Legal
Global Privacy Policy
Zimji.com - how we protect personal data worldwide
Last reviewed and updated: 11 September 2026
1. Introduction and Scope
Zimji.com ("Zimji," "we," "us," or "our") is committed to protecting the privacy and security of personal data entrusted to us. This Global Privacy Policy explains how we collect, use, disclose, store, transfer, and protect personal data in connection with our platform, website, mobile applications, and related services (collectively, the "Services").
This Policy applies globally to all individuals and entities who interact with Zimji, excluding individuals located in the European Economic Area (EEA), the United Kingdom, and Switzerland (collectively, "Europe"). If you are located in Europe, please refer to our separate Europe Privacy Policy, which is designed to comply with the EU General Data Protection Regulation (GDPR) and applicable local laws.
1.1 Who This Policy Applies To
This Policy applies to:
- B2C Users (Consumers and End-Users): Individual consumers, end-users, and visitors who access or use our Services.
- B2B Users (Business Customers and Partners): Business customers, enterprise clients, vendors, partners, and their authorised representatives who engage with Zimji for business purposes.
- Employees, Contractors, and Job Applicants: Individuals who interact with Zimji in an employment or engagement context.
1.2 Jurisdictions Covered
This Policy is designed to comply with the data protection laws of the following jurisdictions, among others:
Africa
- Kenya - Data Protection Act, No. 24 of 2019
- Nigeria - Nigeria Data Protection Act, 2023 (NDPA)
- South Africa - Protection of Personal Information Act, 2013 (POPIA)
- Egypt - Personal Data Protection Law No. 151 of 2020
- Ghana - Data Protection Act, 2012 (Act 843)
Asia-Pacific
- India - Digital Personal Data Protection Act, 2023 (DPDP Act)
- China - Personal Information Protection Law (PIPL)
- Japan - Act on the Protection of Personal Information (APPI)
- South Korea - Personal Information Protection Act (PIPA)
- Singapore - Personal Data Protection Act 2012 (PDPA)
- Australia - Privacy Act 1988 (Cth)
- Thailand - Personal Data Protection Act B.E. 2562 (2019)
- Indonesia - Law No. 27 of 2022 on Personal Data Protection
- Malaysia - Personal Data Protection Act 2010
- Vietnam - Decree 13/2023/ND-CP on Personal Data Protection
- Philippines - Data Privacy Act of 2012
Middle East
- Saudi Arabia - Personal Data Protection Law (PDPL)
- UAE - Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data
- Qatar - Personal Data Privacy Protection Law No. 13 of 2016
- Israel - Protection of Privacy Law, 5741-1981
Latin America
- Brazil - Lei Geral de Proteção de Dados (LGPD)
- Mexico - Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP)
- Argentina - Personal Data Protection Act No. 25.326
- Colombia - Law 1581 of 2012 (Habeas Data)
- Chile - Law No. 19.628 on the Protection of Private Life
- Peru - Personal Data Protection Law No. 29733
North America (excluding Europe)
- Canada - Personal Information Protection and Electronic Documents Act (PIPEDA)
- United States - California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA); Virginia Consumer Data Protection Act (VCDPA); Colorado Privacy Act (CPA); Connecticut Data Privacy Act (CTDPA); Utah Consumer Privacy Act (UCPA); and other applicable US state privacy laws.
By accessing or using our Services, you acknowledge that you have read, understood, and agree to the terms of this Global Privacy Policy.
2. Definitions
| Term | Definition |
|---|---|
| Personal Data | Any information relating to an identified or identifiable natural person. |
| Data Subject / Data Principal | The individual to whom personal data relates. |
| Data Controller / Data Fiduciary | The entity that determines the purpose and means of processing personal data. |
| Data Processor | An entity that processes personal data on behalf of the Data Controller / Data Fiduciary. |
| Sensitive Personal Data | Data revealing racial or ethnic origin, political opinions, religious beliefs, health data, sexual orientation, genetic data, biometric data, and data relating to a child. |
| Processing | Any operation performed on personal data, including collection, recording, storage, retrieval, use, disclosure, and erasure. |
| Consent | Any freely given, specific, informed, and unambiguous indication of the Data Subject's / Data Principal's wishes by which they signify agreement to the processing of their personal data. |
3. Data We Collect
3.1 B2C Users (Consumers and End-Users)
We collect the following categories of personal data from B2C users:
- Identity Data: Name, username, email for registration.
- Contact Data: Email address, phone number.
- Account Data: Login credentials (encrypted), account preferences, and transaction history.
- Financial Data: Payment card details, bank account information, billing address, and payment transaction records for payment processing by third-party payment gateways.
- Device and Technical Data: IP address, device type, operating system, browser type, unique device identifiers, and mobile network information.
- Usage Data: Browsing history about our website only, search queries, pages viewed, time spent on pages, clickstream data, and interaction with features.
- Location Data: GPS coordinates and approximate location (where location services are enabled).
- Communications Data: Correspondence with our customer support team, feedback, reviews, and survey responses.
3.2 B2B Users (Business Customers and Partners)
We collect the following categories of personal data from B2B users:
- Business Contact Data: Name, business email address, business phone number, and business/company name, location.
- Business Account Data: Company registration details, business address.
- Commercial Data: Payment records.
- Representative Data: Personal data of directors, officers, employees, and authorised representatives of business customers.
- Vendor and Partner Data: Personal data of individuals associated with our vendors, suppliers, and business partners.
3.3 Data Collected Automatically
When you use our Services, we automatically collect certain data, including cookies and similar tracking technologies (see Section 10), server logs and analytics data, and crash reports and performance data.
4. How We Use Personal Data
We process personal data for the following purposes:
4.1 B2C Purposes
- To provide, operate, and maintain the Services.
- To create and manage user accounts.
- To process transactions and send related information.
- To personalise and improve user experience.
- To share images to render futuristic try-on results, which are kept for a maximum of 72 hours in the user’s account only.
- To communicate with users about products, services, and promotions if they agree to receive them.
- To provide customer support and respond to enquiries.
- To detect, prevent, and address technical issues and security incidents.
- To comply with legal and regulatory obligations.
4.2 B2B Purposes
- To enter into and perform contracts with business customers.
- To manage business relationships and provide enterprise services.
- To process invoices and manage payments.
- To share images to render futuristic try-on results, which are kept for a maximum of 72 hours in the user’s account only.
- To conduct due diligence and compliance checks.
- To provide business support and account management.
- To communicate about service updates, renewals, and business opportunities.
4.3 Legal Bases for Processing
We process personal data on the following lawful bases, depending on the applicable jurisdiction:
- Consent: Where the Data Subject / Data Principal has given free, specific, informed, unconditional, and unambiguous consent. Under the India DPDP Act, consent must be limited to the personal data necessary for the specified purpose. Under Brazil's LGPD, consent must be given in writing or by other means that demonstrate the data subject's will.
- Contract: Where processing is necessary for the performance of a contract with the Data Subject / Data Principal, or to take steps at their request before entering into a contract.
- Legal Obligation: Where processing is necessary for compliance with a legal obligation to which Zimji is subject.
- Vital Interests: Where processing is necessary to protect the vital interests of the Data Subject / Data Principal or another person.
- Public Interest: Where processing is necessary for the performance of a task carried out in the public interest.
- Legitimate Interests: Where processing is necessary for the purposes of legitimate interests pursued by Zimji or a third party, provided such interests are not overridden by the rights and freedoms of the Data Subject / Data Principal. This basis is recognised under the Kenya DPA and certain other jurisdictions, but may not be available under all laws.
- Legitimate Uses (India DPDP Act): Where processing is for certain specified legitimate purposes, including where the Data Principal voluntarily provides data and has not indicated that it should not be used, or where processing is necessary for employment purposes.
5. Consent
5.1 Obtaining Consent
Where processing is based on consent, we will obtain your consent before or at the time of collection of personal data. Under Kenya's Data Protection Act and the India DPDP Act, consent must be free, specific, informed, unconditional, and unambiguous, with clear affirmative action, and must be limited to the personal data necessary for the specified purpose. Under the Kenya DPA, consent must be freely given, specific, and informed. Under Brazil's LGPD, consent must be given in writing or by other means that demonstrate the data subject's will.
5.2 Notice Requirements
Before obtaining consent, we will provide you with a clear, independent, and accessible notice that includes the personal data being collected, the specific purpose for which the data is processed, the manner in which you can exercise your rights, and the mechanism to withdraw consent. Under the India DPDP Rules, notices must be available in English and any of the 22 scheduled Indian languages.
5.3 Withdrawal of Consent
You have the right to withdraw your consent at any time. Withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal. Under the India DPDP Act, the process of withdrawing consent must be as easy as giving it. To withdraw consent, please contact us using the details in Section 16.
5.4 Consent Managers
Where applicable under the India DPDP Act, you may give, manage, review, and withdraw consent through a registered Consent Manager-a statutory intermediary acting as an agent for the Data Principal. Details of registered Consent Managers will be made available on our platform.
6. Data Sharing and Disclosure
6.1 Sharing with Third Parties
We do not sell or rent personal data. We may share personal data with service providers (cloud hosting, payment processing, analytics, customer support, and marketing), business partners, legal and regulatory authorities, professional advisors, and affiliates.
6.2 B2B Data Sharing
For B2B users, personal data may be shared with the business customer for whom the individual serves as a representative or contact, with third-party service providers engaged by the business customer, and as part of due diligence processes for mergers, acquisitions, or business transfers.
6.3 Data Processors
Where we engage Data Processors, we ensure that the Processor processes personal data only on our documented instructions, implements appropriate technical and organisational security measures, assists us in responding to data subject rights requests, and deletes or returns personal data upon termination of the contract.
7. Cross-Border Data Transfers
7.1 General Principles
We may transfer personal data to jurisdictions outside the country in which it was collected. When doing so, we implement appropriate safeguards to ensure that the personal data receives an adequate level of protection.
7.2 Jurisdiction-Specific Requirements
- Kenya DPA: Personal data may be transferred outside Kenya only where the data subject has given explicit consent, the transfer is necessary for the performance of a contract, or other specified conditions are met. Adequate safeguards must be in place.
- India DPDP Act: The Central Government may notify countries or territories to which personal data may not be transferred. We will ensure that any cross-border transfer complies with the applicable restrictions and safeguards prescribed under the DPDP Act and DPDP Rules.
- China PIPL: Cross-border transfers require one of the following mechanisms: security assessment by the Cyberspace Administration of China (CAC), certification by a professional institution, or execution of standard contractual clauses with the overseas recipient.
- Brazil LGPD: International transfers are permitted to countries with adequate protection levels or where the data controller provides guarantees of compliance with LGPD principles through standard contractual clauses or binding corporate rules.
- Saudi Arabia PDPL: Transfers outside the Kingdom require prior consent or other specified legal bases, and the recipient must provide an adequate level of protection.
- UAE PDPL: Transfers outside the UAE are permitted where the recipient provides an adequate level of protection or where one of the specified exceptions applies.
7.3 Global Cross-Border Privacy Rules (CBPR)
Where applicable, we may rely on the Global Cross-Border Privacy Rules (CBPR) Framework-a voluntary, accountability-based certification framework designed to facilitate secure and privacy-respecting cross-border data transfers while ensuring robust data protection standards.
8. Data Security
We implement reasonable technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction, including encryption of data in transit (TLS/SSL) and at rest, role-based access controls, regular security assessments and vulnerability testing, continuous monitoring of systems, regular data protection and security training for all employees, and data minimisation.
In the event of a data breach, we will notify the relevant supervisory authority and affected Data Subjects / Data Principals in accordance with the timelines prescribed under applicable law. For example, under the Kenya DPA, we will notify the Office of the Data Protection Commissioner (ODPC) within 72 hours of becoming aware of the breach. Under the India DPDP Act, we will notify the Data Protection Board of India and affected Data Principals within the timelines prescribed under the DPDP Rules.
9. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law.
9.1 Jurisdiction-Specific Retention Requirements
- Kenya DPA: Personal data must be kept in a form which identifies Data Subjects for no longer than is necessary for the purpose for which it was collected.
- India DPDP Act: Personal data must be erased when the Data Principal withdraws consent or when it is reasonable to assume that the specified purpose is no longer being served. Data Fiduciaries must retain logs for at least one year from the date of processing. We will notify Data Principals at least 48 hours before deletion of personal data. E-commerce entities with a minimum of 2 crore Indian users must not retain personal data beyond 3 years.
- China PIPL: Personal information protection impact assessments (PIPIA) must be conducted, and the results and processing records must be retained for at least three years.
- South Korea PIPA: Data controllers must specify retention periods in their privacy policies and destroy personal information without delay when the retention period expires.
9.2 Retention Schedule
| Data Category | Retention Period |
|---|---|
| B2C Account Data | Duration of account + 12 months |
| B2B Account Data | Duration of contract + 7 years (for legal/tax purposes) |
| Transaction Records | 7 years from date of transaction |
| Communications Data | 3 years from date of last interaction |
| Usage and Analytics Data | 24 months |
| Breach Logs | Minimum 12 months |
| Try-on images / render results | Maximum 72 hours in the user’s account |
10. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance user experience, analyse usage patterns, and deliver personalised content. You can control cookie preferences through your browser settings. Under South Korea's PIPA, we are obligated to state in our privacy policy matters concerning the installation, operation, and refusal of a device that automatically collects personal information, such as an internet access data file. For detailed information, please refer to our Cookie Policy.
11. Your Rights
The rights available to you depend on your jurisdiction. We will honor all rights requests in accordance with applicable law.
11.1 Rights Under the Kenya DPA
As a Data Subject under the Kenya DPA, you have the right to be informed, right of access, right to rectification, right to erasure, right to object, right to data portability, right to restrict processing, right to withdraw consent, and rights related to automated decision-making. We will respond to data subject access requests within 7 days (for access requests) or 30 days (for other requests).
11.2 Rights Under the India DPDP Act
As a Data Principal under the DPDP Act, you have the right to access a summary of personal data being processed, right to correction and erasure, right to grievance redressal, right to nominate, and right to withdraw consent. You are required to comply with all applicable laws while exercising your rights and must not impersonate another person or suppress material information.
11.3 Rights Under Brazil's LGPD
As a Data Subject under the LGPD, you have the right to confirmation of processing, access, correction, anonymisation, blocking or elimination, portability, deletion, information about sharing, and information about the possibility of not providing consent. The LGPD sets out 10 principles that must be evaluated, including purpose, adequacy, necessity, transparency, and accountability.
11.4 Rights Under China's PIPL
As a Data Subject under the PIPL, you have the right to be informed, right to decide, right to access and copy, right to correction, right to deletion, right to withdraw consent, and right to explanation. The PIPL requires separate consent for certain processing activities and prohibits bundled consent.
11.5 Rights Under California CCPA/CPRA
As a California consumer, you have the right to know what personal information is collected, used, shared, or sold; right to delete; right to opt out of the sale or sharing of personal information; right to non-discrimination; and right to correct inaccurate personal information.
11.6 Rights Under Other Jurisdictions
- South Africa POPIA: Right to access, correct, delete, object to processing, and lodge complaints with the Information Regulator.
- Nigeria NDPA: Right to be informed, access, rectify, erase, object, and data portability.
- Saudi Arabia PDPL: Right to access, correct, delete, and withdraw consent.
- Japan APPI: Right to request disclosure, correction, suspension of use, and erasure of retained personal data.
- South Korea PIPA: Right to access, correct, delete, suspend processing, and withdraw consent.
- Canada PIPEDA: Right to access, correct, and withdraw consent. PIPEDA is based on ten fair information principles, including accountability, identifying purposes, consent, limiting collection, and individual access.
- Australia Privacy Act: Right to access, correct, and complain. From 10 December 2026, organisations using automated decision-making must clearly disclose how personal information is used in automated decisions.
11.7 How to Exercise Your Rights
To exercise any of your rights, please contact us using the details in Section 16. We will verify your identity and respond within the applicable timelines. We will not charge a fee for the first request within a 12-month period, unless the request is manifestly unfounded or excessive.
12. Children's Privacy
We do not knowingly collect personal data from children under the age of 18 without verifiable parental consent. Under the Kenya DPA, processing of personal data relating to a child requires consent from a parent or guardian. Under the India DPDP Act, verifiable consent of a parent or lawful guardian must be obtained before processing personal data of a child. Under China's PIPL, special rules apply to the processing of personal information of minors under the age of 14. Under South Korea's PIPA, consent from a legal representative is required for processing personal information of children under 14. If we become aware that we have collected personal data from a child without proper consent, we will take steps to delete such data promptly.
13. Data Protection Officer
13.1 Appointment
We have appointed a Data Protection Officer (DPO) to oversee our data protection strategy and ensure compliance with applicable laws. Under the India DPDP Act, entities notified as Significant Data Fiduciaries (SDFs) must appoint a senior, India-based Data Protection Officer. Under Brazil's LGPD, the contact information of the DPO must be made publicly available. Under South Korea's PIPA, organisations meeting certain criteria must appoint a Chief Privacy Officer (CPO) responsible for data protection compliance.
13.2 Responsibilities
Our DPO is responsible for:
- Advising on data processing requirements.
- Monitoring compliance with applicable data protection laws.
- Acting as a point of contact for Data Subjects / Data Principals and supervisory authorities.
- Conducting Data Protection Impact Assessments (DPIAs) where required.
Contact: jirani.deal@gmail.com
14. Significant Data Fiduciary Obligations (India)
If Zimji is notified as a Significant Data Fiduciary under the DPDP Act, we will appoint a Data Protection Officer based in India, conduct annual Data Protection Impact Assessments (DPIAs) and audits, implement enhanced security safeguards and algorithmic due diligence, and report significant observations to the Data Protection Board.
15. Jurisdiction-Specific Provisions
15.1 Africa
- Kenya: We comply with the Kenya Data Protection Act, No. 24 of 2019, and the Data Protection (General) Regulations, 2021. The Office of the Data Protection Commissioner (ODPC) is the supervisory authority.
- Nigeria: We comply with the Nigeria Data Protection Act, 2023 (NDPA) and the General Application and Implementation Directive (GAID) 2025. The Nigeria Data Protection Commission (NDPC) is the supervisory authority. Organisations are required to maintain up-to-date privacy policies, publish them clearly (including cookie notices), and conduct annual data protection compliance audits.
- South Africa: We comply with the Protection of Personal Information Act, 2013 (POPIA). POPIA sets out eight core information protection principles, and responsible parties must develop, implement, monitor, and maintain a data protection and privacy compliance framework.
15.2 Asia-Pacific
- India: We comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Digital Personal Data Protection Rules, 2025. The Data Protection Board of India is the supervisory authority.
- China: We comply with the Personal Information Protection Law (PIPL). The PIPL requires data controllers to undertake personal information protection impact assessments (PIPIA) and to retain the results and processing records for at least three years. Bundled consent is not allowed, and data should be collected on a product-by-product basis.
- Japan: We comply with the Act on the Protection of Personal Information (APPI). The APPI mandates comprehensive privacy notices, sets conditions for consent (especially for sensitive personal information), and imposes requirements on data transfers, particularly those involving third parties outside Japan.
- South Korea: We comply with the Personal Information Protection Act (PIPA). PIPA requires explicit, informed consent for the collection and use of personal information, and mandates that organisations meeting certain criteria must appoint a Chief Privacy Officer (CPO).
- Singapore: We comply with the Personal Data Protection Act 2012 (PDPA). Organisations must inform individuals of the purposes for which their personal data will be collected, used, and disclosed in order to obtain their consent.
- Australia: We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Organisations must have a clearly expressed and up-to-date privacy policy about the management of personal information.
15.3 Middle East
- Saudi Arabia: We comply with the Personal Data Protection Law (PDPL). Controllers must adopt a personal data privacy policy and make it available to personal data subjects for review prior to collecting personal data. The policy should specify the purpose of collection and the rights of individuals. Privacy policies should be available in Arabic and English, where appropriate.
- UAE: We comply with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL). For sensitive data, explicit consent is required; simply stating its use in a privacy policy is not sufficient.
15.4 Latin America
- Brazil: We comply with the Lei Geral de Proteção de Dados (LGPD). The LGPD sets out 10 principles that must be evaluated and factored into the processing of personal data, including purpose, adequacy, necessity, transparency, and accountability. The contact information of the DPO must be made publicly available.
- Mexico: We comply with the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP).
- Argentina: We comply with the Personal Data Protection Act No. 25.326.
- Colombia: We comply with Law 1581 of 2012 (Habeas Data).
15.5 North America
- Canada: We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA). PIPEDA is based on ten fair information principles, including accountability, identifying purposes, consent, limiting collection, limiting use, disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance.
- United States: We comply with applicable federal and state privacy laws, including the CCPA as amended by the CPRA, VCDPA, CPA, CTDPA, UCPA, and other applicable state privacy laws. As of 2026, comprehensive privacy laws are in effect in Indiana, Kentucky, Rhode Island, and other states.
16. Contact Us
If you have any questions, concerns, or requests regarding this Global Privacy Policy or our data processing practices, please contact us:
Data Protection Officer
Zimji.com
Email: dpo@zimji.com
Alternate: jirani.deal@gmail.com
Address: [Insert Registered Address]
Supervisory Authorities
| Jurisdiction | Authority |
|---|---|
| Kenya | Office of the Data Protection Commissioner (ODPC) |
| India | Data Protection Board of India |
| Brazil | Autoridade Nacional de Proteção de Dados (ANPD) |
| China | Cyberspace Administration of China (CAC) |
| South Africa | Information Regulator |
| Nigeria | Nigeria Data Protection Commission (NDPC) |
| Saudi Arabia | Saudi Data and AI Authority (SDAIA) |
| UAE | UAE Data Office |
| Canada | Office of the Privacy Commissioner of Canada |
| Australia | Office of the Australian Information Commissioner (OAIC) |
| California | California Privacy Protection Agency (CPPA) |
17. Changes to This Policy
We may update this Global Privacy Policy from time to time to reflect changes in legal requirements, our practices, or the Services. We will notify you of any material changes by posting the updated policy on our website and, where required, by direct communication. Your continued use of the Services after the effective date of the updated policy constitutes acceptance of the changes.
18. Governing Law and Dispute Resolution
This Global Privacy Policy is governed by and construed in accordance with the laws of the jurisdictions in which Zimji operates and where Data Subjects / Data Principals are located. Any disputes arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts of the applicable jurisdiction.
Also see our Terms of Service and Cookie Policy.
