Privacy Policy
Effective Date: July 21, 2026 · Last updated: July 21, 2026
1. Who We Are and How to Contact Us
WinyMarket AI ("we", "us", or "our") operates the WinyMarket AI Marketing Operating System — an AI-powered platform for content creation, scheduling, and distribution, available at https://winymarket.com. We are the data controller in respect of personal data processed through this platform.
Data Controller: WinyMarket AI, Kenya
Privacy Contact: support@winymarket.com
We aim to respond to all privacy-related enquiries within 30 days of receipt. For urgent data breach concerns, please mark your email subject "URGENT — DATA BREACH".
2. Scope and Applicable Law
This Privacy Policy applies to all users of the WinyMarket AI platform and is written to comply with:
- •Kenya Data Protection Act 2019 (DPA 2019) — our primary applicable legislation as a Kenya-based operator
- •EU General Data Protection Regulation (GDPR) — to the extent we process personal data of individuals in the European Economic Area
- •UK GDPR — to the extent we process personal data of individuals in the United Kingdom
- •Children's Online Privacy Protection Act (COPPA) — governing our obligations in respect of children under 13 in the United States
3. Children's Privacy — COPPA Compliance
This service is strictly not for children under the age of 13.
In compliance with the Children's Online Privacy Protection Act (COPPA) and equivalent international child-protection legislation, WinyMarket AI does not knowingly collect, process, or retain any personal data from children under 13 years of age.
Additionally, our service is designed for business use and requires users to be at least 18 years old to create an account. By registering, you represent and warrant that you are 18 or older.
If you have reason to believe that a child under 13 has provided us with personal data, please contact us immediately at support@winymarket.com. We will delete such data promptly upon verification without requiring a formal written request.
We do not seek parental consent to collect data from children under 13 because our service is not directed at children and we actively prohibit their use of the platform.
4. Information We Collect
4.1 Information You Provide Directly
- •Account information: Name, email address, and hashed password when you register
- •Profile information: Brand voice guidelines, tone preferences, and other customisation settings you configure
- •Content data: URLs, text, uploaded files, images, and other material you add to the Content Brain
- •Support communications: Messages and attachments you send to our support team
- •Payment information: Billing details processed securely by PayPal — we never see or store your full card number or banking credentials
4.2 Information Collected Automatically
- •Usage data: Pages visited, features used, actions taken (e.g., content approval, scheduling), and time spent
- •Device information: Browser type, operating system, screen resolution, and IP address
- •Authentication logs: Login timestamps, session events, 2FA events, and failed login attempts
- •Performance metrics: Post analytics data you manually enter (likes, shares, reach, etc.)
- •Error data: Crash reports and error traces captured by Sentry to help us fix bugs
4.3 Data We Do Not Collect
- •We do not collect government IDs, passport numbers, or national identification numbers
- •We do not collect health or medical data
- •We do not collect biometric data
- •We do not build advertising profiles or sell your data to third parties
Important: Do not upload content containing sensitive personal data (health records, financial account details, government IDs) to the Content Brain. The platform is designed for marketing content only. If such data is inadvertently uploaded, contact us to request deletion.
5. Legal Bases for Processing (GDPR / Kenya DPA 2019)
We process your personal data only where we have a lawful basis to do so. The table below sets out our processing activities and the applicable legal basis:
| Processing Activity | Legal Basis | Details |
|---|---|---|
| Creating and managing your account | Contract performance (Art. 6(1)(b) GDPR; DPA 2019 s.30(a)) | Necessary to provide the service you signed up for |
| Processing payments via PayPal | Contract performance | Necessary to fulfil your subscription |
| AI content generation using your input | Contract performance | The core service you contracted for |
| Sending transactional emails (verification, password reset, billing) | Contract performance | Necessary account operations |
| Detecting and preventing fraud or abuse | Legitimate interests (Art. 6(1)(f) GDPR; DPA 2019 s.30(d)) | We have a legitimate interest in protecting our platform and users |
| Error monitoring via Sentry | Legitimate interests | Needed to maintain service quality and fix bugs |
| Improving AI quality using your approval/rejection feedback (per-account only) | Legitimate interests | We do not use your data to train shared AI models |
| Sending product update emails | Legitimate interests / Consent | You may opt out at any time |
| CAPTCHA verification (hCaptcha) on login / registration | Legitimate interests | Necessary to prevent automated bot abuse |
| Responding to legal requests | Legal obligation (Art. 6(1)(c) GDPR; DPA 2019 s.30(b)) | Required by applicable law |
| Aggregate platform usage analytics | Legitimate interests | Non-identifiable statistics to improve the product |
6. AI Processing and Your Content
When you use AI generation features, your source content and preferences are transmitted to Anthropic's Claude API for processing. We recommend reviewing Anthropic's Privacy Policy.
- •Your content is sent to Anthropic solely to generate the requested output — not for general model training
- •Generated outputs and your approval or rejection decisions are stored in your account to improve future content quality for your brand voice specifically
- •We do not use your content to train shared or public AI models
- •You retain ownership of all content you upload and all AI-generated outputs produced from your inputs
7. Third-Party Data Processors
We do not sell your personal data. We share your information with the following sub-processors, all of whom are bound by appropriate data processing agreements:
| Processor | Purpose | Data Shared | Location |
|---|---|---|---|
| Vercel Inc. | Hosting and serving the web application | All platform data (encrypted at rest and in transit) | USA (EU SCCs in place) |
| Railway Corp. | PostgreSQL database hosting | All structured user and content data | USA (EU SCCs in place) |
| Anthropic PBC | AI content generation via Claude API | Content you submit for generation + brand preferences | USA (EU SCCs in place) |
| PayPal Holdings Inc. | Payment processing and subscription billing | Email, subscription plan, billing confirmation | USA (EU SCCs in place) |
| Resend Inc. | Transactional email delivery | Your email address + email content | USA (EU SCCs in place) |
| Upstash Inc. | Redis rate limiting and caching | IP addresses, request identifiers (ephemeral, auto-expires) | USA (EU SCCs in place) |
| Sentry Inc. | Error monitoring and crash reporting | Error traces, session IDs, anonymised IP addresses | USA (EU SCCs in place) |
| Intuition Machines (hCaptcha) | CAPTCHA verification to prevent bot sign-ups | Browser fingerprint, CAPTCHA response token | USA (EU SCCs in place) |
Social media platforms: When you use scheduling and publishing features, approved content is sent to the relevant platform (Facebook, Instagram, Twitter/X, LinkedIn, TikTok, YouTube) via their official APIs. Each platform's own privacy policy governs their processing.
We review our sub-processor list regularly and will update this policy when processors change. We will notify you of significant processor changes by email.
8. International Data Transfers
WinyMarket AI is operated from Kenya. Most of our sub-processors are located in the United States. When we transfer personal data internationally, we rely on the following safeguards:
- •Standard Contractual Clauses (SCCs): For transfers from the EEA/UK, we use the European Commission's approved SCCs incorporated into our Data Processing Agreements with each sub-processor
- •Kenya DPA 2019 cross-border compliance: We assess each sub-processor's data protection standards under DPA 2019 Section 48 before transferring data to them, and ensure they provide an adequate level of protection
- •Data minimisation: We transfer only the minimum data necessary for the specific processing purpose
You may request a copy of the relevant transfer safeguards by contacting support@winymarket.com.
9. Data Retention
We retain your data only as long as necessary for the stated purpose or as required by law:
| Data Category | Retention Period | Reason |
|---|---|---|
| Account profile data | Duration of account + 90 days after deletion | Recovery window; then permanently deleted |
| Content Brain items | Until you archive or delete them | Admin/Staff can delete; persists otherwise |
| Generated posts and drafts | Duration of account, or until you delete | Required for analytics and AI learning |
| Approval / rejection decisions | Duration of account | Powers per-account AI personalisation |
| Post analytics data | 24 months | Trend analysis; then anonymised |
| Authentication and login logs | 90 days | Security and fraud investigation |
| Payment transaction records | 7 years | Legal / tax obligation (Kenya Revenue Authority) |
| Support email correspondence | 3 years | Dispute resolution |
| Error logs (Sentry) | 90 days | Bug investigation; automatically purged by Sentry |
| Upstash rate-limit records | 24 hours (ephemeral) | Security; automatically expires in Redis TTL |
When your account is deleted, we will permanently delete or irreversibly anonymise all personal data within 30 days, except where retention is required by law. You will receive a deletion confirmation by email.
10. Security Measures (SOC 2 Alignment)
We implement the following technical and organisational security measures, aligned with SOC 2 Trust Service Criteria:
Confidentiality
- •All data in transit is encrypted using TLS 1.2 or higher (HTTPS enforced via HSTS preload)
- •Passwords are hashed using bcrypt with a minimum of 12 salt rounds — we never store or transmit plain-text passwords
- •Authentication tokens are cryptographically signed JWTs with rolling expiry and token-version invalidation on logout or password change
- •Database access is restricted to authorised systems via network-level access controls
- •API keys and secrets are stored as encrypted environment variables in Vercel — never committed to source code
Availability
- •Platform is hosted on Vercel's global edge network with automatic failover
- •Database is hosted on Railway with automatic daily backups
- •Uptime monitoring is active with immediate alerting on downtime
- •We target 99.5% monthly uptime, excluding planned maintenance windows
Processing Integrity
- •All API routes include input validation and schema enforcement
- •Rate limiting is enforced via Upstash Redis sliding-window algorithm to prevent abuse
- •Role-based access control prevents users from accessing data beyond their permissions
- •A human-in-the-loop content approval workflow runs before any AI-generated content is published
Incident Response and Breach Notification
- •Security incidents are monitored continuously via Sentry error tracking
- •In the event of a personal data breach, we will notify affected individuals and relevant supervisory authorities within 72 hours of becoming aware, as required by GDPR Article 33
- •Breach notifications will include: nature of the breach, categories and approximate number of affected individuals, likely consequences, and remediation measures taken
- •For Kenya DPA 2019 notifications, we will comply with the procedures prescribed by the Office of the Data Protection Commissioner (ODPC)
11. Cookies and Tracking
We use only essential and functional cookies. See our full Cookie Policy for complete details. In summary:
- •Essential cookies: Authentication session (HttpOnly, Secure, SameSite=Lax) and CSRF protection — cannot be disabled without breaking the service
- •Functional storage: UI preferences in localStorage — never transmitted to third parties
- •No advertising cookies: We use zero third-party advertising, retargeting, or cross-site tracking cookies
12. Your Rights Under GDPR and Kenya DPA 2019
You have the following rights in respect of your personal data. We will respond to all valid requests within 30 days (extendable by a further 60 days for complex requests, with advance notice):
| Right | What It Means | How to Exercise |
|---|---|---|
| Right of Access (Art. 15 GDPR; DPA 2019 s.26) | Receive a copy of the personal data we hold about you | Email support@winymarket.com — subject: "Data Access Request" |
| Right to Rectification (Art. 16; DPA 2019 s.35) | Correct inaccurate or incomplete data | Update in account Settings, or email us |
| Right to Erasure (Art. 17; DPA 2019 s.36) | Have your data deleted, subject to legal retention obligations | Use Delete Account in Settings or email support@winymarket.com |
| Right to Data Portability (Art. 20; DPA 2019 s.38) | Receive your data in a structured, machine-readable format (JSON/CSV) | Email support@winymarket.com — subject: "Data Portability Request" |
| Right to Restriction (Art. 18; DPA 2019 s.37) | Limit how we process your data in certain circumstances | Email support@winymarket.com |
| Right to Object (Art. 21; DPA 2019 s.39) | Object to processing based on legitimate interests | Email support@winymarket.com |
| Right to Withdraw Consent | Withdraw consent at any time where processing is consent-based | Email us or use account settings |
| Right to Lodge a Complaint | Complain to a supervisory authority if you believe we have breached applicable law | Kenya: ODPC (odpc.go.ke) | EU: your local DPA | UK: ICO (ico.org.uk) |
We will not charge a fee for exercising your rights unless a request is manifestly unfounded or excessive. We may need to verify your identity before processing a request.
Kenya Supervisory Authority: You have the right to lodge a complaint with the Office of the Data Protection Commissioner (ODPC) at odpc.go.ke.
13. Marketing Communications
We may send you product updates and feature announcements by email. You may opt out at any time by:
- •Clicking the unsubscribe link in any marketing email
- •Emailing support@winymarket.com with subject "Unsubscribe"
Opting out of marketing emails will not affect transactional emails (account verification, password reset, billing notifications) which are necessary for the service.
14. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or applicable legal requirements. We will notify you of material changes by:
- •Updating the effective date at the top of this page
- •Sending an email notification to your registered address, at least 14 days before significant changes take effect
- •Displaying an in-platform notice
For changes that materially affect your rights or how we use your data, we will seek fresh consent where required by law.
15. Contact Our Privacy Team
For any privacy questions, data requests, complaints, or concerns, please contact us:
WinyMarket AI
Email: support@winymarket.com
Website: https://winymarket.com
We aim to respond to all privacy requests within 30 days as required by the Kenya DPA 2019 and GDPR.
© 2026 WinyMarket AI. All rights reserved.