Back to home
Legal Document

Privacy Policy

How we collect, use, store and protect your personal information.

Last updated: June 25, 2026

Important: Please read this document carefully. By using the Bush House app or website, you agree to be bound by these terms. If you do not agree, please discontinue use of our services.

1. Introduction

Bush House General Merchants ("Bush House", "we", "us", or "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and website (collectively, the "Platform").

This policy is compliant with the General Data Protection Regulation (GDPR), the Malawi Electronic Transactions and Cyber Security Act, and applicable data protection laws in the jurisdictions we operate in.

By using our Platform, you consent to the data practices described in this Policy. If you do not agree, please discontinue use of our Platform immediately.

2. Information We Collect

2.1 Information You Provide

  • Full name, email address, and phone number during registration
  • Billing and shipping address for order fulfillment
  • Payment information (processed securely via PayChangu — we do not store card numbers)
  • Profile information including profile picture and preferences
  • Communications with our support team
  • Product reviews and ratings you submit

2.2 Information Collected Automatically

  • Device information (device type, operating system, unique device identifiers)
  • Log data (IP address, browser type, pages visited, time stamps)
  • Usage data (features used, products viewed, search queries)
  • Location data (only if explicitly permitted by you)
  • Cookies and similar tracking technologies (see our Cookie Policy)

2.3 Information from Third Parties

  • Payment processors (transaction confirmation data only)
  • Analytics providers (aggregated, anonymised usage statistics)

3. How We Use Your Information

We use the information we collect to:

  • Create and manage your account and verify your identity
  • Process and fulfill your orders and send order confirmations
  • Send transactional emails (OTP codes, order updates, receipts)
  • Detect, prevent and respond to fraud, abuse, and security incidents
  • Improve and personalise your experience on our Platform
  • Comply with legal obligations and enforce our Terms & Conditions
  • Send marketing communications (only with your explicit consent; you may opt out at any time)
  • Conduct analytics and research to improve our services

We do not sell your personal data to any third party.

4. Legal Basis for Processing (GDPR)

  • Contract performance: Processing necessary to fulfill your orders
  • Legitimate interests: Fraud prevention, security, platform improvement
  • Consent: Marketing emails, cookies (you may withdraw at any time)
  • Legal obligation: Compliance with applicable laws and regulations

5. Data Sharing and Disclosure

We may share your information with:

  • Vendors: Only the information necessary to fulfill your order (name, delivery address, order details)
  • Payment processors: PayChangu for secure payment processing
  • Service providers: Cloud hosting, email delivery, analytics (bound by strict data processing agreements)
  • Law enforcement: When required by law, court order, or to protect our rights
  • Business transfers: In the event of a merger, acquisition, or sale of assets (you will be notified)

We do not share your data with any third party for marketing purposes without your explicit consent.

6. Data Retention

We retain your personal data for as long as your account is active or as needed to provide services. Upon account deletion, we delete or anonymise your personal data within 30 days, except where we are required by law to retain it (e.g., transaction records for tax purposes — typically 7 years).

7. Your Rights

Depending on your jurisdiction, you have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Request correction of inaccurate data
  • Erasure: Request deletion of your personal data ("right to be forgotten")
  • Restriction: Request that we limit our processing of your data
  • Portability: Receive your data in a structured, machine-readable format
  • Object: Object to processing based on legitimate interests
  • Withdraw consent: For any processing based on consent

To exercise any of these rights, contact us at support@bushhousegeneralmerchants.com. We will respond within 30 days.

8. Data Security

We implement industry-standard security measures including:

  • TLS/SSL encryption for all data in transit
  • Bcrypt password hashing (plaintext passwords are never stored)
  • JWT-based authentication with OTP verification
  • Rate limiting and brute-force protection
  • Regular security audits and Winston-based audit logging

Despite these measures, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.

9. Children's Privacy

Our Platform is not directed to persons under the age of 18. We do not knowingly collect personal information from children under 18. If we discover we have collected such information, we will delete it immediately. If you believe your child has provided us with personal data, contact us at support@bushhousegeneralmerchants.com.

10. International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for such transfers in accordance with applicable data protection law.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or prominent notice on our Platform. The "Last updated" date at the top of this Policy reflects the most recent revision. Your continued use of the Platform after the effective date constitutes acceptance of the updated Policy.

12. Contact Us

For any privacy-related questions, requests, or complaints, contact our Data Protection Officer at:

  • Email: support@bushhousegeneralmerchants.com
  • Address: Lilongwe, Malawi