Legal
Privacy Policy
How we collect, use, and protect your personal data — in plain language. Last updated: 16 December 2024
In Short
- • We only collect data we genuinely need.
- • We never sell your data.
- • You can access, correct, or delete your data at any time.
- • We use industry-standard security to protect what we hold.
- • For any privacy question: info@amaniluxe.com
Who we are
For the purposes of GDPR and similar laws, the data controller is:
SAFIR TRADE GHANA LTD (trading as AMANI)
Registration No: CS204971224 · TIN: C0064911527
Email: info@amaniluxe.com
What we collect
We collect different categories of personal data depending on how you interact with us:
When you create an account:
- Name, email address, phone number (optional)
- Encrypted password (we cannot see it)
- Account creation date and login history
When you place an order:
- Billing and shipping address
- Payment confirmation (not card details — handled by our payment provider)
- Order history and tracking information
- Customs identification number, where required by destination country
When you contact us:
- The content of your message and any attachments
- Your contact details
When you browse the Site:
- IP address, browser type, device type, operating system
- Pages visited, time spent, referring sites
- Cookies (see our Cookie Policy for details)
Why we use your data
We process personal data only for clearly defined purposes:
- To fulfil your order — process payment, manufacture if bespoke, ship, handle customs, manage returns. (Legal basis: contract)
- To manage your account — keep your order history, save your favourites, allow you to log in. (Legal basis: contract)
- To respond to your enquiries — answer questions you send us. (Legal basis: legitimate interest / contract)
- To send marketing communications — only if you have explicitly opted in. You can unsubscribe at any time. (Legal basis: consent)
- To comply with legal obligations — tax records, anti-money-laundering, customs declarations. (Legal basis: legal obligation)
- To protect against fraud — detect and prevent unauthorized transactions. (Legal basis: legitimate interest)
- To improve our service — anonymous analytics about how the Site is used. (Legal basis: legitimate interest)
Who we share data with
We share personal data only with carefully selected service providers, and only to the extent necessary for them to perform their function:
- Payment processors — to process your payment securely (Stripe, our virtual POS provider). They are independently certified to PCI-DSS standards.
- Couriers — DHL, FedEx, UPS for delivery. They receive only the data needed to ship and contact you about your delivery.
- Email service — to send order confirmations, shipping notifications, and (only if you opted in) marketing.
- Cloud infrastructure — our website and database run on secure cloud servers within the EU or Ghana.
- Analytics — anonymized usage data via cookies (see Cookie Policy).
- Legal & tax authorities — only when required by law.
We do not sell your personal data. Ever.
International transfers
Because we are based in Ghana but serve customers worldwide, your data may be transferred outside the country you live in. When we transfer personal data outside the EEA/UK, we ensure adequate safeguards are in place — typically Standard Contractual Clauses approved by the European Commission, or transfers to countries with an adequacy decision.
How long we keep your data
We retain personal data only as long as necessary:
- Account data: until you delete your account
- Order records: 10 years (tax law requirement)
- Marketing consent: until you withdraw it
- Contact form submissions: 2 years
- Anonymous analytics: 26 months
Your rights
Under GDPR (and similar laws in your country), you have the following rights:
- Right of access — request a copy of the personal data we hold about you
- Right to rectification — correct inaccurate or incomplete data
- Right to erasure ("right to be forgotten") — request deletion of your data
- Right to restriction — limit how we use your data
- Right to portability — receive your data in a structured, machine-readable format
- Right to object — to processing based on legitimate interest or for marketing
- Right to withdraw consent — at any time, where processing is based on consent
- Right to lodge a complaint — with your local data protection authority
To exercise any of these rights, email info@amaniluxe.com. We will respond within 30 days. We may ask you to verify your identity before acting on a request.
Security
We protect your data with industry-standard measures:
- HTTPS encryption on every page of the Site
- Passwords stored using bcrypt (one-way hashing — we cannot read them)
- Card details never stored on our servers
- Access to personal data restricted to authorized staff only
- Regular security audits and monitoring
No system is perfectly secure. If a breach occurs that may put your rights at risk, we will notify you and the relevant authority within 72 hours, as required by GDPR.
Children
Our Site is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you become aware that a child has provided us with personal data, contact us and we will delete it.
Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email to account holders or by a notice on the Site. The "Last updated" date at the top reflects the current version.
Contact & complaints
For any privacy-related question or request:
SAFIR TRADE GHANA LTD
Trading as AMANI
Email: info@amaniluxe.com
If you are in the EU/EEA and believe we have mishandled your personal data, you have the right to lodge a complaint with your national data protection authority. A list of authorities is available at edpb.europa.eu/about-edpb/board/members_en.