Privacy Policy
Last updated: September 1, 2026
At Venus Poultry, we respect your privacy and are committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.
This policy is written to reflect what our systems actually do. It should be read together with our Terms of Service.
By using our website, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
We collect information that you provide directly to us when placing orders or making export inquiries:
1.1 Personal Information
- Name: To identify you and personalize our service
- Email Address: To send order confirmations and communicate about your orders
- Phone Number: To contact you regarding your order and delivery
- Delivery Address: To deliver your products to the correct location
- City and Country: For delivery logistics and shipping calculations
1.2 Order Information
- Products ordered and quantities
- Order numbers and timestamps
- Special delivery instructions or notes
- Your chosen payment method, and the transaction reference you give us after paying (see section 9)
- Any promotional code you use
1.3 Export Inquiry Information
For export inquiries, we collect:
- Company name and contact person
- Business email and phone number
- Destination country
- Product requirements and quantities
- Preferred delivery method and payment method
- Additional business requirements
1.4 Technical Information
We do not run any analytics or tracking software, so we do not build a profile of the pages you visit or how long you spend on them. The technical information we do hold is limited to the following:
- Server access logs: Standard web server records of requests made to our site, including IP address, kept by our hosting provider.
- Session records: While you have an active session, we store its IP address and browser user-agent string. These records expire when the session does.
- Change history: When you use a self-service link to update your order or export inquiry, we record the date and time, the IP address, the browser user-agent, and which details were changed. This is kept as an audit record for the life of that order or inquiry.
- Security logging: We record IP addresses in connection with failed or invalid access attempts, and to enforce request rate limits.
2. How We Use Your Information
We use the collected information for the following purposes:
2.1 Order Processing
- Process and fulfill your product orders
- Send order confirmations via email
- Contact you about your order status, delivery fee, and delivery
- Prepare and send quotes for export inquiries
- Provide customer support
2.2 Communication
- Send order-related updates and notifications
- Respond to your inquiries and requests
- Contact you via phone regarding deliveries
- Occasionally send you a promotional code (see section 10)
2.3 Business Operations
- Maintain our internal records
- Improve our products and services
- Prevent fraud, abuse, and unauthorised access
2.4 Legal Compliance
- Comply with applicable laws and regulations, including tax and export requirements
- Respond to legal requests and prevent harm
3. Information Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:
3.1 Service Providers
- Brevo (formerly Sendinblue), our email delivery provider. Every email we send you passes through Brevo's servers, which means your name, email address, and the contents of the message — such as your order number, items, totals, and delivery address — are processed by them on our behalf. Brevo operates outside Kenya.
- Our web hosting provider, which stores our website, database, and server logs.
- Delivery and logistics partners, who receive the name, address, and phone number needed to deliver your order.
- Freight forwarders, clearing agents, and customs authorities, for export shipments, where your company and shipment details are required for lawful export and import.
We do not share your information with any advertising network, data broker, or analytics provider, because we do not use any.
3.2 Legal Requirements
We may disclose your information if required by law or in response to valid legal requests.
3.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the new entity.
4. Data Security
We implement appropriate technical and organizational security measures to protect your personal information:
- 4.1 Encryption in transit: We use TLS encryption for data transmitted between your browser and our site, and for email sent through our mail provider.
- 4.2 Encrypted sessions: Session data is encrypted, and session cookies are marked HttpOnly and SameSite so they cannot be read by scripts or sent from other sites.
- 4.3 Access controls: Access to personal information is limited to authorised staff. Our staff areas are additionally protected by a single-use access link sent to a verified email address before any login form can even be reached.
- 4.4 Password protection: Staff passwords are stored only as strong one-way hashes, never as readable text.
- 4.5 Security headers: XSS protection, CSRF protection, clickjacking protection, and a strict Content Security Policy that permits no external scripts or resources at all.
- 4.6 Rate limiting: Protection against automated attacks and abuse.
- 4.7 Input validation: Sanitization of all user inputs to prevent security vulnerabilities.
- 4.8 Secure database: Password-protected database with restricted access.
Please note that we do not encrypt individual database fields; protection at rest relies on the security of the hosting environment. And while we strive to protect your information, no method of transmission or storage is completely secure, so we cannot guarantee absolute security.
5. Data Retention
We keep your personal information for as long as we need it for the purposes described in this policy, and for as long as the law requires. In practice:
- 5.1 Paid orders and quotes are kept indefinitely. These are financial records, and confirmation of payment exists only on those records. They are excluded from all automatic deletion.
- 5.2 Other business records — including unpaid orders, export inquiries, and customer contact records — are removed from active use when deleted, held for a recovery period, and then permanently erased. We intend this period to be approximately 12 months, subject to the statutory retention periods that apply to us.
- 5.3 Operational records such as expired promotional codes and superseded shipping rates are permanently erased after a shorter period, intended to be approximately 90 days.
- 5.4 Self-service update links expire 30 days after they are issued.
- 5.5 Staff access tokens are deleted automatically each day once they have expired.
- 5.6 Session records expire with the session, which ends when you close your browser or after two hours of inactivity.
- 5.7 Change history attached to an order or inquiry is kept for as long as that record is kept.
Where a record must be kept longer to meet a tax, accounting, or regulatory obligation, we keep it for that period.
6. Your Rights
We handle personal information as a data controller under the Kenya Data Protection Act, 2019. Under that Act you have the following rights:
6.1 Access
You have the right to be informed of the use of your personal data, and to obtain a copy of the personal data we hold about you.
6.2 Correction
You have the right to have inaccurate or misleading data corrected, and incomplete data completed.
6.3 Deletion
You may request deletion of your personal information. We will comply unless we are required to keep the information — for example, where it forms part of a financial record we must retain by law (see section 5).
6.4 Objection
You can object to the processing of your personal information in certain circumstances, including objecting to receiving promotional messages from us.
6.5 Data Portability
You have the right to receive your personal information in a structured, commonly used format.
6.6 How to Exercise These Rights
Contact us using the details in section 15. We will respond within a reasonable period and in any event within the time required by law. We may need to verify your identity before acting on a request, which for most customers means confirming details of an order you placed.
6.7 Complaints
If you are not satisfied with how we have handled your personal data, you have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) of Kenya.
7. Cookies and Local Storage
Our website uses only what is strictly necessary to work. We set no advertising, marketing, or analytics cookies of any kind.
7.1 Cookies We Set
- Session cookie: Identifies your browsing session so the site works correctly. It is encrypted, marked HttpOnly and SameSite, lasts two hours of inactivity, and is cleared when you close your browser.
- CSRF token cookie: A security measure that protects our forms against cross-site request forgery.
- "Remember me" cookie: Set only for our own staff when they choose to stay signed in to a staff area. It is never set for customers.
7.2 Local Storage
Your shopping cart is stored in your browser's local storage, not in a cookie and not on our servers. It stays on your own device until you complete an order or clear it, and its contents are only sent to us when you check out.
7.3 What We Do Not Use
We do not use Google Analytics, advertising pixels, session recording, third-party fonts, or any external content delivery network. Our Content Security Policy blocks external resources entirely, so no third party can track you through our website.
8. No Customer Accounts
Our platform does not require customer registration or account creation. You can place orders by simply providing the necessary delivery and contact information at checkout. This means:
- 8.1 We do not create a customer login, and we never store a password for you.
- 8.2 You control what information you share with each order.
- 8.3 Your information is used solely for order fulfillment and the purposes in section 2.
- 8.4 Our own staff do have accounts in order to process orders. Those accounts store passwords only as strong one-way hashes, and are protected by the additional email access gate described in section 4.
9. Payment Information
Important clarification about payments:
- 9.1 We do NOT process payments through our website — there is no payment page and no payment gateway.
- 9.2 We do NOT ask for, receive, or store credit or debit card numbers, CVV codes, PINs, or banking passwords.
- 9.3 We display payment instructions (M-Pesa Paybill, Bank Transfer details) and you pay directly through your bank or mobile money provider.
- 9.4 We verify payments manually against our own payment records.
- 9.5 When we record your payment, we store the transaction reference issued by your bank or mobile money provider, the payment date, and the payment method, against your order. This is how we evidence that an order has been paid.
- 9.6 If anyone claiming to be Venus Poultry asks you for a card number, PIN, password, or one-time code, it is not us. Please report it to us.
10. Email Communications
We send emails for the following purposes:
- 10.1 Order Confirmations: Sent to the email address you provide at checkout.
- 10.2 Order Updates: Including payment instructions, delivery fee confirmation, payment confirmation, and order changes.
- 10.3 Export Inquiries: Confirmation of received export inquiry requests.
- 10.4 Quotes: Your quote, any revisions to it, and confirmation once it is accepted or paid.
- 10.5 Promotional codes: Occasionally, we may email a promotional code to customers who have ordered from us before.
- 10.6 Delivery provider: Our emails are delivered through Brevo, a third-party email service provider (see section 3.1). Your email address is not shared with any third party for their own marketing.
- 10.7 Opting out of promotional emails: our promotional emails do not currently include an automatic unsubscribe link. If you do not wish to receive them, email us using the address in section 15 and we will remove you from those sends. This does not affect transactional emails about an order you have placed, which we need to send in order to fulfil it.
11. Secure Links We Email You
Because we do not use customer accounts, we give you access to your order, export inquiry, or quote through a secure link containing a long, randomly generated token. You should be aware of what this means for your privacy:
- 11.1 The link itself is the credential. Anyone who has the link can view that record, and in the case of a quote, can accept or decline it.
- 11.2 The tokens are long and randomly generated, so they cannot realistically be guessed.
- 11.3 Please do not forward, post, or share these links.
- 11.4 Links that allow you to update an order or inquiry expire after 30 days.
- 11.5 If you think a link has been exposed, contact us and we will invalidate it.
12. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us.
13. International Data Transfers
Venus Poultry operates from Kenya, and your information is processed by us here. Some of it is necessarily handled outside Kenya:
- 13.1 Email: All outbound email is processed by Brevo, which operates servers outside Kenya. This includes your name, email address, and the contents of the message.
- 13.2 Hosting: Our website and database are held with a commercial hosting provider. If you would like to know the country in which our servers are located, please ask us and we will tell you.
- 13.3 Export orders: Where you place an export order, your company and shipment details are shared with freight, clearing, and customs parties in the destination country, as required for lawful import.
Where personal data is transferred outside Kenya, we take reasonable steps to ensure it remains appropriately protected.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by:
- 14.1 Updating the "Last updated" date at the top of this policy.
- 14.2 Posting the new Privacy Policy on this page.
We encourage you to review this Privacy Policy periodically for any changes.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
16. Your Consent
By using our website and services, you consent to this Privacy Policy and to our Terms of Service. If you do not agree with either, please do not use our website or services.