Privacy Policy

Last updated 13 July 2026.

1. Who we are, and what this covers

The Provender platform is operated by Handisi Digital Solutions Limited, a company registered in Tanzania (“Provender”, “we”, “us”), which is the controller for the personal data described in this policy. You can reach us at the support address published in the footer of this site.

This policy explains how Provender handles personal data for which Provender itself is the controller: visitors to this website, people who request a demo, and the users and billing contacts of our customers’ accounts.

It does not cover the personal data our customers process inside their own Provender tenant — for example, their end customers’ order and shipping details. For that data the customer is the controller and Provender is the processor, acting only on their instructions. If you are an end customer of a brand that runs on Provender, please contact that brand directly.

2. What we collect

Account and billing data: name, work email address, company, role, and the billing contact and payment-method token held by our payment processor. We do not store full card numbers.

Demo requests: the name, work email address, company and stated interest you submit on our demo form. This is used to contact you about that request. We do not store demo requests in our product database — the request is delivered to our sales inbox by email.

Usage and diagnostic data: application logs, error reports, and — only if you consent — product-analytics events describing how the application is used.

Website data: strictly necessary cookies needed to run the site and to remember your cookie choice. Nothing else is set until you agree to it.

3. Cookies and analytics consent

We do not write any non-essential cookie or browser storage until you have explicitly agreed to it. Declining, or dismissing the banner, means no analytics storage is written at all — it is not treated as agreement.

You can change your mind at any time. Withdrawing consent clears the analytics identifiers already stored in your browser; it does not merely stop new ones being collected.

The single exception is the record of your own choice, which we must store in order to honour it.

4. Why we process it, and on what basis

To provide the Service and to perform our contract with you: account, billing and support data.

On our legitimate interests: keeping the Service secure, preventing abuse, and diagnosing faults — balanced against your rights, and limited to what those purposes need.

On your consent: product analytics and any advertising measurement. You may withdraw it at any time.

To meet legal obligations: tax, accounting and lawful requests from authorities.

5. Subprocessors

We use the third parties listed below to run the Service. Each receives only the data it needs for its stated purpose, under a data-processing agreement. Our error monitoring, feature flags, embedded reporting, metrics and log storage all run on infrastructure we operate ourselves — no personal data leaves our boundary to a third party through them, so they are not subprocessors and are not listed here.

Where we transfer personal data outside your region, we rely on the appropriate safeguards, including standard contractual clauses.

Third parties that receive personal data, what they use it for, and what they receive
SubprocessorPurposeData received
StripePayment processing and subscription billingBilling contact details, payment-method tokens, transaction records
Amazon Web Services (Amazon SES)Transactional and notification email deliveryRecipient email address, message subject and body
PostHog CloudProduct analytics, only where the visitor has consentedPseudonymous usage events, device and browser metadata, IP address
MetaAdvertising measurement — browser pixel and server-side Conversions API relayHashed customer identifiers and purchase events, sent from the browser and from our servers
TikTokAdvertising measurement — browser pixel and server-side Conversions API relayHashed customer identifiers and purchase events, sent from the browser and from our servers
PinterestAdvertising measurement — browser pixel and server-side Conversions API relayHashed customer identifiers and purchase events, sent from the browser and from our servers
Smile.ioLoyalty and rewards on storefronts that enable itCustomer identifier, email address, loyalty balance
S3-compatible object storageEncrypted off-box backups and data-return archivesEncrypted backups of tenant databases and uploaded documents

6. Your rights, and how to use them

You have the right to access the personal data we hold about you, to correct it, to have it erased, to restrict or object to its processing, and to receive it in a portable form.

To exercise any of these, submit a data-subject request to our support address, or use the data-export path inside the application. We respond without undue delay and within the timeframe required by applicable law — we aim to respond promptly, and typically do so well inside that period. We may need to verify your identity first, and personal data held in encrypted backups is purged on the backup rotation cycle rather than instantly.

If you think we have handled your data badly, please tell us first — we would rather fix it. You also have the right to complain to your local supervisory authority.

7. How long we keep it

Account and billing records are kept for as long as the account is active, and afterwards for as long as we are required to keep them for tax and accounting purposes.

Demo requests are kept in our sales inbox and deleted when they are no longer needed.

On termination, customer data is available for export for 90 days, after which it may be deleted. Encrypted backups age out on their own retention schedule.

8. Security

Data is encrypted in transit and at rest. Access to production systems is restricted, multi-factor authentication is required, and administrative actions are recorded in an append-only audit chain. Backups are encrypted and stored off the machine that produced them.

Provender implements the controls expected of a food-compliance platform — tenant isolation enforced in the database, append-only audit records, and e-signature workflows. We do not hold a third-party security accreditation, and we do not claim one.

9. Changes, and how to reach us

If we change this policy materially we will say so on this page and, where the change affects you directly, by email.

Questions, requests and complaints can be sent to our support address, published in the footer of this site.