Privacy Policy
Last Updated: April 11, 2025
Welcome to Ghana Web Shop! We are committed to protecting your personal data and respecting your privacy rights. This Privacy Policy explains how we collect, process, store, share, and protect your personal data when you visit our website (ghanawebshop.com - *replace if different*), use our services, or make purchases. We adhere to Ghana's Data Protection Act, 2012 (Act 843) and strive to incorporate best practices inspired by international regulations such as the EU General Data Protection Regulation (GDPR).
For the purposes of this policy, Ghana Web Shop is the 'Data Controller'.
Key Definitions
- Personal Data: Any information relating to an identified or identifiable natural person ('Data Subject').
- Processing: Any operation performed on personal data (collection, recording, storage, use, disclosure, erasure, etc.).
- Data Controller: The entity determining the purposes and means of processing personal data (Ghana Web Shop).
- Data Processor: An entity processing personal data on behalf of the controller (e.g., payment providers, delivery companies).
Personal Data We Collect
We collect personal data necessary to provide and improve our services, adhering to the principle of data minimization. This includes:
Data You Provide Directly:
- Account & Contact Information: Name, email address, phone number, shipping/billing address when you register, place an order, or contact us.
- Transaction Information: Details about products purchased, order history (payment details are processed by third parties, see below).
- Communication Data: Records of your correspondence with us (email, chat, contact forms).
Data Collected Automatically:
- Device & Usage Information: IP address, browser type, operating system, device identifiers, pages visited, time spent on site, referring URLs, and interaction data collected via cookies and similar technologies (see 'Cookies' section).
Data from Third Parties:
- Payment Processors: We receive confirmation of payment success/failure from our payment partners (e.g., Paystack, Flutterwave, Mobile Money providers - *be specific if possible*), but not your full sensitive payment details.
Lawful Basis for Processing and Purposes
We process your personal data based on specific lawful grounds and only for the purposes described below:
- Performance of a Contract: To fulfill our contractual obligations when you place an order (e.g., processing payments, delivering goods, handling returns). (Lawful Basis: Contract Necessity)
- Legitimate Interests: To operate and improve our business, provide customer support, personalize your experience, maintain security, prevent fraud, and analyze website performance, provided these interests are not overridden by your fundamental rights and freedoms. (Lawful Basis: Legitimate Interests)
- Consent: For sending direct marketing communications (e.g., newsletters, promotions) or using non-essential cookies. We will always obtain your explicit consent for these activities, and you can withdraw it at any time. (Lawful Basis: Consent)
- Legal Obligation: To comply with applicable laws, regulations, and legal processes in Ghana (e.g., financial record-keeping, responding to lawful requests). (Lawful Basis: Legal Obligation)
Sharing and Disclosure of Personal Data
We respect your privacy and limit the sharing of your personal data.
We do not sell your personal data in the traditional sense. We do not provide your name, phone number, address, email address or other sensitive information to third parties in exchange for money.
We may disclose your data to the following categories of recipients:
- Service Providers (Data Processors): Trusted third-party companies that perform services on our behalf, such as payment processing, delivery logistics, IT hosting, email delivery, marketing assistance, and data analytics. These processors are contractually bound to protect your data and use it only for the tasks we assign.
- Legal Authorities: If required by law, court order, or governmental regulation within Ghana, or if necessary to protect the rights, property, or safety of Ghana Web Shop, our customers, or others.
- Business Transfers: In connection with any merger, sale of company assets, financing, or acquisition of all or a portion of our business by another company, user information may be transferred as a business asset.
International Data Transfers
Some of our service providers may be located outside of Ghana. If we transfer your personal data outside Ghana, we will ensure appropriate safeguards are in place to protect your data, such as using Standard Contractual Clauses approved by relevant authorities or ensuring the recipient country has an adequate level of data protection recognised by Ghana's Data Protection Commission.
Data Security
We implement appropriate technical and organizational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. This includes encryption (SSL/TLS for data in transit), access controls, secure servers, and regular security reviews.
Despite our efforts, no security system is impenetrable. We cannot guarantee the absolute security of your data during transmission or storage.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements. Typically, order information is retained for [Specify Period, e.g., 6 years] to comply with financial regulations, while account information is kept as long as your account is active. Data processed based on consent (like marketing subscriptions) is kept until you withdraw consent.
Your Data Protection Rights
Under Ghana's Data Protection Act and influenced by international standards, you have several rights concerning your personal data. Subject to legal limitations and identity verification, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure ('Right to be Forgotten'): Request deletion of your personal data where it's no longer needed for the original purpose, consent is withdrawn, or processing is unlawful.
- Restriction of Processing: Request limitation of how we process your data under certain circumstances.
- Data Portability: Request your data in a structured, commonly used, machine-readable format, and potentially transfer it to another controller (where processing is based on consent or contract and automated).
- Object: Object to the processing of your data based on legitimate interests or for direct marketing purposes.
- Withdraw Consent: Withdraw your consent at any time where processing relies on consent (this does not affect the lawfulness of processing before withdrawal).
- Lodge a Complaint: File a complaint with Ghana's Data Protection Commission if you believe your rights have been infringed. (www.dataprotection.org.gh)
- Rights Regarding Automated Decision-Making: You have rights related to decisions made solely based on automated processing, including profiling, if they produce legal or similarly significant effects (we currently do not engage in such processing - *adjust if you do*).
To exercise any of these rights, please contact us using the details below. We aim to respond within one month, as required by law.
Cookies and Similar Technologies
Our website uses cookies and similar technologies (like web beacons or pixels). Some are essential for site functionality ('Strictly Necessary'), while others help us analyze usage ('Analytics'), personalize content ('Functional'), or deliver relevant advertising ('Marketing'). We request your consent for non-essential cookies via our cookie banner/management tool. You can adjust your preferences at any time and manage cookies through your browser settings.
Children's Privacy
Our services are not directed at individuals under the age of 16 (or a higher age if required by local law). We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child without verifiable parental consent, we will take steps to delete such information promptly.
Changes to This Privacy Policy
We may update this policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. We will post any changes on this page and update the "Last Updated" date. Significant changes may be communicated more directly if appropriate. Please review this policy regularly.
Contact Us
If you have questions about this Privacy Policy, our data practices, or wish to exercise your data protection rights, please contact us:
Data Privacy Contact: Ghana Web Shop Privacy Team
Email: privacy@ghanawebshop.com (Suggest using a dedicated privacy email)
Or write to us at: [Your Company's Physical Address, Ghana - Optional but good practice]
Please note that this policy provides a general overview and does not constitute legal advice.