All documents

Legal

Privacy Policy

What Kasa does with personal data, who else touches it, how long it is kept, and what you can ask us to do about it.

Version v1.0 · In force from 25 July 2026

1.Who we are

Kasa is a WhatsApp sales assistant for sellers in Ghana. This policy explains what we do with personal data, and it applies to our website, the seller dashboard, and the assistant that answers messages for a shop.

If you have a question about anything here, write to support@kasarm.com and put Data protection in the subject line so it reaches the right person quickly.

2.Two roles, and why the difference matters

Under the Data Protection Act, 2012 (Act 843), whoever decides why personal data is used is the data controller and answers for it. Whoever only handles it on someone else's instructions is the data processor. Kasa is both, in different places.

  • For a seller's own data we are the controller. Your name, your email address, your shop details, your billing records and how you use the dashboard. This policy covers all of it.
  • For a buyer's data we are the seller's processor. When someone messages a shop, that shop decides why the conversation happens and what to do with it. The shop is the controller. We hold and handle that conversation on the shop's instructions and for no purpose of our own. The terms of that arrangement are in the Data Processing Agreement.

In practice: if you are a buyer and you want your chat deleted, the shop you messaged is the one to ask, and we give every shop the tools to do it. If they cannot help, write to us and we will act on the shop's behalf as their processor.

3.What we collect

From sellers

  • Account details: your name, email address, password (stored only as a strong one way hash, never as text we can read), your workspace handle, and the second step of sign in if you switch it on.
  • Shop details: your shop name, your products, prices, photos, delivery areas and charges, your business phone numbers, and the WhatsApp number you connect.
  • Payment details for receiving money: your mobile money number and name, which we store encrypted and show only in a masked form.
  • Billing records: your plan, invoices, payments to us, and the assistant usage counted against your allowance.
  • Support conversations: the requests you send us and our replies.

From buyers, on behalf of the shop they messaged

  • Their WhatsApp number and profile name as the channel provides it.
  • The messages they send and receive, including voice notes, photos and screenshots.
  • Any delivery location or landmark they give.
  • Their orders with that shop, and the record of what was agreed and confirmed.

Buyers are not asked for sensitive information such as health, religion or political views, and no part of the product needs it. If someone volunteers something like that in a chat, it is held as ordinary message content and nothing is built on it.

Automatically, when the service is used

  • A record of requests to our systems, holding the time, the route, the result, the IP address, a coarse location (country, and at most a region) and a plain description of the browser and device family.
  • Sign in events, including failures, which is what lets us lock an account that is under attack and tell you about a sign in from a new device.
  • Aggregate page speed and page view measurements for our website, which carry no identifier and no cookie.

Location is worked out on our own servers from a local database, so no visitor's IP address is ever sent to an outside location service. Device details are grouped into families, so we know a request came from a phone browser without recording which phone.

4.Why we use it, and on what basis

Every use below is tied to a lawful basis under the Data Protection Act, 2012 (Act 843). We do not sell personal data, we do not rent it, and we do not profile buyers for advertising.

What we use it forWhat that involvesBasis
Running your shopAnswering buyer messages, quoting your prices, agreeing a price within your floor, recording orders and showing your payment details.Performing the agreement we have with you, and for buyer data the instruction of the shop under its own basis.
Your accountSigning you in, keeping your session, letting you invite staff, and sending account and security emails.Performing our agreement with you.
BillingIssuing invoices, recording payment, counting assistant conversations against your allowance and telling you when a period is ending.Performing our agreement, and our legal obligation to keep financial records.
Keeping the service safeLocking accounts under attack, spotting a flood of automated messages, rate limiting, fraud checks and investigating incidents.Our legitimate interest in a secure service, which is also what protects your shop and your buyers.
SupportAnswering the request you sent, and looking at the record of what happened so we can explain it.Performing our agreement with you.
Improving KasaCounting how features are used and where the product is slow or failing, using figures rather than message content.Our legitimate interest in a product that works.
Legal dutiesKeeping records that tax law and other Ghanaian law require us to keep, and responding to a lawful request from an authority.Our legal obligation.

5.How the assistant uses conversations

The assistant reads the recent part of a conversation, along with the shop's products and rules, and drafts a reply. To do that, the conversation text, any photo the buyer sent and any voice note they recorded are sent to the artificial intelligence providers listed below, for that single request.

Three limits apply, and they are built into the product:

  • Your content is not used to train anyone’s models. Our agreements with those providers do not permit it.
  • Secrets never leave. Passwords, one time codes, recovery codes, mobile money numbers and access tokens are never included in what is sent to a model.
  • The model never decides money. Prices, floors, stock, payment details and the state of an order are filled in by our own server from your records after the model has drafted the words.

Product photos are also turned into a numeric representation so the assistant can match a screenshot a buyer sends to the right item. That representation cannot be turned back into the photo.

6.Who else touches the data

We use a small number of specialist companies to run Kasa. Each one is bound to use the data only to provide their service to us, and we tell sellers before we make a material change to this list.

CompanyWhat it does for KasaWhat it can reach
RailwayHosts the application and the database.All stored data, encrypted at rest.
CloudflareStores photos and other media, and holds our encrypted backups in a separate account.Media files and encrypted database backups.
VercelHosts this website and the seller dashboard, and measures page speed.Requests to the site. Buyer messages are not stored here.
UpstashRuns the queues that carry background work.Job records, which can reference an order or a conversation.
OpenRouterRoutes our requests to the AI models.The conversation content sent for a single reply.
AnthropicProvides the Claude models that draft replies and read images.The conversation content sent for a single reply.
Voyage AITurns product photos and text into the numeric form used for matching.Product images and descriptions.
MetaRuns WhatsApp, Instagram and Messenger, the channels buyers message you on.Buyer numbers and message content, under Meta’s own terms.
BrevoDelivers our account and security emails.Your email address and the content of those emails.
Mobile money providersCarry the payment between your buyer and you.Payment references. Money never passes through Kasa.

We also share personal data in three other situations:

  • With the seller whose shop a buyer messaged, because that shop is the controller of the conversation.
  • Where the law, a court or a regulator requires it. We check that a request is lawful and, unless we are forbidden from doing so, we tell the person affected.
  • If our business is transferred to another company, in which case the new owner is bound by this policy until it lawfully replaces it.

7.Cookies and what is kept in your browser

We do not use advertising cookies, and we do not track you across other websites. Our page view and page speed measurements are collected without cookies and without an identifier for you.

The dashboard does keep a few things in your own browser, on your own device, which never leave it except when you are talking to us:

  • Your sign in token, so you stay signed in between visits. Signing out removes it.
  • The page you were heading to before you signed in, which is discarded as soon as you get there.
  • Drafts of anything you were typing, such as a support request, so a lost connection does not lose your words.

Clearing your browser storage removes all of it and signs you out. If we ever introduce a cookie that is not strictly necessary, we will ask you first.

8.How long we keep things

Chat content is kept only as long as it is useful and is then removed from the record. Money records are kept longer, because tax law and disputes need them, and where a buyer asks to be erased those records stay but stop naming them.

WhatHow longCounted fromThen
Buyer messages and chat details2 yearsthe last activity in that chatthe content is erased and an anonymous shell of the thread remains
Orders and their event history6 yearsthe order closingkept, and stripped of anything naming the buyer if they are erased
Mobile money change records6 yearsthe changekept, already masked
Records of data requests6 yearsthe requestkept, as proof the request was honoured
Incoming message ledger30 daysreceiptdeleted
Sign in sessions90 days after expiryexpirydeleted
Request logs90 daysthe requestdeleted, leaving only counts that name nobody
Security related request logs12 monthsthe requestdeleted
Encrypted backups30 days for daily copies, 12 months for monthly copiesthe copy being takenexpire on their own rotation

A nightly job applies these windows automatically. Account details are held while your account is open, and after it closes they are removed or made anonymous on the same timetable.

Deletion in our live systems happens straight away. Copies inside encrypted backups expire on the rotation above rather than on demand, because a backup that can be edited is not a backup. No restored copy is ever used to bring erased data back into service.

9.How we protect it

  • Every shop’s data is separated inside the database itself, so one shop cannot read another’s even if the application is wrong. This is tested on every change.
  • Data is encrypted while it travels and while it is stored. Mobile money numbers, second step secrets and channel tokens are separately encrypted on top of that, and are never shown in full.
  • Passwords are stored as a strong one way hash. Nobody at Kasa can read your password.
  • Access is limited by role. Staff accounts cannot reach money, billing or data requests. Our own administrators work behind a second step of sign in, and what they do is written to a record that cannot be edited.
  • Every action that touches money is written to an append only log.
  • Backups are encrypted, stored in a separate account, and restored regularly to prove they work.
  • Automated checks watch the service continuously and raise an alert when something looks wrong.

If a breach affects personal data we hold, we investigate at once, tell the sellers affected without undue delay, and notify the Data Protection Commission of Ghana where the law requires it. Where the incident is a cybersecurity incident of the kind the Cybersecurity Act, 2020 (Act 1038) covers, we report it as that Act requires.

10.Where the data is held

Kasa is built and run in Ghana, and some of the companies that host it store data outside Ghana. That is the case for our application hosting, our database, our media and backup storage, and the AI providers that draft replies.

Where data leaves Ghana we make sure it is protected to a standard consistent with the Data Protection Act, 2012 (Act 843): written agreements with each provider limiting what they may do with it, encryption while it travels and while it is stored, and a ban on using it for their own purposes. The regions used are recorded internally and are available to a seller who asks.

11.Your rights

Under the Data Protection Act, 2012 (Act 843) you can ask us to do the following with personal data we hold about you:

  • Tell you what we hold and why, and give you a copy of it.
  • Correct anything that is wrong or out of date.
  • Delete it, or block a particular use of it, where we have no lasting reason or legal duty to keep it.
  • Stop using it for a purpose you object to, including any marketing.
  • Withdraw a consent you gave, which does not undo what was lawfully done before you withdrew it.

How to ask

Sellers can export a whole workspace, or one buyer's data, from the dashboard at any time, and can erase a buyer from there too. For anything else, write to support@kasarm.com. We will confirm we received it, check that the request really comes from you, and answer within 7 business days. If a request is complicated we will tell you and finish it within 30 days.

Asking is free. We only charge where a request is repeated or clearly excessive, and we say so before doing any work.

If you are a buyer

Ask the shop you messaged first, because they hold the relationship and the tools. If they do not resolve it, write to us at support@kasarm.com naming the shop, and we will act on their behalf.

If we get it wrong

Tell us and we will try to put it right. You can also complain to the Data Protection Commission of Ghana, which supervises the use of personal data in Ghana and publishes its contact details on its own website. You do not have to come to us first, but it is usually quicker.

12.Children

Kasa is a business tool for adults. You must be at least 18 to open an account, and the service is not directed at children. If we learn that we hold the personal data of a child who has no business being on the platform, we remove it.

13.Changes to this policy

As Kasa grows, this policy will change with it. Every version carries a number and a date at the top of the page. When a change materially affects you we will tell you by email or in the dashboard before it takes effect, rather than quietly replacing the text.

14.Contact

Write to support@kasarm.com with Data protection in the subject, or use any of the ways listed on our contact page. We reply within one business day.