Privacy Policy
Last updated 13 July 2026.
1. Who we are, and what this covers
The Provender platform is operated by Handisi Digital Solutions Limited, a company registered in Tanzania (“Provender”, “we”, “us”), which is the controller for the personal data described in this policy. You can reach us at the support address published in the footer of this site.
This policy explains how Provender handles personal data for which Provender itself is the controller: visitors to this website, people who request a demo, and the users and billing contacts of our customers’ accounts.
It does not cover the personal data our customers process inside their own Provender tenant — for example, their end customers’ order and shipping details. For that data the customer is the controller and Provender is the processor, acting only on their instructions. If you are an end customer of a brand that runs on Provender, please contact that brand directly.
2. What we collect
Account and billing data: name, work email address, company, role, and the billing contact and payment-method token held by our payment processor. We do not store full card numbers.
Demo requests: the name, work email address, company and stated interest you submit on our demo form. This is used to contact you about that request. We do not store demo requests in our product database — the request is delivered to our sales inbox by email.
Usage and diagnostic data: application logs, error reports, and — only if you consent — product-analytics events describing how the application is used.
Website data: strictly necessary cookies needed to run the site and to remember your cookie choice. Nothing else is set until you agree to it.
3. Cookies and analytics consent
We do not write any non-essential cookie or browser storage until you have explicitly agreed to it. Declining, or dismissing the banner, means no analytics storage is written at all — it is not treated as agreement.
You can change your mind at any time. Withdrawing consent clears the analytics identifiers already stored in your browser; it does not merely stop new ones being collected.
The single exception is the record of your own choice, which we must store in order to honour it.
4. Why we process it, and on what basis
To provide the Service and to perform our contract with you: account, billing and support data.
On our legitimate interests: keeping the Service secure, preventing abuse, and diagnosing faults — balanced against your rights, and limited to what those purposes need.
On your consent: product analytics and any advertising measurement. You may withdraw it at any time.
To meet legal obligations: tax, accounting and lawful requests from authorities.
5. Subprocessors
We use the third parties listed below to run the Service. Each receives only the data it needs for its stated purpose, under a data-processing agreement. Our error monitoring, feature flags, embedded reporting, metrics and log storage all run on infrastructure we operate ourselves — no personal data leaves our boundary to a third party through them, so they are not subprocessors and are not listed here.
Where we transfer personal data outside your region, we rely on the appropriate safeguards, including standard contractual clauses.
| Subprocessor | Purpose | Data received |
|---|---|---|
| Stripe | Payment processing and subscription billing | Billing contact details, payment-method tokens, transaction records |
| Amazon Web Services (Amazon SES) | Transactional and notification email delivery | Recipient email address, message subject and body |
| PostHog Cloud | Product analytics, only where the visitor has consented | Pseudonymous usage events, device and browser metadata, IP address |
| Meta | Advertising measurement — browser pixel and server-side Conversions API relay | Hashed customer identifiers and purchase events, sent from the browser and from our servers |
| TikTok | Advertising measurement — browser pixel and server-side Conversions API relay | Hashed customer identifiers and purchase events, sent from the browser and from our servers |
| Advertising measurement — browser pixel and server-side Conversions API relay | Hashed customer identifiers and purchase events, sent from the browser and from our servers | |
| Smile.io | Loyalty and rewards on storefronts that enable it | Customer identifier, email address, loyalty balance |
| S3-compatible object storage | Encrypted off-box backups and data-return archives | Encrypted backups of tenant databases and uploaded documents |
6. Your rights, and how to use them
You have the right to access the personal data we hold about you, to correct it, to have it erased, to restrict or object to its processing, and to receive it in a portable form.
To exercise any of these, submit a data-subject request to our support address, or use the data-export path inside the application. We respond without undue delay and within the timeframe required by applicable law — we aim to respond promptly, and typically do so well inside that period. We may need to verify your identity first, and personal data held in encrypted backups is purged on the backup rotation cycle rather than instantly.
If you think we have handled your data badly, please tell us first — we would rather fix it. You also have the right to complain to your local supervisory authority.
7. How long we keep it
Account and billing records are kept for as long as the account is active, and afterwards for as long as we are required to keep them for tax and accounting purposes.
Demo requests are kept in our sales inbox and deleted when they are no longer needed.
On termination, customer data is available for export for 90 days, after which it may be deleted. Encrypted backups age out on their own retention schedule.
8. Security
Data is encrypted in transit and at rest. Access to production systems is restricted, multi-factor authentication is required, and administrative actions are recorded in an append-only audit chain. Backups are encrypted and stored off the machine that produced them.
Provender implements the controls expected of a food-compliance platform — tenant isolation enforced in the database, append-only audit records, and e-signature workflows. We do not hold a third-party security accreditation, and we do not claim one.
9. Changes, and how to reach us
If we change this policy materially we will say so on this page and, where the change affects you directly, by email.
Questions, requests and complaints can be sent to our support address, published in the footer of this site.