kingdom, and European Economic Area member states, depending on the Cloudflare edge node, Railway region, and provider data center selected automatically for your request.

Whenever we transfer personal data across borders from Cote d'Ivoire or any other jurisdiction whose law requires a transfer safeguard, we rely on one or more of the following mechanisms: (a) an adequacy decision or equivalent finding issued by the Ivorian data protection authority or the equivalent authority in your jurisdiction; (b) standard contractual clauses or model clauses approved by the relevant data protection authority, incorporated into our agreements with sub-processors; (c) binding intra-group data transfer agreements if processing crosses entities within our group; or (d) your explicit informed consent, obtained where required before transfer.

By using our Services and voluntarily submitting your personal data through the website or checkout flow, you acknowledge that your data may be transferred internationally as described above.

7. How Long We Keep Your Information

We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, or as required by applicable law, tax regulations, or record-keeping obligations. The specific retention periods we apply:

Cart token (client side): Kept in your browser's localStorage until you clear storage or it expires naturally. The backend copy in the cart_sessions and related cart tables is retained for a maximum of 30 days of inactivity before being anonymized or purged by our maintenance jobs.

Locale preferences (user_locale): Retained in localStorage until you clear storage or select a different country or language. If you never confirm the locale popup, the values are stored with 'confirmed: false' and may be re-prompted on your next visit.

Authenticated user account record (users table row): Retained for the lifetime of your account plus a reasonable wind-down period after account deletion or a valid request to delete. Deletion is subject to the carve-outs in the next paragraph for tax and legal records.

Orders table, order_items, and associated delivery fields (recipient_name, phone, address, city, notes): Retained for a minimum of 7 years from the date of the last transaction or financial close associated with the order, as consistent with Ivorian commercial record-keeping requirements, Kenyan tax law where goods originate, and general African cross-border audit standards.

Payment_transactions table rows and raw_payload JSONB: Retained for the same 7-year minimum as orders, because Paystack transaction references, statuses, and amounts are required for tax filings, dispute resolution, and financial audits. Where a row has no linked order_id (abandoned or failed checkout), the row is retained for no more than 180 days before being anonymized by nulling email and redacting non-reconciliation fields, or deleted entirely.

OTP and magic_links rows: Deleted or hard-deleted by maintenance jobs no later than 30 days after their expires_at timestamp, because they are single-use tokens with no long-term audit value once expired. Auth_logs are retained for a minimum of 12 months for active security investigations and up to a maximum of 24 months, after which they are aggregated into anonymous event counts (email, IP, and user_agent fields purged) or deleted entirely.

Axiom request logs: Retained in Axiom for a configurable retention window aligned with our security and SRE needs, currently no longer than 90 days for raw per-request events, after which they are either rolled into aggregated anonymous traffic statistics (without IP or user agent strings) or purged.

Order notes (free-form text): Retained for the same period as the rest of the order row. Please do not include highly sensitive information (medical conditions, national ID numbers, financial account details) in order notes; we are not required to retain order notes for any period longer than the order itself and will redact or purge them upon request where legally permissible.

At the end of the applicable retention period, we securely dispose of personal information through permanent database deletion (with corresponding WAL and backup cycle purges where operationally possible), anonymization (such that the data can no longer be linked back to a natural person through reasonable means), or cryptographic erasure of the storage media, whichever is most appropriate given the storage class.

8. How We Protect Your Information

We take the security of your personal information seriously and implement a combination of technical, organizational, and contractual safeguards appropriate to the sensitivity of the data. Specific measures include:

Encryption in transit: All traffic between your browser and TAG Market (frontend on Cloudflare Pages, API calls to our backend), and between TAG Market backend and our service providers (Paystack webhooks, Resend API, LocationIQ API, Axiom ingest, R2 signed URLs, Redis TLS, Postgres TLS) is encrypted using TLS 1.2 or higher. Payment-related redirects always go to HTTPS URLs on Paystack's domain, and our PaystackCallbackURL is configured to an HTTPS endpoint.

Tokenization and secret handling: The JWT secret is loaded from the JWT_SECRET environment variable only on backend startup; it is never logged or serialized into responses. Refresh tokens with durable powers are stored only in Redis and validated by our auth middleware; they are never written to JavaScript-accessible browser storage and cannot be exfiltrated via XSS. Client-side localStorage contains only the cart UUID and locale selection, both of which are non-identifying on their own.

Database integrity: The schema is enforced at the SQL level by PostgreSQL CHECK constraints (delivery_method in allowed set, quantity > 0, address required when delivery_method = delivery), UNIQUE constraints on email in users and reference in payment_transactions, and ON DELETE CASCADE or RESTRICT foreign keys as appropriate. Admin-only routes are gated by a layered middleware stack: CORS with explicit AllowedOrigins, then request logging, then locale extraction, then the Protected middleware (validating access token signature, session_id, and Redis refresh existence), then AdminOnly middleware checking role from the database.

Form validation and sanitization: All user-submitted fields (email, phone, address, notes, search queries, category and tag slugs) are validated client-side using Zod schemas and re-validated server-side through handler code and database constraints before being written. Order notes, product descriptions, and user-displayable strings are rendered as plain text in the UI, never as unescaped HTML, to prevent injection attacks.

Debounced autocomplete and search: Address and product search queries are debounced on the client (300 to 400 milliseconds) to avoid unnecessarily transmitting large numbers of partial keystrokes to our backend.

Internal access control: Access to customer data within Tag Market West Africa Limited is restricted to authorized personnel on a role-based, need-to-know basis. Admin dashboard access requires both a valid authenticated session and the admin-only role check. Staff actions on orders (status updates, refund notes) are traceable in application logs. Backend credentials are stored as Railway environment variables and injected at runtime; they are never committed to source control or logged in Axiom.

DDoS and WAF protection: The frontend application is deployed to Cloudflare Pages through the OpenNext adapter, which benefits from Cloudflare's edge DDoS protection, Web Application Firewall (WAF) rules, bot management, and TLS-termination infrastructure. Our backend on Railway sits behind Railway's own network edge protections.

Incident response: No system can guarantee absolute security. If we become aware of a security incident that affects your personal data, we will: (a) contain and investigate the incident; (b) notify you without undue delay where required by law (generally within 72 hours of becoming aware of a notifiable breach); and (c) notify the Ivorian data protection authority (and, where required, your local supervisory authority) within the timeframes mandated by applicable law.

9. Cookies and Similar Technologies

Our website uses the following classes of browser storage and cookies. Most are strictly necessary for the Services to function correctly, and are set without a consent banner where permitted by the applicable jurisdiction. Where a consent management banner is required for optional analytics or marketing cookies, it will be presented on your first visit and all choices will be honoured for the lifetime of the consent cookie or localStorage key.

Necessary localStorage keys (set by our frontend JavaScript):

1) cart_token (a UUID v4): remembers your cart across page navigations. Lifetime: persists until you clear browser storage or generate a new one by clearing your cart manually.

2) user_locale (a JSON object carrying country, language, confirmed flag): remembers your selected country, language, and popup confirmation state. Lifetime: persists until you clear storage or change settings through the popup.

3) zustand and React Query data in memory: product and auth caches live only in the current tab's memory; they are cleared on page reload unless explicitly persisted through one of the two named localStorage keys above.

Necessary cookies set by backend or infrastructure:

1) Fiber session or temporary cookies if the framework issues them during authentication flow; any such cookie is marked Secure and HttpOnly where applicable, and carries only an opaque session reference. Lifetime: bounded by authentication token lifetime (access token 15 minutes, refresh token 7 days).

2) Cloudflare edge cookies (examples: __cf_bm, cf_ob_info, cf_use_ob) may be set by Cloudflare's WAF or bot management to distinguish between humans and automated traffic, mitigate DDoS, or enforce challenge pages. These are set by Cloudflare and governed by Cloudflare's Cookie Policy, not ours. We do not read or store their contents.

Paystack and third-party cookies during payment: When you are redirected to Paystack's payment page, Paystack may set its own cookies for fraud detection, session continuity, 3DS verification, and cardholder authentication purposes. Those cookies are governed by Paystack's cookie policy; we do not have visibility into or control over them.

Marketing and analytics third-party cookies: As of the effective date of this policy, Tag Market West Africa Limited does not load third-party marketing analytics (examples: Google Analytics, Meta Pixel, TikTok Pixel) on its public frontend, and does not operate a retargeting or behavioural advertising programme. If this changes, we will update this policy and, where required by law, present a consent banner before loading any such script.

Managing storage: You can view, edit, or clear localStorage and cookies for the TAG Market domain through your browser's developer tools or privacy settings. Clearing may sign you out and reset your cart, but will not affect orders already placed; those remain in our database per the retention schedule in Section 7.

10. Product Search and Internal AI Use (Groq)

Our backend configuration includes a GROQ_API_KEY credential. As of the date of this policy, this credential is reserved for internal or future features such as product search relevance tuning, natural language search query understanding, or catalog enrichment. If and when it is enabled for end-user-facing features, we will describe the specific inputs sent, the processing performed, and any retention, and we will update this policy accordingly.

At the current time, no end-user personal data (email, address, phone, order notes) is included in any inference call to Groq; product search uses database-level search indexes and SQL queries alone.

11. Children's Privacy

TAG Market does not knowingly collect or solicit personal information from children under the age of 18 (or the age of majority in your jurisdiction). Our Services are directed at adult consumers who are legally capable of entering into binding sales contracts. You must be 18 years of age or older to create an authenticated account or place an order.

If you are a parent or guardian and believe that a child under your care has submitted personal information to us, please contact us immediately via the channels listed in Section 17. We will take commercially reasonable steps to delete that information from our active records within 30 days, subject to any legal retention obligations we cannot override (examples: tax or customs records tied to a paid order).

12. Marketing Communications

As of the effective date of this policy, TAG Market does not operate an opt-in newsletter, SMS marketing programme, or loyalty programme, and we do not send promotional emails or SMS to our customers.

We will only ever send you transactional or service-related communications without further consent: order confirmations, dispatch tracking, delivery status updates, replies to support requests (via MAIL_FROM_SUPPORT), passwordless authentication (OTP or magic link emails you explicitly requested via MAIL_FROM_AUTH), and important legal or policy change notifications.

In the future, if we introduce marketing communications (examples: a seasonal tea newsletter, or a Kericho Gold limited-release announcement), we will only send them after obtaining your explicit, documented opt-in, separate from any checkout or authentication flow. Every such message will include clear, one-click unsubscribe instructions and a summary of your right to withdraw consent at any time, exercisable by either the unsubscribe link or a direct request to our support channels.

13. Your Rights Under Data Protection Law

Depending on your jurisdiction, you may hold the following rights with respect to your personal information, in addition to any non-waivable consumer protections under Ivorian or local law. You may exercise any of them at any time by contacting us using the details in Section 17. We will respond to verifiable requests within 30 calendar days, extendable by a further 60 days for complex or high-volume requests, in which case we will notify you of the extension and the reason within the first 30 days.

Right of access: You may request a copy of the personal information we hold about you, including your authenticated user record, order history tied to your email, any data explicitly stored in our payment_transactions table under your email, and details of any third parties to whom your data has been disclosed in the preceding 12 months (to the extent we are able to enumerate them from logs and contracts).

Right to rectification: You may ask us to correct inaccurate, incomplete, or out-of-date personal information, examples: a misspelled recipient name on a pending order, an outdated delivery address before dispatch, an incorrect contact number, or a typo in the optional full_name field of your user record.

Right to erasure (right to be forgotten): You may request deletion of your personal information where one of the following applies: (a) the information is no longer necessary for the purpose it was collected; (b) you withdraw consent on which processing was based; (c) you object to processing and we have no overriding legitimate grounds; (d) we have processed your information unlawfully; or (e) erasure is required to comply with a legal obligation binding on Tag Market West Africa Limited. Exclusions apply, particularly where retention is required by Ivorian or Kenyan tax law, customs records, active anti-fraud investigations, or ongoing dispute resolution with Paystack or a courier.

Right to restrict processing: In certain circumstances (examples: while we verify the accuracy of contested data, while an erasure request is under review, while we verify the legal basis for a disputed processing activity) you may ask us to restrict processing of your data to storage only. Where we grant a restriction, we will mark the applicable rows and notify you before lifting the restriction.

Right to data portability: Where processing is based on consent or contract and is carried out by automated means, you may request that your personal information (examples: order history, contact details, user profile fields) be provided to you in a structured, commonly-used, machine-readable format such as JSON or CSV, or transmitted directly to another controller where technically feasible and not unduly burdensome.

Right to object: Where processing is based on legitimate interests or is for direct marketing purposes (should we ever introduce it), you may object at any time. We will cease processing unless we can demonstrate compelling, legitimate grounds for the processing that override your interests, rights, and freedoms, or unless we need to continue processing for the establishment, exercise, or defence of legal claims.

Right to withdraw consent: Where we have relied on your consent (for example, if you opted in to a future newsletter or gave separate consent for a specific processing), you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal.

Right to lodge a complaint: If you are dissatisfied with how we have handled your personal information or a rights request, you have the right to complain to your national data protection authority. For individuals resident in Cote d'Ivoire this is the national authority responsible for enforcing Law No. 2013-456; for individuals resident elsewhere it is the equivalent supervisory authority in your country of habitual residence or place of the alleged infringement.

Fees and identity verification: We do not charge a fee for the first request of each type in any 12-month period. For manifestly excessive, repetitive, or clearly unfounded requests, we may either charge a reasonable administrative fee reflecting our actual costs, or refuse to act. Before disclosing any personal data in response to a rights request, we will take reasonable steps to verify your identity using at least two identifiers (examples: email plus order number, email plus phone number on file, or email plus authenticated session confirmation) to prevent unauthorized disclosure.

15. Additional Disclosures for California Residents (CCPA/CPRA)

Although TAG Market primarily serves customers on the African continent, if you are a California resident accessing our Services from California while visiting or residing there, the California Consumer Privacy Act (CCPA), as amended by the CPRA, may apply to the limited personal information we collect about you. In that event, the following additional disclosures apply alongside the rest of this policy.

Categories of personal information collected in the preceding 12 months: identifiers (email address, cart UUID, device-level locale selection, user_id if authenticated, session_id, order UUID, transaction reference); commercial information (order history, line items, quantities, SKUs, amounts paid, payment status, Paystack transaction reference, currency of charge); geolocation data (country selected in the locale popup, delivery address and optional city submitted at checkout, plus approximate country derived from IP-based metadata captured in Axiom request logs and auth_logs); internet or other electronic network activity information (product search queries submitted through the search bar, paths visited on our frontend per Axiom request logs, auth events per auth_logs); and, where you choose to provide it, other personal information in free-text order notes.

Categories of sources from which we collect information: directly from you (email, recipient name, phone, address, notes, OTP or magic-link requests, locale selection, order notes); automatically from your device and requests (cart UUID generation on first paint, approximate geolocation for locale detection, IP and User-Agent strings captured by middleware); indirectly from our service providers (Paystack transaction status callbacks with masked card data and last four digits, courier delivery confirmations, Open Exchange Rates currency values with no personal data attached).

Business or commercial purposes for which we collect information: fulfilling orders and processing refunds or replacements; processing payments through Paystack; detecting security incidents, fraud, and abuse; debugging to repair functionality errors; auditing related to a current interaction with you and concurrent transactions; short-term, transient use (cart token across page loads); performing services including customer support, courier coordination, and order tracking; internal research for product assortment and site experience improvement; undertaking activities to verify or maintain the quality or safety of the Services; and complying with legal obligations such as tax, customs, and court-ordered production.

Sale or sharing of personal information: We do not 'sell' personal information as defined under the CCPA, nor do we engage in 'cross-context behavioral advertising' (the definition of 'sharing' under the CPRA) with third parties for our own account. We have not sold or shared the personal information of any consumers in the preceding 12 months.

Disclosures for a business purpose in the preceding 12 months: For each category of personal information listed above, we have disclosed that information to the following categories of recipients for a business purpose, strictly under contract and not for the recipient's own independent secondary use: payment processors (Paystack); logistics and courier providers; geocoding providers (LocationIQ for autocomplete); transactional email providers (Resend); observability and log analytics providers (Axiom); infrastructure, hosting, and storage providers (Railway, Postgres operator, Redis operator, Cloudflare R2 and Cloudflare Pages); and professional advisors (auditors, lawyers) where required in connection with a business purpose.

Retention: As described in Section 7, tailored by category above. You have the right to request, free from discriminatory treatment, access to and deletion of the personal information we hold about you, as well as to correct inaccurate data, to know to whom we have disclosed it for a business purpose in the last 12 months, and to not be discriminated against for exercising your CCPA rights. To exercise these rights, contact us via Section 17 and include 'California Rights Request' in your subject line. We will verify your identity before complying, as required by the CCPA and its implementing regulations.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, new product features, legal obligations, technology, or business structure. Material changes (examples: changes to the categories of data we collect, new third-party disclosures that materially expand sharing, changes to your rights, replacement of major sub-processors) will be indicated by updating the 'Last Updated' date at the end of this policy and, where appropriate, by a more prominent notice on our homepage or via email to customers with active accounts.

We encourage you to review this policy periodically. Your continued use of our Services after the effective date of a revised policy constitutes your acceptance of the changes.

17. How to Contact Us About Privacy

If you have questions, concerns, or complaints about this Privacy Policy or our data practices, or if you wish to exercise any of your individual rights under Section 13 or Section 15, please contact us in writing, marked to the attention of our Data Protection Lead. You can reach us:

Via the 'Contact Us' link in our website footer (when that page goes live; in the interim, via any official social media channel with a follow-up switch to verified email).

By direct message to any of our official social media accounts (Instagram, Twitter/X, Facebook) linked in the footer. Please do not include sensitive personal data in the first message; we will switch to a verified, private channel after acknowledging you.

By email to the support sender identity configured under our MAIL_FROM_SUPPORT Resend sender; for the avoidance of doubt, any valid rights request received at the official support address published on the website at the time of request will be treated as properly submitted.

When contacting us about a data rights request, suspected personal data breach, or privacy incident, please include as much identifying detail as you are comfortable sharing (email address used to place orders, approximate dates of orders, order numbers if available, specific endpoints or events the request concerns) so we can locate your records, scope the request accurately, and verify your identity before disclosing or modifying any information.

We acknowledge and respond to all legitimate inquiries within the timelines prescribed by applicable data protection law.

Last Updated

This Privacy Policy was last updated on August 10, 2026.