Legal
Privacy Policy
What EzStaw does with your information, what we hold on a merchant's behalf, who else sees it, and how to get it back or delete it.
Last updated 21 July 2026 · Version 1
This policy covers what EzStaw does with personal information. EzStaw is run by PeekTower Limited, a company registered in Sierra Leone.
Each section starts with a one-line summary. The summary helps you read faster; the section under it is the actual policy.
1. Two different roles
What this means: for merchant data we decide what happens. For shopper data the merchant decides and we follow instructions.
Read this section first, because the rest of the policy depends on it.
When you sign up as a merchant, we hold your information for our own purposes: running your account, taking your plan payment, paying you out, and meeting the rules that apply to us. For that information we are the controller, and this policy is the whole answer.
When somebody buys from a shop on EzStaw, their information belongs to that shop's business relationship, not ours. The merchant decides what to collect and what to do with it. We store and process it on the merchant's behalf. For that information the merchant is the controller and we are the processor.
So a shopper with a question about their data should ask the shop they bought from. Each shop has its own privacy page where a shopper can request a copy of their data or ask for it to be deleted. If a shopper cannot get an answer from the shop, they can write to us and we will help.
2. What we collect from merchants
What this means: your account details, your identity documents, and how you use the product.
Account details. Your name, email address, phone number and password. You give us these at signup, and we use them to identify you, sign you in and contact you about your account.
Shop details. Your shop name, description, logo, contact details, opening hours and the social accounts you link. Most of this is on your storefront where anyone can see it, because that is the point of it.
Identity documents. Before your first payout we ask for identity documents, and for a registered business the business documents. These sit in a private storage bucket that is not publicly readable. Access is through short-lived signed links, and only staff reviewing verification can generate one.
Payout details. The mobile-money account you want to be paid into, and the payout history attached to it.
Billing. Your plan, your invoices, and what you have been charged. We do not see or store your mobile-money PIN. The payment is authorised on your phone, by your provider.
Usage. Which pages of the dashboard you open, what you do there, and the technical details your browser sends: IP address, browser and device type. We keep an audit log of significant actions on an account, because when money moves it has to be possible to say who did what.
Support messages. Whatever you write to us, and our reply.
3. What shoppers' data we hold, on merchants' behalf
What this means: we store what a shop needs to fulfil an order, and the shop decides what happens to it.
For each shop we store the customer record it needs to sell: name, phone number, email if given, delivery addresses, order history, totals, wishlist, and any notes or tags the merchant adds. Guest orders are matched by phone number, which is how a guest can later claim their orders.
We record consent separately. Every time a shopper answers a cookie banner, opts in at checkout, or changes their marketing preferences, that answer is written to an append-only log with the time, the IP address and the browser. The log is never edited, so the record of what someone agreed to cannot be quietly rewritten.
Storefront analytics. When someone visits a storefront we record the store, the page path, and a random visitor id kept in a cookie. That id lets us count how many different people visited. It is not linked to a name, an account or an order, and it is not shared between shops.
We do not sell shopper data. We do not use one merchant's customers to market to them on behalf of another merchant.
4. Why we use it
What this means: to run your shop, move your money, keep the platform safe, and obey the law.
- To give you the product you signed up for: the shop, the catalogue, checkout, orders, delivery.
- To take payments from shoppers, hold them in escrow, and pay you out.
- To bill you for your plan, and to chase a payment that failed.
- To verify who you are, which we have to do before we can send you money.
- To email or message you about orders, payouts, and problems with your account. These are not marketing and you cannot turn them off while the account is open.
- To spot fraud, abuse and listings that break the Terms of Service.
- To fix bugs, and to understand which parts of the product get used.
- To answer you when you contact support.
- To keep the records the law requires us to keep, including the accounting record of every payment.
We only send you marketing if you have asked for it, and every marketing message has an unsubscribe link that works.
5. Who else sees it
What this means: payment providers, the companies that host and deliver for us, and anyone the law compels. Nobody who wants to buy it.
We share information with:
Payment providers. Our mobile-money provider processes payments and payouts through Orange Money and Afrimoney. They receive what a payment needs: amount, reference, and the phone number paying or being paid.
Hosting and storage. Our servers and databases, and the object storage holding your images and documents.
Messaging. The services that deliver our email, SMS and WhatsApp messages.
AI. The AI features send your prompt and the relevant content to Anthropic, which runs the model that answers. That includes the product text you ask it to rewrite, the store description you type in, and the catalogue you ask it to import. It also covers the sales figures behind a question you ask about your own data. Do not paste anything into an AI feature that you would not want processed by a third party.
Meta. If you connect Facebook, Instagram or WhatsApp as a sales channel, your product information goes to Meta so it can appear there, and Meta's own terms and privacy policy then apply to it. You choose whether to connect, and you can disconnect.
The law. We disclose information when a court, a regulator or the police lawfully require it, and when we have to in order to establish or defend a legal claim.
A buyer. If the business is sold or merged, account information moves with it. We would tell you before that happened.
We do not sell personal information and we do not rent it out for advertising.
TODO(legal): confirm whether a public sub-processor list should be maintained and linked here.
6. Where it is kept, and for how long
What this means: on servers outside Sierra Leone, for as long as we need it and the law requires.
Our servers and storage are outside Sierra Leone, so your information is transferred and processed abroad. We pick providers that hold recognised security certifications, and we require contract terms that keep our obligations attached to the data.
While your account is open we keep your information. When you close it, most of it goes: identity documents are deleted, and your email address and phone number are replaced with anonymous values.
What survives is the financial record. Orders, payments, refunds and ledger entries stay, attached to an account that no longer names you. We keep them because they are the accounting record of money that actually moved, and neither we nor you can lawfully erase that on request.
TODO(legal): the retention period for the financial record, and for the audit log.
7. How we protect it
What this means: encryption in transit, restricted access, and an audit trail. No system is perfect.
Traffic to EzStaw is encrypted with TLS. Passwords are hashed, never stored as text. Identity documents live in a private bucket reachable only through short-lived signed links. Access to production data is limited to staff who need it, and significant actions are written to an audit log.
None of that makes a breach impossible. If one happens and it puts you at risk, we will tell you and the relevant authority, and we will say what we know rather than waiting until we know everything.
TODO(legal): the notification deadline, and which authority in Sierra Leone is notified.
8. Your choices
What this means: you can see your data, correct it, take it with you, and delete your account.
You can:
- See and correct it. Most of your information is editable in the dashboard under Account and Store settings.
- Export it. Your products, orders and customers can be exported from the dashboard. Ask us if you need something the export does not cover.
- Delete it. Close your shop and delete your account. What happens then is set out at ezstaw.com/legal/delete-account.
- Stop marketing. Unsubscribe from any marketing message, or turn it off in Account settings. Messages about your orders and payouts carry on, because they are part of the service.
- Object or complain. Write to us. If you are not satisfied with the answer, you can take it to the relevant authority.
Shoppers use the privacy page on the shop they bought from, not this one. We identify a shopper's record by the phone number used at checkout.
We answer requests within 30 days. If a request would require us to break a record we have to keep, we will say so and explain which part we cannot action.
TODO(legal): the authority a Sierra Leonean data subject complains to.
9. Cookies
What this means: the ones that keep you signed in are necessary. The counting ones you can refuse.
The dashboard and storefronts use cookies to keep you signed in, to remember what is in a cart, and to protect against cross-site request forgery. These are necessary and the product does not work without them.
Storefronts also set an analytics cookie holding the random visitor id described in section 3. Shoppers are asked before it is set, and the answer is recorded in the consent log.
Your browser can block or clear cookies. Blocking the necessary ones will sign you out and empty your cart.
10. Children
What this means: EzStaw is not for under-18s.
You must be 18 to hold an EzStaw account. We do not knowingly collect information from children. If you believe a child's information has reached us, write to us and we will delete it.
11. Changes
What this means: we will tell you before anything important changes.
We update this policy as the product changes. For a change that meaningfully affects what we do with your information, we will email the address on your account before it takes effect. The version and date at the top tell you which text you are reading.
12. Contacting us
What this means: here is where to write about your data.
TODO(legal): confirm the addresses below before publishing.
- Privacy and data requests: TODO(legal): privacy address
- Everything else: TODO(legal): support address
- Post: TODO(legal): registered office address
PeekTower Limited, trading as EzStaw. Registered in Sierra Leone.
Also on this site
Questions about this page? Get in touch through the contact form. For how EzStaw protects payments and data, see Trust & security.
EzStaw is an e-commerce platform owned and operated by PeekTower Limited, a company registered in Sierra Leone.
