Privacy Policy
Last Updated: July 27, 2026
Garnets Data Governance Framework
This Privacy Policy articulates our rigorous protocols regarding the acquisition, encryption, processing, and protection of personal data across our multi-tenant marketplace infrastructure. We are committed to safeguarding buyer financial transactions and vendor proprietary information in accordance with international data privacy mandates (including GDPR and CCPA equivalent standards).
1. Information We Collect
1.1 Identity & Contact Data: When registering an account or initiating a checkout pipeline, we collect Personally Identifiable Information (PII) including full legal name, email address, physical delivery/billing addresses, primary telephone number, and account credentials.
1.2 Financial & Payment Settlement Data: For buyers, payment instrument details (such as masked credit card PANs, expiration dates, M-Pesa mobile identifiers, and PayPal billing tokens) are acquired directly by our PCI-DSS Level 1 certified payment gateway partners. For verified vendors, we collect institutional tax identification numbers, government KYC documents, and direct deposit bank account coordinates for escrow disbursements.
1.3 Device & Log Telemetry: Our servers automatically record technical metadata when you access our storefront or vendor dashboard, including IP addresses, browser user agents, operating system telemetry, referring URLs, and cryptographic timestamp logs.
2. How We Use Your Data
2.1 Transaction Processing & Fulfillment: Collected data is utilized primarily to execute commercial contracts of sale, process multi-currency payments, generate invoices, and transmit delivery manifests to integrated global carrier networks (e.g., DHL, FedEx).
2.2 AML Compliance & Fraud Prevention: We leverage automated machine learning algorithms and heuristic risk scoring to analyze transaction velocity, detect anomalous login patterns, prevent fraudulent chargebacks, and enforce Anti-Money Laundering (AML) statutory mandates.
2.3 Infrastructure Optimization: Aggregated, anonymized telemetry is processed to optimize database query caching, balance multi-region server loads, and refine search merchandising algorithms without exposing individual identity.
3. Information Sharing & Third-Party Disclosures
3.1 Merchant Sourcing Partners: When you purchase a gemstone or luxury item, your shipping address, contact name, and order manifest are transmitted securely to the specific vendor purveyor fulfilling the order. Vendors are bound by strict contractual data processor agreements prohibiting unauthorized marketing or external data retention.
3.2 Critical Infrastructure Service Providers: We disclose necessary data slices to audited third-party service providers who support our core operations, including cloud hosting providers (e.g., AWS/GCP), payment processors, KYC identity verification bureaus, and SMS/email notification gateways.
3.3 Regulatory & Statutory Compulsion: We will disclose personal information to law enforcement agencies, tax authorities, or judicial bodies if required by a valid subpoena, court order, or mandatory statutory disclosure obligation under applicable international law.
4. Cookie Policy & Tracking Technologies
4.1 Essential Session Cookies: We deploy cryptographically signed HTTP-only cookies to maintain authentication state, preserve active cart sessions, and protect against Cross-Site Request Forgery (CSRF) attacks. These cookies are strictly necessary for platform functionality and cannot be disabled.
4.2 Analytics & Performance Tracking: With your consent, we utilize first-party analytical tokens to measure page navigation velocity, user funnel drop-offs, and storefront layout engagement. We do not sell your personal telemetry or deploy third-party advertising retargeting pixels without explicit opt-in consent.
5. Your Privacy Rights & Data Sovereignty
5.1 Right of Access & Portability: You may request a comprehensive electronic export of all personal data, order histories, and vendor telemetry associated with your identity in a machine-readable JSON/CSV format at any time via your account settings dashboard.
5.2 Right to Rectification & Erasure:You retain the right to correct inaccurate biographical data or request permanent deletion of your profile ("Right to be Forgotten"). Note that certain financial transaction records and KYC verification logs must be retained for up to seven (7) years to satisfy anti-money laundering statutory retention laws.
5.3 Consent Revocation: Where data processing relies on explicit consent (such as promotional newsletters or non-essential analytical cookies), you may revoke your consent instantaneously without affecting the lawfulness of prior processing.