Privacy Policy
At Source Grid, we are committed to protecting your privacy and handling your personal information with care and transparency. This Privacy Policy explains how we collect, use, store, and protect your information when you use our agricultural sourcing platform.
1. About Source Grid
Source Grid is an agricultural sourcing platform operated in Kenya. We connect Kenyan agricultural producers with buyers both in Kenya and worldwide, facilitating the trade of coffee, tea, nuts, honey, spices, herbs, fresh and dried fruits, vegetables, superfoods, seeds, oils, flowers and other natural agricultural ingredients.
- Platform Type: Agricultural sourcing platform, covering both export orders and local Kenyan orders
- No Customer Accounts: You do not need to register, create a password, or log in to submit an inquiry or place a sourcing request. Everything a customer needs is done through our forms and through secure links we email to you
- Staff Accounts: Our own administrators and employees do have password-protected accounts, used only to manage orders and inquiries internally. These are not available to the public and are described in Section 6
- Primary Users: International buyers, Kenyan buyers, and Kenyan agricultural suppliers
2. Information We Collect
We collect information mainly through voluntary form submissions on our website. We do not operate any advertising, profiling, or cross-site tracking of our own.
2.1 Export Order Requests
When you submit an international sourcing request through our booking form, we collect:
- Personal Information: Full name, company name (optional), email address, phone number, country, city, and delivery location
- Order Details: Products requested (name, quantity, unit), preferred delivery method (sea, air or road), payment method preference (telegraphic transfer, letter of credit, cash on delivery, online payment, M-PESA or bank transfer), preferred delivery date, and any additional notes you provide
- Privacy Consent: Confirmation that you accept this privacy policy. The form cannot be submitted without it
- Purpose: To process your sourcing request, prepare a quote, and arrange fulfilment and shipping
2.2 Local (Kenya) Order Requests
Our local sourcing form serves customers ordering within Kenya, and collects a slightly different set of details:
- Personal Information: Full name, company name (optional), email address, and phone number
- Delivery Location: County, town, and delivery address
- Order Details: Products requested (category, product, quantity, unit), delivery method (standard delivery, express delivery, or self-collection), payment method preference (M-PESA, bank transfer, cash on delivery, or cheque), preferred delivery date, and any additional notes
- Privacy Consent: Confirmation that you accept this privacy policy. The form cannot be submitted without it
- Purpose: To process your local order, prepare a quote, and arrange delivery within Kenya
2.3 Contact Inquiries
When you submit a contact inquiry (supplier or buyer connection), we collect:
- Personal Information: Full name, company name (optional), email address, phone number (optional)
- Business Information: Your role (supplier or buyer), area of interest, and message content
- Privacy Consent: Confirmation that you accept this privacy policy. The form cannot be submitted without it
- Purpose: To facilitate sourcing connections and respond to your inquiries
2.4 General Inquiries
When you submit a general inquiry through our contact form, we collect:
- Personal Information: Name, email address, phone number (optional)
- Inquiry Information: Subject and message content
- Privacy Consent: Confirmation that you accept this privacy policy. The form cannot be submitted without it
- Purpose: To respond to your questions and provide information about our services
2.5 Job Applications
If you apply for an advertised position through our careers page, we collect:
- Personal Information: First name, middle name (optional), last name, email address, phone number
- Professional Information: Role of interest, your CV or resume as an uploaded PDF or Word document (maximum 5 MB), and your LinkedIn profile URL (optional)
- Purpose: To evaluate your application and contact you about the position
- Note on Confirmation Emails: Applications are recorded and reviewed, but the platform does not currently send an automatic acknowledgement email for job applications. We will contact you directly. See Section 5.3
2.6 Technical and Security Information
We collect a limited amount of technical information, some of it retained as a security record:
- Session Cookie: An encrypted Laravel session cookie used for form functionality and CSRF protection. See Section 8
- Server Logs: IP addresses, browser type, and access times are written to application log files. On our live site these rotate daily and are kept for 14 days before being deleted automatically. They are used for security monitoring and troubleshooting
- Order Update Audit Trail: When you open or use one of the secure order-update links we email you, we record the IP address and browser user-agent of that visit, along with what was changed, as a stored record against your order. This is a deliberate security measure: because these links are not password-protected, the audit trail is how we can tell you who changed your order and when. Unlike server logs, these records are retained alongside the order itself
- Staff Access Records: When an administrator or employee requests access to a staff panel, we record the email address used and the IP address that made the request
- No Analytics of Our Own: We do not run Google Analytics, Facebook Pixel, or any comparable analytics or tracking script
- No Advertising Cookies of Our Own: We do not set any cookie for advertising, profiling, or marketing purposes. Please see Section 7.2 regarding the embedded map on our contact page, which is operated by Google
3. How We Use Your Information
We use the information you provide strictly for the purposes stated at collection:
3.1 Processing Your Requests
- Processing export orders and local Kenyan orders
- Preparing quotes, applying any promotional codes, and calculating delivery or shipping charges
- Matching buyers with appropriate agricultural suppliers
- Responding to inquiries and providing requested information
- Processing job applications and recruitment activities
3.2 Communication
- Sending confirmation and quote emails for orders and inquiries, delivered through our email provider, Brevo. Section 5 lists every email we send
- Sending you the secure links described in Section 4, so you can view your quote or update your order
- Contacting you regarding your sourcing requests, inquiries, or job applications
- Providing updates on order status and delivery arrangements
3.3 Internal Record Keeping
- Maintaining records of orders, quotes, contacts, and inquiries in our database
- Maintaining a consolidated customer record, so that repeat orders from the same email address can be linked together. Local and export records are kept separately
- Tracking order and quote status through their lifecycle, including fulfilment and payment confirmation
- Maintaining the security audit trail described in Section 2.6
3.4 Legal Compliance
- Complying with legal obligations under Kenyan law
- Protecting against fraud and unauthorized access
- Enforcing our Terms of Service
3.5 What We Do Not Do
We do not:
- Sell or rent your personal information to third parties
- Use your information for unsolicited marketing communications
- Share your data with advertisers or marketing companies
- Operate any tracking of your browsing behaviour across other websites
4. Secure Links We Email You
Because we do not ask customers to create accounts, we instead email you a secure link containing a long, randomly generated token. Anyone holding that link can view the page it addresses without a password. This is worth understanding clearly, because it affects how you should treat those emails.
- Quote Link: Lets you view your quote, and — for export orders only — accept or reject it
- Order View Link: Lets you view your local order
- Payment Link: Displays the payment details for an accepted quote. No payment is taken through this page. See Section 7.4
- Promotional Code Link: Lets you apply a promotional code to a quote
- Order Update Link: Lets you amend your order details. These links expire 30 days after your order is placed
Please do not forward these emails or share these links. Anyone who receives one can see the order information it addresses. Every use of an update link is recorded as described in Section 2.6. If you believe a link has been shared or misused, contact us and we will invalidate it.
5. Emails We Send You
When you give us your email address we use it to send the messages set out below, and nothing else. All of them are delivered through Brevo, as described in Section 7.1.
5.1 Emails About Your Order or Inquiry
- Acknowledgement: Confirming that we have received your export order, local order, contact inquiry or general inquiry, and giving you your reference
- Quote: Your quote for an export or local order, and any revised quote that replaces it
- Shipping and Delivery Charges: Confirmation of the shipping cost for an export order, or the delivery fee for a local order
- Promotional Codes: A promotional code issued to you by a member of our team, and confirmation once a code has been applied to your quote
- Payment Confirmation: Confirmation once a member of our team has recorded your payment against your order
- Update Confirmation: A summary of the changes made whenever you amend your order through an update link, so that an unexpected change is visible to you
- Replies From Our Team: Direct replies to your inquiry or messages about your order
5.2 Internal Copies
Each of the four form submissions listed in Section 2.1 to 2.4, and every self-service order update, also generates a copy to our own internal Source Grid business address, so that our team can act on it. That copy contains the same information you submitted. It is not sent to anyone outside Source Grid. Job applications are the exception: they generate no email at all, in either direction, and are read directly in our administrator panel.
5.3 What We Do Not Send
- No Marketing Mailing List: We do not operate one, and submitting a form does not add you to one. Every message listed in Section 5.1 relates to something you asked us for
- No Job Application Acknowledgement: The platform sends no automatic email when you apply for a position. Your application is recorded and reviewed, and we contact you directly
6. Staff Access to Your Data
Your information is visible internally only to authorised Source Grid staff, through two password-protected panels that are not accessible to the public:
- Administrator Panel: Full access to orders, quotes, customers, inquiries and job applications, including uploaded CVs
- Employee Panel: Restricted access. Employees see only the orders and inquiries assigned to them, and cannot delete records
- Two-Step Sign In: Neither panel's login page can be reached directly. A staff member must first request access, receive a single-use link by email, and follow it. That link expires after 30 minutes and each address is limited to five requests per hour
- Password Security: Staff passwords are stored as bcrypt hashes and are never stored or recoverable in readable form
- Rate Limiting: Login attempts are rate limited to slow down automated guessing
7. Third-Party Services
We use a small number of third-party services to operate our platform. Two of them are contacted directly by your browser, which means they can see your IP address when you visit our site.
7.1 Brevo (Email Delivery)
- Purpose: Delivering confirmation emails, quotes, order updates and staff access links over SMTP
- Data Shared: Your email address, your name, and the content of the message we send you
- Operated By: Sendinblue SAS, based in France. This means our outgoing email is processed within the European Union. See Section 11
- Privacy Policy: Brevo Privacy Policy
7.2 Google Maps (Contact Page Only)
- Purpose: Displaying an embedded map of our location on the contact page
- What This Means: The map is loaded from Google's servers by your browser. Google therefore receives your IP address and may set its own cookies, over which we have no control. This happens only on the contact page, and the map is loaded lazily, so it is not requested until that part of the page is reached
- Privacy Policy: Google Privacy Policy
7.3 jsDelivr (Content Delivery Network)
- Purpose: Serving two open-source JavaScript libraries used for pop-up dialogs and form submission
- What This Means: Your browser fetches these files from jsDelivr, which therefore receives your IP address. jsDelivr is a public code CDN and is not an advertising or analytics service. All of our fonts, icons and stylesheets are served from our own servers, not from any third party
- Privacy Policy: jsDelivr Privacy Policy
7.4 What We Do Not Use
- Google Analytics or any comparable analytics service
- Facebook Pixel or social media tracking scripts
- Advertising networks, retargeting or remarketing services
- Online payment processors. We record which payment method you prefer, but no card, bank or M-PESA credentials are ever collected or processed through this website. Payment is arranged directly with our team
- Third-party cloud storage for your personal data. Uploaded CVs are stored on our own server, outside the publicly accessible area of the website
8. Cookies
Our own use of cookies is minimal and strictly functional:
8.1 Essential Cookies (Required)
- Laravel Session Cookie: Maintains your session while you use the website. It is encrypted, marked HTTP-only so that scripts cannot read it, and set to SameSite=Lax. On our live site it is also marked Secure, so it is only ever sent over HTTPS
- Session Lifetime: The session expires after 120 minutes of inactivity. It is not cleared simply because you close your browser
- CSRF Token: Protects form submissions against cross-site request forgery
- Purpose: These are strictly necessary for the website to function and cannot be disabled
8.2 No Marketing or Analytics Cookies
We do not set any cookie of our own for:
- Tracking your browsing behaviour
- Building advertising profiles
- Sharing data with advertisers
- Retargeting or remarketing campaigns
The one exception we cannot control is the embedded Google map on our contact page, which may set cookies belonging to Google. This is described in Section 7.2.
9. Data Storage, Security and Retention
9.1 Where We Store Your Data
- Database: A MySQL database on our hosting account, not publicly reachable
- File Storage: Uploaded CVs are stored on our server's private disk, deliberately outside the web-accessible area, and can only be downloaded from within the administrator panel
- Email Delivery: Outgoing messages are relayed through Brevo, as described in Section 7.1
9.2 Security Measures
- Encryption in Transit: The live site is served over HTTPS with TLS. HTTP requests are redirected to HTTPS, and we send an HSTS header instructing browsers to use HTTPS only
- Encrypted Session Cookie: Session cookies are encrypted, HTTP-only and SameSite-restricted
- CSRF Protection: All form submissions carry a CSRF token, so a third-party site cannot submit a form on your behalf
- Content Security Policy: A strict policy restricts which sources the browser may load scripts, styles, fonts and frames from, which limits the damage any injected content could do
- Access Control: Staff access is restricted as described in Section 6
- Password Security: Staff passwords are stored as bcrypt hashes
- Input Validation: All form input is validated and escaped, protecting against SQL injection and cross-site scripting
- Rate Limiting: Form submissions, file uploads, quote responses and login attempts are all rate limited to resist automated abuse
- Regular Updates: We keep the Laravel framework and its dependencies patched
No system can be guaranteed completely secure, but we take these measures seriously and review them as the application changes.
9.3 Data Retention
We want to be precise here, because "deleted" means two different things in our system:
- Business Records Are Not Deleted Automatically: Orders, quotes, customer records, contacts, inquiries and job applications are never removed by any automated process. They are removed only when a member of our staff removes them, or when you ask us to
- Deletion Happens in Two Stages: When a record is deleted, it is first moved to an internal recoverable area, where it retains all its information and can be restored. It is erased from the database only when it is then permanently deleted
- Automatic Clearing of the Recoverable Area Is Currently Switched Off: Nothing is currently removed from it on its own. If we enable this in future, we will update this policy first
- Paid Orders Are Exempt From Automatic Clearing: Even if we do enable it, our automatic clean-up will never remove a quote recorded as paid, nor the order attached to it. Records of confirmed payments can only ever be removed deliberately by an administrator
- Routine Automated Clean-Up: A nightly maintenance task removes only the system's own leftovers — expired cache entries, timed-out sessions, records of failed emails older than one week, and abandoned partial file uploads. It never touches business records
- Accounting and Legal Records: Where we are required to retain an order or payment record to meet a legal, tax or accounting obligation, we will retain it for as long as that obligation requires, even after a deletion request
- Your Right to Erasure: You may ask us to permanently erase your data at any time. See Section 10.3
10. Your Rights and Choices
You have the following rights regarding your personal information:
10.1 Right to Access
- You may request a copy of the personal information we hold about you
- We will provide this information in a commonly used electronic format
10.2 Right to Correction
- If your information is inaccurate or incomplete, you may request corrections
- We will update your information promptly upon verification
- For an active order, you can often make these changes yourself using the update link we emailed you, within 30 days of placing the order
10.3 Right to Deletion
- You may request deletion of your personal information at any time
- On request we will carry out a permanent erasure, not merely the first, recoverable stage described in Section 9.3
- We may retain records where we have a legal, tax or accounting obligation to do so, and we will tell you if that applies to your request
- Deletion may prevent us from fulfilling any order that is still in progress
10.4 Right to Object
- You may object to certain processing of your personal information
- You may opt out of email communications by contacting us
10.5 Right to Data Portability
- You may request your data in a structured, machine-readable format
- We will provide your data in JSON or CSV format upon request
10.6 How to Exercise Your Rights
To exercise any of these rights, please contact us at:
Email: privacy@sourcegrid.co.ke
Subject Line: "Privacy Rights Request"
Response Time: We will respond to your request within 30 days
11. International Data Transfers
Source Grid operates in Kenya, and your information is stored and processed in Kenya. If you are accessing our platform from outside Kenya, your information will be transferred to Kenya for processing.
In addition, two categories of data leave Kenya as a normal part of running the site:
- Email: Messages we send you are relayed through Brevo, operated by Sendinblue SAS in France, and are therefore processed within the European Union
- Your IP Address: Google and jsDelivr receive your IP address when your browser loads the embedded map or the shared JavaScript libraries, as described in Sections 7.2 and 7.3
By using our platform and submitting your information, you consent to these transfers. We work to ensure appropriate safeguards are in place in accordance with this Privacy Policy and applicable data protection law.
12. Children's Privacy
Source Grid is a business-to-business agricultural sourcing platform. We do not knowingly collect personal information from individuals under the age of 18. Our services are designed for agricultural producers, suppliers, and buyers, and our Terms of Service require you to be at least 18 to use them.
If you believe we have inadvertently collected information from a minor, please contact us immediately, and we will delete such information promptly.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or platform features. When we make changes:
- We will update the "Last Updated" date at the top of this policy
- If the changes are significant, we will notify users by email, where we hold an email address, or by a prominent notice on our website
- Your continued use of our platform after changes constitutes acceptance of the updated policy
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
14. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), we process your personal information under the following legal bases:
- Consent: You have given explicit consent for processing your information. Each of our four public forms — the export booking form, the local sourcing form, the contact form and the general inquiry form — carries a privacy checkbox that must be ticked before the form can be submitted
- Contract Performance: Processing is necessary to fulfil the order or sourcing request you have submitted
- Legitimate Interest: Processing is necessary for our legitimate business interests — responding to inquiries, maintaining the security audit trail described in Section 2.6, and improving our services — while respecting your privacy rights
- Legal Obligation: Processing is required to comply with legal obligations under applicable laws
15. Data Breach Notification
In the event of a data breach that compromises your personal information, we will:
- Notify affected individuals without undue delay, and within 72 hours of becoming aware of the breach wherever that is possible
- Inform you of the nature of the breach, the types of data affected, and the potential consequences
- Describe the measures we are taking to address the breach and prevent a recurrence
- Provide guidance on steps you can take to protect yourself
- Report the breach to the relevant authorities as required by law
16. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Source Grid - Data Privacy Team
Nairobi, Kenya
Privacy Requests: privacy@sourcegrid.co.ke
General Inquiries: info@sourcegrid.co.ke
You may also reach us through our contact page.
We are committed to working with you to resolve any privacy concerns in a timely and transparent manner.
17. Governing Law
This Privacy Policy and our data processing practices are governed by the laws of Kenya, including the Kenya Data Protection Act, 2019. Any disputes arising from this policy will be resolved in accordance with Kenyan law and jurisdiction.
Your use of this platform is also governed by our Terms of Service.