Privacy policy.
How TidalFlow Tech collects, uses, stores and protects information across our websites, applications and related services.
1. About this privacy policy
This privacy policy applies to applications, websites and services developed or operated by TidalFlow Tech.
Our services include business management, sales, merchandising, attendance, delivery, point-of-sale, reporting and other operational applications.
By using a TidalFlow Tech application or submitting information through our website, you acknowledge the practices described in this privacy policy.
2. Information we collect
The information we collect depends on the application you use, the features enabled by your organisation and the information you choose to provide.
Account and profile information
We may collect:
- Email address.
- Authentication credentials.
- Full name.
- Telephone number.
- Profile image.
- Staff number or employee identifier.
- Company, branch or outlet information.
- Job title, role or designation.
- Account status and access permissions.
Your email address and authentication credentials are used to verify your identity and allow you to access your account.
Authentication credentials are handled through secure authentication systems. Passwords are not intended to be stored or displayed in readable plain-text form.
Your name, phone number and related profile information are used for account management, identification, communication and administration within the application.
3. User-generated information
Our applications allow users to enter, create, upload and manage business or operational information.
Depending on the application, this may include:
- Sales and transaction records.
- Product and inventory information.
- Customer and supplier information.
- Attendance and work activity records.
- Delivery and route information.
- Outlet and merchandising information.
- Invoices, receipts and supporting documents.
- Notes, comments and form responses.
- Reports generated through the application.
This information is collected and processed so that the application can provide its intended functions, maintain business records and generate reports for authorised users.
4. Images, photographs and files
Some TidalFlow Tech applications allow users to take photographs using their device camera or upload images and files from their device.
These may include:
- Product photographs.
- Shelf and merchandising photographs.
- Outlet and display photographs.
- Stock verification photographs.
- Profile photographs.
- Receipts and invoices.
- Delivery confirmation images.
- Other user-generated documents or images.
Images and files are collected only when a user takes, selects or uploads them through an application feature.
These files are used to support application functionality, verify completed work, maintain records, prepare reports and allow authorised users within the relevant organisation to review submitted information.
5. Location information
Some of our applications may request access to your device's location.
Location information is required for the correct operation of certain field-based features, particularly within the TidalFlow merchandising application.
Depending on the features enabled by your organisation, location information may be used to:
- Confirm visits to assigned outlets or work locations.
- Record where merchandising activity was completed.
- Support employee check-in and check-out.
- Validate sales, delivery or field activity.
- Record the location associated with submitted images.
- Improve route, territory and outlet visibility.
- Protect the accuracy of business reports.
- Help prevent false or inaccurate field submissions.
Location information is not collected for advertising purposes.
The application may not be able to provide location-dependent features correctly when location permission is disabled.
Your device operating system may allow you to control whether location access is permitted only while using the application or under other permission settings supported by your device.
6. Camera, storage and device permissions
Depending on the application and the features you use, we may request access to:
- Your camera, to capture photographs, receipts and documents.
- Your photos or files, to select and upload existing content.
- Your location, to support field, attendance, merchandising and delivery features.
- Notifications, to send account, activity, security or service alerts.
- Internet connectivity, to synchronise information with our online services.
You may manage these permissions through your device settings. Disabling a permission may prevent the associated application feature from working correctly.
7. Technical and usage information
When you use our applications or websites, we may automatically receive limited technical information needed to operate, protect and improve the service.
This may include:
- Device and operating-system information.
- Application version.
- Browser type.
- Login and session timestamps.
- Crash reports and error information.
- Security and authentication events.
- Feature usage and performance information.
- Internet Protocol address where available.
We use this information to maintain security, investigate errors, prevent misuse, improve reliability and provide technical support.
8. How we use personal information
We use personal information to:
- Create and manage user accounts.
- Authenticate users and protect account access.
- Provide requested application features.
- Associate users with the correct organisation or branch.
- Store business and operational records.
- Generate reports and dashboards.
- Verify merchandising and field activity.
- Provide customer and technical support.
- Communicate important service and security information.
- Detect fraud, misuse and unauthorised access.
- Troubleshoot and improve application performance.
- Maintain backups and service continuity.
- Comply with applicable legal obligations.
We do not use personal information for purposes unrelated to the operation, administration, security or improvement of our services unless we have a lawful reason to do so.
9. Organisational accounts
Many TidalFlow Tech accounts are created for employees, agents, contractors or representatives of an organisation using our services.
When your account is associated with an organisation, authorised administrators from that organisation may access information connected to your work account.
This may include:
- Your name and contact information.
- Your assigned role, branch or outlet.
- Your attendance and work activity.
- Your submitted images and documents.
- Your sales, merchandising or delivery activity.
- Your assigned tasks and completed work.
- Location records connected to field activity.
Organisations are responsible for managing their authorised users, assigning access permissions and using employee or business information appropriately.
10. How we share information
TidalFlow Tech does not sell, rent or trade user personal information.
We do not share user information with unrelated third parties for advertising, data-brokerage or independent marketing purposes.
Information may be made available only in the following limited circumstances:
- To authorised users and administrators within the organisation associated with the account.
- To service providers that process information on our behalf to provide authentication, cloud hosting, database storage, notifications, email, mapping, security or technical support.
- When disclosure is required by applicable law, a court order or a lawful request from a competent authority.
- When reasonably necessary to protect users, prevent fraud, investigate security incidents or protect our legal rights.
- As part of a business restructuring, acquisition or transfer, subject to appropriate confidentiality and data-protection safeguards.
Service providers are permitted to process information only as necessary to provide services to TidalFlow Tech and are not permitted to use it for their own unrelated advertising or marketing purposes.
11. Data security and encryption
Information transmitted between supported TidalFlow Tech applications, your device and our online services is encrypted while in transit using secure communication technologies.
We use reasonable technical and organisational safeguards designed to protect information against:
- Unauthorised access.
- Accidental loss.
- Improper disclosure.
- Alteration or destruction.
- Misuse and fraudulent activity.
Security measures may include authentication controls, role-based permissions, encrypted network connections, security logging, controlled administrative access and system backups.
No electronic storage or transmission method can be guaranteed to be completely secure. Users should use strong passwords, protect their devices and immediately report suspected unauthorised access.
12. Data retention
We retain personal and application information only for as long as reasonably necessary to:
- Provide and maintain the application.
- Support the organisation using the service.
- Maintain required business and transaction records.
- Resolve disputes and support enquiries.
- Prevent fraud and investigate security incidents.
- Enforce agreements.
- Meet contractual and legal obligations.
Retention periods may vary depending on the application, record type, customer agreement, account status and applicable legal requirements.
When information is no longer required, it may be deleted, anonymised or securely archived.
13. Account deletion
Users may request deletion of their TidalFlow Tech account and associated personal information.
You can submit an account-deletion request by:
- Using the account-deletion option inside the application, where that option is available.
- Contacting your organisation's account administrator.
- Emailing info@tidalflow.co.ke using the email address connected to your account.
Your request should include enough information for us to identify and verify the account, such as your registered email address, name, company and telephone number.
Before deleting an account, we may take reasonable steps to verify the identity and authority of the person making the request.
After a valid deletion request is approved, we will delete or anonymise personal information that is no longer required for the operation of the service.
Some information may be retained where necessary for legal, security, fraud-prevention, accounting, contractual or legitimate business-record purposes.
Where an account was created and managed by an employer or other organisation, business records created through that account may belong to or remain under the control of that organisation. Deleting the user account may therefore not automatically delete all company-owned transaction, attendance, merchandising, sales or operational records.
14. Your privacy rights
Subject to applicable law and reasonable identity verification, you may have the right to:
- Be informed about how your personal information is used.
- Request access to personal information held about you.
- Request correction of inaccurate or incomplete information.
- Request deletion of eligible personal information.
- Object to certain processing of your information.
- Request restriction of certain processing.
- Request an eligible copy of your information.
- Withdraw consent where processing depends on consent.
- Submit a complaint to the appropriate data-protection authority.
These rights may be limited where information must be retained for legal, contractual, security or legitimate business-record purposes.
To exercise a privacy right, contact us at info@tidalflow.co.ke .
15. Data belonging to children
TidalFlow Tech business applications are intended for authorised business users and are not directed to children.
Users must not create accounts for children or submit children's personal information unless this is lawful, necessary for an authorised service and supported by the required consent or other legal authority.
Contact us if you believe that a child's personal information has been submitted to our services without proper authorisation.
16. International processing
Some technology and cloud service providers used to operate our applications may process or store information using infrastructure located outside Kenya.
Where cross-border processing occurs, we take reasonable steps to use appropriate service providers and safeguards consistent with applicable data-protection requirements.
17. Website enquiries and support communications
When you contact us through our website, email, telephone or support channels, we may collect:
- Your name.
- Your email address.
- Your telephone number.
- Your company information.
- The contents of your enquiry or support request.
- Documents or screenshots you choose to provide.
We use this information to respond to your enquiry, arrange demonstrations, prepare proposals, provide support and maintain appropriate communication records.
18. Changes to this privacy policy
We may update this privacy policy when our applications, technology, business practices or legal obligations change.
The updated policy will be published on this page with a revised effective date.
Where appropriate, significant changes may also be communicated through the application, email or another suitable method.
19. Contact us
For privacy questions, account-deletion requests, access requests or concerns about how your information is handled, contact:
TidalFlow Tech
Kahawa Sukari, Ruiru, Kiambu County, Kenya
Email:
info@tidalflow.co.ke
Telephone:
0732325269
For account-deletion requests, please use the subject: Account Deletion Request.
