Privacy Policy
Effective: 28 May 2026. Compliant with the Data Protection Act 2017 of Mauritius. Governed by the laws of the Republic of Mauritius.
Komers.mu collects only what it needs, keeps it only as long as required, and does not sell your data. This policy explains what we collect, why, and what rights you have.
1. Who We Are
Komers.mu is an online marketplace platform operated from Port Louis, Mauritius. For the purposes of the Data Protection Act 2017, Komers.mu is the data controller responsible for personal data collected through this platform.
Contact the data controller: hello@komers.mu — Port Louis, Mauritius.
2. Data We Collect
We collect only what is necessary for the purposes described below. We do not collect data "just in case."
- Account & identity data — name, email address, phone number, password (hashed), business name and registration details for vendors. Purpose: account management, identity verification, KYC compliance.
- Transaction data — order details, booking records, payment amounts, payment status, invoice history. Purpose: fulfilling purchases, vendor payouts, tax and accounting obligations.
- Platform activity — pages visited, products and stores viewed, searches performed, items added to cart, checkout steps. Purpose: vendor analytics dashboard, improving search relevance, ranking algorithm.
- Contact interactions — WhatsApp button clicks, phone clicks, map/directions clicks, aggregated and not linked to identity for anonymous visitors. Purpose: vendor lead tracking, ranking signals.
- Device & session data — device type, browser, approximate location (country/city), referrer source, anonymous session ID. Purpose: UX analytics, preventing duplicate counts, fraud detection.
- Support communications — emails or messages sent to hello@komers.mu. Purpose: responding to your request, improving our service.
3. Data We Do Not Collect
- Exact GPS or precise device location
- Mouse movement recordings or keystroke logs
- Full IP address stored beyond the minimum required for security logging
- Cross-site or third-party tracking profiles
- Browsing history outside of Komers.mu
- Sensitive categories of data (health, biometric, religious, political)
4. Cookies & Analytics
Komers.mu uses first-party cookies and local storage only. We do not use third-party advertising trackers, social media pixels, or cross-site tracking technologies at this time.
Cookies we use:
- Authentication cookie — keeps you logged in during a session.
- Anonymous session ID — a random identifier used to count unique visits without linking them to a person. Rotated regularly.
- Cart and preference data — stored locally in your browser to persist your cart between page loads.
If Komers.mu introduces third-party analytics or advertising cookies in the future, we will update this policy, add a cookie consent banner, and give you a meaningful choice before those cookies are set.
5. How We Use Your Data
- Operating the platform — processing orders, bookings, payments, and account management.
- Vendor analytics dashboard — giving vendors aggregated, anonymised insights on store views, product views, and contact interactions.
- Search and ranking — using aggregated engagement signals to rank search results fairly. No individual user profile is used for ranking.
- Fraud and security — detecting and preventing fraudulent transactions, fake accounts, and misuse of the platform.
- Legal compliance — meeting obligations under the Data Protection Act 2017, FIAMLA, and requests from lawful authorities.
- Platform improvement — understanding how pages are used to fix bugs and improve the user experience.
- Communications — sending transactional emails (order confirmations, booking receipts, account alerts). We do not send marketing emails without consent.
6. Who We Share Data With
We do not sell personal data. We share data only in the following cases:
- Licensed payment service providers — to process your payment.
- Vendors — when you place an order or booking, the relevant vendor receives your name, contact details, and order information to fulfil it.
- Hosting and infrastructure providers — our cloud hosting provider stores platform data on servers with appropriate data protection standards.
- Legal authorities — where required by law, court order, or a legitimate request from a competent authority in Mauritius.
7. How Long We Keep Data
- Raw visitor events — 90 days, then aggregated and anonymised.
- Aggregated vendor stats — 12–24 months, retained in anonymised form.
- Account data — duration of account plus 2 years, required for disputes and legal compliance.
- Order and booking records — 7 years, tax and accounting obligations under Mauritius law.
- Security and fraud logs — 6–12 months, then deleted.
- Support correspondence — 2 years from resolution.
8. Your Rights
Under the Data Protection Act 2017 of Mauritius you have the following rights. To exercise any of them, email hello@komers.mu. We will respond within 30 days.
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — request deletion of your data, subject to legal retention obligations.
- Restriction — ask us to limit how we process your data while a dispute is pending.
- Portability — receive your account data in a machine-readable format.
- Objection — object to processing based on legitimate interests.
You also have the right to lodge a complaint with the Data Protection Office of Mauritius if you believe your rights have not been respected.
9. Security
We implement technical and organisational measures appropriate to the risk, including encrypted connections (HTTPS), hashed password storage, access controls, and regular security reviews. No system is perfectly secure; we will notify affected users without undue delay if a breach is likely to result in a high risk to their rights.
10. Children
Komers.mu is not directed at children under 18. We do not knowingly collect personal data from anyone under 18. If we become aware that we have inadvertently collected such data, we will delete it promptly.
11. Vendor Accounts & Business Data
Vendors have additional data collected and stored compared to buyers, reflecting their role as active business operators on the platform.
Additional data collected for vendors:
- Business name, business registration number (BRN), and trade licence details
- Bank or payment account details required for payouts (stored encrypted)
- Identity documents (ID card front and back) for KYC verification
- Proof of address documents
- Store analytics: aggregated views, contact clicks, and product engagement
- Terms acceptance record — the date and time at which the vendor accepted the Terms & Conditions (stored as
terms_accepted_at)
The terms acceptance timestamp is a compliance record. It may be provided to payment service providers, financial regulators, or legal authorities on request as evidence that the vendor agreed to platform rules prior to transacting.
Sensitive vendor documents (BRN, payment details, identity documents) are stored encrypted at rest and are accessible only to authorised Komers.mu staff for verification purposes. They are not shared with other vendors or buyers.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to registered users by email or prominent notice on the platform at least 14 days before taking effect. The effective date at the top of this page will always reflect the latest version.
Contact
Privacy questions or data requests? Email hello@komers.mu with the subject "Data Request". We respond within 30 days. Komers.mu, Port Louis, Mauritius.